# Possible way to access router api?

**URL:** <https://discourse.nodered.org/t/possible-way-to-access-router-api/55148>\
**Category:** Developing Nodes\
**Tags:** http-request\
**Created:** [14 December 2021 06:06 UTC](https://discourse.nodered.org/t/possible-way-to-access-router-api/55148 "2021-12-14T06:06:46Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![alpha815](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/alpha815/32/47825_2.png) [@alpha815](https://discourse.nodered.org/u/alpha815)\
**Post date:** [14 December 2021 06:06 UTC](https://discourse.nodered.org/t/possible-way-to-access-router-api/55148/1 "2021-12-14T06:06:46Z")

</div>

Hi there, hope you guys are doing fine. I am trying to access my LTE modem from node-red, I used the HTTP request node with the basic authentication method but in return, I got an error `125002` which means `wrong session `

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/5/d/5da9c4d9d8bc021021bf0207a9e0b7b738e46834.png)  
 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/e/d/ed7332a5a5e50a063d1d77217b7c01be8c328d89.png)

![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/f/3/f301ea1766f1566f61b7bf50a6d04fcc28f674ba.png)  
this image is from the main.js script from my home router I have downloaded it has all the functions and commands I need.  
I can access `http://192.168.*.*/api/monitoring/traffic-statistics/r/nConnection`  
 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/a/e/ae8bee06ad4aa279587ec30a2de1551f034f4112.png)

from my chrome browser, this API provides everything u need. I need a valid session token for accessing this API, as far I understand I need to provide the password in base64 for a successful login, is there any way to achieve this in node-red. I have uploaded the main.js file to GitHub, the login functions start at line `4947`. [main.js](https://github.com/alpha815/main.js/blob/main/main.js)

---

<div class="post-metadata">

**Author:** ![UnborN](https://avatars.discourse-cdn.com/v4/letter/u/4491bb/32.png) [@UnborN](https://discourse.nodered.org/u/UnborN)\
**Post date:** [14 December 2021 08:47 UTC](https://discourse.nodered.org/t/possible-way-to-access-router-api/55148/2 "2021-12-14T08:47:19Z")

</div>

> [@alpha815](#):
>
> I need to provide the password in base64 for a successful login

hello .. if the question is about converting the password to base64 then nodejs provides some methods to achieve this in a Function node.

**Example:**

```auto
let password = "Hello World"

msg.payload = Buffer.from(password).toString('base64')

return msg;

```

**Test Flow:**

```auto
[{"id":"33eef32a2ab48099","type":"function","z":"54efb553244c241f","name":"base64","func":"\nlet password = \"Hello World\"\n\nmsg.payload = Buffer.from(password).toString('base64')\n\nreturn msg;","outputs":1,"noerr":0,"initialize":"","finalize":"","libs":[],"x":410,"y":960,"wires":[["f47e1d154a28919b"]]},{"id":"8797293b78340b51","type":"inject","z":"54efb553244c241f","name":"","props":[{"p":"payload"},{"p":"topic","vt":"str"}],"repeat":"","crontab":"","once":false,"onceDelay":0.1,"topic":"","payload":"","payloadType":"date","x":240,"y":960,"wires":[["33eef32a2ab48099"]]},{"id":"f47e1d154a28919b","type":"debug","z":"54efb553244c241f","name":"","active":true,"tosidebar":true,"console":false,"tostatus":false,"complete":"payload","targetType":"msg","statusVal":"","statusType":"auto","x":610,"y":960,"wires":[]}]

```

ps. Regarding how you pass that to the http request headers .. you have to provide some more information or documentation of your modems API.

---

<div class="post-metadata">

**Author:** ![alpha815](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/alpha815/32/47825_2.png) [@alpha815](https://discourse.nodered.org/u/alpha815)\
**Post date:** [14 December 2021 10:08 UTC](https://discourse.nodered.org/t/possible-way-to-access-router-api/55148/3 "2021-12-14T10:08:02Z")

</div>

Can you have a look at main.js file i have attack with the post, it contains everything about login functions.

