invalid_key
401 authentication. The key is unknown, revoked or expired.
| HTTP status | type | Surfaces |
|---|---|---|
| 401 | authentication | REST, GraphQL |
What it means
The key is unknown, revoked or expired.
| When | What the hint tells you |
|---|---|
| unknown, revoked or expired key | no hint on REST: check the key's expiry and active flag under Developers > Keys |
What to do
Use a current key from Developers > Keys in the Capa admin. The answer is the same for an unknown, revoked or expired key, so read the key's row there rather than the body.
The response
HTTP 401:
{
"error": {
"type": "authentication",
"code": "invalid_key",
"message": "This API key is not valid.",
"docs": "https://docs.capacms.com/errors/invalid_key"
},
"meta": {
"version": "2026-10-01",
"contract": 1,
"requestId": "req_0f3c…"
}
}On GraphQL
/api/graphql answers the same code inside errors[].extensions. The status depends on the Accept header you send (status codes):
application/json | graphql-response+json | When |
|---|---|---|
| 401 | 401 | no key, or a key Capa does not know |