# How to catch an exception for "Authentication using apikey failed - api key is expired"

**URL:** <https://discuss.elastic.co/t/how-to-catch-an-exception-for-authentication-using-apikey-failed-api-key-is-expired/346158>\
**Category:** Elasticsearch\
**Tags:** language-clients\
**Created:** [October 31, 2023, 8:06pm UTC](https://discuss.elastic.co/t/how-to-catch-an-exception-for-authentication-using-apikey-failed-api-key-is-expired/346158 "2023-10-31T20:06:33Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jim\_Song](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jim_song/32/122429_2.png) [@Jim\_Song](https://discuss.elastic.co/u/Jim_Song)\
**Post date:** [October 31, 2023, 8:06pm UTC](https://discuss.elastic.co/t/how-to-catch-an-exception-for-authentication-using-apikey-failed-api-key-is-expired/346158/1 "2023-10-31T20:06:33Z")

</div>

I am using client lib to perform a search operation. The API key used for constructing an ElasticsearchClient expired. How can I catch this specific type of "API Key expired" error, so that I can handle it, e.g. creating another key?

```auto
Caused by: co.elastic.clients.elasticsearch._types.ElasticsearchException: [es/search] failed: [security_exception] unable to authenticate with provided credentials and anonymous access is not allowed for this request
	at co.elastic.clients.transport.ElasticsearchTransportBase.getApiResponse(ElasticsearchTransportBase.java:286)
	at co.elastic.clients.transport.ElasticsearchTransportBase.performRequest(ElasticsearchTransportBase.java:111)
	at co.elastic.clients.elasticsearch.ElasticsearchClient.search(ElasticsearchClient.java:1887)
	at co.elastic.clients.elasticsearch.ElasticsearchClient.search(ElasticsearchClient.java:1904)

```

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [November 7, 2023, 4:48am UTC](https://discuss.elastic.co/t/how-to-catch-an-exception-for-authentication-using-apikey-failed-api-key-is-expired/346158/2 "2023-11-07T04:48:54Z")

</div>

You can't.

If the API Key is no longer valid then you can't authenticate.  
If you can't authenticate then the server will consider you to be an untrusted client.  
If you are an untrusted client then the server will not give you any details about expired API Keys.

The only things you can do are:

- Track the expiry of your API key and create a new one ahead of time
- Assume that any authentication error is caused by expired credentials.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 5, 2023, 4:49am UTC](https://discuss.elastic.co/t/how-to-catch-an-exception-for-authentication-using-apikey-failed-api-key-is-expired/346158/3 "2023-12-05T04:49:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
