Skip to main content
← Back to list
01Issue
BugOpenSwamp ClubPublic
AssigneesNone

Relationships

#2564 swamp-club: unknown collective API token returns 422 instead of the documented 404

Opened by skunk-ape · 9/26/2026

swamp-club answers an unknown collective API token id with 422, but its own API spec says 404.

Observed (swamp-club 79b28281)

DELETE /api/v1/collectives/<c>/api-tokens/<unknown-id> (and PATCH on the same route) returns:

HTTP 422
{"error":"Token not found"}

The route's only 404 is for an unknown collective slug ({"error":"Not found"} from the collectiveRepo.findBySlug check).

Cause

  • deleteCollectiveApiToken and revokeCollectiveApiToken in lib/app/collective-api-token-commands.ts throw CollectiveApiTokenInvariantError("Token not found") when the token is missing or belongs to another collective. That error class also carries genuine invariant violations, such as invalid names or scopes.
  • routes/api/v1/collectives/[slug]/api-tokens/[tokenId].ts maps every CollectiveApiTokenInvariantError to 422, so "not found" can't be told apart from "invalid".
  • lib/app/api-spec.ts documents 200 / 401 / 404 for both patch and delete on /api/v1/collectives/{slug}/api-tokens/{tokenId}, with no 422.
  • Other features model this separately (ExtensionNotFoundError, PromoteVersionNotFoundError).

Impact

A client that follows the spec gets it wrong. The swamp CLI assumed that 404 meant token not found. As a result, an unknown token shows a raw Failed to revoke collective token (HTTP 422): {"error":"Token not found"}, and an unknown collective is misreported as Token "x" not found in collective "...". Found while fixing lab #2555.

Suggested fix

Add a dedicated not-found error (e.g. CollectiveApiTokenNotFoundError) and map it to 404 in both handlers, so the code matches the spec. Keep answering a token id that exists in a different collective exactly like a missing one, so token ids can't be probed across collectives. The body can stay {"error":"Token not found"}, which lets a client tell an unknown token from an unknown collective ({"error":"Not found"}).

Changing 422 to 404 changes what swamp CLI users see: the unknown-token case would move from the generic HTTP 422 message to the CLI's 404 message. Coordinate with a swamp-side follow-up to the error mapping in revokeCollectiveToken.

02Bog Flow
◉OPEN○TRIAGED○IN PROGRESS○SHIPPED

Open

9/26/2026, 2:27:30 AM

No activity in this phase yet.

03Sludge Pulse
Editable. Press Enter to edit.

system commented 9/26/2026, 2:27:30 AM

Classified automatically when this issue was filed.

  • Source: Swamp Club

If you feel this classification is incorrect, add a ripple to tell us so.

Sign in to post a ripple.