> ## Documentation Index
> Fetch the complete documentation index at: https://developers.authlete.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Interpreting Token Migrator Logs

> Explains what the Token Migrator logs in each phase — initialization, client scope resolution, token migration and shutdown — and what to check when a log reports a problem.

The Token Migrator runs in several phases. This page groups the logs written by the `token-migrator` container by phase, and explains what each log tells you and what to check when a log reports a problem.

This page is based on logs from Token Migrator version `1.4`. When searching the logs, search by message text rather than by class line number (for example instead of `ArgsUtils:113` search for `No batch size provided`), because line numbers are more likely to change between versions.

The logs are grouped into the following phases: initialization, determining in-scope clients, token migration iteration, and shutdown.

## Initialization

### Parsing arguments

These logs show the value of each argument and option in effect. If a provided value is missing or invalid, a `WARN` line shows the default value used instead.

```text theme={null}
WARN [main] com.authlete.token.migrator.config.TokenMigratorConfig:59 - Invalid model version: [], detected database version [V2]
INFO [main] com.authlete.token.migrator.config.TokenMigratorConfig:62 - Using source model version: [V2]
...
INFO [main] com.authlete.token.migrator.etl.audit.AuditLogger:61 - Detected timestamp difference between local time and destination database time: [0]ms
INFO [main] org.springframework.boot.StartupInfoLogger:59 - Started TokenMigratorApplication in 12.499 seconds (process running for 13.802)
...
WARN [main] com.authlete.token.migrator.util.ArgsUtils:113 - No batch size provided, using [10000].
INFO [main] com.authlete.token.migrator.util.ArgsUtils:188 - Using batch-size [10000]
WARN [main] com.authlete.token.migrator.util.ArgsUtils:68 - No poll-interval provided, using 10000ms.
INFO [main] com.authlete.token.migrator.util.ArgsUtils:191 - Using poll-interval 10000ms.
WARN [main] com.authlete.token.migrator.util.ArgsUtils:57 - Failed to create migration directory, using default directory path /mapping-output
INFO [main] com.authlete.token.migrator.util.ArgsUtils:194 - Writing migration configuration output files to folder [/migrator/./mapping-output]
INFO [main] com.authlete.token.migrator.util.ArgsUtils:198 - No client IDs specified via the command line. In scope client's IDs will be determined by any common clients with the same client ID in the source and destination databases.
WARN [main] com.authlete.token.migrator.util.ArgsUtils:91 - No timestamp provided, using 0.
INFO [main] com.authlete.token.migrator.util.ArgsUtils:205 - Retrieving token creation and update events after timestamp: [0] as date: [1970-01-01 00:00:00.0]
WARN [main] com.authlete.token.migrator.util.ArgsUtils:162 - No audit log period provided, using [4].
INFO [main] com.authlete.token.migrator.util.ArgsUtils:213 - Using audit log period [4] hours.
...
INFO [main] com.authlete.token.migrator.tasks.MigrationTask:115 - Detected timestamp difference between local time and source database time: [0]ms
```

### Client credentials client resolution (audit log client)

The Token Migrator uses client credentials to verify that it can access the destination Authlete 3.0 environment. This check acts as a control: token migration is performed only while these credentials are valid. During initialization, the Token Migrator calls the Process Token Request API of the destination Authlete 3.0 server with the client credentials grant. If it obtains an access token, initialization continues; otherwise the Token Migrator stops.

The resolved client from the configured credentials is also used on behalf of the Token Migrator to create audit log events. All token change events performed by the Token Migrator are linked to this client.

When an access token is obtained, logs like the following are written during startup:

```text theme={null}
INFO [main] com.authlete.token.migrator.auth.CredentialValidator:95 - Resolved client credentials to client id: [<client-id>] in service with number [<service-number>].
INFO [main] com.authlete.token.migrator.TokenMigratorApplication:67 - Provided client credentials were used to successfully retrieve an access token from [https://<api-host>/api/<service-id>/auth/token]
```

The following examples show only the message part of each log line.

If a required credential property is not configured, an error such as the following is logged:

* `token_request_url` (set automatically via the Helm Chart)

  ```text theme={null}
  No `token_request_url` provided
  ```

* `service_token` (set by the `tokenmigrator.serviceToken` credential in the `authlete-credentials-secret.yml` secrets):

  ```text theme={null}
  No `service_token` provided
  ```

If the client's credentials cannot be validated, one of the following errors is logged with the reason. Check the client's configuration in the destination environment and the credentials provided to the Token Migrator. The exact message depends on the error:

Generic error, accompanied by a more detailed error message:

```text theme={null}
Retrieved access token is null from access token retrieval endpoint.
```

The service specified by `tokenmigrator.serviceApiKey` in the `authlete-credentials-secret.yml` secrets does not exist in the destination database:

```text theme={null}
Expected service with api key [<service-id>] to exist in destination database, but it does not.
```

The client with the configured alias does not exist (default alias is expected to be `migration-service@system.authlete.com` and cannot be changed in the Helm Chart):

```text theme={null}
Expected client with client alias: [<alias>] to exist in destination database, but it does not.
```

The Process Token Request API returned an HTTP status other than 200:

```text theme={null}
Failed to retrieve access token, received status code [<status-code>] and response [<response-body>]
```

