# Api-Token Invalid

**URL:** <https://community.sendbird.com/t/api-token-invalid/2647>\
**Category:** Sendbird Voice/Video Calls\
**Tags:** sendbird-call\
**Created:** [July 14, 2021, 5:09pm UTC](https://community.sendbird.com/t/api-token-invalid/2647 "2021-07-14T17:09:33Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![mark](https://sea2.discourse-cdn.com/flex020/user_avatar/community.sendbird.com/mark/32/1353_2.png) [@mark](https://community.sendbird.com/u/mark)\
**Post date:** [July 14, 2021, 5:09pm UTC](https://community.sendbird.com/t/api-token-invalid/2647/1 "2021-07-14T17:09:33Z")

</div>

Hi @Woo , I’m getting the followking error when calling the rooms end point `https://api-{key}.calls.sendbird.com/v1/rooms/{room}`.

```auto
message: 'The Api-Token specifies invalid value. Check your api token.',
code: 400100,
type: 'INVALID_PARAMS'

```

It seems however that this is only happening when I deploy to production ie. it is not happening on my localhost. I am definitely sending the Api-Token as I can see this being set in the headers, and it’s working locally. I also tried setting the domains in the dashboard, but this seemed to have to effect.

I’m using axios to call, so I’m not sure if it’ messes with the headers, but again, not sure why this would be showing up only when deployed

```auto
axios.get(`https://api-${process.env.SENDBIRD_APP_ID}.calls.sendbird.com/v1/rooms/${doc.data().value}`, { headers: { 'Api-Token': process.env.SENDBIRD_API_TOKEN }})

```

---

<div class="post-metadata">

**Author:** ![Woo](https://sea2.discourse-cdn.com/flex020/user_avatar/community.sendbird.com/woo/32/125_2.png) [@Woo](https://community.sendbird.com/u/Woo)\
**Post date:** [July 14, 2021, 7:54pm UTC](https://community.sendbird.com/t/api-token-invalid/2647/2 "2021-07-14T19:54:55Z")

</div>

so are you using same token when you calling the endpoint both local and production? please dm me your application id and I will check on server log

---

<div class="post-metadata">

**Author:** ![imju](https://sea2.discourse-cdn.com/flex020/user_avatar/community.sendbird.com/imju/32/49_2.png) [@imju](https://community.sendbird.com/u/imju)\
**Post date:** [July 14, 2021, 7:55pm UTC](https://community.sendbird.com/t/api-token-invalid/2647/3 "2021-07-14T19:55:04Z")

</div>

Hi Mark,  
Did you use right API token for the app?

---

<div class="post-metadata">

**Author:** ![mark](https://sea2.discourse-cdn.com/flex020/user_avatar/community.sendbird.com/mark/32/1353_2.png) [@mark](https://community.sendbird.com/u/mark)\
**Post date:** [July 14, 2021, 8:25pm UTC](https://community.sendbird.com/t/api-token-invalid/2647/4 "2021-07-14T20:25:46Z")

</div>

yeah definitley the same token @imju but I’m wondering if the headers are case sensitive and something isbneing mangled. I’m still trying to investigate. @Woo will DM you

---

<div class="post-metadata">

**Author:** ![Woo](https://sea2.discourse-cdn.com/flex020/user_avatar/community.sendbird.com/woo/32/125_2.png) [@Woo](https://community.sendbird.com/u/Woo)\
**Post date:** [July 14, 2021, 8:42pm UTC](https://community.sendbird.com/t/api-token-invalid/2647/5 "2021-07-14T20:42:46Z")

</div>

headers should be case insensitive. Are there any code difference between local and production?

---

<div class="post-metadata">

**Author:** ![mark](https://sea2.discourse-cdn.com/flex020/user_avatar/community.sendbird.com/mark/32/1353_2.png) [@mark](https://community.sendbird.com/u/mark)\
**Post date:** [July 14, 2021, 8:48pm UTC](https://community.sendbird.com/t/api-token-invalid/2647/6 "2021-07-14T20:48:54Z")

</div>

@woo I think I’ve figured it out. It’s actually the webpack build step that’s mangling the token in some way, but his only happens in prod. I can fix the issue by hardcoding the value, so the api is actually working as expected. Sorry for the hassle and thanks for jumping on this so quickly.
