Chasing an "Unauthorized" error led to Google Cloud, a stale setting, and a bug hiding for months
The new AI cover-image button kept failing with "Unauthorized" for no obvious reason. Tracking it down meant real logging, Google Cloud's own command-line tools, and a leftover setting from a product I'd already removed, and it ended with a bug fix that quietly repaired a second, unrelated feature that may never have actually worked.
Tooling note: this session ran on Claude Sonnet 5.
The new "generate a cover image" button kept failing with "Unauthorized," even though I was clearly logged into the admin panel. Tracking it down meant adding real logging, reading Vercel's server logs together, and eventually reaching into Google Cloud's own command-line tools to inspect the actual security settings on the key involved. The answer: one of this project's API keys is deliberately restricted to only accept requests that say they're coming from the real website, a normal security precaution. But the server-to-server call this new feature needed to make doesn't come from a browser at all, so nothing was there to check, and Google's servers blocked it. The fix was one line: supply that expected value ourselves, since we control both sides of the call and know it's legitimate.
Getting to that answer took a detour worth mentioning. Along the way I asked the obvious question: wouldn't it just be easier to switch to a different AI company entirely instead of fighting this? It wouldn't have, and figuring out why is the actual lesson. The problem was never which AI model was drawing the picture, generation had worked perfectly on the very first try, it was a security setting on a completely unrelated key that checks who's allowed to log in as me. Swapping AI providers would have left that exact same wall standing.
Inspecting that setting meant logging into Google Cloud's command line twice (it turns out there are two separate logins, one for the tool itself and one for what it does on your behalf), only to find it was quietly pointed at the wrong project the whole time, a leftover setting from the old "Staffed" product I removed a while back. Old, disconnected work can leave invisible tripwires behind long after you've moved on from it.
Here's the part that actually matters most. That exact same security check has quietly guarded a completely different feature for months, the one that's supposed to instantly refresh a page the moment I approve a story or publish a post. Because that feature swallows its own errors instead of showing them to me, it's entirely possible it's never actually worked, and pages have just been updating on their own within the normal few-minute delay the whole time, silently disguised as the fast version working. One fix, once we finally found it, repaired three separate features at once, because they all shared the same underlying check.
Last, once cover images were generating successfully, I noticed the same full-size file was being sent to every visitor whether it showed up as a big featured image or a small thumbnail, so a quick follow-up now resizes and compresses AI-generated covers automatically for wherever they're actually displayed.
What I learned
- •An error that gets silently swallowed instead of shown to you doesn't mean the thing is broken, it means you genuinely can't tell whether it's broken. Add real logging before you need it, not after.
- •When several features share the same underlying check or piece of code, finding and fixing one real bug in that shared piece fixes all of them at once. It's worth building shared pieces even when it takes an extra step upfront.
- •Before swapping out a tool because something feels too hard, make sure you actually know where the problem lives. This one had nothing to do with the AI model and everything to do with an unrelated security setting; changing providers would have changed nothing.
- •Work you've fully moved on from, a removed product, an old project, can still leave settings behind that quietly interfere with something new and completely unrelated. When a tool behaves strangely, it's worth checking what else is configured in the same place.
- •The fastest way to actually resolve a mystery bug is real logs from the real system, not guessing from reading code. I added logging, then let the system tell me exactly what was happening.