POST Request to Knowledge Base API Fails with 401 Unauthorized #20357

Closed
opened 2026-02-21 20:07:00 -05:00 by yindo · 3 comments
Owner

Originally created by @VoidWood on GitHub (Nov 16, 2025).

Self Checks

  • I have read the Contributing Guide and Language Policy.
  • This is only for bug report, if you would like to ask a question, please head to Discussions.
  • I have searched for existing issues search for existing issues, including closed ones.
  • I confirm that I am using English to submit this report, otherwise it will be closed.
  • 【中文用户 & Non English User】请使用英语提交,否则会被关闭 :)
  • Please do not modify this template :) and fill in all the required fields.

Dify version

1.10.0

Cloud or Self Hosted

Self Hosted (Docker)

Steps to reproduce

Image Image

Obtain a valid API key from the knowledge base service
Send a POST request to the knowledge base API endpoint
Include the API key in the Authorization header with format "Bearer API_KEY"
Observe the response status code

✔️ Expected Behavior

The API should return a 200 OK response with the requested data when a valid API key is provided.

Actual Behavior

The API returns a 401 Unauthorized error despite using a correct and valid API key.

Originally created by @VoidWood on GitHub (Nov 16, 2025). ### Self Checks - [x] I have read the [Contributing Guide](https://github.com/langgenius/dify/blob/main/CONTRIBUTING.md) and [Language Policy](https://github.com/langgenius/dify/issues/1542). - [x] This is only for bug report, if you would like to ask a question, please head to [Discussions](https://github.com/langgenius/dify/discussions/categories/general). - [x] I have searched for existing issues [search for existing issues](https://github.com/langgenius/dify/issues), including closed ones. - [x] I confirm that I am using English to submit this report, otherwise it will be closed. - [x] 【中文用户 & Non English User】请使用英语提交,否则会被关闭 :) - [x] Please do not modify this template :) and fill in all the required fields. ### Dify version 1.10.0 ### Cloud or Self Hosted Self Hosted (Docker) ### Steps to reproduce <img width="905" height="656" alt="Image" src="https://github.com/user-attachments/assets/d2da35df-3dd7-48da-80a0-2db8384029a1" /> <img width="909" height="651" alt="Image" src="https://github.com/user-attachments/assets/cb491c1c-89f7-49a0-97b7-f9101e423ee1" /> Obtain a valid API key from the knowledge base service Send a POST request to the knowledge base API endpoint Include the API key in the Authorization header with format "Bearer API_KEY" Observe the response status code ### ✔️ Expected Behavior The API should return a 200 OK response with the requested data when a valid API key is provided. ### ❌ Actual Behavior The API returns a 401 Unauthorized error despite using a correct and valid API key.
yindo added the 🐞 bug label 2026-02-21 20:07:00 -05:00
yindo closed this issue 2026-02-21 20:07:00 -05:00
Author
Owner

@dosubot[bot] commented on GitHub (Nov 16, 2025):

Hi @VoidWood! I'm Dosu and I’m helping the dify team.

There is an open issue tracking this exact problem, so it's a known issue in Dify 1.10.0 self-hosted via Docker. Recent changes in the codebase have introduced stricter validation of user context and permissions for API key operations, which could cause 401 errors if the API key is not associated with the correct tenant or lacks the required permissions.

In self-hosted Docker setups, 401 errors can also result from misconfigured or missing environment variables, especially those related to authentication or vector database services (like Weaviate). Double-check that all relevant environment variables (such as API keys, tenant IDs, and vector store configs) are correctly set and consistent across your containers. If you recently updated your Docker setup, make sure to restart all containers to apply any changes.

If your API key was generated before recent updates or changes to user/tenant validation, try generating a new API key and ensure it's scoped for the correct resource. Also, confirm that the key has the necessary permissions for POST operations on the knowledge base API.

For more details on similar configuration issues and troubleshooting steps, see this documentation thread and the recent pull request introducing stricter user context checks.

To reply, just mention @dosu.


How did I do? Good | Irrelevant | Incorrect | Verbose | Hallucination | Report 🐛 | Other  Chat with Dosu Join Discord Share on X

