# Make an authenticated JSON request

**URL:** <https://discourse.processing.org/t/make-an-authenticated-json-request/14224>\
**Category:** Coding Questions\
**Created:** [September 26, 2019, 10:43pm UTC](https://discourse.processing.org/t/make-an-authenticated-json-request/14224 "2019-09-26T22:43:17Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![prismspecs](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.processing.org/prismspecs/32/6421_2.png) [@prismspecs](https://discourse.processing.org/u/prismspecs)\
**Post date:** [September 26, 2019, 10:43pm UTC](https://discourse.processing.org/t/make-an-authenticated-json-request/14224/1 "2019-09-26T22:43:17Z")

</div>

I see this page  
[https://p5js.org/reference/#/p5/httpDo](https://p5js.org/reference/#/p5/httpDo)

But when I try to make an API request with my access token from [https://littlesis.org/api](https://littlesis.org/api) it doesn’t work.

I see that LittleSis wants the string “Littlesis-Api-Token:” but I don’t know how to insert that into the header. All I see in examples is “Bearer XXXXXX”, should that work here? I’ve tried a few things and no avail. Any ideas?

---

<div class="post-metadata">

**Author:** ![jeremydouglass](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.processing.org/jeremydouglass/32/20_2.png) [@jeremydouglass](https://discourse.processing.org/u/jeremydouglass)\
**Post date:** [September 30, 2019, 2:01am UTC](https://discourse.processing.org/t/make-an-authenticated-json-request/14224/2 "2019-09-30T02:01:32Z")

</div>

Possibly helpful?:

[![](https://img.youtube.com/vi/ecT42O6I_WI/hqdefault.jpg "10.5: Working with APIs in Javascript - p5.js Tutorial") ](https://www.youtube.com/watch?v=ecT42O6I_WI)

---

<div class="post-metadata">

**Author:** ![prismspecs](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.processing.org/prismspecs/32/6421_2.png) [@prismspecs](https://discourse.processing.org/u/prismspecs)\
**Post date:** [September 30, 2019, 8:09pm UTC](https://discourse.processing.org/t/make-an-authenticated-json-request/14224/3 "2019-09-30T20:09:07Z")

</div>

Thanks for the suggestion! It looks like the API he’s using allows you to pass the key via the URL whereas for littlesis you need to do it in a special way.

---

<div class="post-metadata">

**Author:** ![George](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.processing.org/george/32/5858_2.png) [@George](https://discourse.processing.org/u/George)\
**Post date:** [October 1, 2019, 11:50am UTC](https://discourse.processing.org/t/make-an-authenticated-json-request/14224/4 "2019-10-01T11:50:28Z")

</div>

Here’s a rough example of how to include the API Token in the request header:

```javascript
function preload() {
  let url = 'https://littlesis.org/api/entities/1';
  httpDo(
    url,
    {
      method: 'GET',
			// Other Request options, like special headers for apis
      headers: { 'littlesis-api-token': 'YOUR_TOKEN_HERE'},
			mode: 'no-cors',// no-cors, *cors, same-origin
			credentials: 'include',// include, *same-origin, omit
			redirect: 'follow', // manual, *follow, error
    	referrer: 'client', // no-referrer, *client
    },
    function(res) {
      console.log(res);
    },
		function(err) {
			console.log(err);
		}
  );
}

function setup() {
	createCanvas(300, 300);
}

function draw() {

}

```

I am getting [CORS](https://developer.mozilla.org/en-US/docs/Web/HTTP/CORS) related errors and unfortunately unable to provide a quick solution, but I’m sure the more web experienced will provide advice there.

As a hacky backup-plan I can suggest using a basic server side script to cache the request locally so p5.js can access it. (e.g. a node script that receives the same request you would to little-sister, does the request and funnels the message back, but from localhost/same domain the p5 sketch is served from)

---

<div class="post-metadata">

**Author:** ![prismspecs](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.processing.org/prismspecs/32/6421_2.png) [@prismspecs](https://discourse.processing.org/u/prismspecs)\
**Post date:** [October 1, 2019, 4:49pm UTC](https://discourse.processing.org/t/make-an-authenticated-json-request/14224/5 "2019-10-01T16:49:23Z")

</div>

Thanks so much for taking the time to help out.

This looks a bit better than what I had worked out, but I get a 422 Error, “No Reason Phrase”, any idea what that’s about?

---

<div class="post-metadata">

**Author:** ![jeremydouglass](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.processing.org/jeremydouglass/32/20_2.png) [@jeremydouglass](https://discourse.processing.org/u/jeremydouglass)\
**Post date:** [October 1, 2019, 6:29pm UTC](https://discourse.processing.org/t/make-an-authenticated-json-request/14224/6 "2019-10-01T18:29:00Z")

</div>

[https://httpstatuses.com/422](https://httpstatuses.com/422)

Not sure, but possibly you submitted a well-formed request that is against their policies? Like for example:

> <https://github.com/rails/rails/pull/30780>

You may want to consult
