Access Token Authentication

As of the Netsweeper 8.2 and above releases, all APIs can now authenticate using an Access Token. This can be done using either a Cookie, or via the NswAuthentication header. Futhermore, as of Netsweeper 9.1, we have added a 'NswTokenSession:true' header to allow for persistent sessions. After logging in, you can call the specific, desired API.

Cookie Jar Authentication

Example

curl -b cookie.jar -c cookie.jar https://servername/webadmin/api/token.php?token=VALUE

curl -b cookie.jar -c cookie.jar https://servername/webadmin/api/account_list.php

Example Output

[root@localhost ~]# curl -b cookie.jar -c cookie.jar localhost/webadmin/api/token.php?token=VALUE

OK:

[root@localhost ~]# curl -b cookie.jar -c cookie.jar localhost/webadmin/api/account_list.php

OK:

login=>admin

login=>jacob.newly@schoola.org

login=>jean.rambaux@schoola.org

login=>mark.callaway@schoola.org

login=>richard.bachman@schoola.org

login=>sally.ryan@schoola.org

login=>samuel.clemens@schoola.org

login=>saul.hudson@schoola.org

NswAuthentication Header Method

Alternatively, the 'NswAuthentication' header can be used. In version 8.2, it requires sending the token with every Direct or SOAP API request, or you can use the 'NswTokenSession:true' header with it, (shown later in this document).

Example

curl -H "NswAuthentication: VALUE" -k "https://servername/webadmin/api/account_list.php"

OK:

login=>admin

login=>jacob.newly@schoola.org

login=>jean.rambaux@schoola.org

login=>mark.callaway@schoola.org

login=>richard.bachman@schoola.org

login=>sally.ryan@schoola.org

login=>samuel.clemens@schoola.org

login=>saul.hudson@schoola.org

NswTokenSession:true Header Method

As of Netsweeper 9.1, we have added a 'NswTokenSession:true' header to allow for persistent sessions, which can allow for the active Organization to be changed.

Example

curl -b ../cookie -c ../cookie -H "NswAuthentication:VALUE" -H "NswTokenSession:ON" "http://servername/webadmin/api/organization_set.php?orgname=example.org"

OK: Organization set to 'example.org'.

Additional information on Access Tokens can be found in our My Account Preferences documentation.