invalid_token
- HTTP status
- 401 Unauthorized
- Returned by
- OAuth for apps
What it means
The OAuth access token (kwk_at_…) is not valid: it is unknown, expired, revoked, or its installation was removed.
Typical causes
- Access tokens live for 1 hour.
- The workspace uninstalled the app.
- A rotated refresh token was used twice, which revokes the whole installation.
How to fix it
- Refresh the token with your refresh token (
grant_type=refresh_token) and retry once. - If refreshing fails, send the user through the OAuth flow again. See OAuth for apps.
Message
English text, as sent with Accept-Language: en. With ru or uz the API sends the translation.
- The access token is invalid, expired or revoked.
RU: Токен доступа недействителен, просрочен или отозван.
UZ: Kirish tokeni notoʻgʻri, muddati oʻtgan yoki bekor qilingan.
Example response
Response
HTTP/1.1 401 Unauthorized
Content-Type: application/json; charset=utf-8
X-Request-Id: req_4f2a9c1e0b7d3a55
{
"error": {
"code": "invalid_token",
"message": "The access token is invalid, expired or revoked.",
"request_id": "req_4f2a9c1e0b7d3a55",
"docs_url": "https://developers.kweko.uz/errors/invalid_token"
}
}