Skip to content
Cyber Courses

15 min · enseigne: http-headers-use, rest-api-read

Headers and authenticated requests

Send the header an API expects, and a 401 becomes a 200.

APIs use request headers to carry things that don't belong in the URL: the content type, the language, and credentials such as an API key. Send the header the API documents and it authorises your request; omit it and you get a 401.

Add the API key header

Request

GET /api/invoices/INV-20507 HTTP/1.1
Host: portal.globex.example
Accept: application/json

Response

Send the request to see the response.

This is exactly the skill the Supplier portal API lab measures: read the docs, send X-Portal-Key, and read the amount out of the JSON response. A lesson teaches it; a lab proves you can do it for real.