# API response "unauthorized"

**URL:** <https://community.awork.com/t/api-response-unauthorized/696>\
**Category:** Developer Forum\
**Created:** [5. März 2024 um 16:00 UTC](https://community.awork.com/t/api-response-unauthorized/696 "2024-03-05T16:00:38Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![sh1](https://avatars.discourse-cdn.com/v4/letter/s/e9a140/32.png) [@sh1](https://community.awork.com/u/sh1)\
**Post date:** [5. März 2024 um 16:00 UTC](https://community.awork.com/t/api-response-unauthorized/696/1 "2024-03-05T16:00:39Z")

</div>

Hi all,

ich experimentiere seit heute mit der AWORK API via Postman. Leider erhalten ich bei jedem Request (z.B. GET /users oder POST /projecttimebookings; URL: [https://api.awork.com/api/v1](https://api.awork.com/api/v1)) eine Response:  
{  
„message“: „Unauthorized“  
}

Ich habe:

- als Admin User einen API Client Token erstellt
- den Token als Bearer in den Header eingefügt

Muss ich irgendwo weitere Berechtigungen setzen/die API aktivieren?

Beste Grüße, Sebastian

---

<div class="post-metadata">

**Author:** ![Sebastian](https://dub1.discourse-cdn.com/flex013/user_avatar/community.awork.com/sebastian/32/89_2.png) [@Sebastian](https://community.awork.com/u/Sebastian)\
**Post date:** [5. März 2024 um 16:05 UTC](https://community.awork.com/t/api-response-unauthorized/696/2 "2024-03-05T16:05:33Z")

</div>

Hi @sh1, kannst du bitte einen cURL deines Requests posten und den Token unkenntlich machen? Dann kann ich besser sehen wo der Fehler liegt. Danke

---

<div class="post-metadata">

**Author:** ![sh1](https://avatars.discourse-cdn.com/v4/letter/s/e9a140/32.png) [@sh1](https://community.awork.com/u/sh1)\
**Post date:** [5. März 2024 um 16:11 UTC](https://community.awork.com/t/api-response-unauthorized/696/3 "2024-03-05T16:11:49Z")

</div>

curl --location ‚[https://api.awork.com/api/v1/users](https://api.awork.com/api/v1/users)‘ \

–header ‚Authorization: Bearer \*\*\*‘

---

<div class="post-metadata">

**Author:** ![sh1](https://avatars.discourse-cdn.com/v4/letter/s/e9a140/32.png) [@sh1](https://community.awork.com/u/sh1)\
**Post date:** [5. März 2024 um 16:13 UTC](https://community.awork.com/t/api-response-unauthorized/696/4 "2024-03-05T16:13:29Z")

</div>

Der Fehler ist mittlerweile:  
{  
„message“: „Bad token; invalid JSON“  
}

---

<div class="post-metadata">

**Author:** ![Nils](https://dub1.discourse-cdn.com/flex013/user_avatar/community.awork.com/nils/32/96_2.png) [@Nils](https://community.awork.com/u/Nils)\
**Post date:** [5. März 2024 um 16:13 UTC](https://community.awork.com/t/api-response-unauthorized/696/5 "2024-03-05T16:13:37Z")

</div>

Was sind die ersten beiden Buchstaben deines Bearer Tokens?

---

<div class="post-metadata">

**Author:** ![sh1](https://avatars.discourse-cdn.com/v4/letter/s/e9a140/32.png) [@sh1](https://community.awork.com/u/sh1)\
**Post date:** [5. März 2024 um 16:14 UTC](https://community.awork.com/t/api-response-unauthorized/696/6 "2024-03-05T16:14:53Z")

</div>

Der Token beginnt mit „ta“

---

<div class="post-metadata">

**Author:** ![Nils](https://dub1.discourse-cdn.com/flex013/user_avatar/community.awork.com/nils/32/96_2.png) [@Nils](https://community.awork.com/u/Nils)\
**Post date:** [5. März 2024 um 16:16 UTC](https://community.awork.com/t/api-response-unauthorized/696/7 "2024-03-05T16:16:55Z")

</div>

Dann hast du nicht den richtigen Token verwendet. Der Token muss mit `ey` beginnen. Kann es sein, dass du das Client Secret verwendet hast? Hier ist noch einmal die Step by Step Anleitung: [Authentication - awork.com](https://developers.awork.com/authentication)

---

<div class="post-metadata">

**Author:** ![sh1](https://avatars.discourse-cdn.com/v4/letter/s/e9a140/32.png) [@sh1](https://community.awork.com/u/sh1)\
**Post date:** [5. März 2024 um 16:20 UTC](https://community.awork.com/t/api-response-unauthorized/696/8 "2024-03-05T16:20:58Z")

</div>

Danke für die Unterstützung!

