err:unkey:authentication:portal_session_not_foundExample response
Likely causes
- The session in the
portal_sessioncookie expired or was revoked. The message is the same for an unknown token, so it doesn’t say which. - On
portal.exchangeCode, the code was already used, has expired, or was never issued. The message isSession is invalid, expired, or has already been used.A code works once, so a second exchange fails even if the first succeeded.
How to fix
- Start a new session from your backend with
portal.createSessionand complete the exchange promptly. - If your frontend retries
portal.exchangeCodeon a slow network, keep the access token from the first success instead of exchanging again. - If an active session starts returning this error, send the user back through your login flow.
Related errors
err:unkey:authentication:portal_token_missing: no token was sent at all.err:unkey:data:portal_not_found: the portal itself doesn’t exist or isn’t visible to your root key.err:unkey:authorization:forbidden: the portal is disabled or can’t serve sessions right now.