All questions

Getting "Invalid credentials" calling the API even though my key is set

Asked by arjun on

Aarjun

My server call to the Croct API keeps coming back with:

Invalid credentials

I am certain the key is set. It is in the environment, I logged it (masked) at startup, and the value matches what the dashboard shows. So the key is present and being read, yet the API rejects it.

What actually triggers that error, and how do I confirm whether the key is being sent and accepted correctly rather than just assuming the env var is the whole story?

Was this helpful?

2 answers

PRPriya RamanAccepted answer

"Invalid credentials" is not only about the value. The API authenticates with the X-Api-Key header, and it returns that error when the key is missing, wrong, or lacks the permission the call needs. Since you have confirmed the value is present and correct, the third case is the usual culprit.

The specific one that catches people: issuing user tokens server-side requires the key to have the "Issue user tokens" permission. A key created without it looks completely valid, sits in the right env var, and still fails auth for exactly this kind of call. Check the key's permissions in the workspace, not just the env var. Same root cause is walked through in fetchContent works locally but returns auth errors in prod.

Was this helpful?
Mmartin_ok

To confirm what is actually happening rather than guessing, read the response body. Croct returns errors as RFC 9457 problem+json, so the body has a title/detail describing the exact problem instead of just the generic string your client surfaced. Log the raw response once and it will tell you whether it is a bad key or a permission gap. There is a rundown of the error envelope in What error format does the Croct HTTP API return?.

Was this helpful?
Aarjun

It was the permission. The key was missing "Issue user tokens", added it and the calls go through now. The problem+json body said as much once I stopped swallowing it, lesson learned.

Still have questions?