The response from the Process Token Request API does not contain the `accessToken` property:

```text theme={null}
Failed to retrieve access token, response body did not contain 'accessToken' property. Response [<response-body>]
```

### Dry run indication

When the Token Migrator runs in dry run mode (`tokenmigrator.mode: dryrun` in `values.yaml`), no tokens are written, and the following log is written during initialization to confirm that dry run is enabled:

```text theme={null}
Skipping access token updates because the dry run flag is enabled.
```

### Moving timestamp confirmation

When the Token Migrator restarts and continues from where it left off, it logs a non-zero moving timestamp. This value is the last recovery point that the Token Migrator saved, and it looks for token changes after this point. See [Stopping and Resuming the Token Migrator](/deployment-and-operations/self-managed-deployment/token-migrator/stopping-and-resuming-token-migrator) for details.

```text theme={null}
INFO [main] com.authlete.token.migrator.tasks.SyncTask:185 - Read in moving timestamp initial value [1784401524667]ms
```

***

## Determining in-scope clients

After initialization succeeds, the Token Migrator moves on to the migration phase, starting with resolving the clients that are in scope for migration.
The Token Migrator logs each new client that it detects and adds to the scope. Tokens of in-scope clients are checked and migrated when they are created or updated.

The Token Migrator also logs when clients are removed from the scope.

Each client is identified as `<service ID>:<client ID>`, for example `170886802516:143761865171655`.

### Initial client and service state

After initialization, the current service and client state is logged once at the start of the migration phase:

```text theme={null}
INFO [main] com.authlete.token.migrator.etl.processor.ServiceAndClientMapper:65 - Initializing Client and Service ID mapping...
INFO [main] com.authlete.token.migrator.etl.processor.ServiceAndClientMapper:129 - Found [58166] clients in source database
INFO [main] com.authlete.token.migrator.etl.processor.ServiceAndClientMapper:137 - Found [50578] in-scope clients in destination database
INFO [main] com.authlete.token.migrator.etl.processor.ServiceAndClientMapper:171 - Found [30] services in source database
INFO [main] com.authlete.token.migrator.etl.processor.ServiceAndClientMapper:187 - Found [32] services in destination database
```

### Clients added to scope

When clients are added to the migration scope, the following log is written. It contains the identifier of every client whose tokens will be considered for migration:

```text theme={null}
INFO [main] com.authlete.token.migrator.tasks.MigrationTask:144 - Found [2] new client IDs to add to migration scope [170886802516:143761865171655, 202488662850:518982711477060]
```

<Note>This message lists every in-scope client and can be very long. It is the complete record of the clients the Token Migrator handles.</Note>

### Clients removed from scope

When clients are removed from the scope, a similar message is written:

```text theme={null}
Removed [2] client(s) from scope [170886802516:143761865171655, 202488662850:518982711477060]
```

### Client secret doesn't match

A client is added to the scope only if its decrypted client secret is the same in the source and destination databases.

If a client meets all other conditions but is excluded only because its client secret does not match, the following warning is logged:

```text theme={null}
WARN [main] com.authlete.token.migrator.util.InScopeClientProvider:120 - Client [49864508303:9419823106018] exists in both database, but is not included in-scope because its client secret does not match.
```

Tokens of the clients in these logs are not migrated. If these logs are present, confirm and update the client secret of the affected clients. If this is logged for all clients, confirm that the client import or creation process keeps the client secret value when it creates the destination clients.

See [Client Token Migration Conditions](/deployment-and-operations/migration-from-existing-system/migrating-settings-from-an-older-version-of-authlete#client-token-migration-conditions) for every condition a client must meet.

***

## Token migration iteration

Next, the Token Migrator retrieves and copies the tokens of each in-scope client.

### Found tokens

For each client, the Token Migrator logs how many tokens it found and will migrate, and the time period that was queried:

```text theme={null}
INFO [main] com.authlete.token.migrator.tasks.MigrationTask:221 - Found [150000] active token(s) for client with ID [49864508303:9184996925979] which have been created or modified after [2026-07-02 02:02:34.0] (1782957754000ms) and before [2026-07-02 02:02:53.0] (1782957773000ms)
```

### Migrating tokens

For each batch of tokens written, the following log shows how many of the written tokens were updated and how many were created:

```text theme={null}
INFO [main] com.authlete.token.migrator.etl.writer.AccessTokenItemWriter:78 - Wrote batch of [10000] token(s) for client ID [49864508303:9184996925979]. [10000] were updated, and [0] were created.
```

When all tokens of a client for the queried time period are migrated, the following log is written, noting the time taken, the client, the number of tokens written, and the queried time period:

```text theme={null}
INFO [main] com.authlete.token.migrator.tasks.MigrationTask:280 - Migrated [150000] token(s) in 531978ms for client with ID [49864508303:9184996925979] which have been created or modified after [2026-07-02 02:02:34.0] (1782957754000ms) and before [2026-07-02 02:02:53.0] (1782957773000ms)
```

***

## Shutdown logs

When the container is stopped, the Token Migrator logs, during shutdown, the last timestamp up to which it successfully processed token changes. You can use this value to recover the point to continue from if the state on the mounted volume is lost.

```text theme={null}
INFO [Thread-1] com.authlete.token.migrator.tasks.SyncTask:92 - Shutting down sync migration task, latest timestamp [1784401524667]ms
```