Ich habe das Client Secret statt dem API Token verwendet 😵‍💫

---

<div class="post-metadata">

**Author:** ![Nils](https://dub1.discourse-cdn.com/flex013/user_avatar/community.awork.com/nils/32/96_2.png) [@Nils](https://community.awork.com/u/Nils)\
**Post date:** [5. März 2024 um 16:21 UTC](https://community.awork.com/t/api-response-unauthorized/696/9 "2024-03-05T16:21:52Z")

</div>

Gerne! Viel Spaß mit der API 🙂

---

<div class="post-metadata">

**Author:** ![it12](https://avatars.discourse-cdn.com/v4/letter/i/ea5d25/32.png) [@it12](https://community.awork.com/u/it12)\
**Post date:** [8. Oktober 2024 um 20:19 UTC](https://community.awork.com/t/api-response-unauthorized/696/10 "2024-10-08T20:19:54Z")

</div>

Hallo und sorry, dass ich den Thread nochmals öffne. Ich bin, wie sh1 auch, dabei mit der api und postman zu experimentieren.  
Dazu hab ich auch den API-Key angelegt. Wenn ich das korrekt verstehe, muss ich nun einen OAuth-AccessToken generieren. Dazu hab ich für den authorization code folgenden request: curl ‚[https://api.awork.com/api/v1/accounts/authorize?client\_id=%client-ID%&response\_type=code&grant\_type=authorization\_code&redirect\_uri=http%3A%2F%2Flocalhost&scope=offline\_access](https://api.awork.com/api/v1/accounts/authorize?client_id=%25client-ID%25&response_type=code&grant_type=authorization_code&redirect_uri=http%3A%2F%2Flocalhost&scope=offline_access)‘   
–header ‚Content-Type: application/x-www-form-urlencoded‘ \

als response bekomme ich hier eine http-seite zurück.  
ich habe die generierte Url auch in den Browser gepastet und dort consent eingegeben.

könnt ihr mir bitte helfen und sagen, was ich hier falsch machen?  
danke!

---

<div class="post-metadata">

**Author:** ![Nils](https://dub1.discourse-cdn.com/flex013/user_avatar/community.awork.com/nils/32/96_2.png) [@Nils](https://community.awork.com/u/Nils)\
**Post date:** [8. Oktober 2024 um 20:29 UTC](https://community.awork.com/t/api-response-unauthorized/696/11 "2024-10-08T20:29:49Z")

</div>

Hi @it12 ,

es gibt zwei Wege die API zu benutzen:

1. Mit einem fixen Bearer Token den du im Ui in awork generieren kannst (nicht das Client Secret). Siehe hier: [Authentication — awork API | Documentation](https://developers.awork.com/authentication?_gl=1*16c5qfr*_gcl_au*Mzc3MDYxOTgyLjE3MjgwMzcxMjkuMjExMTczMjY5Ni4xNzI4NDAxODU0LjE3Mjg0MDE4NTQ.*_ga*MjQyODA2NTQwLjE3MjgwNjk3MTk.*_ga_3GHX1B7SVZ*MTcyODQxOTMwNi4zLjAuMTcyODQxOTMwNi42MC4wLjA.#api-key)
2. Über den Oauth Flow für deinen User. Dafür musst du den Oauth Flow implementieren (deutlich komplizierter).

Reicht für deinen Fall nicht ein fixer token?

Grüße

Nils

---

<div class="post-metadata">

**Author:** ![it12](https://avatars.discourse-cdn.com/v4/letter/i/ea5d25/32.png) [@it12](https://community.awork.com/u/it12)\
**Post date:** [9. Oktober 2024 um 06:21 UTC](https://community.awork.com/t/api-response-unauthorized/696/12 "2024-10-09T06:21:08Z")

</div>

Hallo Nils, danke für die fixe Antwort!  
ich würde gerne Weg 1 nutzen, hab aber keine Idee, wie ich mit dem Client-Secret einen fixen Token machen kann. in der Doku steht:

### Using the API Key

To authenticate with and receive resources from the API, add the `API Key` to the `Authorization` header in the following form: Authorization: Bearer {api\_key}

aber welche API muss ich aufrufen, um mit dem api\_key das Token zu bekommen?