---

<div class="post-metadata">

**Author:** ![UnborN](https://avatars.discourse-cdn.com/v4/letter/u/4491bb/32.png) [@UnborN](https://discourse.nodered.org/u/UnborN)\
**Post date:** [14 December 2021 10:43 UTC](https://discourse.nodered.org/t/possible-way-to-access-router-api/55148/4 "2021-12-14T10:43:28Z")

</div>

What is the brand and model of your LTE modem .. doesnt it have documentation online of how to access its API ? ... instead of trying to decipher a 6000 line javascript file ? 😉

---

<div class="post-metadata">

**Author:** ![alpha815](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/alpha815/32/47825_2.png) [@alpha815](https://discourse.nodered.org/u/alpha815)\
**Post date:** [14 December 2021 11:06 UTC](https://discourse.nodered.org/t/possible-way-to-access-router-api/55148/5 "2021-12-14T11:06:21Z")

</div>

yeah, there is some GitHub repo [huawei-lte-api](https://github.com/Salamek/huawei-lte-api) that contains complete documentation on Huawei LTE API, mostly written in python. the device I am using is not supported yet. it should be fairly easy to access device API with HTTP post request, including user name and password encoded in base64.

```auto
 http://192.168.1.1/api/user/login\
 --data "<?xml version=""1.0"" encoding=""UTF-8""?><request>\
<Username>admin</Username>\
<Password>password in base-64</Password>
<password_type>4</password_type>
</request>" --compressed

<?xml version="1.0" encoding="UTF-8"?><response>OK</response>

```

this is how I am supposed to make an HTTP post request and I can't figure it out yet. this will authenticate me to the device from then I will be able to make further requests to access API

---

<div class="post-metadata">

**Author:** ![UnborN](https://avatars.discourse-cdn.com/v4/letter/u/4491bb/32.png) [@UnborN](https://discourse.nodered.org/u/UnborN)\
**Post date:** [14 December 2021 11:20 UTC](https://discourse.nodered.org/t/possible-way-to-access-router-api/55148/6 "2021-12-14T11:20:02Z")

</div>

instead of python .. there is also this **Nodejs** module by the same developer

> **[GitHub - Salamek/huawei-lte-api-ts: API For huawei LAN/WAN LTE Modems written...](https://github.com/Salamek/huawei-lte-api-ts#readme)**
>
> API For huawei LAN/WAN LTE Modems written in TypeScript - GitHub - Salamek/huawei-lte-api-ts: API For huawei LAN/WAN LTE Modems written in TypeScript

Maybe in a Function node, using the `functionExternalModules` option load the `huawei-lte-api` library and see how it goes.

You can read more about functionExternalModules [here](https://nodered.org/docs/user-guide/writing-functions#using-the-functionexternalmodules-option)

---

<div class="post-metadata">

**Author:** ![alpha815](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/alpha815/32/47825_2.png) [@alpha815](https://discourse.nodered.org/u/alpha815)\
**Post date:** [14 December 2021 11:45 UTC](https://discourse.nodered.org/t/possible-way-to-access-router-api/55148/7 "2021-12-14T11:45:40Z")

</div>

actually there is node-red [Node](https://flows.nodered.org/node/node-red-contrib-huawei-router) provides same functionality but unfortunately my router is not supported and it returns the same error that I described above .

---

<div class="post-metadata">

**Author:** ![alpha815](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/alpha815/32/47825_2.png) [@alpha815](https://discourse.nodered.org/u/alpha815)\
**Post date:** [14 December 2021 11:51 UTC](https://discourse.nodered.org/t/possible-way-to-access-router-api/55148/8 "2021-12-14T11:51:33Z")

</div>

is there anyway to send http request in node -red i described above ?

