Error reference

invalid_token

HTTP status
401 Unauthorized
Returned by
OAuth for apps

What it means

The OAuth access token (kwk_at_…) is not valid: it is unknown, expired, revoked, or its installation was removed.

Typical causes

  • Access tokens live for 1 hour.
  • The workspace uninstalled the app.
  • A rotated refresh token was used twice, which revokes the whole installation.

How to fix it

  • Refresh the token with your refresh token (grant_type=refresh_token) and retry once.
  • If refreshing fails, send the user through the OAuth flow again. See OAuth for apps.

Message

English text, as sent with Accept-Language: en. With ru or uz the API sends the translation.

  • The access token is invalid, expired or revoked.
    RU: Токен доступа недействителен, просрочен или отозван.
    UZ: Kirish tokeni notoʻgʻri, muddati oʻtgan yoki bekor qilingan.

Example response

Response
HTTP/1.1 401 Unauthorized
Content-Type: application/json; charset=utf-8
X-Request-Id: req_4f2a9c1e0b7d3a55

{
  "error": {
    "code": "invalid_token",
    "message": "The access token is invalid, expired or revoked.",
    "request_id": "req_4f2a9c1e0b7d3a55",
    "docs_url": "https://developers.kweko.uz/errors/invalid_token"
  }
}

All error codes · The error format