diff --git a/docs/api/authentication.md b/docs/api/authentication.md index 69c7006b..0c588662 100644 --- a/docs/api/authentication.md +++ b/docs/api/authentication.md @@ -222,7 +222,7 @@ withdraw_balance(old_key) - Typo in API key - The credential is neither an `sk-...` key nor a `cashu...` token -A well-formed `sk-...` key that this node has no record of is reported +A credential starting with `sk-` that this node has no record of is reported separately as `key_not_found` (also 401) — see [Error Handling → Authentication Errors](errors.md#authentication-errors). diff --git a/docs/api/errors.md b/docs/api/errors.md index f87e802f..15dcd0b1 100644 --- a/docs/api/errors.md +++ b/docs/api/errors.md @@ -119,10 +119,10 @@ Returned when the `Authorization` value is neither an `sk-...` API key nor a preview and length (`Invalid API key format: preview=… length=…`) to distinguish a typo from a wrong-shaped header. -#### API Key Not Found (well-formed but unknown to this node) +#### API Key Not Found (`sk-` key unknown to this node) -Returned when the credential is a well-formed `sk-...` key that this node has no -record of — for example a key minted by a different Routstr node, or one removed +Returned when the credential starts with `sk-` and this node has no record of +it — for example a key minted by a different Routstr node, or one removed by key pruning. This is *not* a formatting problem. ```json diff --git a/routstr/auth.py b/routstr/auth.py index bb3f00f8..885b0ab9 100644 --- a/routstr/auth.py +++ b/routstr/auth.py @@ -293,12 +293,6 @@ async def _validate_bearer_key_locked( "sk- API key not found in database", extra={"key_preview": bearer_key[:10] + "..."}, ) - # The credential is a well-formed 'sk-...' API key: the format is - # valid and the failure is that the key does not exist on this node. - # Falling through to the generic handler below would report it as - # "Invalid API key format", sending callers after a formatting bug - # that does not exist. Report the real cause instead. - # # Keep the "Key not found." prefix verbatim: @routstr/sdk (<=0.4.6) # detects a dead key with a case-sensitive `body.includes("Key not # found")` probe, and uses it to purge the key from its store. The