backend error: invalid key: API key does not exist
Fixes tailscale failing with backend error: invalid key: API key does not exist after a key rotation or expiry. Use when a previously working key is rejected as nonexistent, commonly after Docker restarts past the 90-day expiry. Covers minting a replacement key. Not for expired-but-present keys.
backend error: invalid key: API key does not exist
TL;DR: the key in your config no longer exists server-side. The usual story is the 90-day expiry silently deleting it, then a container restart surfacing the failure. Create a fresh key in the admin console and update the config. The old key cannot be resurrected.
backend error: invalid key: API key does not existSteps
- Open the admin console keys page and confirm the old key is gone.
Expected: it is not listed, or shows as expired and removed.
- Generate a new auth key. For automation, tick reusable and consider disabling expiry.
Expected: the console shows the new key value once.
- Update the key everywhere it is referenced: compose files, env files, CI secrets.
- Restart the service:
docker compose up -dExpected: the container joins the tailnet with no backend error.
When this applies
- Docker setups that ran fine for months then fail after a restart
- keys created with the default 90-day expiry on long-lived automation
- the error appears immediately at startup, not mid-session
When it doesnt
authkey expired— that key still exists but aged outauthkey already used— one-time key spent twice- login or OAuth browser flows — no API key involved
Compatibility
Any tailscale deployment using auth keys: Docker, CI, cloud-init.
Other phrasings
tailscale API key does not exist after restartinvalid key after 90 days tailscale
Why it happens
Expired keys are eventually removed server-side. The local config still references the old value, so the first join attempt after the deletion fails with this error. Docker restarts are the classic trigger because the container only reads the key at startup.
Edge cases
- If you use a secrets manager, rotate the secret there rather than editing compose files by hand.
- After replacing the key, remove the stale node entry in the admin console to avoid confusion.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.