使用用户名密码认证Hashicorp Vault时出现"Missing client token"错误
That error definitely feels counterintuitive—after all, you're trying to get a token in the first place! I've run into this exact issue before, and it almost always boils down to one of a few common misconfigurations:
1. The userpass auth method isn't enabled in Vault
Vault doesn't enable the userpass authentication method by default. If you haven't explicitly turned it on, Vault will treat your login request as a regular API call that requires a valid token (hence the confusing error).
To check if userpass is enabled:
vault auth list
Look for an entry like userpass/ in the output. If it's missing, enable it with:
vault auth enable userpass
Or via the API (using your root token if you don't have a client token yet):
curl --request POST --data '{"type": "userpass"}' https://<myurl>:8200/v1/sys/auth/userpass -k -H "X-Vault-Token: <your-root-token>"
2. The user you're trying to log in with doesn't exist
Even if userpass is enabled, if the <mylogin> user hasn't been created yet, Vault might misroute the request (instead of returning an "invalid credentials" error, it sometimes throws this token missing message).
Create the user first with the CLI:
vault write auth/userpass/users/<mylogin> password=<your-password> policies=<optional-policy-name>
Or via the API:
curl --request POST --data '{"password": "<your-password>", "policies": "<optional-policy-name>"}' https://<myurl>:8200/v1/auth/userpass/users/<mylogin> -k -H "X-Vault-Token: <your-root-token>"
3. Your payload.json has invalid syntax
Double-check that your payload file uses valid JSON—Vault is strict about this. The file should contain exactly:
{"password": "your-actual-password"}
Make sure you're using double quotes (not single quotes) and there are no trailing commas or typos.
4. Verify your request path is correct
Ensure the endpoint path is exactly v1/auth/userpass/login/<mylogin>. If you enabled userpass under a custom path (e.g., auth/custom-userpass), you'll need to adjust the URL accordingly.
Once you've corrected these issues, re-run your original curl command:
curl --request POST --data @payload.json https://<myurl>:8200/v1/auth/userpass/login/<mylogin> -k
You should get a valid token response instead of the confusing "missing client token" error.
内容的提问来源于stack exchange,提问作者Karreg

