Skip to content
Error codes · Monitors, checks & agents

RU-3013: Invalid check authentication

The authentication on a private-location check was refused. Every header value and every password must be a secret reference written as ${SECRET:NAME}, sent only in a header name the location allows. realuptime never stores a credential's value: the private location reads it on its own machine.

On the wire

Ships with HTTP status 400, carrying "code": "RU-3013" in the response body alongside the human-readable error message. Existing fields are never replaced by the code: it is additive.

Common causes

  • A header value or password with no ${SECRET:NAME} reference, which would store a real credential.
  • A credential pasted beside a reference.
  • A reference whose NAME is not capital letters, digits and underscores.
  • A header name outside Authorization, Proxy-Authorization, Cookie, X-Api-Key and the names the location allows with REALUPTIME_AUTH_HEADERS.
  • URL credentials and an Authorization header on the same check.

How to fix it

  1. Put the credential on the location's machine as REALUPTIME_SECRET_NAME, or in the file named by REALUPTIME_SECRETS_FILE.
  2. Reference it in the header value as ${SECRET:NAME}, for example Bearer ${SECRET:API_TOKEN}.
  3. To send another header, add its name to REALUPTIME_AUTH_HEADERS on the location's machine and restart the agent.

Related codes

  • RU-3001: Invalid check request
  • RU-3014: Check authentication not available

Still stuck?

Ask support and mention RU-3013: the code pins down the exact refusal path, so you skip the diagnostic back-and-forth.