Cisco CCNA (200-301)Automation and ProgrammabilityMedium
A developer must authenticate to a Cisco DNA Center REST API before making configuration calls. The API documentation states that after submitting valid credentials, the server returns a token that must be included in the header of all subsequent requests. Which HTTP header is typically used to pass this token for authentication?
- AAccept
- BUser-Agent
- CContent-Type
- DX-Auth-Token
Show answer & explanationAnswer & explanation
Correct answer: D. X-Auth-Token
Many controller REST APIs, including Cisco DNA Center, use a custom header such as 'X-Auth-Token' to carry the authentication token obtained from a login/token request. This token must be included in the header of subsequent API calls to prove the caller is authorized.
Why the other options are wrong
- A. Accept specifies the desired response format, not credentials.
- B. User-Agent identifies the client application, not authentication data.
- C. Content-Type describes the format of the request body, not authentication.
Token-Based API Authentication
An authentication method where a client submits credentials once, receives a token, and then includes that token in a header (e.g., X-Auth-Token) on subsequent API requests instead of resending credentials.
- Reduces repeated transmission of passwords
- Tokens often expire and must be refreshed
- Cisco DNA Center uses X-Auth-Token after a POST to /dna/system/api/v1/auth/token
Memory trick: Get the key once, flash it in every header after.