# Odd problem with Bearer Authentication

**URL:** <https://discourse.nodered.org/t/odd-problem-with-bearer-authentication/12422>\
**Category:** General\
**Tags:** security\
**Created:** [20 June 2019 08:00 UTC](https://discourse.nodered.org/t/odd-problem-with-bearer-authentication/12422 "2019-06-20T08:00:48Z")\
**Posts on this page:** 1\
**Page:** 2

<div class="post-metadata">

**Author:** ![AlexKalopsia](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/alexkalopsia/32/7195_2.png) [@AlexKalopsia](https://discourse.nodered.org/u/AlexKalopsia)\
**Post date:** [3 January 2023 14:55 UTC](https://discourse.nodered.org/t/odd-problem-with-bearer-authentication/12422/21 "2023-01-03T14:55:39Z")

</div>

Hi, I am still struggling with this.

First of all, this works:

```auto
curl -i -X PUT -H 'Authorization: Bearer xxxxxxxxxxxx' -H 'Content-Type: application/json' -d '{"id": "xxxxxxxxxxxxxxxx", "message": "I edited this"}' https://xxxxxxxxxxxxx/api/v4/posts/xxxxxxxxxxxxxxxxxxxx

```

Now, whenever I try and do this from NodeRed, i get `403` with payload

```auto
"{"id":"api.context.permissions.app_error","message":"You do not have the appropriate permissions.","detailed_error":"","request_id":"caywpjumijbqdr8jagwd68dwhc","status_code":403}"

```

- I have tried enabling `User authentication` set to `bearer` and passing the token
- I have tried passing the `Authorization` header via the UI
- I have tried passing all headers via code

```auto
var idToken = "xxxxxxxxxxxxxxxxxx"

msg.headers = {}
msg.headers['Authorization'] = "Bearer " + idToken
msg.headers['Content-Type'] = "application/json" 

```

- I have tried passing headers via code, keeping `Basic authentication` with empty user and psw

None of these approaches works. Hope someone can help me out

EDIT: the issue was not with Node-RED but with another service API. I can confirm that passing the bearer via code works just fine

[Previous page](https://discourse.nodered.org/t/odd-problem-with-bearer-authentication/12422.md?page=1)