@dosubot[bot] commented on GitHub (Nov 16, 2025): <!-- Greeting --> Hi @VoidWood! I'm [Dosu](https://go.dosu.dev/dosubot) and I’m helping the dify team. <!-- Answer --> There is an open issue tracking this exact problem, so it's a known issue in Dify 1.10.0 self-hosted via Docker. Recent changes in the codebase have introduced stricter validation of user context and permissions for API key operations, which could cause 401 errors if the API key is not associated with the correct tenant or lacks the required permissions. In self-hosted Docker setups, 401 errors can also result from misconfigured or missing environment variables, especially those related to authentication or vector database services (like Weaviate). Double-check that all relevant environment variables (such as API keys, tenant IDs, and vector store configs) are correctly set and consistent across your containers. If you recently updated your Docker setup, make sure to restart all containers to apply any changes. If your API key was generated before recent updates or changes to user/tenant validation, try generating a new API key and ensure it's scoped for the correct resource. Also, confirm that the key has the necessary permissions for POST operations on the knowledge base API. For more details on similar configuration issues and troubleshooting steps, see [this documentation thread](https://github.com/langgenius/dify-docs/issues/397) and the recent [pull request introducing stricter user context checks](https://github.com/langgenius/dify/pull/26745). <!-- Dosu Comment Footer --> *To reply, just mention [@dosu](https://go.dosu.dev/dosubot).* --- <sup>How did I do? [Good](https://app.dosu.dev/response-feedback/8d795fb9-1438-496a-ae3a-42771a277f66?feedback_type=great_response) | [Irrelevant](https://app.dosu.dev/response-feedback/8d795fb9-1438-496a-ae3a-42771a277f66?feedback_type=irrelevant_answer) | [Incorrect](https://app.dosu.dev/response-feedback/8d795fb9-1438-496a-ae3a-42771a277f66?feedback_type=incorrect_sources) | [Verbose](https://app.dosu.dev/response-feedback/8d795fb9-1438-496a-ae3a-42771a277f66?feedback_type=too_verbose) | [Hallucination](https://app.dosu.dev/response-feedback/8d795fb9-1438-496a-ae3a-42771a277f66?feedback_type=hallucination) | [Report 🐛](https://app.dosu.dev/response-feedback/8d795fb9-1438-496a-ae3a-42771a277f66?feedback_type=bug_report) | [Other](https://app.dosu.dev/response-feedback/8d795fb9-1438-496a-ae3a-42771a277f66?feedback_type=other)</sup>&nbsp;&nbsp;[![Chat with Dosu](https://dosu.dev/dosu-chat-badge.svg)](https://app.dosu.dev/6088a4f4-073a-43f3-b3d4-4f06fb0c05a0/ask?utm_source=github)&nbsp;[![Join Discord](https://img.shields.io/badge/join-5865F2?logo=discord&logoColor=white&label=)](https://go.dosu.dev/discord-bot)&nbsp;[![Share on X](https://img.shields.io/badge/X-share-black)](https://twitter.com/intent/tweet?text=%40dosu_ai%20helped%20me%20solve%20this%20issue!&url=https%3A//github.com/langgenius/dify/issues/28268)
Author
Owner

@VoidWood commented on GitHub (Nov 17, 2025):

Hi @VoidWood! I'm Dosu and I’m helping the dify team.

There is an open issue tracking this exact problem, so it's a known issue in Dify 1.10.0 self-hosted via Docker. Recent changes in the codebase have introduced stricter validation of user context and permissions for API key operations, which could cause 401 errors if the API key is not associated with the correct tenant or lacks the required permissions.

In self-hosted Docker setups, 401 errors can also result from misconfigured or missing environment variables, especially those related to authentication or vector database services (like Weaviate). Double-check that all relevant environment variables (such as API keys, tenant IDs, and vector store configs) are correctly set and consistent across your containers. If you recently updated your Docker setup, make sure to restart all containers to apply any changes.

If your API key was generated before recent updates or changes to user/tenant validation, try generating a new API key and ensure it's scoped for the correct resource. Also, confirm that the key has the necessary permissions for POST operations on the knowledge base API.

For more details on similar configuration issues and troubleshooting steps, see this documentation thread and the recent pull request introducing stricter user context checks.

To reply, just mention @dosu.

How did I do? Good | Irrelevant | Incorrect | Verbose | Hallucination | Report 🐛 | Other  Chat with Dosu Join Discord Share on X

The issue was already present in version 1.8 and persisted even after upgrading to 1.10.0. In both versions.

