# getJSON HTTP authorization request header?

**URL:** <https://discourse.gohugo.io/t/getjson-http-authorization-request-header/31795>\
**Category:** feature\
**Created:** [March 17, 2021, 9:19am UTC](https://discourse.gohugo.io/t/getjson-http-authorization-request-header/31795 "2021-03-17T09:19:37Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![sgrins](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/sgrins/32/10498_2.png) [@sgrins](https://discourse.gohugo.io/u/sgrins)\
**Post date:** [March 17, 2021, 9:19am UTC](https://discourse.gohugo.io/t/getjson-http-authorization-request-header/31795/1 "2021-03-17T09:19:38Z")

</div>

Hi

I’m trying to access a JSON API with getJSON.  
Is there a way to send user & pswd in the header and not as part of the url? The API would only allow header authorization .

Thanks

---

<div class="post-metadata">

**Author:** ![alexandros](https://avatars.discourse-cdn.com/v4/letter/a/ecc23a/32.png) [@alexandros](https://discourse.gohugo.io/u/alexandros)\
**Post date:** [March 17, 2021, 11:39am UTC](https://discourse.gohugo.io/t/getjson-http-authorization-request-header/31795/2 "2021-03-17T11:39:36Z")

</div>

Hugo is a static site generator.

To send a [HTTP authorization request header](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Authorization) you need to configure your server.

Your question is OT in this forum. Look in other channels about server configuration and the like.

---

<div class="post-metadata">

**Author:** ![sgrins](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/sgrins/32/10498_2.png) [@sgrins](https://discourse.gohugo.io/u/sgrins)\
**Post date:** [March 17, 2021, 11:54am UTC](https://discourse.gohugo.io/t/getjson-http-authorization-request-header/31795/4 "2021-03-17T11:54:40Z")

</div>

Sorry to insist about the possibility of using getJSON with the authorization in the header. I’m trying to achieve this with hugo’s getJSON:

```
curl --location --request GET API_URL \
--header 'user: USER' \
--header 'pass: PSWD'

```

If this is out of topic, please forgive my ignorance on the topic.

---

<div class="post-metadata">

**Author:** ![alexandros](https://avatars.discourse-cdn.com/v4/letter/a/ecc23a/32.png) [@alexandros](https://discourse.gohugo.io/u/alexandros)\
**Post date:** [March 17, 2021, 12:16pm UTC](https://discourse.gohugo.io/t/getjson-http-authorization-request-header/31795/5 "2021-03-17T12:16:15Z")

</div>

Hugo is a static site generator built with Go.

getJSON is meant to retrieve a file not send an authorization request header.  
Typically one uses the API key in the URL to retrieve the JSON.

If the API you are working with does not provide public API keys and you need to send a username and password then you need to look for help elsewhere.

This is not a forum for generic web development and servers.  
Please respect that and do not open another topic with the same question.

---

<div class="post-metadata">

**Author:** ![alexandros](https://avatars.discourse-cdn.com/v4/letter/a/ecc23a/32.png) [@alexandros](https://discourse.gohugo.io/u/alexandros)\
**Post date:** [March 17, 2021, 12:18pm UTC](https://discourse.gohugo.io/t/getjson-http-authorization-request-header/31795/6 "2021-03-17T12:18:43Z")

</div>



---

<div class="post-metadata">

**Author:** ![bep](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/bep/32/3332_2.png) [@bep](https://discourse.gohugo.io/u/bep)\
**Post date:** [March 17, 2021, 1:17pm UTC](https://discourse.gohugo.io/t/getjson-http-authorization-request-header/31795/7 "2021-03-17T13:17:40Z")

</div>



---

<div class="post-metadata">

**Author:** ![bep](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/bep/32/3332_2.png) [@bep](https://discourse.gohugo.io/u/bep)\
**Post date:** [March 17, 2021, 1:20pm UTC](https://discourse.gohugo.io/t/getjson-http-authorization-request-header/31795/8 "2021-03-17T13:20:03Z")

