Repository navigation
Planetary Computer API issuing pre-expired tokens #463
Description
Activity
Can you share the link of the URL you are requesting a SAS token for?
I encountered an issue where the API is issuing tokens for the correct start TIME, but for the incorrect start DATE (the start date is exactly 1 -day prior). This renders the tokens expired because I can even use them.
AFAIK, SAS tokens are valid as long as the start date (
st=query parameter) is in the past (or omitted) and the expiration date (se=query parameter) is in the future. From the debug message you provided it looks like your code may be checking whether the token has expired by comparing current time against the token start time. If so, it should probably be comparing against the expiration date?The following code demonstrates that the SAS token returned by the PC data API with a start date in the past is valid:
from datetime import datetime, timezone from urllib.parse import parse_qs, urlparse import planetary_computer import pystac_client import requests client = pystac_client.Client.open( "https://planetarycomputer.microsoft.com/api/stac/v1", ) item = next( client.search( collections="sentinel-2-l2a", ids=["S2B_MSIL2A_20250717T161829_R040_T17SKV_20250717T200918"], ).items() ) print( f"Before signing, HTTP status code: {requests.head(item.assets['AOT'].href).status_code}" ) current_time = datetime.now(tz=timezone.utc).isoformat() print(f"Current UTC time: {current_time}") print("Signing assets...") # sign assets planetary_computer.sign_inplace(item) params = parse_qs(urlparse(item.assets["AOT"].href).query) print(f"SAS start time: {params['st'][0]} | SAS expiration time: {params['se'][0]}") print("Start precedes current:", params["st"][0] < current_time) print( f"After signing, HTTP status code: {requests.head(item.assets['AOT'].href).status_code}" )
Produces the following output:
Before signing, HTTP status code: 409 (error) Current UTC time: 2026-01-05T18:15:03.692103+00:00 Signing assets... SAS start time: 2026-01-04T18:15:04Z | SAS expiration time: 2026-01-06T18:15:04Z Start precedes current: True After signing, HTTP status code: 200 (success)Hi, I'm having similar issues with the GBIF dataset (which is outdated by the way...).
How long is the token supposed to last ? Because having a start date in the past is fine as long as the expiry date is not barely an hour in the future which is the issue I'm encountering with the GBIF dataset
Yesterday while trying to download data from the Planetary Computer using dask, I encountered an issue where the API is issuing tokens for the correct start TIME, but for the incorrect start DATE (the start date is exactly 1 -day prior). This renders the tokens expired because I can even use them.
Here is a snippet of output from a debugging I did. I instructed the code to pull a fresh url from the API for batch each time and print out the token start time. The time, for example 2025-11-19 22:40:33Z is off by exactly one day and so when the code tries to compute on that already-expired URL it fails. In summary, the API was assigning the token to Nov 19 but this code was run on Nov 20.
Data Found Fetching fresh items from API for batch... DEBUG: Token start time = 2025-11-19T22%3A40%3A33Z DEBUG: Current time = 2025-11-20 22:42:24.229570 UTC DEBUG: Token expired? True Fetching fresh items from API for batch... DEBUG: Token start time = 2025-11-19T22%3A40%3A33Z DEBUG: Current time = 2025-11-20 22:43:23.053583 UTC DEBUG: Token expired? True