---

<div class="post-metadata">

**Author:** ![UnborN](https://avatars.discourse-cdn.com/v4/letter/u/4491bb/32.png) [@UnborN](https://discourse.nodered.org/u/UnborN)\
**Post date:** [14 December 2021 13:04 UTC](https://discourse.nodered.org/t/possible-way-to-access-router-api/55148/9 "2021-12-14T13:04:41Z")

</div>

If you run this do you get a reply from the modem ?  
(replace the password)

```auto
[{"id":"6e215f49.aadfe","type":"inject","z":"54efb553244c241f","name":"","props":[{"p":"payload","v":"","vt":"date"},{"p":"topic","v":"","vt":"str"}],"repeat":"","crontab":"","once":false,"onceDelay":0.1,"topic":"","payload":"","payloadType":"date","x":140,"y":1020,"wires":[["e74c77e60cdab6d1"]]},{"id":"2bd2ae1f.24ec22","type":"http request","z":"54efb553244c241f","name":"","method":"POST","ret":"txt","paytoqs":"ignore","url":"http://192.168.1.1/api/user/login","tls":"","persist":false,"proxy":"","authType":"","senderr":false,"x":550,"y":1020,"wires":[["41fb1ba0.9393f4"]]},{"id":"41fb1ba0.9393f4","type":"debug","z":"54efb553244c241f","name":"","active":true,"tosidebar":true,"console":false,"tostatus":false,"complete":"true","targetType":"full","x":710,"y":1020,"wires":[]},{"id":"e74c77e60cdab6d1","type":"function","z":"54efb553244c241f","name":"request","func":"let password = \"your password\" // replace\n\nlet base64pass = Buffer.from(password).toString('base64')\n\nmsg.payload = `<?xml version=\"1.0\" encoding=\"UTF-8\"?>\n<request>\n<Username>admin</Username>\n<Password>${base64pass}</Password>\n<password_type>4</password_type>\n</request>`\n\n\nmsg.headers = { \"Content-Type\": \"text/xml\"}\n\n\nreturn msg;","outputs":1,"noerr":0,"initialize":"","finalize":"","libs":[],"x":320,"y":1020,"wires":[["2bd2ae1f.24ec22","b2bb1968cea6f9f2"]]},{"id":"b2bb1968cea6f9f2","type":"debug","z":"54efb553244c241f","name":"","active":false,"tosidebar":true,"console":false,"tostatus":false,"complete":"true","targetType":"full","x":430,"y":940,"wires":[]}]

```

* * *

Another thing to try is also open your browsers Developer tools, to the network tab, and follow the authentication requests to see what request headers and body is being sent when you login from the browser in order to try to replicate that.

---

<div class="post-metadata">

**Author:** ![alpha815](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/alpha815/32/47825_2.png) [@alpha815](https://discourse.nodered.org/u/alpha815)\
**Post date:** [14 December 2021 13:35 UTC](https://discourse.nodered.org/t/possible-way-to-access-router-api/55148/10 "2021-12-14T13:35:29Z")

</div>

```auto
<?xml version="1.0" encoding="UTF-8"?>
<error>
<code>125002</code>
<message></message>
</error>

```

this is response I get in debug window.

---

<div class="post-metadata">

**Author:** ![alpha815](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/alpha815/32/47825_2.png) [@alpha815](https://discourse.nodered.org/u/alpha815)\
**Post date:** [14 December 2021 14:40 UTC](https://discourse.nodered.org/t/possible-way-to-access-router-api/55148/11 "2021-12-14T14:40:43Z")