</div>

`getJSON` does not support auth request headers, but we really should. I had planned to do this as as part of replacing the `getJSON` with a more flexible `resources.GetRemote` function – but time … This is probably important enough that we probably should just do it for `getJSON` as well, but time …

---

<div class="post-metadata">

**Author:** ![jmooring](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/jmooring/32/4214_2.png) [@jmooring](https://discourse.gohugo.io/u/jmooring)\
**Post date:** [March 17, 2021, 1:42pm UTC](https://discourse.gohugo.io/t/getjson-http-authorization-request-header/31795/9 "2021-03-17T13:42:17Z")

</div>

Related:

> <https://github.com/gohugoio/hugo/issues/7699>
>
> A lot of Jamstack services like Formspree require the Authorization header for authentication. Without being able to supply headers, we cannot...

> <https://github.com/gohugoio/hugo/issues/5617>
>
> As suggested in #3395 "Add an HTTP Accept header when downloading JSON", it would be nice if one could add user-defined...

> <https://github.com/gohugoio/hugo/issues/3395>
>
> Some sites, like atlas.hashicorp.com, decide whether to serve HTML or JSON based on the HTTP Accept header (Atlas defaults to HTML...

> <https://github.com/gohugoio/hugo/issues/7083>
>
> As far as I'm aware current SRI function requires resources.Get, which requires the file to be in assets folder.
> I think it'd...

> <https://github.com/gohugoio/hugo/issues/5255>
>
> It'll be nice to have a getCSS function for external URL where the caching are not in our hands and also...

> <https://github.com/gohugoio/hugo/pull/5686>

---

<div class="post-metadata">

**Author:** ![alexandros](https://avatars.discourse-cdn.com/v4/letter/a/ecc23a/32.png) [@alexandros](https://discourse.gohugo.io/u/alexandros)\
**Post date:** [March 17, 2021, 1:56pm UTC](https://discourse.gohugo.io/t/getjson-http-authorization-request-header/31795/10 "2021-03-17T13:56:54Z")

</div>



---

<div class="post-metadata">

**Author:** ![alexandros](https://avatars.discourse-cdn.com/v4/letter/a/ecc23a/32.png) [@alexandros](https://discourse.gohugo.io/u/alexandros)\
**Post date:** [March 17, 2021, 2:04pm UTC](https://discourse.gohugo.io/t/getjson-http-authorization-request-header/31795/11 "2021-03-17T14:04:04Z")

</div>

Thank you for posting for all those links @jmooring  
Really appreciate it.

@sgrins I have re-opened the topic and re-categorized it as a feature request, since the maintainer thinks that `getJSON` should be expanded to add support for sending auth request headers.

---

<div class="post-metadata">

**Author:** ![sgrins](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/sgrins/32/10498_2.png) [@sgrins](https://discourse.gohugo.io/u/sgrins)\
**Post date:** [March 18, 2021, 9:10am UTC](https://discourse.gohugo.io/t/getjson-http-authorization-request-header/31795/12 "2021-03-18T09:10:35Z")

</div>

Great. Thanks.

---

<div class="post-metadata">

**Author:** ![bep](https://yyz2.discourse-cdn.com/flex036/user_avatar/discourse.gohugo.io/bep/32/3332_2.png) [@bep](https://discourse.gohugo.io/u/bep)\
**Post date:** [March 18, 2021, 9:26am UTC](https://discourse.gohugo.io/t/getjson-http-authorization-request-header/31795/13 "2021-03-18T09:26:06Z")

</div>

I have reopened and labeled this issue:

> <https://github.com/gohugoio/hugo/issues/5617#issuecomment-801767375>
>
> As suggested in #3395 "Add an HTTP Accept header when downloading JSON", it would be nice if one could add user-defined...

PR welcome …
