# “401 Content access is protected by token” authentication failure while performing maven release

## post by rsmckinney on Jun 17, 2024

I am getting a “401 Content access is protected by token” authentication failure while performing maven release. But I did not make any changes regarding Sonatype/Nexus.

`[ERROR] Failed to execute goal org.sonatype.plugins:nexus-staging-maven-plugin:1.6.8:deploy (injected-nexus-deploy) on project manifold-all: Remote staging failed: Failed to deploy artifacts: Could not transfer artifact systems.manifold:manifold-tuple-rt:jar.asc:javadoc:2024.1.19 from/to ossrh (https://oss.sonatype.org:443/service/local/staging/deployByRepositoryId/systemsmanifold-1279): authentication failed for https://oss.sonatype.org:443/service/local/staging/deployByRepositoryId/systemsmanifold-1279/systems/manifold/manifold-tuple-rt/2024.1.19/manifold-tuple-rt-2024.1.19-javadoc.jar.asc, status: 401 Content access is protected by token`

This is my own FOSS repo and I’m not doing anything special. I released the prior version a few days ago with no problems. And reading [this](https://support.sonatype.com/hc/en-us/articles/360049469534-401-Content-access-is-protected-by-token-when-accessing-repositories) it appears this “protected by token” feature can only be set in Sonatype Nexus Repository software, which I do not have or use.

Not sure how this could happen without my making changes via Sonatype/Nexus. Any ideas?

Sonatype won’t help me because I’m not a paying customer. Thanks.

## post by kyle-stytch on Jun 18, 2024

I’m having the exact same issue. FOSS project that can no longer be published with our existing credentials, and no way to configure User Tokens.

## post by mben-soula on Jun 18, 2024

We’ve recently made [necessary changes to our account management system](https://central.sonatype.org/news/20240617_migration_of_accounts/) that involves requiring a user token to publish. Although we attempted to reach out to all of our publishers before this change, we realize that the communication might not have reached you. Please follow [the instructions on publishing via a user token](https://central.sonatype.org/publish/generate-token/) in order to resolve this issue.

## post by bitspittle on Jun 18, 2024

I ran into this as well. The instructions from [@mben-soula](https://community.sonatype.com/u/mben-soula) worked for me –

1. Go to [https://s01.oss.sonatype.org/](https://s01.oss.sonatype.org/)
2. Go to profile
3. Change the pulldown from “Summary” to “User Token”
4. Click on “Access User Token”

I am using Gradle in my project, so I have all my credentials stored in a private gradle.properties file. Using the username and password values from the “Access User Token” popup, I created two new entries:

```ini
ossrhToken=...
ossrhTokenPassword=...
```

And finally, I updated my Gradle build script, should look something like this:

```javascript
maven {
    credentials {
        username = findProperty("ossrhToken") as String
        password = findProperty("ossrhTokenPassword") as String
    }
}
```

## post by bthomas on Jun 19, 2024

I have an existing project that publishes to [oss.sonatype.org](http://oss.sonatype.org/). I’ve accessed my token, stored it in my private gradle.properties, and replaced my old username / password configuration with:

```javascript
    maven {
      name = "nexus"
      url = uri("https://oss.sonatype.org/service/local/staging/deploy/maven2/")
      credentials {
        username = findProperty("ossrhToken") as String
        password = findProperty("ossrhTokenPassword") as String
      }
    }
```

but I still get `Received status code 401 from server: Content access is protected by token`. I don’t understand what I’m missing.

Do I need to start publishing via `s01.oss.sonatype.org`? I don’t have account credentials there and my understanding was existing projects keep using the original server.

## post by yegor256 on Jun 24, 2024

I’m experiencing the same problem. The token has been created, the `settings.xml` file has been updated, but I’m getting “401 - Unauthorized” reply from the server. What’s my next step?

## post by zenglb on Jun 25, 2024

can you tell me more info about where to insert this code in gradle file ?

## post by cruisba on Jun 25, 2024

Mmm I am having the same problem. But the artifacts are in the staging repository.

## post by iandiam on Jun 25, 2024

I was able to fix it by creating a user token :)

## post by bitspittle on Jun 27, 2024

You can see my relevant [Sonatype publishing code here](https://github.com/varabyte/kotter/blob/3ce3a096a0eedbaecd656e4a452cf07d362b8fc0/kotter/build.gradle.kts#L97). I hope that helps. Misc. information about the Gradle maven publishing plugin [here](https://docs.gradle.org/current/userguide/publishing_maven.html#publishing_maven:complete_example) and also [here](https://www.jetbrains.com/help/space/publish-artifacts-from-a-gradle-project.html#publish-maven-artifacts-using-the-gradle-command-line-tool).

## post by shutty on Jul 2, 2024

Got the same issue, and creating a user token got me to the same situation as for [@yegor256](https://community.sonatype.com/u/yegor256) (Hi Egor, I’ve read your book once!) - getting `401 - Unauthorized`. For some reason recreating a user token for the second time fixed the issue for me.

## post by yegor256 on Jul 2, 2024

I solved this problem by making sure my token is created at [oss.sonatype.org](http://oss.sonatype.org/) and I deploy to the same server (mentioning it in `settings.xml`). Apparently, there are many servers and you can create tokens at each one of them. Apparently, the tokens won’t work on other servers.

## post by nguyenlequang19120121 on Jul 2, 2024

Can every one guide me the username and password to access nexus repository manager because I use the same username and password in maven central repository but it not match.

## post by steinarba on Jul 2, 2024

Can’t make this work. I can log in to [https://oss.sonatype.org/](https://oss.sonatype.org/) But when I select the profile I get an error message and the profiles come up empty.

## post by stokpop on Jul 5, 2024

We had the same “401 content access is protected by token”. First did not work after generating user token. We tried “Reset User Token” button (under the “Access User Token” button), and generating a new one via “Access User Token” button. Plus we pressed explicit “Close” button after generating in the popup containing the credentials (instead of letting it automatically close after 1 minute). After this we could upload artifacts again with these new user token credentials, so seems either the “reset” or the “explicit close” fixed it. Maybe this helps others.

## post by graebm on Jul 5, 2024

+1 had the same issue. Resetting the token value fixed it. Token worked for several releases of our library (most recently June 21), but then failed with the next release on July 3. Reset the token values July 5 and retried the release and it succeeded!

## post by cjbooms on Jul 5, 2024

Also hit by this issue. I cannot get this to work for [https://s01.oss.sonatype.org/](https://s01.oss.sonatype.org/), I have done the UserToken reset dance multiple times now to no avail.

## post by yidun on Jul 8, 2024

I also encountered this problem. I tried generating user token multiple times and configured it properly, but kept getting 401. I finally made it work by upgrading my maven version to 3.9.8, maybe it also suits your situation.
