# Error:"enableUnautorized"

**URL:** <https://openziti.discourse.group/t/error-enableunautorized/3461>\
**Category:** zrok\
**Created:** [November 20, 2024, 4:55pm UTC](https://openziti.discourse.group/t/error-enableunautorized/3461 "2024-11-20T16:55:05Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kiwi\_Emotivo968](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/kiwi_emotivo968/32/2781_2.png) [@Kiwi\_Emotivo968](https://openziti.discourse.group/u/Kiwi_Emotivo968)\
**Post date:** [November 20, 2024, 4:55pm UTC](https://openziti.discourse.group/t/error-enableunautorized/3461/1 "2024-11-20T16:55:05Z")

</div>

Hi, I'm trying to connect a windows 11 laptop to an enviroment that I created, for some reason zrok returns an error [POST /enable][401] enableUnauthorized. I tryied to change the apiEndpoint but it changes nothing.

 ![image](https://global.discourse-cdn.com/free1/uploads/netfoundry/original/2X/7/74a392add302f75435e18bacb53afa56842721c1.png)

---

<div class="post-metadata">

**Author:** ![qrkourier](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/qrkourier/32/52_2.png) [@qrkourier](https://openziti.discourse.group/u/qrkourier)\
**Post date:** [November 20, 2024, 5:09pm UTC](https://openziti.discourse.group/t/error-enableunautorized/3461/2 "2024-11-20T17:09:46Z")

</div>

Hi there! 👋 Are you self-hosting your own zrok instance? If so, you need to run that `set apiEndpoint` command to tell your local `zrok.exe` command to use your instance. The value of `<newEndpoint>` will be something like `https://some.zrok.io`.

In case you're not self-hosting your own zrok instance, then the problem is likely an incorrect account token (the one that's redacted), because `zrok enable ACCOUNT_TOKEN` is the correct command, substituting your token, of course.

Your account token can be found in the zrok web console where the profile drop down menu says "enable your environment" or the "detail" tab of your account where it says "token."

---

<div class="post-metadata">

**Author:** ![Kiwi\_Emotivo968](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/kiwi_emotivo968/32/2781_2.png) [@Kiwi\_Emotivo968](https://openziti.discourse.group/u/Kiwi_Emotivo968)\
**Post date:** [November 20, 2024, 5:19pm UTC](https://openziti.discourse.group/t/error-enableunautorized/3461/3 "2024-11-20T17:19:20Z")

</div>

Hi, I'm self hosting and already run set apiEndpoint.

---

<div class="post-metadata">

**Author:** ![qrkourier](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/qrkourier/32/52_2.png) [@qrkourier](https://openziti.discourse.group/u/qrkourier)\
**Post date:** [November 20, 2024, 5:23pm UTC](https://openziti.discourse.group/t/error-enableunautorized/3461/4 "2024-11-20T17:23:53Z")

</div>

I think the `config set apiEndpoint` command did not work because your zrok.exe still thinks it should be talking to `https://api.zrok.io` (the default instance from NetFoundry).

You can see the current configuration by running:

```powershell
C:\> zrok status

```

---

<div class="post-metadata">

**Author:** ![Kiwi\_Emotivo968](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/kiwi_emotivo968/32/2781_2.png) [@Kiwi\_Emotivo968](https://openziti.discourse.group/u/Kiwi_Emotivo968)\
**Post date:** [November 20, 2024, 5:26pm UTC](https://openziti.discourse.group/t/error-enableunautorized/3461/5 "2024-11-20T17:26:43Z")

</div>

Yes, zrok is talking to `https://api.zrok.io` how I see what instance should I be using?

---

<div class="post-metadata">

**Author:** ![qrkourier](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/qrkourier/32/52_2.png) [@qrkourier](https://openziti.discourse.group/u/qrkourier)\
**Post date:** [November 20, 2024, 5:37pm UTC](https://openziti.discourse.group/t/error-enableunautorized/3461/6 "2024-11-20T17:37:17Z")

</div>

You can configure your Windows environment by running this command:

```powershell
C:\> zrok config set apiEndpoint https://zrok.example.com

```

...substituting your self-hosted zrok controller's URL for `https://zrok.example.com`.

So, if you have a Linux VPS with a public IP where you installed zrok controller, and you made a wildcard DNS record like `*.example.com` for your VPS's public IP, then you probably have an nginx or caddy HTTP route for your controller like `zrok.example.com zrok-controller:18080`.

Are you following one of the self-hosting guides, like for Linux, Docker, or Kubernetes?

[https://docs.zrok.io/docs/category/self-hosting/](https://docs.zrok.io/docs/category/self-hosting/)

---

<div class="post-metadata">

**Author:** ![Kiwi\_Emotivo968](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/kiwi_emotivo968/32/2781_2.png) [@Kiwi\_Emotivo968](https://openziti.discourse.group/u/Kiwi_Emotivo968)\
**Post date:** [November 20, 2024, 5:44pm UTC](https://openziti.discourse.group/t/error-enableunautorized/3461/7 "2024-11-20T17:44:29Z")

</div>

I'm sorry but I misunderstood the self hosting thing and I'm not self hosting, I'm dumb.  
So, I know the token is correct, what could be the problem?

