Relationships
#2564 swamp-club: unknown collective API token returns 422 instead of the documented 404
Opened by skunk-ape · 9/26/2026
swamp-club answers an unknown collective API token id with 422, but its own API spec says 404.
Observed (swamp-club 79b28281)
DELETE /api/v1/collectives/<c>/api-tokens/<unknown-id> (and PATCH on the same route) returns:
HTTP 422
{"error":"Token not found"}The route's only 404 is for an unknown collective slug ({"error":"Not found"} from the collectiveRepo.findBySlug check).
Cause
deleteCollectiveApiTokenandrevokeCollectiveApiTokeninlib/app/collective-api-token-commands.tsthrowCollectiveApiTokenInvariantError("Token not found")when the token is missing or belongs to another collective. That error class also carries genuine invariant violations, such as invalid names or scopes.routes/api/v1/collectives/[slug]/api-tokens/[tokenId].tsmaps everyCollectiveApiTokenInvariantErrorto 422, so "not found" can't be told apart from "invalid".lib/app/api-spec.tsdocuments200/401/404for bothpatchanddeleteon/api/v1/collectives/{slug}/api-tokens/{tokenId}, with no 422.- Other features model this separately (
ExtensionNotFoundError,PromoteVersionNotFoundError).
Impact
A client that follows the spec gets it wrong. The swamp CLI assumed that 404 meant token not found. As a result, an unknown token shows a raw Failed to revoke collective token (HTTP 422): {"error":"Token not found"}, and an unknown collective is misreported as Token "x" not found in collective "...". Found while fixing lab #2555.
Suggested fix
Add a dedicated not-found error (e.g. CollectiveApiTokenNotFoundError) and map it to 404 in both handlers, so the code matches the spec. Keep answering a token id that exists in a different collective exactly like a missing one, so token ids can't be probed across collectives. The body can stay {"error":"Token not found"}, which lets a client tell an unknown token from an unknown collective ({"error":"Not found"}).
Changing 422 to 404 changes what swamp CLI users see: the unknown-token case would move from the generic HTTP 422 message to the CLI's 404 message. Coordinate with a swamp-side follow-up to the error mapping in revokeCollectiveToken.
Open
No activity in this phase yet.
system commented 9/26/2026, 2:27:30 AM
Classified automatically when this issue was filed.
- Source: Swamp Club
If you feel this classification is incorrect, add a ripple to tell us so.
Sign in to post a ripple.