# invalid_key

Source: https://capacms.com/docs/errors/invalid_key

401 authentication. The key is unknown, revoked or expired.

| HTTP status | `type`           | Surfaces      |
| ----------- | ---------------- | ------------- |
| 401         | `authentication` | REST, GraphQL |

## What it means

The key is unknown, revoked or expired.

| When                            | What the `hint` tells you                                                       |
| ------------------------------- | ------------------------------------------------------------------------------- |
| unknown, revoked or expired key | no hint on REST: check the key's expiry and active flag under Developers > Keys |

## What to do

Use a current key from Developers > Keys in the Capa admin. The answer is the same for an unknown, revoked or expired key, so read the key's row there rather than the body.

## The response

HTTP 401:

```json
{
  "error": {
    "type": "authentication",
    "code": "invalid_key",
    "message": "This API key is not valid.",
    "docs": "https://docs.capacms.com/errors/invalid_key"
  },
  "meta": {
    "version": "2026-10-01",
    "contract": 1,
    "requestId": "req_0f3c…"
  }
}
```

## On GraphQL

`/api/graphql` answers the same `code` inside `errors[].extensions`. The status depends on the `Accept` header you send ([status codes](https://capacms.com/docs/api/graphql#status-codes)):

| `application/json` | `graphql-response+json` | When                                |
| ------------------ | ----------------------- | ----------------------------------- |
| 401                | 401                     | no key, or a key Capa does not know |

## See also

* [Keys and scopes](https://capacms.com/docs/api/authentication)
