Skip to main content

Authentication Issues

Solutions for API authentication, token management, and credential problems.

Invalid API Key​

Symptoms​

  • 401 Unauthorized errors
  • "Invalid API key" messages
  • SDK initialization fails

Solutions​

1. Verify API Key Format​

// Correct format: alphanumeric string
const appKey = 'abc123def456...'; // Your actual key

// ❌ Common mistakes:
// - Extra spaces or quotes
// - Incomplete key (copied partially)
// - Using environment key instead of app key

2. Check Dashboard​

  1. Go to app.toggly.io
  2. Navigate to Settings → App Keys
  3. Copy the correct key
  4. Verify it matches your environment variable

3. Verify Environment Variables​

# Check if variables are set
echo $TOGGLY_APP_KEY
echo $TOGGLY_ENVIRONMENT

# For Node.js apps
node -e "console.log(process.env.TOGGLY_APP_KEY)"

SDK-Specific Configuration:


Token Invalidation Issues​

Token Already Invalidated​

If you receive "Token has been invalidated" errors:

  1. Sign out completely from all devices
  2. Clear browser cache and extension storage
  3. Sign in again to obtain a new token
  4. Verify logout process - ensure you're using the official sign out button

Token Not Invalidating on Logout​

If your token is not being invalidated when you sign out:

  1. Check network connectivity - the invalidation request requires internet
  2. Verify API endpoint - ensure the invalidation endpoint is accessible
  3. Check browser console for errors during logout
  4. Try signing out from the web interface instead of the extension

Chrome Extension specific:

  • Open Chrome DevTools (F12)
  • Navigate to the Console tab
  • Look for messages starting with [AuthService]
  • Check for any errors during the logout process

"No bearer token provided" Error​

If you see this error when trying to invalidate a token:

  • Cause: Authorization header is missing or malformed
  • Solution: Ensure your request includes Authorization: Bearer YOUR_TOKEN

Token Still Working After Logout​

If API requests succeed with a token that should be invalidated:

  1. Verify logout completed - check the logout API response
  2. Check token expiration - the token may have already expired naturally
  3. Clear all local storage - remnants may cause confusion
  4. Contact support if the issue persists

To verify token invalidation:

# Try using the token after logout
curl -H "Authorization: Bearer YOUR_OLD_TOKEN" \
https://app.toggly.io/api/v2/applications

# Expected response: 401 Unauthorized

Bearer Token Errors​

401 Unauthorized (API Requests)​

Cause: Invalid or missing Bearer token, expired token, or invalidated token

Solutions:

  1. Verify token is included in Authorization header:
curl -H "Authorization: Bearer YOUR_TOKEN" \
https://app.toggly.io/api/v2/applications
  1. Check if token is expired:

    • Tokens expire after 30 days of inactivity
    • Sign out and sign back in to get a new token
  2. Verify token wasn't invalidated:

    • If you signed out on another device, the token is invalidated
    • Obtain a new token by signing in
  3. Check for typos:

    • Ensure no extra spaces before or after the token
    • Verify you copied the complete token

Wrong Environment​

Symptoms​

  • Can't find feature flags that exist in dashboard
  • Flags work in one environment but not another
  • Seeing different behavior than expected

Solutions​

1. Verify Environment Key​

// Make sure you're using the right environment
const toggly = new TogglyClient({
appKey: 'your-app-key',
environment: 'development' // or 'staging', 'production', etc.
});

// Check what environment you're actually using
console.log('Current environment:', toggly.environment);

2. Check Dashboard​

  1. Click the environment selector in dashboard (top bar)
  2. Verify you're viewing the correct environment
  3. Confirm your feature flags are enabled in THIS environment

3. Environment Key vs App Key​

// ❌ Wrong - using environment key as app key
const toggly = new TogglyClient({
appKey: 'env-abc123', // This is an environment key!
environment: 'production'
});

// ✅ Correct - app key + environment name
const toggly = new TogglyClient({
appKey: 'app-abc123', // App key
environment: 'production' // Environment name
});

Permission Denied​

Symptoms​

  • 403 Forbidden errors
  • "Insufficient permissions" messages
  • Can't access certain features

Solutions​

1. Check Team Membership​

  1. Go to dashboard → Team Settings
  2. Verify you're a member of the correct team
  3. Check your role permissions

2. Verify Feature Access​

Some features are plan-restricted:

  • Check your subscription plan
  • Verify the feature is included in your plan
  • Contact your workspace administrator

3. Check Resource Ownership​

You can only modify:

  • Feature flags you created
  • Flags in teams you belong to
  • Flags where you have write permissions

SDK Installation Issues​

NPM/Yarn Installation Fails​

# Clear cache and retry
npm cache clean --force
npm install @ops-ai/feature-flags-toggly

# Or with yarn
yarn cache clean
yarn add @ops-ai/feature-flags-toggly

Package Not Found​

Verify package name is correct:

  • JavaScript: @ops-ai/feature-flags-toggly
  • React: @ops-ai/react-feature-flags-toggly
  • Angular: @ops-ai/ngx-feature-flags-toggly
  • Vue: @ops-ai/vue-feature-flags-toggly

Version Compatibility​

Check SDK version compatibility:

  • Node.js version requirements
  • Framework version requirements
  • TypeScript version (if applicable)

Still Need Help?​

Next Steps​

  1. Check Specific Troubleshooting:

  2. Check SDK-Specific Guide:

  3. Contact Support: