# API OAuth1a

**URL:** <https://forum.mautic.org/t/api-oauth1a/2566>\
**Category:** Product Support\
**Created:** [October 12, 2015, 3:40pm UTC](https://forum.mautic.org/t/api-oauth1a/2566 "2015-10-12T15:40:15Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![trops](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/trops/32/3998_2.png) [@trops](https://forum.mautic.org/u/trops)\
**Post date:** [October 12, 2015, 3:40pm UTC](https://forum.mautic.org/t/api-oauth1a/2566/1 "2015-10-12T15:40:15Z")

</div>

Im trying to implement the OAuth1a authorization with the Mautic API. I have two servers. One on a main .com where Mautic lives, and another “services” subdomain which I am trying to request the API.  
  
  
  
Ive created keys in Mautic, enabled the API.  
  
  
  
I am trying to use the apitester in the api-library to test OAuth1a, It is sending the authorization request but getting back a “signature\_invalid” response.  
  
  
  
Anyone having this issue?  
  
  
  
Im just trying to get access to the API without having to deal with a browser login/ Im calling from my services server which does not have a web front end.  
  
  
  
Thanks,  
  
John

---

<div class="post-metadata">

**Author:** ![trops](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/trops/32/3998_2.png) [@trops](https://forum.mautic.org/u/trops)\
**Post date:** [October 12, 2015, 3:40pm UTC](https://forum.mautic.org/t/api-oauth1a/2566/2 "2015-10-12T15:40:15Z")

</div>

Im trying to implement the OAuth1a authorization with the Mautic API. I have two servers. One on a main .com where Mautic lives, and another “services” subdomain which I am trying to request the API.

Ive created keys in Mautic, enabled the API.

I am trying to use the apitester in the api-library to test OAuth1a, It is sending the authorization request but getting back a “signature\_invalid” response.

Anyone having this issue?

Im just trying to get access to the API without having to deal with a browser login/ Im calling from my services server which does not have a web front end.

Thanks,  
John

---

<div class="post-metadata">

**Author:** ![escopecz](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/escopecz/32/370_2.png) [@escopecz](https://forum.mautic.org/u/escopecz)\
**Post date:** [October 14, 2015, 8:20am UTC](https://forum.mautic.org/t/api-oauth1a/2566/3 "2015-10-14T08:20:37Z")

</div>

I tested the connection via oAuth1a with API tester and the authorization went fine. Then I tried to get all leads and all leads were received.

---

<div class="post-metadata">

**Author:** ![emmanuel](https://avatars.discourse-cdn.com/v4/letter/e/3e96dc/32.png) [@emmanuel](https://forum.mautic.org/u/emmanuel)\
**Post date:** [May 10, 2016, 9:14am UTC](https://forum.mautic.org/t/api-oauth1a/2566/4 "2016-05-10T09:14:51Z")

</div>

I’m having the same issue.  
I’m using org.springframework.social.oauth1.OAuth1Template exchangeForToken method

My generated header is like :  
Authorization: OAuth oauth\_nonce=“1174183694”, oauth\_callback=“https%3A%2F%[2Fmy.server.com](http://2Fmy.server.com)%2Fmain%2FoAuth1.html”, oauth\_consumer\_key=“myKey”, oauth\_signature\_method=“HMAC-SHA1”, oauth\_timestamp=“1462874380”, oauth\_version=“1.0”, oauth\_signature="%2F4bqF6vSL1IfwkBCN3%2BzfTrGHWM%3D"

---

<div class="post-metadata">

**Author:** ![emmanuel](https://avatars.discourse-cdn.com/v4/letter/e/3e96dc/32.png) [@emmanuel](https://forum.mautic.org/u/emmanuel)\
**Post date:** [May 10, 2016, 12:11pm UTC](https://forum.mautic.org/t/api-oauth1a/2566/5 "2016-05-10T12:11:51Z")

</div>

when I didn’t send the oauth\_callback, it works, but I need to send it.

---

<div class="post-metadata">

**Author:** ![emmanuel](https://avatars.discourse-cdn.com/v4/letter/e/3e96dc/32.png) [@emmanuel](https://forum.mautic.org/u/emmanuel)\
**Post date:** [May 10, 2016, 12:37pm UTC](https://forum.mautic.org/t/api-oauth1a/2566/6 "2016-05-10T12:37:53Z")

</div>

ok when I don’t send “oauth\_callback” in the" /oauth/v1/request\_token" url but only in the “/oauth/v1/authorize” url, it seems to work.

---

<div class="post-metadata">

**Author:** ![emmanuel](https://avatars.discourse-cdn.com/v4/letter/e/3e96dc/32.png) [@emmanuel](https://forum.mautic.org/u/emmanuel)\
**Post date:** [May 11, 2016, 9:10am UTC](https://forum.mautic.org/t/api-oauth1a/2566/7 "2016-05-11T09:10:48Z")

</div>

unconnected whit that, it seems you missed one thing in the delete lead api doc

[https://developer.mautic.org/?json#delete-lead](https://developer.mautic.org/?json#delete-lead)

I think the right url is /leads/ID/delete instead of /leads/ID

---

<div class="post-metadata">

**Author:** ![silavapi](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/silavapi/32/7424_2.png) [@silavapi](https://forum.mautic.org/u/silavapi)\
**Post date:** [February 2, 2020, 10:57pm UTC](https://forum.mautic.org/t/api-oauth1a/2566/8 "2020-02-02T22:57:49Z")

</div>


