Skip to content

fix(ai/prompts): give HTTP 401 a real error message - #893

Merged
turnipdabeets merged 2 commits into
mainfrom
posthog-self-driving/fixaiprompts-give-http-401-a-real-error-20922a
Aug 24, 2026
Merged

fix(ai/prompts): give HTTP 401 a real error message#893
turnipdabeets merged 2 commits into
mainfrom
posthog-self-driving/fixaiprompts-give-http-401-a-real-error-20922a

Conversation

@posthog

@posthog posthog Bot commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

💡 Motivation and Context

  • Onboarding operators hit HTTP 401 from a prompt fetch with no hint why the key was rejected — missing, expired, or the wrong type. The caller falls back to a bundled prompt, so onboarding still works but quietly serves a stale prompt instead of the production label, and nobody watching error tracking can tell why.
  • _fetch_prompt_from_api handled only 404 and 403 explicitly; every other status, 401 included, fell through to a generic HTTP {status_code} string.
  • One real trap: a project secret key sent as a Bearer token to an endpoint that only accepts a personal API key answers 401. The new message names this case.

Applies to every SDK user hitting an auth failure, not just the onboarding path.

💚 How did you test it?

  • Added test_handle_401_response, which asserts the new message names the prompt and mentions the personal API key.
  • Ran the prompt test suite: pytest posthog/test/ai/test_prompts.py (401 and 403 cases pass).
  • Ran ruff format and ruff check on both changed files.

📝 Checklist

  • I reviewed the submitted code.
  • I added tests to verify the changes.
  • I updated the docs if needed.
  • No breaking change or entry added to the changelog.

If releasing new changes

  • Ran sampo add to generate a changeset file

🤖 Agent context

Autonomy: Fully autonomous

  • Authored by Claude (Opus 4.8) via PostHog Desktop from an inbox report.
  • Scope kept to the reported symptom: one 401 branch next to the existing 403 branch in posthog/ai/prompts.py, plus one test. No adjacent refactoring.

Created with PostHog Desktop from this inbox report.

Prompt fetches that fail with 401 fell through to a generic "HTTP 401"
error that gave no hint the personal API key was missing, expired, or the
wrong type. Add a 401 branch, alongside the existing 403 branch, that names
the likely causes, including the common personal-key-versus-secret-key
mixup.

Generated-By: PostHog Desktop
Task-Id: cece44a6-1807-431b-8a3e-7f00e0d75eac
@posthog

posthog Bot commented Aug 24, 2026

Copy link
Copy Markdown
Contributor Author

🦔 ReviewHog reviewed this pull request

Found 0 must fix, 1 should fix, 0 consider.

Published 1 finding (view the review).

Resolved comments: 1 fixed

@github-actions

github-actions Bot commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

posthog-python Compliance Report

Date: 2026-08-24 19:50:23 UTC
Duration: 256273ms

✅ All Tests Passed!

