Troubleshoot authentication errors
Use this article to resolve authentication and authorization errors when you connect to the Nexus MFT API or configure endpoint credentials.
Security reminder
Never share API keys or credentials in support tickets, chat messages or emails. If you suspect that a key is compromised, revoke it immediately from the Admin Console.
API returns 401 Unauthorized on every request
Cause: Your API key is missing from the request, incorrectly formatted or expired.
Resolution:
- Verify that your request includes the
Authorizationheader in the formatBearer YOUR_API_KEY. - Check that the API key has no extra spaces or line breaks.
- Go to Settings > API Keys in the Admin Console and verify that the key hasn't expired.
- If the key has expired, generate a new key and update your integration.
# Correct format
curl -H "Authorization: Bearer sk_live_abc123def456" ...
# Common mistakes:
# - Missing "Bearer" prefix
# - Extra space: "Bearer sk_live_abc123def456"
# - Using the key ID instead of the key value
API returns 403 Forbidden for specific operations
Cause: Your API key doesn't have the permission that the operation requires.
Resolution:
- Check which permission the operation requires in the API reference.
- Go to Settings > API Keys and select the key you're using.
- Verify that the key has the required permission scope.
- If the permission is missing, generate a new key with the correct permissions. You can't change a key's permissions after you create it.
SFTP sign-in fails with "Authentication failed"
Cause: The credentials stored in the endpoint configuration are incorrect, or the user account on the destination server is disabled or locked.
Resolution:
- Go to Settings > Endpoints and select the affected endpoint.
- Verify that the username and password, or the SSH key, are correct.
- Test the credentials manually by connecting to the SFTP server from a terminal.
- If you use key-based authentication, verify that the public key is in the
authorized_keysfile on the destination server. - Ask the server administrator whether the account is active and unlocked.
# Test SFTP credentials manually with a key
sftp -i /path/to/private_key user@destination-server.com
# Or with password authentication
sftp user@destination-server.com
Still need help?
If the issue continues after you follow these steps, collect the following information before you contact support:
- The full error message, with any credentials or API keys removed
- The transfer ID or request ID from the API response
- The endpoint configuration name
- The time of the failed attempt, in UTC