Upstash REST 401 Unauthorized: missing or invalid token, prefer the Bearer header
REST 401 Unauthorized means the auth token is missing or invalid. Prefer the Authorization header over the _token query param. Not for different error messages.
TL;DR: REST 401 Unauthorized means the auth token is missing or invalid. Prefer the Authorization header over the _token query param. The command never executed. The REST URL should not redirect, but check you are hitting the exact console URL.
The fix
TL;DR: REST 401 Unauthorized means the auth token is missing or invalid. Prefer the Authorization header over the _token query param. The command never executed. The REST URL should not redirect, but check you are hitting the exact console URL.
The fix
- No token sent at all. The SDK was constructed without url/token, or Redis.fromEnv() ran with the env vars unset.
- Wrong token - truncated copy, token from a different database, or a token that was revoked by a password reset.
- The _token query param got mangled: some HTTP clients or proxies strip query strings on redirects. The REST URL should not redirect, but check you are hitting the exact console URL.
- Set UPSTASHREDISRESTURL and UPSTASHREDISRESTTOKEN in the environment and use Redis.fromEnv().
- Prefer the Authorization header over the _token query param. Query params land in access logs and are easier to leak.
- In Cloudflare Workers, make sure the secrets were set with wrangler secret put and that fromEnv receives env in module workers.
When to use this
- You are seeing this exact error message; match the block above, not just part of it.
- The failing call matches the scenario in the title: Upstash REST 401 Unauthorized.
- You want the fastest verified fix before digging through logs.
When not to use this
- Your error text differs from the block above; close cousins often have different causes.
- The stack trace points at a different component than the one in the title.
- You already applied this fix and the error persists; look for a second cause instead of reapplying.
Compatibility
- Not pinned to a specific version; follows current Upstash behavior.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.