111/111 tests passed


Capture_V1 Tests

94/94 tests passed

View Details
Test Status Duration
Endpoint And Method.Targets V1 Endpoint 515ms
Endpoint And Method.Does Not Use Legacy Endpoints 510ms
Required Headers.Has Authorization Bearer Header 510ms
Required Headers.Has Content Type Json 511ms
Required Headers.Has Posthog Sdk Info Format 510ms
Required Headers.Has Posthog Attempt Header 510ms
Required Headers.Has Posthog Request Id 510ms
Required Headers.Has Posthog Request Timestamp 510ms
Required Headers.Has User Agent 510ms
Body Format.Body Has Created At And Batch 510ms
Body Format.No Api Key In Body 510ms
Body Format.No Sent At In Body 510ms
Event Format.Event Has Required Root Fields 510ms
Event Format.Event Uuid Is Valid 511ms
Event Format.Event Timestamp Is Rfc3339 510ms
Event Format.Distinct Id Is String 510ms
Event Format.Distinct Id At Root Not Properties 510ms
Event Format.Custom Properties Preserved 510ms
Event Format.Set Properties Preserved 510ms
Event Format.Set Once Properties Preserved 510ms
Event Format.Groups Properties Preserved 509ms
Event Format.Sdk Generates Uuid If Not Provided 511ms
Event Format.Event Has Required Root Fields Batch 513ms
Event Format.Event Uuid Is Valid Batch 513ms
Event Format.Event Timestamp Is Rfc3339 Batch 513ms
Event Format.Distinct Id Is String Batch 514ms
Event Format.Distinct Id At Root Not Properties Batch 513ms
Event Format.Custom Properties Preserved Batch 514ms
Event Format.Set Properties Preserved Batch 513ms
Event Format.Set Once Properties Preserved Batch 514ms
Event Format.Groups Properties Preserved Batch 514ms
Event Format.Sdk Generates Uuid If Not Provided Batch 513ms
Batch Behavior.Multiple Events In Single Batch 518ms
Batch Behavior.Batch Envelope Smoke 514ms
Batch Behavior.Flush With No Events Sends Nothing 507ms
Batch Behavior.Flush At Triggers Batch 1013ms
Batch Behavior.Created At Reflects Batch Creation Time 510ms
Deduplication.Generates Unique Uuids 517ms
Deduplication.Different Events Same Content Different Uuids 513ms
Deduplication.Preserves Uuid On Retry 6519ms
Deduplication.Preserves Timestamp On Retry 6515ms
Deduplication.Preserves Uuid And Timestamp On Batch Retry 6522ms
Deduplication.No Duplicate Events In Batch 518ms
Header Behavior On Retry.Attempt Header Starts At One 510ms
Header Behavior On Retry.Attempt Header Increments On Retry 13527ms
Header Behavior On Retry.Request Id Preserved On Retry 6519ms
Header Behavior On Retry.Different Requests Have Different Request Ids 3019ms
Header Behavior On Retry.Request Timestamp Changes On Retry 6519ms
Response Format Validation.Success Response Has Uuid Keyed Results 511ms
Response Format Validation.Success Response Has Ok For Each Event 515ms
Response Format Validation.Success No Retry After When All Ok 512ms
Response Format Validation.Success Retry After Present When Retry Events 1516ms
Response Format Validation.Success No Retry After When Drop Only 512ms
Response Format Validation.Response Echoes Request Id 510ms
Retry Behavior.Retries On 408 6520ms
Retry Behavior.Retries On 500 6518ms
Retry Behavior.Retries On 503 8519ms
Retry Behavior.Retries On 504 6515ms
Retry Behavior.Retryable Errors Have Retry After 3516ms
Retry Behavior.Respects Retry After On Retryable Error 11523ms
Retry Behavior.Does Not Retry On 400 2513ms
Retry Behavior.Does Not Retry On 401 2514ms
Retry Behavior.Does Not Retry On 402 2513ms
Retry Behavior.Does Not Retry On 413 2512ms
Retry Behavior.Does Not Retry On 415 2513ms
Retry Behavior.Non Retryable Errors Have No Retry After 2514ms
Retry Behavior.Implements Backoff 22524ms
Retry Behavior.Max Retries Respected 22535ms
Partial Batch Handling.Handles 200 Full Success 2511ms
Partial Batch Handling.Handles 200 With All Ok 3517ms
Partial Batch Handling.Does Not Retry Dropped Events 3516ms
Partial Batch Handling.Does Not Retry Limited Events 3517ms
Partial Batch Handling.Prunes Ok Events On Partial Retry 6521ms
Partial Batch Handling.Prunes Dropped Events On Partial Retry 6520ms
Partial Batch Handling.Retries Only Retry Events From Partial 6522ms
Partial Batch Handling.Partial Retry Preserves Uuids 6522ms
Partial Batch Handling.Partial Retry Attempt Header Increments 6521ms
Partial Batch Handling.Partial Retry Request Id Preserved 6516ms
Partial Batch Handling.Respects Retry After On Partial 8519ms
Partial Batch Handling.Unknown Result Treated As Terminal 3515ms
Partial Batch Handling.Mixed Ok Drop Limited No Retry 3518ms
Compression.Sends Gzip Content Encoding 511ms
Compression.No Content Encoding When Disabled 510ms
Compression.Compressed Body Is Decompressible 510ms
Error Handling.Does Not Retry On Unknown 4Xx 2513ms
Event Options.Cookieless Mode Override 510ms
Event Options.Disable Skew Correction Override 510ms
Event Options.Process Person Profile Override 510ms
Event Options.Product Tour Id Override 510ms
Event Options.Unset Options Omitted 510ms
Event Options.Options Override In Batch 513ms
Geoip And Historical Migration.Geoip Disable Injected Into Properties 510ms
Geoip And Historical Migration.Historical Migration Set In Body 510ms
Geoip And Historical Migration.Historical Migration Absent By Default 511ms

Feature_Flags Tests

17/17 tests passed

View Details
Test Status Duration
Request Payload.Request With Person Properties Device Id 11ms
Request Payload.Flags Request Uses V2 Query Param 8ms
Request Payload.Flags Request Hits Flags Path Not Decide 9ms
Request Payload.Flags Request Omits Authorization Header 8ms
Request Payload.Token In Flags Body Matches Init 9ms
Request Payload.Groups Round Trip 8ms
Request Payload.Groups Default To Empty Object 9ms
Request Payload.Disable Geoip False Propagates As Geoip Disable False 8ms
Request Payload.Disable Geoip Omitted Defaults To False 8ms
Request Payload.Flag Keys To Evaluate Contains Only Requested Key 9ms
Request Lifecycle.No Flags Request On Init Alone 3ms
Request Lifecycle.No Flags Request On Normal Capture 509ms
Request Lifecycle.Two Flag Calls Produce Two Remote Requests 14ms
Request Lifecycle.Mock Response Value Is Returned To Caller 9ms
Retry Behavior.Retries Flags On 502 313ms
Retry Behavior.Retries Flags On 504 313ms
Side Effect Events.Get Feature Flag Captures Feature Flag Called Event 511ms

@posthog

posthog Bot commented Aug 24, 2026

Copy link
Copy Markdown
Contributor Author

ReviewHog Alpha 🦔 If you find any issues helpful - please reply "valid", "invalid", etc., for evaluation purposes 🙏

@posthog posthog Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ReviewHog Report

Found 1 should fix.

Comment thread posthog/ai/prompts.py Outdated
The 401 auth-failure message told users to "pass a personal_api_key and
not a secret key", conflating the key type (personal API key vs project
secret key) with the parameter name. A correctly-configured client user
(`Posthog(..., secret_key='phx_...')`) would read this as "switch to
personal_api_key=", which resolves to the same value and re-triggers the
401 plus a DeprecationWarning.

Reword so the message names the key type (personal API key, starts with
'phx_'; a project secret key is not accepted) separately from the
parameter to use per entry point: personal_api_key when constructing
Prompts directly, secret_key when configuring the PostHog client.

Generated-By: PostHog Desktop
Task-Id: add0fc6a-5a9d-4035-882a-aa60824939bf
@posthog
posthog Bot marked this pull request as ready for review August 24, 2026 19:53
@posthog
posthog Bot requested a review from a team as a code owner August 24, 2026 19:53
@turnipdabeets
turnipdabeets merged commit 4936852 into main Aug 24, 2026
43 checks passed
@turnipdabeets
turnipdabeets deleted the posthog-self-driving/fixaiprompts-give-http-401-a-real-error-20922a branch August 24, 2026 19:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant