err:unkey:authentication:portal_token_missingportal_session cookie. You get HTTP 400.
Example response
Likely causes
- The session flow didn’t finish, so there’s no token to send.
- The cookie was lost, for example across a redirect.
portal.listKeys, portal.rerollKey, and portal.getVerifications use the access token from portal.exchangeCode in the portal_session cookie, not a root key. A request with no cookie at all returns err:unkey:application:invalid_input. A token that’s unknown, expired, or revoked returns err:unkey:authentication:portal_session_not_found.
How to fix
- Finish the session flow: your backend calls
portal.createSessionwith a root key to get an exchange code, and the user’s browser callsportal.exchangeCodewith it to get the access token. - Send that token in the
portal_sessioncookie on every portal request. If the browser calls the portal API directly, make sure the cookie is set after the exchange and survives redirects. - Don’t send the token as
Authorization: Bearer. Portal endpoints ignore the cookie when anAuthorizationheader is present, and you geterr:unkey:authentication:missing.
Related errors
err:unkey:authentication:portal_session_not_found: the token is present but not an active session.err:unkey:authentication:missing: a portal endpoint was called with anAuthorizationheader instead of the cookie.