</div>

Could not find in chrom but here is wireshark packet dump of login request:

```auto
POST /api/user/login HTTP/1.1
Host: 192.168.1.1
Connection: keep-alive
Content-Length: 224
Accept: */*
DNT: 1
X-Requested-With: XMLHttpRequest
__RequestVerificationToken: uqXDO3yhXUfWACBFj30MY1nbJABZZ9WV
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
Origin: http://192.168.1.1
Referer: http://192.168.1.1/html/home.html
Accept-Encoding: gzip, deflate
Accept-Language: en-US,en;q=0.9
Cookie: SessionID=+S+E2lI3r7jLaiixz5Y9zyZncEpuey9P9U+14rl1zt6KGzu0544QoOO/TxsltiRU5PpUc5YPJrMsKkmO/z09jn0syLZv1VXLRsHulQmCIJbKI48AetePP3f9eTa3v8Mw

<?xml version="1.0" encoding="UTF-8"?><request><Username>admin</Username><Password>ZmUxNzJlY2RiNjU3OWI2ZWE5ODQ5Y2UwN2FmM2NlNzIyNDEyNzhjODQ2Y2ViZWVhMjI1MzFmYzZlNTBiZTgwMw==</Password><password_type>4</password_type></request>HTTP/1.1 200 OK
Date: Thu, 01 Jan 1970 00:00:00 GMT
Server: WebServer
Connection: close
X-Download-Options: noopen
X-Frame-Options: deny
X-XSS-Protection: 1; mode=block
Strict-Transport-Security: max-age=31536000; includeSubdomains
Cache-Control: no-cache, no-store
Pragma: no-cache
Content-Type: text/html
Content-Length: 61
__RequestVerificationTokenone:EIvo+wIeK5BxqMXZ4SB5ORlSfQcsOIiB
__RequestVerificationTokentwo:V6B+RW/lKFzlqcdra75rl8kq9miO4Rri
__RequestVerificationToken:EIvo+wIeK5BxqMXZ4SB5ORlSfQcsOIiB#V6B+RW/lKFzlqcdra75rl8kq9miO4Rri#BgiuY9qIWQdc/2Kd7J6cjbq4Sz8U1w/C#iRFU0TJgPGA4LetXo2XqvP8QjwUuHQp3#DtIm2vuhJtSeGIWiZNo5Y2wYcCVxk2Dh#e6OKio5wKsjMnal+a15l82G0RkYJkRvh#So1rTyT6ReRi/mCph0g1NDv8Ha07YTXf#YnUE5sFBS2h2HHWJrGszXAuB1Q8WkZl8#JH8qO03csRhDqwb6hEzzyF8So/2Bb1eq#o1+1i2sWIpEc1TRkYN7gJF1vIVxCtmpm#hZK2TZuHikvDaOLZmZkWWe/KtuA91meh#j05rfgIX/dO8c38Jpjs6ZcS0gokl8D+d#vVFT8rlaWwWimFnpv62NffpU8Vy5up3y#AXaoGeDYuZKJg5ymMrE946vshhMIy41t#zmoOPny8yHOJWvnZGJNEXjPMCqnokaJ2#iY/SzOm5UK70egNeF7t5AGlKHCVGRpai#C7v0yLvcKUwIiYhk+06ycQ0NqZBkX21+#hIEBjexpgbslZbY1WqXiEaCtVxmCyZeg#dXKR8j4/2n3obarMqypttj5OZSdT31J5#Kd/d2A3pQc6uR4IKpfoJrGIOPIFxf4sx#3ahVvpq4E+FhXre0ROKx6zpeZR20yjFm#SGsei0PZQ7T8+lTvQ4BOe5SBBGbVRp8k#b2cChY7wOV/S2WZ/9Pwmy+Og+2M5BH5g#E+r97Ph/bvRAsUimJNDRU221qQJ22QuQ#kOj2ElRhJLT0V+Z3TowvqQgFUmYdTOZv#qUpq06zigQgehn887zK22AJXMG8WqyLU#+wqBczGUZlbsSe7l1LCLb1iViFD5BkAZ#hzjGrw/nAsKvp++Ct84NjClNYAXIHEl3#POuvZc0y4ubP7S4JyX1oWmBxPuyYCq3d#4dAQdk1CXyQrY57kwsQY8nXvbQOvnEF6#4WB6XMyRsuYUplALMkiW3MNy0x3mR790#CmMhSZZr49qh++BQCPWUPwHpD9ff8KB6#
Set-Cookie:SessionID=LBt42/Xj/vHoYsNyqNJjEe3AaFG2jwTGsVB0KtgjRPqICtIKIH68eOq9oPWc+YWAKwpkUO5po3J65W0t0Z5PcAcUqweRgc6mBGXOy6b9OhBSKQhCmF1Zo9gNQkRxyubI;path=/;HttpOnly;

<?xml version="1.0" encoding="UTF-8"?><response>OK</response>

