Authentication Token less than 4 characters

Hi matt,

Thank you for raising the issue - we believe this is down to our hashing algorithm and we actively working to fix it.

There are a few mitigating factors worth considering:

  1. This does not affect our cloud our hybrid environment
  2. This does not affect environments that are not using key hashing
  3. We believe it only affects environments that are sparsely populated - I.e have few keys issued

For new installations: the workaround is to disable key hashing in the Tyk.conf

Alternatively - generating several dummy keys (doing so with a separate organisation would be better) should also suffice.

We’ll post more information here as we investigate.

Kind regards,
Martin