Skip to main content
err:unkey:authentication:portal_token_missing
You called a portal endpoint with an empty portal_session cookie. You get HTTP 400.
Example response

Likely causes

  • The session flow didn’t finish, so there’s no token to send.
  • The cookie was lost, for example across a redirect.
Portal endpoints such as portal.listKeys, portal.rerollKey, and portal.getVerifications use the access token from portal.exchangeCode in the portal_session cookie, not a root key. A request with no cookie at all returns err:unkey:application:invalid_input. A token that’s unknown, expired, or revoked returns err:unkey:authentication:portal_session_not_found.

How to fix

  1. Finish the session flow: your backend calls portal.createSession with a root key to get an exchange code, and the user’s browser calls portal.exchangeCode with it to get the access token.
  2. Send that token in the portal_session cookie on every portal request. If the browser calls the portal API directly, make sure the cookie is set after the exchange and survives redirects.
  3. Don’t send the token as Authorization: Bearer. Portal endpoints ignore the cookie when an Authorization header is present, and you get err:unkey:authentication:missing.
Last modified on October 6, 2026