---
title: "User Issues"
description: "When using Comp AI, you might occasionally encounter issues related to accessing the platform or its API. These issues are typically related to authentication (verifying who you are) or authorizati..."
last_updated: "2026-05-06T07:36:18.479777+00:00"
canonical_url: "https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/guide/section-5/user-issues"
---

When using Comp AI, you might occasionally encounter issues related to accessing the platform or its API. These issues are typically related to **authentication** (verifying who you are) or **authorization** (determining what you're allowed to do). This guide explains common access problems and how to resolve them, ensuring you can securely and effectively use Comp AI.

### Key Concepts

Before diving into specific issues, understanding a few key terms will be helpful:

*   **Authentication**: The process of verifying your identity. This could be by logging in with your username and password, or by providing a secret API Key.
*   **Authorization**: After you're authenticated, authorization determines what resources or actions you are permitted to access or perform within Comp AI.
*   **API Key**: A unique, secret code that identifies your application or service when it communicates with the Comp AI API. It acts like a password for your automated tools.
*   **JWT (JSON Web Token)**: A secure, digitally signed token used to verify your identity after you log in to the Comp AI web application. It represents your active session.
*   **Organization ID**: A unique identifier for your organization within Comp AI. Many actions require specifying which organization you are performing them for.

### Common Access Issues and Solutions

Here are some common issues you might encounter and steps to resolve them.

#### 1. Missing or Invalid API Key

This issue occurs when you are trying to access the Comp AI API using an API Key, but the key is either not provided, incorrectly formatted, or no longer valid.

<Callout variant="info">
API Keys are typically used for programmatic access to Comp AI, such as integrating with other systems or running automated tasks.
</Callout>

**Symptoms:**
You might receive error messages like:
*   `X-API-Key header is required`
*   `Invalid API key format`
*   `Invalid or expired API key`

<Steps>
<Step>
### Check if the API Key is provided
Ensure that your request includes the `X-API-Key` header with your valid API Key. For example, in an API request, it should look like:
```
X-API-Key: your_api_key_here
```
</Step>
<Step>
### Verify API Key format
Make sure the API Key is correctly copied and pasted without any extra spaces or characters.
</Step>
<Step>
### Validate API Key expiration and status
API Keys can expire or be revoked. If you suspect your key is no longer valid, you may need to generate a new one within your Comp AI account settings or contact your organization's administrator.
</Step>
</Steps>

#### 2. Invalid or Expired Login Session (JWT)

This issue typically affects users interacting with the Comp AI web application or client applications that rely on your logged-in session. Your session token (JWT) might have expired or become invalid.

**Symptoms:**
You might be redirected to the login page, or receive error messages such as:
*   `Authentication token is invalid. Please log out and log back in to refresh your session.`
*   `Invalid or expired JWT token`

<Steps>
<Step>
### Log out and log back in
The most common solution for an expired or invalid session is to simply log out of Comp AI and then log back in. This will generate a new, valid session token.
</Step>
</Steps>

#### 3. Missing Organization Context for Logged-in Users

When you are logged into Comp AI (using a JWT), many actions require you to specify which organization you are working within. If this context is missing, your request will be denied.

**Symptoms:**
You might receive an error message like:
*   `Organization context required: X-Organization-Id header is mandatory for JWT authentication`

<Steps>
<Step>
### Provide the X-Organization-Id header
Ensure that your request includes the `X-Organization-Id` header with the unique identifier of the organization you wish to access. This is crucial for all authenticated actions when using a JWT.
```
X-Organization-Id: your_organization_id_here
```
</Step>
</Steps>

#### 4. User Not Authorized for Organization

Even if you are logged in and provide an `X-Organization-Id`, you must be a member of that specific organization to access its resources.

**Symptoms:**
You might receive an error message like:
*   `User does not have access to organization: your_organization_id_here`

<Steps>
<Step>
### Contact your organization administrator
If you believe you should have access to a particular organization, reach out to an administrator within that organization. They can add you as a member or adjust your roles and permissions.
</Step>
</Steps>

#### 5. Cross-Origin Resource Sharing (CORS) Errors

CORS errors typically occur in web browsers when a web page tries to make requests to a server (like Comp AI's API) that is on a different domain than the web page itself. This is a security measure.

<Callout variant="info">
Comp AI is configured to allow access from its official web application domains and common local development environments (e.g., `localhost`). If you are developing a custom application, ensure your development server's origin is correctly configured.
</Callout>

**Symptoms:**
You might see error messages in your browser's developer console related to CORS, such as:
*   `Access to XMLHttpRequest at '...' from origin '...' has been blocked by CORS policy: No 'Access-Control-Allow-Origin' header is present on the requested resource.`

<Steps>
<Step>
### Verify your application's origin
If you are developing a custom application, ensure that the domain where your application is hosted is among the allowed origins for Comp AI. For local development, `http://localhost:3000`, `http://localhost:3001`, and `http://127.0.0.1:3000` are typically allowed.
</Step>
<Step>
### Contact support if persistent
If you encounter CORS errors from an officially supported Comp AI application or a correctly configured custom application, please contact support.
</Step>
</Steps>

#### 6. Internal System Errors

Very rarely, you might encounter an error message indicating a problem with Comp AI's internal configuration or services. These are not typically user-facing issues but indicate a system-level problem.

**Symptoms:**
You might receive error messages like:
*   `Cannot connect to authentication service. Please check BETTER_AUTH_URL configuration.`
*   `Internal access is not configured` (in specific scenarios)
*   `Invalid internal token` (in specific scenarios)

<Steps>
<Step>
### Contact Comp AI support
These errors indicate a problem with the Comp AI service itself. Please report the issue to Comp AI support, providing any error messages and details about what you were doing when the error occurred.
</Step>
</Steps>

### Tips for Troubleshooting

*   **Check Headers Carefully**: Many authentication and authorization issues stem from missing or incorrect HTTP headers (`X-API-Key`, `Authorization`, `X-Organization-Id`). Double-check their presence and values.
*   **Keep API Keys Secure**: Treat your API Keys like passwords. Do not share them publicly or embed them directly in client-side code.
*   **Refresh Your Session**: If you're having trouble with the web application, logging out and logging back in often resolves session-related issues.
*   **Provide Context**: Always ensure you're providing the necessary `X-Organization-Id` when interacting with organization-specific resources.
*   **Contact Support**: If you've followed these steps and are still experiencing issues, don't hesitate to contact Comp AI support with details about the problem, including any error messages you received.

## Sitemap

See the full [sitemap](https://www.doc0.dev/docs/49c89830-117b-4def-8edc-b5bcc50766e0/llms.txt) for all pages in this wiki.
