Authentication and token diagnostics
Authentication and token diagnostics
This page covers diagnosis and recovery for API authentication failures: HTTP 401 Unauthorized, HTTP 403 Forbidden, token expiry, credential scope mismatches, and the common confusion between application credentials and EC2 (S3) credentials. Use this when API calls fail with authentication or authorization errors.
Quick diagnosis: 401 vs 403#
| HTTP status | Meaning | Most likely cause |
|---|---|---|
| 401 Unauthorized | Identity not established | Expired token, missing X-Auth-Token header, invalid credentials |
| 403 Forbidden | Identity established but action not permitted | Wrong project scope, insufficient role, quota exceeded |
Start with the 401 path if you cannot authenticate at all. Start with the 403 path if you can authenticate but specific operations fail.
401 Unauthorized: token and credential failures#
Symptom#
Any API call returns 401. The OpenStack CLI shows:
Unauthorized (HTTP 401)Or SDK/HTTP calls return:
{"error": {"message": "The request you have made requires authentication.", "code": 401}}Diagnosis#
Step 1: Test token issuance
openstack token issueIf this succeeds, your credentials are valid and a fresh token was issued. The original failure was likely a stale token in your environment.
If this fails with 401, your credentials are invalid or expired.
Step 2: Verify your environment
env | grep OS_Check that:
OS_AUTH_URLpoints to the correct Keystone endpointOS_PROJECT_NAMEorOS_PROJECT_IDis setOS_APPLICATION_CREDENTIAL_IDandOS_APPLICATION_CREDENTIAL_SECRETare set (if using app credentials)- No stale
OS_TOKENvariable overrides the credential flow
Step 3: Re-source your credentials
source openrc.sh
openstack token issueResolution#
Expired token: tokens have a limited lifetime (typically 1 hour). Re-source your credentials and retry:
source openrc.shStale environment: if you have multiple terminal sessions, each may have different credentials loaded. Source the correct openrc.sh in the session where you are working.
Invalid credentials: if openstack token issue fails even after re-sourcing:
- Verify the
openrc.shfile has not been modified or corrupted - Re-download your application credentials from the Quake AI console under Identity > Application Credentials
- Create new application credentials if the existing ones are compromised
Cached token override: if OS_TOKEN is set in your environment, unset it:
unset OS_TOKEN
openstack token issue403 Forbidden: scope and role failures#
Symptom (403 Forbidden: scope and role failures)#
Authentication succeeds (openstack token issue works) but specific operations fail with 403.
Diagnosis (403 Forbidden: scope and role failures)#
Step 1: Verify project scope
openstack token issue -c project_idCompare the returned project ID with the project that owns the resources you are trying to access.
Step 2: Check your assigned roles
The openstack role assignment list command requires the identity:list_role_assignments policy, which is reserved for identity administrators. Under an ordinary application credential it returns its own 403, so it cannot diagnose the error you are troubleshooting:
You are not authorized to perform the requested action: identity:list_role_assignments. (HTTP 403)To see the roles your credential carries, open the Quake AI console under Identity > Application Credentials. The console lists the roles each credential was created with, and the same roles appear when you create a credential.
Common roles and their permissions:
| Role | Permissions |
|---|---|
member | Create, read, update, delete project resources |
reader | Read-only access to project resources |
admin | Full administrative access (not assigned to regular users in normal operation) |
Step 3: Check quota. Some 403 errors indicate quota exhaustion:
openstack quota show --usageIf a resource is at its limit, the API returns 403 with a quota message rather than a role/scope message.
Resolution (403 Forbidden: scope and role failures)#
Wrong project scope: re-source with the correct project:
Verify your openrc.sh specifies the correct OS_PROJECT_NAME. If you work with multiple projects, create separate openrc.sh files for each.
Insufficient role: if you need a role upgrade, contact your project administrator.
Quota exhaustion: see quota and limits troubleshooting.
Credential type confusion: application credentials vs EC2 credentials#
This is the most common authentication issue for users working with both the OpenStack API and the S3-compatible object storage API.
| Application credentials | EC2 credentials | |
|---|---|---|
| Purpose | OpenStack API authentication (CLI, SDK, API) | S3-compatible object storage API |
| Create command | openstack application credential create | openstack ec2 credentials create |
| Stored in | openrc.sh or environment variables | AWS-style config or environment variables |
| Project scope | Yes, scoped to one project | Yes, scoped to one project |
Works with openstack CLI | Yes | No |
Works with aws s3 / boto3 | No | Yes |
Symptoms of using the wrong credential type#
| Scenario | Error |
|---|---|
Using application credentials with aws s3 | InvalidAccessKeyId (403) |
Using EC2 credentials with openstack CLI | Unauthorized (401) |
| Using EC2 credentials from project A to access containers in project B | AccessDenied (403) |
Resolution (credential type confusion: application credentials vs EC2 credentials)#
For OpenStack API access:
source openrc.sh
openstack token issueFor S3-compatible API access:
openstack ec2 credentials listIf no credentials appear, create them:
openstack ec2 credentials createThen configure your S3 client:
export AWS_ACCESS_KEY_ID="YOUR_ACCESS_KEY"
export AWS_SECRET_ACCESS_KEY="YOUR_SECRET_KEY"
export AWS_ENDPOINT_URL="RUMBLE_S3_ENDPOINT"Verification#
After resolving an authentication issue, verify with these tests:
OpenStack API:
openstack token issue
openstack server listS3-compatible API:
aws s3 ls --endpoint-url $RUMBLE_S3_ENDPOINTBoth commands should succeed without authentication errors.
Escalation signals#
Escalate to support when:
openstack token issuefails with 401 after downloading fresh application credentials from the console- A valid token (verified via
openstack token issue) is rejected by a specific service endpoint - EC2 credentials created moments ago fail with
InvalidAccessKeyIdimmediately - Your assigned roles (shown in the console under Identity > Application Credentials) look correct but 403 persists for operations the role should allow
Include in your ticket:
- The exact error message
- Output of
openstack token issue(the token ID, not the credential secret) - Project ID and user ID
- The specific operation that fails
See also#
Usage Guidelines
The sample code, software libraries, command line tools, proofs of concept, templates, and other related technology on this page (including any of the foregoing that is provided by Quake AI personnel) is provided to you as Quake AI Content under the Quake AI Customer Agreement, or the relevant written agreement between you and Quake AI (whichever applies). Do not use this Quake AI Content in your production accounts, or on production or other critical data. You are responsible for testing, securing, and optimizing the Quake AI Content (such as sample code) as appropriate for production grade use based on your specific quality control practices and standards. Deploying Quake AI Content may incur Quake AI charges for creating or using Quake AI chargeable resources, such as running Compute instances or storing data in Object Storage. Your use is also subject to the Acceptable Use Policy.
For the full policy, see Usage Guidelines.
Last validated: 19.06.2026
See Also
How to get an API token
Shares: Tokens, Authentication
API Access Console Reference
Shares: Authentication, Credentials
Application Credentials
Shares: Authentication, Credentials
How to create application credentials
Shares: Authentication, Credentials
IAM and identity on Quake AI
Shares: Authentication