JsonWebTokenError: jwt must be provided
jwt.verify() was called with an empty value — the token never reached the server code.
Seen on:
REST API
Meaning
The Authorization header is missing, the Bearer prefix wasn’t stripped correctly, the cookie name differs, or the frontend sent "Bearer undefined".
Common causes
- Authorization header missing (CORS preflight, proxy)
- Splitting "Bearer x" incorrectly
- Token stored under a different key/cookie
- Frontend sending undefined/null
⚡ Quick fix
- Return 401 when no token is present instead of calling verify
- Parse the header safely
- Log what the client actually sends
Detailed fix by platform
JavaScript
- `const auth = req.headers.authorization
- ""; const token = auth.startsWith("Bearer ") ? auth.slice(7) : null; if (!token) return res.status(401).json({ error: "missing token" }); jwt.verify(token, secret);`
How to diagnose
- Header — Present?
- Value — "Bearer undefined"?
- Storage — Client-side key
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- AADSTS50076 Azure AD (Entra ID): AADSTS50076 / AADSTS50079 — multi-factor authentication required
- AADSTS50126 AADSTS50126: Error validating credentials due to invalid username or password
- auth/invalid-credential Firebase Auth: auth/invalid-credential (auth/wrong-password, auth/user-not-found, auth/invalid-login-credentials)
Most viewed in Authentication
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026