# Using REST API call with http request object

**URL:** <https://discourse.nodered.org/t/using-rest-api-call-with-http-request-object/46985>\
**Category:** General\
**Created:** [10 June 2021 12:42 UTC](https://discourse.nodered.org/t/using-rest-api-call-with-http-request-object/46985 "2021-06-10T12:42:53Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![laurialo](https://avatars.discourse-cdn.com/v4/letter/l/a8b319/32.png) [@laurialo](https://discourse.nodered.org/u/laurialo)\
**Post date:** [10 June 2021 12:42 UTC](https://discourse.nodered.org/t/using-rest-api-call-with-http-request-object/46985/1 "2021-06-10T12:42:53Z")

</div>

Hello !

Foe example i have following curl example tht useses token for authentification

curl --header "Authorization: X-Road-ApiKey token=c6804432-37f8-43e3-b3f1-b7bd0b1ac3b0" "[https://127.0.0.1:4000/api/v1/member-classes](https://127.0.0.1:4000/api/v1/member-classes)" -k

it works as expected and returns:

["COM","NGO","GOV","NEE"]

I tried implement this curl functionality under red-node environment creating flow using the inject , change and http request node.and two debug nodes for debugging

under the change node i implemented following set rules

msg.method get  
msg.headers Authorization: X-Road-ApiKey token=c6804432-37f8-43e3-b3f1-b7bd0b1ac3b0  
msg.url [https://127.0.0.1:4000/api/v1/member-classes](https://127.0.0.1:4000/api/v1/member-classes)

and under http request

Method -set by msg.method -  
URL http://  
check the Enable secure (SSL/TLS) and unchecked the check box "Use key and certificates from local "

I connceted the nodes and deployed and runned them

dubug node that was conncted to change object displayed in debug window following:

object  
\_msgid: "a52fd5f2.3feeb8"  
payload: 1623328045476  
topic: ""  
method: "get"  
headers: "Authorization: X-Road-ApiKey token=c6804432-37f8-43e3-b3f1-b7bd0b1ac3b0"  
url: \< same url as above in change node\>

This looked fine but other debug object connected to http request node displyed in debug window  
object  
\_msgid: "a52fd5f2.3feeb8"  
payload: object  
topic: ""  
method: "get"  
headers: object  
x-road-ui-correlation-id: "8ea4c7d547089572"  
x-content-type-options: "nosniff"  
x-xss-protection: "1; mode=block"  
cache-control: "no-cache, no-store, max-age=0, must-revalidate"  
pragma: "no-cache"  
expires: "0"  
strict-transport-security: "max-age=31536000 ; includeSubDomains"  
x-frame-options: "DENY"  
content-security-policy: "default-src 'none'"  
content-type: "application/json"  
transfer-encoding: "chunked"  
date: "Thu, 10 Jun 2021 12:27:25 GMT"  
connection: "close"  
x-node-red-request-node: "383da789"  
url: \< same url as above in change node\>  
statusCode: 401  
responseUrl: " \< same url as above in change node\>"  
redirectList: array[0]

I looks like something went wrong.  
I would be happy if some could help find what is wrong about this node-red flow

---

<div class="post-metadata">

**Author:** ![E1cid](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/e1cid/32/77971_2.png) [@E1cid](https://discourse.nodered.org/u/E1cid)\
**Post date:** [10 June 2021 13:28 UTC](https://discourse.nodered.org/t/using-rest-api-call-with-http-request-object/46985/2 "2021-06-10T13:28:08Z")

</div>

> [@laurialo](#):
>
> headers: "Authorization: X-Road-ApiKey token=c6804432-37f8-43e3-b3f1-b7bd0b1ac3b0"

Try this in change node.  
set - `msg.headers.Authorization `  
to - `X-Road-ApiKey token=c6804432-37f8-43e3-b3f1-b7bd0b1ac3b0`

---

<div class="post-metadata">

**Author:** ![laurialo](https://avatars.discourse-cdn.com/v4/letter/l/a8b319/32.png) [@laurialo](https://discourse.nodered.org/u/laurialo)\
**Post date:** [10 June 2021 14:00 UTC](https://discourse.nodered.org/t/using-rest-api-call-with-http-request-object/46985/3 "2021-06-10T14:00:31Z")

</div>

Clarfication the msg.header is already settted to "Authorization: X-Road-ApiKey token=c6804432-37f4-43e3-b3f1-b7bb0b1ac3b0"

As in the curl example  
curl --header "Authorization: X-Road-ApiKey token=c6804432-37f8-43e3-b3f1-b7bd0b1ac3b0" "[https://127.0.0.1:4000/api/v1/member-classes](https://127.0.0.1:4000/api/v1/member-classes)" -k  
Sceen shot chang and http request objects

 ![Screenshot at 2021-06-10 16-54-13](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/1/2/12166d4b862b817788774dae6b6c82798669f835.png)  
 ![Screenshot at 2021-06-10 16-55-21](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/e/2/e28827c109d2044548d6fb9cb278c935badb44ce.png)

---

<div class="post-metadata">

**Author:** ![E1cid](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/e1cid/32/77971_2.png) [@E1cid](https://discourse.nodered.org/u/E1cid)\
**Post date:** [10 June 2021 15:19 UTC](https://discourse.nodered.org/t/using-rest-api-call-with-http-request-object/46985/4 "2021-06-10T15:19:36Z")

</div>

yes you set msg.headers  
to "Authorization: X-Road-ApiKey token=c6804432-37f8-43e3-b3f1-b7bd0b1ac3b0"

but that's not what i said try setting msg.headers.Authorization to"X-Road-ApiKey token=c6804432-37f8-43e3-b3f1-b7bd0b1ac3b0"

one sets headers to a string (but headers should be an object)  
the other set headers to an object containing one property Authorization

---

<div class="post-metadata">

**Author:** ![laurialo](https://avatars.discourse-cdn.com/v4/letter/l/a8b319/32.png) [@laurialo](https://discourse.nodered.org/u/laurialo)\
**Post date:** [11 June 2021 12:22 UTC](https://discourse.nodered.org/t/using-rest-api-call-with-http-request-object/46985/5 "2021-06-11T12:22:24Z")

</div>

Thanks It worked

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [25 June 2021 12:23 UTC](https://discourse.nodered.org/t/using-rest-api-call-with-http-request-object/46985/6 "2021-06-25T12:23:20Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
