invalid_token: The access token is invalid (JsonWebTokenError: invalid signature / jwt malformed)
A token was sent but the server couldn’t verify it — bad signature, malformed, revoked, or issued for another audience or environment.
Meaning
OAuth 2.0 resource servers answer 401 with WWW-Authenticate: Bearer error="invalid_token". JWT libraries are more specific: “invalid signature” (signed with a different secret/key), “jwt malformed” (not three base64url parts — often the literal string "undefined" or a token with "Bearer " still attached), “invalid audience/issuer” (minted for another API or tenant).
Expiry is a separate case — see TokenExpiredError.
Common causes
- Verifying with a different secret or public key than the issuer used (env mismatch, key rotation)
- Token is malformed: "undefined", quotes, or the "Bearer " prefix included
- Audience/issuer doesn’t match this API
- Token revoked or the session logged out
- ID token sent where an access token is required
⚡ Quick fix
- Decode the token (jwt.io / base64) and compare iss, aud, kid with the server config
- Strip the "Bearer " prefix before verifying
- Use the same secret/JWKS as the issuer, refreshed after key rotation
- Get a new token
Detailed fix by platform
Node.js
- javascript
const raw = req.headers.authorization?.replace(/^Bearer\s+/i, ''); const payload = jwt.verify(raw, publicKey, { algorithms: ['RS256'], audience: 'api://orders', issuer: 'https://auth.example.com/' });
Python
jwt.decode(token, key, algorithms=["RS256"], audience="api://orders") # PyJWT: InvalidSignatureError / InvalidAudienceError
How to diagnose
- Decode — iss, aud, kid, exp in the token
- Key — Which secret/JWKS is the server using?
- Format — Exactly what string reaches verify()?
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Report a correction or suggest an improvement
Last updated 7 Oct 2026