# Unable to create API keys for an user using curl

**URL:** <https://forums.suse.com/t/unable-to-create-api-keys-for-an-user-using-curl/12899>\
**Category:** General\
**Created:** [January 7, 2019, 9:35am UTC](https://forums.suse.com/t/unable-to-create-api-keys-for-an-user-using-curl/12899 "2019-01-07T09:35:06Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ranjith](https://avatars.discourse-cdn.com/v4/letter/r/8797f3/32.png) [@ranjith](https://forums.suse.com/u/ranjith)\
**Post date:** [January 7, 2019, 9:35am UTC](https://forums.suse.com/t/unable-to-create-api-keys-for-an-user-using-curl/12899/1 "2019-01-07T09:35:06Z")

</div>

**Below is the curl command:**

curl --header “Content-Type: application/json” --request POST --data ‘{“type”:“apikey”,“accountId”:“1a405”,“name”:“test”}’ [http://IPADDRESS](http://IPADDRESS):PORT/v2-beta/apikey

**Error:**

{“id”:“a201401f-5d3f-43bd-a5c0-4ef651e406e6”,“type”:“error”,“links”:{},“actions”:{},“status”:401,“code”:“Unauthorized”,“message”:“Unauthorized”,“detail”:null,“baseType”:“error”}

I want to create API keys without giving auth as input. What is the error in this curl command.

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [January 7, 2019, 3:57pm UTC](https://forums.suse.com/t/unable-to-create-api-keys-for-an-user-using-curl/12899/2 "2019-01-07T15:57:12Z")

</div>

Access control is always on. It would serve no purpose is anybody could request an API key without providing credentials first.

---

<div class="post-metadata">

**Author:** ![ranjith](https://avatars.discourse-cdn.com/v4/letter/r/8797f3/32.png) [@ranjith](https://forums.suse.com/u/ranjith)\
**Post date:** [January 11, 2019, 4:07am UTC](https://forums.suse.com/t/unable-to-create-api-keys-for-an-user-using-curl/12899/3 "2019-01-11T04:07:59Z")

</div>

Thanks for the info.

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [January 11, 2019, 7:16am UTC](https://forums.suse.com/t/unable-to-create-api-keys-for-an-user-using-curl/12899/4 "2019-01-11T07:16:16Z")

</div>

The initial account is `admin` / `admin`, so if you want to automate everything you can start with logging in with that, changing the password, and then generating an API key… Something like this (assuming the server is on localhost)

```auto
# Login token good for 1 minute
LOGINTOKEN=`curl -k -s 'https://127.0.0.1/v3-public/localProviders/local?action=login' -H 'content-type: application/json' --data-binary '{"username":"admin","password":"admin","ttl":60000}' | jq -r .token`

# Change password
curl -k -s 'https://127.0.0.1/v3/users?action=changepassword' -H 'Content-Type: application/json' -H "Authorization: Bearer $LOGINTOKEN" --data-binary '{"currentPassword":"admin","newPassword":"something better"}'

# Create API key good forever
APIKEY=`curl -k -s 'https://127.0.0.1/v3/token' -H 'Content-Type: application/json' -H "Authorization: Bearer $LOGINTOKEN" --data-binary '{"type":"token","description":"for scripts and stuff"}' | jq -r .token`
echo "API Key: ${APIKEY}"

# Set server-url
curl -k -s 'https://127.0.0.1/v3/settings/server-url' -H 'Content-Type: application/json' -H "Authorization: Bearer $APIKEY" -X PUT --data-binary '{"name":"server-url","value":"https://your-rancher.com/"}'

# Do whatever else you want
```

---

<div class="post-metadata">

**Author:** ![ranjith](https://avatars.discourse-cdn.com/v4/letter/r/8797f3/32.png) [@ranjith](https://forums.suse.com/u/ranjith)\
**Post date:** [January 24, 2019, 4:35am UTC](https://forums.suse.com/t/unable-to-create-api-keys-for-an-user-using-curl/12899/5 "2019-01-24T04:35:15Z")

</div>

Thanks for your detailed response @vincent
