Cisco CCNA (200-301)Automation and ProgrammabilityMedium

A developer must authenticate to a Cisco DNA Center REST API before making configuration calls. The API documentation states that after submitting valid credentials, the server returns a token that must be included in the header of all subsequent requests. Which HTTP header is typically used to pass this token for authentication?

  1. AAccept
  2. BUser-Agent
  3. CContent-Type
  4. DX-Auth-Token
Show answer & explanation

Correct answer: D. X-Auth-Token

Many controller REST APIs, including Cisco DNA Center, use a custom header such as 'X-Auth-Token' to carry the authentication token obtained from a login/token request. This token must be included in the header of subsequent API calls to prove the caller is authorized.

Why the other options are wrong

  • A. Accept specifies the desired response format, not credentials.
  • B. User-Agent identifies the client application, not authentication data.
  • C. Content-Type describes the format of the request body, not authentication.

Token-Based API Authentication

An authentication method where a client submits credentials once, receives a token, and then includes that token in a header (e.g., X-Auth-Token) on subsequent API requests instead of resending credentials.

  • Reduces repeated transmission of passwords
  • Tokens often expire and must be refreshed
  • Cisco DNA Center uses X-Auth-Token after a POST to /dna/system/api/v1/auth/token

Memory trick: Get the key once, flash it in every header after.

More Automation and Programmability questions