---

<div class="post-metadata">

**Author:** ![Sebastian](https://dub1.discourse-cdn.com/flex013/user_avatar/community.awork.com/sebastian/32/89_2.png) [@Sebastian](https://community.awork.com/u/Sebastian)\
**Post date:** [9. Oktober 2024 um 07:13 UTC](https://community.awork.com/t/api-response-unauthorized/696/13 "2024-10-09T07:13:23Z")

</div>

Hi @it12, the developer docs have a step by step instructions with screenshots on how to get a static token: [Authentication — awork API | Documentation](https://developers.awork.com/authentication#api-key)

You then use this token in every request. You don’t need an client id or client secret in this case at all.

---

<div class="post-metadata">

**Author:** ![it12](https://avatars.discourse-cdn.com/v4/letter/i/ea5d25/32.png) [@it12](https://community.awork.com/u/it12)\
**Post date:** [9. Oktober 2024 um 07:33 UTC](https://community.awork.com/t/api-response-unauthorized/696/14 "2024-10-09T07:33:33Z")

</div>

Hi @Sebastian, thank you for your response. Unfortunatelly, i am not smart enough to find out how it works. So it would be great if you could help me. Obviously, linking 2 times to the same documenation does not really help me!  
maybe a screenshot or the headline of the relevant part in the documentation would help?! If I navigate to Settings-\> Integration in the UI, then I am only able to create an API-Client with a name/id/secret/redirct-uri. I can not find a button which states: „click here to create a static token“.  
Thank you!

---

<div class="post-metadata">

**Author:** ![Sebastian](https://dub1.discourse-cdn.com/flex013/user_avatar/community.awork.com/sebastian/32/89_2.png) [@Sebastian](https://community.awork.com/u/Sebastian)\
**Post date:** [9. Oktober 2024 um 07:45 UTC](https://community.awork.com/t/api-response-unauthorized/696/15 "2024-10-09T07:45:13Z")

</div>

I am pasting a screenshot of the developer docs here where it shows the exact buttons to click. I hope this helps.

 ![Screenshot 2024-10-09 at 09.44.12](https://europe1.discourse-cdn.com/flex013/uploads/awork1/original/1X/c17318c5c399a78bcff9f8d66bb49fdb2ea7790a.jpeg)

---

<div class="post-metadata">

**Author:** ![it12](https://avatars.discourse-cdn.com/v4/letter/i/ea5d25/32.png) [@it12](https://community.awork.com/u/it12)\
**Post date:** [9. Oktober 2024 um 07:59 UTC](https://community.awork.com/t/api-response-unauthorized/696/16 "2024-10-09T07:59:50Z")

</div>

Thank you @Sebastian,  
this brings me back to the beginning. If i use this API-Key (which starts with ‚qO‘) for the request (e.g. B. [https://api.awork.com/api/v1/projects](https://api.awork.com/api/v1/projects) -H „Authorization: Bearer %api-key%“) then i also get a 401 (like SH1 did). Therefore, I assume that I have to use the api-key to generate such a token.

---

<div class="post-metadata">

**Author:** ![Sebastian](https://dub1.discourse-cdn.com/flex013/user_avatar/community.awork.com/sebastian/32/89_2.png) [@Sebastian](https://community.awork.com/u/Sebastian)\
**Post date:** [9. Oktober 2024 um 08:05 UTC](https://community.awork.com/t/api-response-unauthorized/696/17 "2024-10-09T08:05:52Z")

</div>

The API keys start with `ey` so you’re most likely not using the API key.

---

<div class="post-metadata">

**Author:** ![Sebastian](https://dub1.discourse-cdn.com/flex013/user_avatar/community.awork.com/sebastian/32/89_2.png) [@Sebastian](https://community.awork.com/u/Sebastian)\
**Post date:** [9. Oktober 2024 um 08:09 UTC](https://community.awork.com/t/api-response-unauthorized/696/18 "2024-10-09T08:09:31Z")

</div>

I created a quick recording to show how to get one.

---

<div class="post-metadata">

**Author:** ![it12](https://avatars.discourse-cdn.com/v4/letter/i/ea5d25/32.png) [@it12](https://community.awork.com/u/it12)\
**Post date:** [9. Oktober 2024 um 08:16 UTC](https://community.awork.com/t/api-response-unauthorized/696/19 "2024-10-09T08:16:19Z")

</div>

I’m embarrassed! I’m sorry that I wasn’t able to read the documentary properly! Sorry and thank you!

---

<div class="post-metadata">

**Author:** ![Sebastian](https://dub1.discourse-cdn.com/flex013/user_avatar/community.awork.com/sebastian/32/89_2.png) [@Sebastian](https://community.awork.com/u/Sebastian)\
**Post date:** [9. Oktober 2024 um 08:24 UTC](https://community.awork.com/t/api-response-unauthorized/696/20 "2024-10-09T08:24:12Z")

</div>

You’re welcome!
