# unauthorized

> The credential was rejected: the token or sign-in is invalid, expired or revoked.

| | |
| --- | --- |
| Kind | `disko` command error |
| `disko` exit code | 3 (auth) |

A signed-in command reports `unauthorized` when the credential it sent was
rejected. The command exits with code 3 and never falls back to browser
sign-in.

- `disko publish`: the registry answered `401` or `403`. The registry
  rejects any invalid credential, even for requests that would work without
  one. Typical causes are a revoked or expired CLI token, or an expired
  browser sign-in.
- `disko dev`: disko-master did not accept your browser sign-in when creating
  the test room, or, later in the session, rejected the test room's own
  credential, for example after the test room expired. A rejected CLI token
  is reported as [missing_permission](/errors/missing_permission) instead,
  because disko-master answers the same way for a token without the
  `test_rooms` permission.

## Fix

The message says which credential was rejected:

- `DISKO_TOKEN`: create a new CLI token in the Creator Portal and set
  `DISKO_TOKEN` to it.
- A token stored by `disko login --with-token`: pipe a new token to
  `disko login --with-token`, or run `disko logout` to go back to browser
  sign-in.
- A browser sign-in: run `disko login` to sign in again.
- The test room's credential: run `disko dev` again, which creates a new test
  room.

## See also

- [CLI tokens](/registry/cli-tokens)
- [invalid_token](/errors/invalid_token)
