Skip to content

Planetary Computer API issuing pre-expired tokens #463

Description

@drmika

Yesterday while trying to download data from the Planetary Computer using dask, I encountered an issue where the API is issuing tokens for the correct start TIME, but for the incorrect start DATE (the start date is exactly 1 -day prior). This renders the tokens expired because I can even use them.

Here is a snippet of output from a debugging I did. I instructed the code to pull a fresh url from the API for batch each time and print out the token start time. The time, for example 2025-11-19 22:40:33Z is off by exactly one day and so when the code tries to compute on that already-expired URL it fails. In summary, the API was assigning the token to Nov 19 but this code was run on Nov 20.

Data Found Fetching fresh items from API for batch... DEBUG: Token start time = 2025-11-19T22%3A40%3A33Z DEBUG: Current time = 2025-11-20 22:42:24.229570 UTC DEBUG: Token expired? True Fetching fresh items from API for batch... DEBUG: Token start time = 2025-11-19T22%3A40%3A33Z DEBUG: Current time = 2025-11-20 22:43:23.053583 UTC DEBUG: Token expired? True

Activity

  1. ghidalgo3 commented on Dec 8, 2025

    @ghidalgo3

    Can you share the link of the URL you are requesting a SAS token for?

  2. bmcandr commented on Jan 5, 2026

    @bmcandr

    I encountered an issue where the API is issuing tokens for the correct start TIME, but for the incorrect start DATE (the start date is exactly 1 -day prior). This renders the tokens expired because I can even use them.

    AFAIK, SAS tokens are valid as long as the start date (st= query parameter) is in the past (or omitted) and the expiration date (se= query parameter) is in the future. From the debug message you provided it looks like your code may be checking whether the token has expired by comparing current time against the token start time. If so, it should probably be comparing against the expiration date?

    The following code demonstrates that the SAS token returned by the PC data API with a start date in the past is valid:

    from datetime import datetime, timezone
    from urllib.parse import parse_qs, urlparse
    
    import planetary_computer
    import pystac_client
    import requests
    
    client = pystac_client.Client.open(
        "https://planetarycomputer.microsoft.com/api/stac/v1",
    )
    
    item = next(
        client.search(
            collections="sentinel-2-l2a",
            ids=["S2B_MSIL2A_20250717T161829_R040_T17SKV_20250717T200918"],
        ).items()
    )
    
    
    print(
        f"Before signing, HTTP status code: {requests.head(item.assets['AOT'].href).status_code}"
    )
    
    current_time = datetime.now(tz=timezone.utc).isoformat()
    
    print(f"Current UTC time: {current_time}")
    
    print("Signing assets...")
    
    # sign assets
    planetary_computer.sign_inplace(item)
    
    params = parse_qs(urlparse(item.assets["AOT"].href).query)
    
    print(f"SAS start time: {params['st'][0]} | SAS expiration time: {params['se'][0]}")
    
    
    print("Start precedes current:", params["st"][0] < current_time)
    
    print(
        f"After signing, HTTP status code: {requests.head(item.assets['AOT'].href).status_code}"
    )

    Produces the following output:

    Before signing, HTTP status code: 409 (error)
    Current UTC time: 2026-01-05T18:15:03.692103+00:00
    Signing assets...
    SAS start time: 2026-01-04T18:15:04Z | SAS expiration time: 2026-01-06T18:15:04Z
    Start precedes current: True
    After signing, HTTP status code: 200 (success)
    
  3. IanOndo commented on May 25, 2026

    @IanOndo

    Hi, I'm having similar issues with the GBIF dataset (which is outdated by the way...).
    How long is the token supposed to last ? Because having a start date in the past is fine as long as the expiry date is not barely an hour in the future which is the issue I'm encountering with the GBIF dataset

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions