HSBC - Error with HTTP Message: Unauthorized

Hi, I send this message header for the first step to obtain the group-id
(request-target): post https://rms-world-check-one-api-pilot.thomsonreuters.com:443/v1/groups
host: rms-world-check-one-api-pilot.thomsonreuters.com
date: Fri, 28 Apr 2017 01:31:26
Authorization:
Signature keyId="509f9b54-4182-XXXX-XXX-XXXXXXX", algorithm="hmac-sha256", headers="(request-target) host date content-type content-length", signature="zgRnHs4/3zt8ycrhN+fYS/K6PAbKJVY+fw9Q9MAfs="
Hi, I am from HSBC Argentina, we are trying to access the World-Chech-One.
I received the API-KEY and Secret-API credentials on Wednesday to be able to generate the authorization header. But we can not make it work gives me the error "401 Unauthorized.
Could I review the request I send with someone from privately to see that I am sending wrong.
Thank you very much.
Best Answer
-
Consider watching:
0
Answers
-
Hi @jcgarcia,
did you try standard settings in the Postman collection before changing to your own API and API secret ?
That should work without any changes, then change the values in Postman to be your own API and API secret.
Once that's working you can see what the valid authorization should look like.0 -
Yes, I have postman in Chrome because here at HSBC we cant download the Windows Version, we dont have permissions to do that.
This is the configuration that I have in Postman:
POST /v1/groups HTTP/1.1
Host: rms-world-check-one-api-pilot.thomsonreuters.com
Date: Fri, 16 Dec 2016 12:34:45 GMT
Content-Type: application/json
Content-Length: 158
Authorization: Signature keyId="a4364e62-e58b-4b64-9c71-faead5417557",algorithm="hmac-sha256",headers="(request-target) host date content-type content-length",signature="TBFK7xyK+Wdk7J8g/OVhxC+NfhC92YM/tvFWrXFo/EQ="
Cache-Control: no-cacheThe body must go empty "{ }" right?
Thanks.
0 -
Hi, I downloaded the latest version of Postman for Windows.
I sent a Signature that you gave me in another mail.
Also I'm having problem because I still received 401 Authentication error.I attached 2 captures images from Postman and the text with the headers
- Request
Headers:- cache-control:"no-cache"
- Postman-Token:"ee4772ce-908d-489b-a909-7469092c0120"
- Authorization:"Signature
keyId="504459e4-f5c4-4368-ba20-6968b335580f",algorithm="hmac-sha256",headers="(request-target)
host date",signature="Qwdo6QHZyAXtcWvwN5igKrnSkbCNMPz4KKiOY6Q57Os="" - Date:"Wed, 03 May 2017 14:29:59
GMT" - Host:"rms-world-check-one-api-pilot.thomsonreuters.com"
- User-Agent:"PostmanRuntime/3.0.11-hotfix.2"
- Accept:"*/*"
- accept-encoding:"gzip, deflate"
- Response
Headers:- authorization:"WWW-Authenticate:
Signature realm="World-Check One
API",algorithm="hmac-sha256",headers="(request-target) host
date content-type content-length" - date:"Wed, 03 May 2017 14:29:59
GMT" - server:"Apache-Coyote/1.1"
- transfer-encoding:"chunked"
- x-application-context:"bootstrap"
- authorization:"WWW-Authenticate:
- Response
Could you help me please I cant pass the first call.
Thanks.
0 - Request
-
Client was given an answer outside of Q&A due to the sensitivity of the information. I will check if the answer can be posted here without compromising it, if not the question will be made private or deleted.
0
Categories
- All Categories
- 3 Polls
- 6 AHS
- 36 Alpha
- 166 App Studio
- 6 Block Chain
- 4 Bot Platform
- 18 Connected Risk APIs
- 47 Data Fusion
- 34 Data Model Discovery
- 689 Datastream
- 1.4K DSS
- 626 Eikon COM
- 5.2K Eikon Data APIs
- 11 Electronic Trading
- 1 Generic FIX
- 7 Local Bank Node API
- 3 Trading API
- 2.9K Elektron
- 1.4K EMA
- 255 ETA
- 558 WebSocket API
- 39 FX Venues
- 15 FX Market Data
- 1 FX Post Trade
- 1 FX Trading - Matching
- 12 FX Trading – RFQ Maker
- 5 Intelligent Tagging
- 2 Legal One
- 23 Messenger Bot
- 3 Messenger Side by Side
- 9 ONESOURCE
- 7 Indirect Tax
- 60 Open Calais
- 277 Open PermID
- 44 Entity Search
- 2 Org ID
- 1 PAM
- PAM - Logging
- 6 Product Insight
- Project Tracking
- ProView
- ProView Internal
- 23 RDMS
- 1.9K Refinitiv Data Platform
- 699 Refinitiv Data Platform Libraries
- 4 LSEG Due Diligence
- LSEG Due Diligence Portal API
- 4 Refinitiv Due Dilligence Centre
- Rose's Space
- 1.2K Screening
- 18 Qual-ID API
- 13 Screening Deployed
- 23 Screening Online
- 12 World-Check Customer Risk Screener
- 1K World-Check One
- 46 World-Check One Zero Footprint
- 45 Side by Side Integration API
- 2 Test Space
- 3 Thomson One Smart
- 10 TR Knowledge Graph
- 151 Transactions
- 143 REDI API
- 1.8K TREP APIs
- 4 CAT
- 27 DACS Station
- 121 Open DACS
- 1.1K RFA
- 106 UPA
- 194 TREP Infrastructure
- 229 TRKD
- 918 TRTH
- 5 Velocity Analytics
- 9 Wealth Management Web Services
- 93 Workspace SDK
- 11 Element Framework
- 5 Grid
- 19 World-Check Data File
- 1 Yield Book Analytics
- 48 中文论坛