```

---

<div class="post-metadata">

**Author:** ![UnborN](https://avatars.discourse-cdn.com/v4/letter/u/4491bb/32.png) [@UnborN](https://discourse.nodered.org/u/UnborN)\
**Post date:** [14 December 2021 14:46 UTC](https://discourse.nodered.org/t/possible-way-to-access-router-api/55148/12 "2021-12-14T14:46:02Z")

</div>

I think the above is useful information ..  
in order to get that `__RequestVerificationToken`  
was there previously another **GET** request to `http://192.168.1.1/api/webserver/SesTokInfo` ??

---

<div class="post-metadata">

**Author:** ![alpha815](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/alpha815/32/47825_2.png) [@alpha815](https://discourse.nodered.org/u/alpha815)\
**Post date:** [14 December 2021 14:55 UTC](https://discourse.nodered.org/t/possible-way-to-access-router-api/55148/13 "2021-12-14T14:55:25Z")

</div>

here is a request made by the browser you described above it is not from the same session, I made this request manually by entering the URL in the browser.

```auto
GET /api/webserver/SesTokInfo HTTP/1.1
Host: 192.168.1.1
Connection: keep-alive
Pragma: no-cache
Cache-Control: no-cache
DNT: 1
Upgrade-Insecure-Requests: 1
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9
Accept-Encoding: gzip, deflate
Accept-Language: en-US,en;q=0.9
Cookie: SessionID=Y3cNrpT9g0bFMhCGFs1ko+0KUHgDK6qf57AqhgKMciwWlLah4HF9eta5TbQP/yIbVNTrEu4ZrOL2lAZXpSwX2U3Zeh9CErfRx7awyNkrQKWtMrMwAtTj/5vu8WSimQax

HTTP/1.1 200 OK
Date: Thu, 01 Jan 1970 00:00:00 GMT
Server: WebServer
Connection: keep-alive
Keep-Alive: timeout=10, max=100
X-Download-Options: noopen
X-Frame-Options: deny
X-XSS-Protection: 1; mode=block
Strict-Transport-Security: max-age=31536000; includeSubdomains
Cache-Control: no-cache
Content-Type: text/html
Content-Length: 277

<?xml version="1.0" encoding="UTF-8"?>
<response>
<SesInfo>SessionID=Y3cNrpT9g0bFMhCGFs1ko+0KUHgDK6qf57AqhgKMciwWlLah4HF9eta5TbQP/yIbVNTrEu4ZrOL2lAZXpSwX2U3Zeh9CErfRx7awyNkrQKWtMrMwAtTj/5vu8WSimQax</SesInfo>
<TokInfo>oj08Gj3Ch2VsJ74ILyaApyM6c99nezPg</TokInfo>
</response>

```

and here is the result from the browser.

```auto
<?xml version="1.0" encoding="UTF-8"?>
<response>
<SesInfo>SessionID=Y3cNrpT9g0bFMhCGFs1ko+0KUHgDK6qf57AqhgKMciwWlLah4HF9eta5TbQP/yIbVNTrEu4ZrOL2lAZXpSwX2U3Zeh9CErfRx7awyNkrQKWtMrMwAtTj/5vu8WSimQax</SesInfo>
<TokInfo>oj08Gj3Ch2VsJ74ILyaApyM6c99nezPg</TokInfo>
</response>

```

---

<div class="post-metadata">

**Author:** ![UnborN](https://avatars.discourse-cdn.com/v4/letter/u/4491bb/32.png) [@UnborN](https://discourse.nodered.org/u/UnborN)\
**Post date:** [14 December 2021 15:04 UTC](https://discourse.nodered.org/t/possible-way-to-access-router-api/55148/14 "2021-12-14T15:04:39Z")

