# Cannot create user

**URL:** <https://community.influxdata.com/t/cannot-create-user/29029>\
**Category:** InfluxDB 2\
**Created:** [March 12, 2023, 10:50am UTC](https://community.influxdata.com/t/cannot-create-user/29029 "2023-03-12T10:50:12Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![silmaril](https://avatars.discourse-cdn.com/v4/letter/s/da6949/32.png) [@silmaril](https://community.influxdata.com/u/silmaril)\
**Post date:** [March 12, 2023, 10:50am UTC](https://community.influxdata.com/t/cannot-create-user/29029/1 "2023-03-12T10:50:12Z")

</div>

I’m currently setting up my first InfluxDB2 instance and got stuck in the user setup process.

The setup worked fine for all things I could do in the UI. So currently there is one user and there are two organizations.  
An “All Access API Token” exists for this user in each of the organizations.

The CLI command

```auto
influx org list -t TOKEN

```

works as expected: depending on the token I get one org or the other.

Now I’d like to create another user:

```auto
influx user create -n USERNAME -o ORGNAME -t TOKEN

```

Depending on which token I use in this command, I get either  
`Error: no organization with name "ORGNAME"` (for the wrong token) or  
`Error: failed to create user "USERNAME": 401 Unauthorized: write:users is unauthorized` (for the correct token).

It seems those tokens don’t have enough privileges to create new users.

Do I need to create some kind of “administrative token”?  
What am I missing?

---

<div class="post-metadata">

**Author:** ![silmaril](https://avatars.discourse-cdn.com/v4/letter/s/da6949/32.png) [@silmaril](https://community.influxdata.com/u/silmaril)\
**Post date:** [March 12, 2023, 12:08pm UTC](https://community.influxdata.com/t/cannot-create-user/29029/2 "2023-03-12T12:08:24Z")

</div>

I think I got a bit further and found out that I need an operator token, which cannot be created from the UI.

So I tried to follow this documentation:

> **[Create an API token in InfluxDB | InfluxDB Cloud Documentation](https://docs.influxdata.com/influxdb/v2.6/security/tokens/create-token/)**
>
> Create an API token in InfluxDB using the InfluxDB UI, the influx CLI, or the InfluxDB API.

It states that there is a bug, which means I have to use a lengthy command to get the token I need:

```auto
influx auth create --org ORGNAME \
                      --read-authorizations \
                      --write-authorizations \
                      --read-buckets \
                      --write-buckets \
                      --read-dashboards \
                      --write-dashboards \
                      --read-tasks \
                      --write-tasks \
                      --read-telegrafs \
                      --write-telegrafs \
                      --read-users \
                      --write-users \
                      --read-variables \
                      --write-variables \
                      --read-secrets \
                      --write-secrets \
                      --read-labels \
                      --write-labels \
                      --read-views \
                      --write-views \
                      --read-documents \
                      --write-documents \
                      --read-notificationRules \
                      --write-notificationRules \
                      --read-notificationEndpoints \
                      --write-notificationEndpoints \
                      --read-checks \
                      --write-checks \
                      --read-dbrp \
                      --write-dbrp \
                      --read-annotations \
                      --write-annotations \
                      --read-sources \
                      --write-sources \
                      --read-scrapers \
                      --write-scrapers \
                      --read-notebooks \
                      --write-notebooks \
                      --read-remotes \
                      --write-remotes \
                      --read-replications \
                      --write-replications \
                      --read-orgs \
                      --write-orgs

```

But this does not succeed, either, because on the command line I am lacking privileges:

```auto
Error: could not write auth with provided arguments: 403 Forbidden: permission read:users is not allowed: read:users is unauthorized

```

So it seems I cannot create an operator token, because I am lacking an operator token to create it?

How to solve this?

---

<div class="post-metadata">

**Author:** ![Anaisdg](https://sea1.discourse-cdn.com/flex023/user_avatar/community.influxdata.com/anaisdg/32/6401_2.png) [@Anaisdg](https://community.influxdata.com/u/Anaisdg)\
**Post date:** [March 19, 2023, 7:57pm UTC](https://community.influxdata.com/t/cannot-create-user/29029/3 "2023-03-19T19:57:42Z")

</div>

Hello @silmaril,  
What version of InfluxDB are you using?  
I believe this is solved in later versions but see:

> [@Creating a new Operator token: InfluxDB V2.0](https://community.influxdata.com/t/creating-a-new-operator-token-influxdb-v2-0/20559/3):
>
> Hi @Anaisdg I’m using version 2.0.7 Regarding the creation of the token with the UI it does not allow the creation of an Operator token which is the one I need. It only allows the creation of an all access token or a read/write token, neither allow performing certain operations like adding a new user, backups and others.

---

<div class="post-metadata">

**Author:** ![Anaisdg](https://sea1.discourse-cdn.com/flex023/user_avatar/community.influxdata.com/anaisdg/32/6401_2.png) [@Anaisdg](https://community.influxdata.com/u/Anaisdg)\
**Post date:** [March 19, 2023, 7:58pm UTC](https://community.influxdata.com/t/cannot-create-user/29029/4 "2023-03-19T19:58:45Z")

</div>

In later versions you can create an operator token like so:

> **[Create an API token in InfluxDB | InfluxDB Cloud Documentation](https://docs.influxdata.com/influxdb/v2.6/security/tokens/create-token/#create-an-operator-token)**
>
> Create an API token in InfluxDB using the InfluxDB UI, the influx CLI, or the InfluxDB API.

---

<div class="post-metadata">

**Author:** ![bchhabra](https://avatars.discourse-cdn.com/v4/letter/b/a88e4f/32.png) [@bchhabra](https://community.influxdata.com/u/bchhabra)\
**Post date:** [May 22, 2024, 6:33pm UTC](https://community.influxdata.com/t/cannot-create-user/29029/5 "2024-05-22T18:33:01Z")

</div>

Dear @Anaisdg  
I dont think we can create operator token from ui. The page you refer only talks about steps to create a read only or all access token. There is no option to specify an operator token.

can you please help with concrete info on how to create an additional user, this seems a kind of chicken and egg situation.

Best regards  
B
