invalid_token 🔐 Authentication

invalid_token: The access token is invalid (JsonWebTokenError: invalid signature / jwt malformed)

A token was sent but the server couldn’t verify it — bad signature, malformed, revoked, or issued for another audience or environment.

Seen on: REST API

Meaning

OAuth 2.0 resource servers answer 401 with WWW-Authenticate: Bearer error="invalid_token". JWT libraries are more specific: “invalid signature” (signed with a different secret/key), “jwt malformed” (not three base64url parts — often the literal string "undefined" or a token with "Bearer " still attached), “invalid audience/issuer” (minted for another API or tenant).

Expiry is a separate case — see TokenExpiredError.

Common causes

  • Verifying with a different secret or public key than the issuer used (env mismatch, key rotation)
  • Token is malformed: "undefined", quotes, or the "Bearer " prefix included
  • Audience/issuer doesn’t match this API
  • Token revoked or the session logged out
  • ID token sent where an access token is required

⚡ Quick fix

  1. Decode the token (jwt.io / base64) and compare iss, aud, kid with the server config
  2. Strip the "Bearer " prefix before verifying
  3. Use the same secret/JWKS as the issuer, refreshed after key rotation
  4. Get a new token

Detailed fix by platform

Node.js

  1. javascript
    const raw = req.headers.authorization?.replace(/^Bearer\s+/i, '');
    const payload = jwt.verify(raw, publicKey, { algorithms: ['RS256'], audience: 'api://orders', issuer: 'https://auth.example.com/' });

Python

  1. jwt.decode(token, key, algorithms=["RS256"], audience="api://orders") # PyJWT: InvalidSignatureError / InvalidAudienceError

How to diagnose

  1. Decode — iss, aud, kid, exp in the token
  2. Key — Which secret/JWKS is the server using?
  3. Format — Exactly what string reaches verify()?

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.