# API Authentication via postman

**URL:** <https://forum.shopware.com/t/api-authentication-via-postman/98781>\
**Category:** Programmierung\
**Created:** [3. März 2023 um 12:50 UTC](https://forum.shopware.com/t/api-authentication-via-postman/98781 "2023-03-03T12:50:00Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![dr-roshyara](https://avatars.discourse-cdn.com/v4/letter/d/4da419/32.png) [@dr-roshyara](https://forum.shopware.com/u/dr-roshyara)\
**Post date:** [3. März 2023 um 12:50 UTC](https://forum.shopware.com/t/api-authentication-via-postman/98781/1 "2023-03-03T12:50:00Z")

</div>

Ich versuche Shopware Api über Postman aufzurufen,leider erfolglos

- Ich habe den

- Im Postman habe ich  
\* base url : [https://my-shopware-seite.de/api/oauth/token](https://my-shopware-seite.de/api/oauth/token)  
\* request POST  
\* Authorization api-key gewählt und  
api-key : access-key-id (Idxxxxxxxxxxxxxxxxxxxxxxx)  
value: access-key-secret (Keyxxxxxxxxxxxxxxxxxxxxxx)  
angegen.  
Es klappt nicht . Mache ich überhaupt richtig? Wenn nicht, könnt Ihr bitte schreiben wie es geht?  
vielen Dank im Voraus.

-

---

<div class="post-metadata">

**Author:** ![dr-roshyara](https://avatars.discourse-cdn.com/v4/letter/d/4da419/32.png) [@dr-roshyara](https://forum.shopware.com/u/dr-roshyara)\
**Post date:** [3. März 2023 um 13:54 UTC](https://forum.shopware.com/t/api-authentication-via-postman/98781/2 "2023-03-03T13:54:25Z")

</div>

I also tried with xml request it did not work.

```auto
<html>
<head>
	<title> testing </title>
</head>
<body>
<script> 
const data = JSON.stringify({
  "client_id": "administration",
  "grant_type": "password",
  "scopes": "write",
  "username": "my-username",
  "password": "my-password"
});

const xhr = new XMLHttpRequest();
xhr.withCredentials = true;

xhr.addEventListener("readystatechange", function () {
  if (this.readyState === this.DONE) {
    console.log(this.responseText);
  }
});

xhr.open("POST", "https://my-shopware-site.de/api/auth/token");
xhr.setRequestHeader("Content-Type", "application/json");
xhr.setRequestHeader("Accept", "application/json");
xhr.send(data);
//console.log("test");
</script>

```

---

<div class="post-metadata">

**Author:** ![Max\_Shop](https://avatars.discourse-cdn.com/v4/letter/m/58f4c7/32.png) [@Max\_Shop](https://forum.shopware.com/u/Max_Shop)\
**Post date:** [3. März 2023 um 14:52 UTC](https://forum.shopware.com/t/api-authentication-via-postman/98781/3 "2023-03-03T14:52:11Z")

</div>

> **[Authentication | Admin API](https://shopware.stoplight.io/docs/admin-api/ZG9jOjEwODA3NjQx-authentication)**
>
> The Admin API uses the OAuth 2.0 standard to authenticate users. In short, OAuth 2.0 requires you to obtain an access token which you will have to include in every subsequent request so the server can confirm your identity. Powered by Stoplight.

```auto
const options = {
  method: 'POST',
  headers: {'Content-Type': 'application/json', Accept: 'application/json'},
  body: '{"client_id":"administration","grant_type":"password","scopes":"write","username":"your.username@shopware.com","password":"your.password@123"}'
};

fetch('http://localhost/api/auth/token', options)
  .then(response => response.json())
  .then(response => console.log(response))
  .catch(err => console.error(err));

```

> **[Quick Start Guide | Admin API](https://shopware.stoplight.io/docs/admin-api/twpxvnspkg3yu-quick-start-guide#authentication-and-setup)**
>
> The Shopware Admin API allows web services to perform administrative tasks. This guide is designed to help you understand the Admin API, its endpoints, and its usage. Powered by Stoplight.
