# Unauthorized response on first device setup

**URL:** <https://hub.mender.io/t/unauthorized-response-on-first-device-setup/1262>\
**Category:** General Discussions\
**Tags:** raspberry-pi-3\
**Created:** [November 18, 2019, 4:34pm UTC](https://hub.mender.io/t/unauthorized-response-on-first-device-setup/1262 "2019-11-18T16:34:49Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Silverkron](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/silverkron/32/429_2.png) [@Silverkron](https://hub.mender.io/u/Silverkron)\
**Post date:** [November 18, 2019, 4:34pm UTC](https://hub.mender.io/t/unauthorized-response-on-first-device-setup/1262/1 "2019-11-18T16:34:49Z")

</div>

Hi guys,

I’m trying to connect my first device on menderhub.  
I’m starting with a default raspbian-lite version converted with “mender-convert” but i receive

```
DEBU[0000] making an authorization request () to server https://hosted.mender.io module=client_auth
DEBU[0001] got response: &{401 Unauthorized 401 HTTP/1.1 1 1 map[X-Men-Requestid:[814bf1b6-3ee1-456f-8ab8-7eca194a0e70] Content-Security-Policy:[default-src https: data: 'unsafe-inline' 'unsafe-eval'] Content-Type:[application/json; charset=utf-8] X-Authentication-Version:[unknown] Strict-Transport-Security:[max-age=31536000; includeSubdomains] Server:[openresty/1.13.6.2] Date:[Mon, 18 Nov 2019 16:24:32 GMT] Connection:[keep-alive] X-Xss-Protection:[1; mode=block] X-Content-Type-Options:[nosniff] Vary:[Accept-Encoding] Access-Control-Allow-Origin:[*] X-Frame-Options:[SAMEORIGIN]] 0x2354080 -1 [] false true map[] 0x2080980 0x209c6c0} module=client_auth
ERRO[0001] authorize failed: transient error: authorization request failed: (request_id: ): authentication request rejected server error message: Unauthorized module=state

```

Any idea?

---

<div class="post-metadata">

**Author:** ![drewmoseley](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/drewmoseley/32/47_2.png) [@drewmoseley](https://hub.mender.io/u/drewmoseley)\
**Post date:** [November 18, 2019, 5:57pm UTC](https://hub.mender.io/t/unauthorized-response-on-first-device-setup/1262/2 "2019-11-18T17:57:02Z")

</div>

Hi @Silverkron, welcome to Mender Hub. Hopefully we can help you with your Mender installation.

This is expected behavior as the server does not know your device yet. If you log into the web interface of the server, then you will see a device in the “pending” state with a button to allow the device into your fleet. Once you accept the device, then it will be part of the fleet and can upload its inventory, receive, updates, etc.  
Drew

---

<div class="post-metadata">

**Author:** ![Silverkron](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/silverkron/32/429_2.png) [@Silverkron](https://hub.mender.io/u/Silverkron)\
**Post date:** [November 19, 2019, 7:58am UTC](https://hub.mender.io/t/unauthorized-response-on-first-device-setup/1262/3 "2019-11-19T07:58:17Z")

</div>

Hi @drewmoseley,

thanks for the feedback. Unfortunately I have no pending device 😕

 ![57](https://canada1.discourse-cdn.com/flex036/uploads/mender/original/1X/9406fc6f04200ffc993cf4cd413a590369bd9458.png)

I replaced the “TenantToken” (i hoped that it was wrong) but i receive the same result

---

<div class="post-metadata">

**Author:** ![Silverkron](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/silverkron/32/429_2.png) [@Silverkron](https://hub.mender.io/u/Silverkron)\
**Post date:** [November 19, 2019, 8:15am UTC](https://hub.mender.io/t/unauthorized-response-on-first-device-setup/1262/4 "2019-11-19T08:15:13Z")

</div>

It works!

“mender-convert” tool formatted the “TenantToken” with single quotes. I removed these to fix it.

---

<div class="post-metadata">

**Author:** ![drewmoseley](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/drewmoseley/32/47_2.png) [@drewmoseley](https://hub.mender.io/u/drewmoseley)\
**Post date:** [November 21, 2019, 11:22pm UTC](https://hub.mender.io/t/unauthorized-response-on-first-device-setup/1262/5 "2019-11-21T23:22:00Z")

</div>

Excellent. Thanks for letting us know.  
And I think the root cause has also been fixed upstream.
