jwt must be provided 🔐 Authentication

JsonWebTokenError: jwt must be provided

jwt.verify() was called with an empty value — the token never reached the server code.

Seen on: REST API

Meaning

The Authorization header is missing, the Bearer prefix wasn’t stripped correctly, the cookie name differs, or the frontend sent "Bearer undefined".

Common causes

  • Authorization header missing (CORS preflight, proxy)
  • Splitting "Bearer x" incorrectly
  • Token stored under a different key/cookie
  • Frontend sending undefined/null

⚡ Quick fix

  1. Return 401 when no token is present instead of calling verify
  2. Parse the header safely
  3. Log what the client actually sends

Detailed fix by platform

JavaScript

  1. `const auth = req.headers.authorization
  2. ""; const token = auth.startsWith("Bearer ") ? auth.slice(7) : null; if (!token) return res.status(401).json({ error: "missing token" }); jwt.verify(token, secret);`

How to diagnose

  1. Header — Present?
  2. Value — "Bearer undefined"?
  3. Storage — Client-side key

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.