@VoidWood commented on GitHub (Nov 17, 2025): > Hi [@VoidWood](https://github.com/VoidWood)! I'm [Dosu](https://go.dosu.dev/dosubot) and I’m helping the dify team. > > There is an open issue tracking this exact problem, so it's a known issue in Dify 1.10.0 self-hosted via Docker. Recent changes in the codebase have introduced stricter validation of user context and permissions for API key operations, which could cause 401 errors if the API key is not associated with the correct tenant or lacks the required permissions. > > In self-hosted Docker setups, 401 errors can also result from misconfigured or missing environment variables, especially those related to authentication or vector database services (like Weaviate). Double-check that all relevant environment variables (such as API keys, tenant IDs, and vector store configs) are correctly set and consistent across your containers. If you recently updated your Docker setup, make sure to restart all containers to apply any changes. > > If your API key was generated before recent updates or changes to user/tenant validation, try generating a new API key and ensure it's scoped for the correct resource. Also, confirm that the key has the necessary permissions for POST operations on the knowledge base API. > > For more details on similar configuration issues and troubleshooting steps, see [this documentation thread](https://github.com/langgenius/dify-docs/issues/397) and the recent [pull request introducing stricter user context checks](https://github.com/langgenius/dify/pull/26745). > > _To reply, just mention [@dosu](https://go.dosu.dev/dosubot)._ > > How did I do? [Good](https://app.dosu.dev/response-feedback/8d795fb9-1438-496a-ae3a-42771a277f66?feedback_type=great_response) | [Irrelevant](https://app.dosu.dev/response-feedback/8d795fb9-1438-496a-ae3a-42771a277f66?feedback_type=irrelevant_answer) | [Incorrect](https://app.dosu.dev/response-feedback/8d795fb9-1438-496a-ae3a-42771a277f66?feedback_type=incorrect_sources) | [Verbose](https://app.dosu.dev/response-feedback/8d795fb9-1438-496a-ae3a-42771a277f66?feedback_type=too_verbose) | [Hallucination](https://app.dosu.dev/response-feedback/8d795fb9-1438-496a-ae3a-42771a277f66?feedback_type=hallucination) | [Report 🐛](https://app.dosu.dev/response-feedback/8d795fb9-1438-496a-ae3a-42771a277f66?feedback_type=bug_report) | [Other](https://app.dosu.dev/response-feedback/8d795fb9-1438-496a-ae3a-42771a277f66?feedback_type=other)  [![Chat with Dosu](https://camo.githubusercontent.com/7c571478962a6b8a5d47cac74b6824c75e4f6731bba52377e6007f9150462923/68747470733a2f2f646f73752e6465762f646f73752d636861742d62616467652e737667)](https://app.dosu.dev/6088a4f4-073a-43f3-b3d4-4f06fb0c05a0/ask?utm_source=github) [![Join Discord](https://camo.githubusercontent.com/7d2066700925db1e370d956834f9ea0e5bc92cecbe84963fbd2a363e45091b4e/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f6a6f696e2d3538363546323f6c6f676f3d646973636f7264266c6f676f436f6c6f723d7768697465266c6162656c3d)](https://go.dosu.dev/discord-bot) [![Share on X](https://camo.githubusercontent.com/a8bd7f3fcf3f5e3bd124eee9ae50ae2ac17b40971726665ac2121d48f9aee155/68747470733a2f2f696d672e736869656c64732e696f2f62616467652f582d73686172652d626c61636b)](https://twitter.com/intent/tweet?text=%40dosu_ai%20helped%20me%20solve%20this%20issue!&url=https%3A//github.com/langgenius/dify/issues/28268) The issue was already present in version 1.8 and persisted even after upgrading to 1.10.0. In both versions.
Author
Owner

@dosubot[bot] commented on GitHub (Dec 22, 2025):

Hi, @VoidWood. I'm Dosu, and I'm helping the Dify team manage their backlog and am marking this issue as stale.

Issue Summary:

  • You reported that POST requests to the knowledge base API return 401 Unauthorized errors despite using a valid API key.
  • This issue has persisted since version 1.8 and remains in version 1.10.0.
  • The problem is linked to stricter user context and permission validation introduced recently.
  • Potential causes include API keys not being correctly associated or lacking necessary permissions, as well as misconfigured environment variables or outdated keys.

Next Steps:

  • Please confirm if this issue is still relevant with the latest version of Dify and if you continue to experience the 401 errors.
  • If the issue remains, you can keep the discussion open by commenting here; otherwise, I will automatically close this issue in 15 days.

Thank you for your understanding and contribution!

@dosubot[bot] commented on GitHub (Dec 22, 2025): Hi, @VoidWood. I'm [Dosu](https://dosu.dev), and I'm helping the Dify team manage their backlog and am marking this issue as stale. **Issue Summary:** - You reported that POST requests to the knowledge base API return 401 Unauthorized errors despite using a valid API key. - This issue has persisted since version 1.8 and remains in version 1.10.0. - The problem is linked to stricter user context and permission validation introduced recently. - Potential causes include API keys not being correctly associated or lacking necessary permissions, as well as misconfigured environment variables or outdated keys. **Next Steps:** - Please confirm if this issue is still relevant with the latest version of Dify and if you continue to experience the 401 errors. - If the issue remains, you can keep the discussion open by commenting here; otherwise, I will automatically close this issue in 15 days. Thank you for your understanding and contribution!
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#20357