---

<div class="post-metadata">

**Author:** ![qrkourier](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/qrkourier/32/52_2.png) [@qrkourier](https://openziti.discourse.group/u/qrkourier)\
**Post date:** [November 20, 2024, 5:56pm UTC](https://openziti.discourse.group/t/error-enableunautorized/3461/8 "2024-11-20T17:56:26Z")

</div>

There are two similar-looking tokens that you might have mixed up: registration token and account token.

You need the account token from the zrok web console in [https://api.zrok.io](https://api.zrok.io)

If you're able to log in there and pull down the menu at top-right where it says "Enable your environment," that is the correct token.

If you're already using that token it could be a strange copy/paste or text encoding issue, or maybe one of the characters got dropped along the way.

Are you placing the account token on your clipboard then right-clicking in the Windows terminal to paste?

If all else fails, especially if your Windows environment is the first one you tried to enable, you can rotate your account token to get another one like this:

 ![image](https://global.discourse-cdn.com/free1/uploads/netfoundry/original/2X/7/7cba73ba198a3e1bf1fd287238b5b68d42b20b5f.png)

---

<div class="post-metadata">

**Author:** ![Kiwi\_Emotivo968](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/kiwi_emotivo968/32/2781_2.png) [@Kiwi\_Emotivo968](https://openziti.discourse.group/u/Kiwi_Emotivo968)\
**Post date:** [November 20, 2024, 6:03pm UTC](https://openziti.discourse.group/t/error-enableunautorized/3461/9 "2024-11-20T18:03:31Z")

</div>

I regenerated my account token and when I went to the '${HOME}/.zrok/environment.json' for updating the files I didn't find the 'enviroment.json' file.

---

<div class="post-metadata">

**Author:** ![qrkourier](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/qrkourier/32/52_2.png) [@qrkourier](https://openziti.discourse.group/u/qrkourier)\
**Post date:** [November 20, 2024, 6:04pm UTC](https://openziti.discourse.group/t/error-enableunautorized/3461/10 "2024-11-20T18:04:52Z")

</div>

Are you using Powershell or CMD prompt for your Windows terminal? We'll need to translate the UNIX `${HOME}` to something the Windows terminal understands.

---

<div class="post-metadata">

**Author:** ![Kiwi\_Emotivo968](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/kiwi_emotivo968/32/2781_2.png) [@Kiwi\_Emotivo968](https://openziti.discourse.group/u/Kiwi_Emotivo968)\
**Post date:** [November 20, 2024, 6:07pm UTC](https://openziti.discourse.group/t/error-enableunautorized/3461/11 "2024-11-20T18:07:42Z")

</div>

I did not use the command, I went to the folder and the file wasn't there.

---

<div class="post-metadata">

**Author:** ![qrkourier](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/qrkourier/32/52_2.png) [@qrkourier](https://openziti.discourse.group/u/qrkourier)\
**Post date:** [November 20, 2024, 6:11pm UTC](https://openziti.discourse.group/t/error-enableunautorized/3461/12 "2024-11-20T18:11:00Z")

</div>

OK, cool. That means the `zrok enable` command never succeeded and you don't need to manually edit `%USERPROFILE%\.zrok\environment.json`.

You're using NetFoundry's default zrok instance, so you don't need to run the `zrok config set` command we discussed earlier since that's only for self-hosters with a custom instance.

I think we're ready to try again with your regenerated zrok account token.

```cmd
C:\> zrok enable ACCOUNT_TOKEN_HERE

```

---

<div class="post-metadata">

**Author:** ![Kiwi\_Emotivo968](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/kiwi_emotivo968/32/2781_2.png) [@Kiwi\_Emotivo968](https://openziti.discourse.group/u/Kiwi_Emotivo968)\
**Post date:** [November 20, 2024, 6:15pm UTC](https://openziti.discourse.group/t/error-enableunautorized/3461/13 "2024-11-20T18:15:23Z")

</div>

It returns the same error even with the new token, in my main pc now it won't connect to the eviroment and has the same error.

---

<div class="post-metadata">

**Author:** ![Kiwi\_Emotivo968](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/kiwi_emotivo968/32/2781_2.png) [@Kiwi\_Emotivo968](https://openziti.discourse.group/u/Kiwi_Emotivo968)\
**Post date:** [November 20, 2024, 6:20pm UTC](https://openziti.discourse.group/t/error-enableunautorized/3461/14 "2024-11-20T18:20:08Z")

</div>

ok I re-re generated the token now it function!! Thanks for the help!

---

<div class="post-metadata">

**Author:** ![qrkourier](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/qrkourier/32/52_2.png) [@qrkourier](https://openziti.discourse.group/u/qrkourier)\
**Post date:** [November 20, 2024, 6:22pm UTC](https://openziti.discourse.group/t/error-enableunautorized/3461/15 "2024-11-20T18:22:14Z")

</div>

Oh good! Yay.

For the next person, another thing that can cause this problem is too many environments. Each hosted [zrok.io](http://zrok.io) plan has limits on the number of environments, so you might need to clean up one to make a new one.

Have fun and let us know if you get stuck again.