</div>

> [@alpha815](#):
>
> ```auto
> <SesInfo>SessionID=Y3cNrpT9g0bFMhCGFs1ko+0KUHgDK6qf57AqhgKMciwWlLah4HF9eta5TbQP/yIbVNTrEu4ZrOL2lAZXpSwX2U3Zeh9CErfRx7awyNkrQKWtMrMwAtTj/5vu8WSimQax</SesInfo>
> <TokInfo>oj08Gj3Ch2VsJ74ILyaApyM6c99nezPg</TokInfo>
> 
> ```

so possibly you need to chain two requests .. one Get request to get the Token and one POST to get the actual information.

Can you show us the msg that you get in **Debug node 1** after you run this ?

```auto
[{"id":"6e215f49.aadfe","type":"inject","z":"54efb553244c241f","name":"","props":[{"p":"payload","v":"","vt":"date"},{"p":"topic","v":"","vt":"str"}],"repeat":"","crontab":"","once":false,"onceDelay":0.1,"topic":"","payload":"","payloadType":"date","x":140,"y":1040,"wires":[["a40a61b15d00928d"]]},{"id":"2bd2ae1f.24ec22","type":"http request","z":"54efb553244c241f","name":"","method":"POST","ret":"txt","paytoqs":"ignore","url":"http://192.168.1.1/api/user/login","tls":"","persist":false,"proxy":"","authType":"","senderr":false,"x":970,"y":1040,"wires":[["41fb1ba0.9393f4"]]},{"id":"41fb1ba0.9393f4","type":"debug","z":"54efb553244c241f","name":"2","active":true,"tosidebar":true,"console":false,"tostatus":false,"complete":"true","targetType":"full","statusVal":"","statusType":"auto","x":1110,"y":1040,"wires":[]},{"id":"e74c77e60cdab6d1","type":"function","z":"54efb553244c241f","name":"request","func":"let password = \"your password\" // replace\n\nlet base64pass = Buffer.from(password).toString('base64')\n\nmsg.payload = `<?xml version=\"1.0\" encoding=\"UTF-8\"?>\n<request>\n<Username>admin</Username>\n<Password>${base64pass}</Password>\n<password_type>4</password_type>\n</request>`\n\n\nmsg.headers = {\n \"Content-Type\": \"text/xml\",\n \"X-Requested-With\": \"XMLHttpRequest\",\n \"__RequestVerificationToken\": \"uqXDO3yhXUfWACBFj30MY1nbJABZZ9WV\"\n}\n\n\nreturn msg;","outputs":1,"noerr":0,"initialize":"","finalize":"","libs":[],"x":800,"y":1040,"wires":[["2bd2ae1f.24ec22"]]},{"id":"b2bb1968cea6f9f2","type":"debug","z":"54efb553244c241f","name":"1","active":true,"tosidebar":true,"console":false,"tostatus":false,"complete":"true","targetType":"full","statusVal":"","statusType":"auto","x":650,"y":960,"wires":[]},{"id":"a40a61b15d00928d","type":"http request","z":"54efb553244c241f","name":"","method":"GET","ret":"txt","paytoqs":"ignore","url":"http://192.168.1.1/api/webserver/SesTokInfo","tls":"","persist":false,"proxy":"","authType":"","senderr":false,"x":310,"y":1040,"wires":[["fd99a01ab6dfe1cf"]]},{"id":"fd99a01ab6dfe1cf","type":"xml","z":"54efb553244c241f","name":"","property":"payload","attr":"","chr":"","x":490,"y":1040,"wires":[["b2bb1968cea6f9f2"]]}]

```

---

<div class="post-metadata">

**Author:** ![Paul-Reed](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/paul-reed/32/66906_2.png) [@Paul-Reed](https://discourse.nodered.org/u/Paul-Reed)\
**Post date:** [14 December 2021 15:08 UTC](https://discourse.nodered.org/t/possible-way-to-access-router-api/55148/15 "2021-12-14T15:08:21Z")

