15 min · teaches: http-headers-use, rest-api-read
Headers and authenticated requests
Send the header an API expects, and a 401 becomes a 200.
APIs use request headers to carry things that don't belong in the URL: the content type, the language, and credentials such as an API key. Send the header the API documents and it authorises your request; omit it and you get a 401.
Request
GET /api/invoices/INV-20507 HTTP/1.1
Host: portal.globex.example
Accept: application/jsonResponse
Send the request to see the response.
This is exactly the skill the Supplier portal API lab measures: read the docs, send X-Portal-Key, and read the amount out of the JSON response. A lesson teaches it; a lab proves you can do it for real.