DevNet Associate (DEVASC) v1.0Understanding and Using APIsMedium
A network engineer is debugging a Python script that interacts with a Cisco DNA Center API. The script is consistently failing with an HTTP 401 Unauthorized error, even though the API key used is known to be correct and active. The engineer suspects an issue with how the authentication token is being sent. Which of the following HTTP headers is typically used to send bearer tokens for API authentication?
- AContent-Type
- BUser-Agent
- CAccept
- DAuthorization
Show answer & explanationAnswer & explanation
Correct answer: D. Authorization
The Authorization header is the standard HTTP header used to send authentication credentials, including bearer tokens, to the server. An incorrect or missing Authorization header would lead to a 401 Unauthorized error.
Why the other options are wrong
- A. Content-Type specifies the media type of the resource in the request body.
- B. User-Agent identifies the client software originating the request.
- C. Accept specifies the media types that the client is able to process.
HTTP Authorization Header
The Authorization HTTP header is used to carry authentication credentials (like API keys, bearer tokens) from the client to the server to prove identity.
- Carries authentication credentials.
- Commonly prefixed with 'Bearer' for tokens.
- Crucial for authenticated API requests.
Memory trick: Authorization is the 'key' to access.