</div>

I access my router - Netgear Nighthawk by running the below in a exec node.  
You'll see that in the first part I save the token as `id`, then use it in the second part of the command to execute `buttonType=2` which reboots my router.

```auto
id=$(wget -q -O- --http-user 'admin' --http-password 'routerPassword' http://192.168.1.1/ADVANCED_home2.htm | perl -lne '/id=([a-f0-9]+)/ && print $1'); wget -O- --http-user 'admin' --http-password 'routerPassword' http://192.168.1.1/newgui_adv_home.cgi?id=$id --post-data "id=$id&buttonType=2";

```

---

<div class="post-metadata">

**Author:** ![alpha815](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/alpha815/32/47825_2.png) [@alpha815](https://discourse.nodered.org/u/alpha815)\
**Post date:** [14 December 2021 15:11 UTC](https://discourse.nodered.org/t/possible-way-to-access-router-api/55148/16 "2021-12-14T15:11:18Z")

</div>

I can send `192.168.1.1/api/webserver/SesTokInfo` with the HTTP request node and the modem replies with token info and session info.

---

<div class="post-metadata">

**Author:** ![alpha815](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/alpha815/32/47825_2.png) [@alpha815](https://discourse.nodered.org/u/alpha815)\
**Post date:** [14 December 2021 15:12 UTC](https://discourse.nodered.org/t/possible-way-to-access-router-api/55148/17 "2021-12-14T15:12:58Z")

</div>

Here is debug output.

`{"_msgid":"8644f7f325613bf0","payload":{"response":{"SesInfo":["SessionID=Baugri5HVuQPwXlvFypdEdxZWIY4GAqvXjzIwMeV4+NNJQiCywAL8JPrJAYwfVPMOzq3Fqoto2WWeaMlBmjRt5Xr5B0v5MwGIRQbc7kAj8+UBb96Gsc6BsjLn88FzVOA"],"TokInfo":["5dN3AQFmhla4tblPoCCAolmhGgWNtwG1"]}},"topic":"","statusCode":200,"headers":{"date":"Thu, 01 Jan 1970 00:00:00 GMT","server":"WebServer","connection":"close","x-download-options":"noopen","x-frame-options":"deny","x-xss-protection":"1; mode=block","strict-transport-security":"max-age=31536000; includeSubdomains","cache-control":"no-cache","content-type":"text/html","content-length":"277","x-node-red-request-node":"40e13dfc"},"responseUrl":"http://192.168.1.1/api/webserver/SesTokInfo","redirectList":[],"retry":0}`

---

<div class="post-metadata">

**Author:** ![UnborN](https://avatars.discourse-cdn.com/v4/letter/u/4491bb/32.png) [@UnborN](https://discourse.nodered.org/u/UnborN)\
**Post date:** [14 December 2021 15:19 UTC](https://discourse.nodered.org/t/possible-way-to-access-router-api/55148/18 "2021-12-14T15:19:23Z")

</div>

With this do you get a reply on Debug 2 ?

We are wiring the Token and SessionID from the GET request and use it for the Login request

