{"message":"Missing Authentication Token"} / No authorization token was found
The request reached a protected endpoint without credentials — or, on AWS API Gateway, it hit a path/method that doesn’t exist.
Meaning
Two very common sources share this wording. AWS API Gateway returns 403 {"message":"Missing Authentication Token"} for any request to a resource or method it doesn’t have — usually a wrong path, stage or method, not a credentials problem. Express-jwt and similar middleware return 401 “No authorization token was found” when the Authorization header is missing.
In the second case the token often exists in the client but isn’t sent: wrong header name, a CORS preflight stripping it, a proxy dropping it, or an HTTP→HTTPS redirect that discards headers.
Common causes
- API Gateway: wrong path, stage name or method, or the API wasn’t redeployed
- Authorization header not added by the client/interceptor
- Header stripped by a proxy, redirect or CORS configuration
- Token stored under a different name (cookie vs header)
- Using "Token x" when the server expects "Bearer x"
⚡ Quick fix
- API Gateway: check the full invoke URL (stage + resource + method) and redeploy the stage
- Send Authorization: Bearer <token> and confirm it in the network tab
- Call the final https URL directly to avoid redirects
Detailed fix by platform
AWS CLI
- bash
aws apigateway get-resources --rest-api-id abc123 --query 'items[].{path:path,methods:resourceMethods}' aws apigateway create-deployment --rest-api-id abc123 --stage-name prod
Node.js
- javascript
// the scheme word matters: Bearer, not Token await fetch(url, { headers: { Authorization: 'Bearer ' + token } });
Nginx
proxy_set_header Authorization $http_authorization; # make sure the proxy forwards it
How to diagnose
- Gateway — Does the path + method exist in the deployed stage?
- Header — Is Authorization present in the outgoing request?
- Redirects — Any 301/302 before the API?
- Scheme — Bearer vs Token vs Basic
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Report a correction or suggest an improvement
Last updated 7 Oct 2026