Skip to content
Nilay Kabariya

Entry No.023·AI··3 min read

Fix: OpenAI 401 Incorrect API key provided (AuthenticationError)

OpenAI rejects a key you just copied. How to read which key was really sent from the error itself, why an old key can beat your .env, and the fix.

by Nilay#openai#node#pythonAI

The error, verbatim

Jump to the fix ↓
AuthenticationError: 401 Incorrect API key provided: sk-old-s*****************1111.
You can find your API key at https://platform.openai.com/account/api-keys.
code: invalid_api_key | type: invalid_request_error

# Python:
openai.AuthenticationError: Error code: 401 - {'error': {'message': 'Incorrect API key provided: sk-old-s*****************1111. ...
✓ Reproduced on Windows 11 Pro

Tested on

openai (JS)
7.23.0
openai (Python)
3.19.2
dotenv / python-dotenv
18.0.3 / 1.2.3
Runtime
Node 24.14.0, Python 3.14.5
OS
Windows 11 Pro
Contents
  1. Read the key in the error01
  2. Why an old key beats your .env02
  3. The fix03
  4. What didn’t work04
  5. How this was tested05

You paste a fresh key into .env, run your code, and OpenAI still says it’s incorrect. Before you regenerate the key again, read the error closely, because it tells you exactly which key was sent.

Read the key in the error

OpenAI echoes the key it received: the first 8 characters and the last 4, with the middle masked.

Incorrect API key provided: sk-old-s*****************1111.

Compare those 12 characters with the key in your .env:

  • They don’t match → your code sent a different key than the one in .env. An older key set somewhere else is winning. Go to the next section.
  • They match → the key itself is wrong: mistyped, revoked, or from a different organisation or project. Create a new one in the OpenAI dashboard.

Why an old key beats your .env

This surprised me more than anything else in the test. If OPENAI_API_KEY is already set in your environment (from your system settings, your shell profile, or an old setx), loading .env does not replace it:

How .env is loaded Shell already has an old key Key actually sent
import 'dotenv/config' (JS) yes the old one
node --env-file=.env yes the old one
load_dotenv() (Python) yes the old one

In every case the request went out with the old key, and the 401 showed its first and last characters, not the new key’s. That’s the whole trap: you can regenerate keys all day and paste each one into .env, and none of them is ever used.

The fix

Option 1: let .env win. Tell the loader to overwrite what’s already set.

// JavaScript
import dotenv from 'dotenv';
dotenv.config({ override: true });
# Python
from dotenv import load_dotenv
load_dotenv(override=True)

Option 2: remove the old key at its source, so there’s only one. Check whether one is set:

echo $env:OPENAI_API_KEY      # PowerShell
echo %OPENAI_API_KEY%         # Command Prompt
echo $OPENAI_API_KEY          # macOS / Linux

If it prints a key, find where it’s defined. On Windows that’s usually Start → “Edit the system environment variables” → Environment Variables; on macOS or Linux, your shell profile (~/.zshrc, ~/.bashrc). Delete it there, then open a new terminal and restart your editor, because running programs keep the environment they started with.

What didn’t work

How this was tested

The OpenAI SDK in JavaScript (7.23.0) and Python (3.19.2) on Windows 11, calling the real API with invented test keys: one in .env and a different one set in the shell. Each loader (dotenv, node --env-file, python-dotenv) was run with and without the override. No real key was used; every result above is OpenAI’s actual 401 response, and the key characters shown are from the invented test keys.

— N.K., end of entry No.023

Useful? Pass it on:Post on XFollow @EmotionalMatter

Related entries

  1. No.021

    Fix: The OPENAI_API_KEY environment variable is missing or empty

    OpenAI's SDK or Codex CLI says your key is missing, though it's in .env. Every wording, in JavaScript, Python and Codex, and the fix for each.

    > OpenAIError: The OPENAI_API_KEY environment variable is missing or empty; either provide it,

    AI4 min
  2. No.045

    Fix: APIConnectionError "Connection error." (OpenAI, Anthropic)

    OpenAI's and Anthropic's SDKs both say only Connection error. Five real causes reproduced, from a local model that isn't running to antivirus HTTPS scanning.

    > APIConnectionError: Connection error.

    AI5 min
  3. No.024

    Fix: Could not resolve authentication method (Anthropic / Claude SDK)

    Anthropic's SDK can't find your key. The old and new wording, ANTHROPIC_API_KEY vs ANTHROPIC_AUTH_TOKEN, and the 401 you get when a key is in the wrong one.

    > Error: Could not resolve authentication method. Expected either apiKey or authToken to be set.

    AI2 min

Post card · Newsletter

Get the next fix in your inbox.

One short email when a new entry is published. No spam, never shared, and you can leave any time.

— Nilay

or follow by RSSor on X

By subscribing you agree to the privacy note. One click to leave.

tip: paste the exact error text