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/e/8/e8f996ea47b22b8cf01c8c8291b599ea8f14bc45.png)

```auto
[{"id":"6e215f49.aadfe","type":"inject","z":"54efb553244c241f","name":"","props":[{"p":"payload","v":"","vt":"date"},{"p":"topic","v":"","vt":"str"}],"repeat":"","crontab":"","once":false,"onceDelay":0.1,"topic":"","payload":"","payloadType":"date","x":140,"y":1040,"wires":[["a40a61b15d00928d"]]},{"id":"2bd2ae1f.24ec22","type":"http request","z":"54efb553244c241f","name":"","method":"POST","ret":"txt","paytoqs":"ignore","url":"http://192.168.1.1/api/user/login","tls":"","persist":false,"proxy":"","authType":"","senderr":false,"x":850,"y":1040,"wires":[["41fb1ba0.9393f4"]]},{"id":"41fb1ba0.9393f4","type":"debug","z":"54efb553244c241f","name":"2","active":true,"tosidebar":true,"console":false,"tostatus":false,"complete":"true","targetType":"full","statusVal":"","statusType":"auto","x":1030,"y":1040,"wires":[]},{"id":"e74c77e60cdab6d1","type":"function","z":"54efb553244c241f","name":"request","func":"let password = \"your password\" // replace\nlet token = msg.payload.response.TokInfo[0] // token from XML\nlet sessionID = msg.payload.response.SesInfo[0] // sessionID from XML\n\nlet base64pass = Buffer.from(password).toString('base64')\n\nmsg.payload = `<?xml version=\"1.0\" encoding=\"UTF-8\"?>\n<request>\n<Username>admin</Username>\n<Password>${base64pass}</Password>\n<password_type>4</password_type>\n</request>`\n\n\nmsg.headers = {\n \"Content-Type\": \"application/x-www-form-urlencoded; charset=UTF-8\",\n \"X-Requested-With\": \"XMLHttpRequest\",\n \"__RequestVerificationToken\": token,\n \"Cookie\" : sessionID\n}\n\n\nreturn msg;","outputs":1,"noerr":0,"initialize":"","finalize":"","libs":[],"x":680,"y":1040,"wires":[["2bd2ae1f.24ec22"]]},{"id":"b2bb1968cea6f9f2","type":"debug","z":"54efb553244c241f","name":"1","active":true,"tosidebar":true,"console":false,"tostatus":false,"complete":"true","targetType":"full","statusVal":"","statusType":"auto","x":650,"y":960,"wires":[]},{"id":"a40a61b15d00928d","type":"http request","z":"54efb553244c241f","name":"","method":"GET","ret":"txt","paytoqs":"ignore","url":"http://192.168.1.1/api/webserver/SesTokInfo","tls":"","persist":false,"proxy":"","authType":"","senderr":false,"x":310,"y":1040,"wires":[["fd99a01ab6dfe1cf"]]},{"id":"fd99a01ab6dfe1cf","type":"xml","z":"54efb553244c241f","name":"","property":"payload","attr":"","chr":"","x":490,"y":1040,"wires":[["b2bb1968cea6f9f2","e74c77e60cdab6d1"]]}]

```

---

<div class="post-metadata">

**Author:** ![alpha815](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/alpha815/32/47825_2.png) [@alpha815](https://discourse.nodered.org/u/alpha815)\
**Post date:** [14 December 2021 15:31 UTC](https://discourse.nodered.org/t/possible-way-to-access-router-api/55148/19 "2021-12-14T15:31:45Z")

</div>

Here is debug output, return code `108006` means the wrong password, I have changed the password in the requesting node for sure.  
 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/a/5/a5bb3b2cd49bd5ec5cf7e271e207c3841ee984a6.png)

Debug output.

```auto
<?xml version="1.0" encoding="UTF-8"?>
<error>
<code>108006</code>
<message></message>
</error>

```

---

<div class="post-metadata">

**Author:** ![UnborN](https://avatars.discourse-cdn.com/v4/letter/u/4491bb/32.png) [@UnborN](https://discourse.nodered.org/u/UnborN)\
**Post date:** [14 December 2021 15:41 UTC](https://discourse.nodered.org/t/possible-way-to-access-router-api/55148/20 "2021-12-14T15:41:17Z")

</div>

a different error message ... hurray progress 😄

i dont know whats going on with that base64? password conversion but maybe you could replace it with what you have captured with wireshark

```auto
let base64pass = "ZmUxNzJlY2RiNjU3OWI2ZWE5ODQ5Y2UwN2FmM2NlNzIyNDEyNzhjODQ2Y2ViZWVhMjI1MzFmYzZlNTBiZTgwMw=="

```

[Next page](https://discourse.nodered.org/t/possible-way-to-access-router-api/55148.md?page=2)
