# Newbie authentication issue

**URL:** <https://forum.mautic.org/t/newbie-authentication-issue/3111>\
**Category:** Product Support\
**Created:** [December 31, 2015, 5:53pm UTC](https://forum.mautic.org/t/newbie-authentication-issue/3111 "2015-12-31T17:53:55Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![pth](https://avatars.discourse-cdn.com/v4/letter/p/e5b9ba/32.png) [@pth](https://forum.mautic.org/u/pth)\
**Post date:** [December 31, 2015, 5:53pm UTC](https://forum.mautic.org/t/newbie-authentication-issue/3111/1 "2015-12-31T17:53:55Z")

</div>

Hi folks,  
  
  
  
I’m trying to get started with your Mautic free hosted service and using the API from a PHP script that is used to to process a download form.  
  
  
  
Here’s my code:  
  
$mauticBaseUrl = ‘[https://my-domain.mautic.com/api](https://my-domain.mautic.com/api)’;  
  
  
  
$settings = array(  
  
‘baseUrl’ =\> $mauticBaseUrl,  
  
‘clientKey’ =\> ‘a-long-string-with-cutnpaste-clientkey-creditials’,  
  
‘clientSecret’ =\> ‘a-long-string-with-cutnpaste-secretkey-creditials’,  
  
‘callback’ =\> ‘[http://localhost:8888/downloads/](http://localhost:8888/downloads/)’, // @todo Change this to your app callback. It should be the same as you entered when you were creating Mautic API credentials.  
  
‘version’ =\> ‘OAuth2’  
  
);  
  
  
  
$auth = MauticAuthApiAuth::initiate($settings);  
  
  
  
But the response header I get back includes:  
  
  
  
www-authenticate:Bearer realm=“Service”, error=“access\_denied”, error\_description=“OAuth2 authentication required”  
  
  
  
The download form is hosted at [http://localhost:8888/downloads/](http://localhost:8888/downloads/) and the Redirect URI is set to [http://localhost:8888/downloads/](http://localhost:8888/downloads/) for OAuth2 authentication.  
  
  
  
I’ve been thru the forums and the help and not seeing much to go on, so any help appreciated. Any pointers as to how to get more information than “access denied” in the response header? I don’t see anything in the mautic online UI that allows me to view the API logs, like you get with MandrillApp for example, which shows all API calls and allows you to click thru for details with the full request and full response.  
  
  
  
Thanks,  
  
Paul

---

<div class="post-metadata">

**Author:** ![pth](https://avatars.discourse-cdn.com/v4/letter/p/e5b9ba/32.png) [@pth](https://forum.mautic.org/u/pth)\
**Post date:** [December 31, 2015, 5:53pm UTC](https://forum.mautic.org/t/newbie-authentication-issue/3111/2 "2015-12-31T17:53:55Z")

</div>

Hi folks,

I’m trying to get started with your Mautic free hosted service and using the API from a PHP script that is used to to process a download form.

Here’s my code:  
$mauticBaseUrl = ‘[https://my-domain.mautic.com/api](https://my-domain.mautic.com/api)’;

```
$settings = array(
    'baseUrl' => $mauticBaseUrl,
    'clientKey' => 'a-long-string-with-cutnpaste-clientkey-creditials',
    'clientSecret' => 'a-long-string-with-cutnpaste-secretkey-creditials',
    'callback' => 'http://localhost:8888/downloads/', // @todo Change this to your app callback. It should be the same as you entered when you were creating Mautic API credentials.
    'version' => 'OAuth2'
);

$auth = MauticAuthApiAuth::initiate($settings);

```

But the response header I get back includes:

www-authenticate:Bearer realm=“Service”, error=“access\_denied”, error\_description=“OAuth2 authentication required”

The download form is hosted at [http://localhost:8888/downloads/](http://localhost:8888/downloads/) and the Redirect URI is set to [http://localhost:8888/downloads/](http://localhost:8888/downloads/) for OAuth2 authentication.

I’ve been thru the forums and the help and not seeing much to go on, so any help appreciated. Any pointers as to how to get more information than “access denied” in the response header? I don’t see anything in the mautic online UI that allows me to view the API logs, like you get with MandrillApp for example, which shows all API calls and allows you to click thru for details with the full request and full response.

Thanks,  
Paul

---

<div class="post-metadata">

**Author:** ![gmillard](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/gmillard/32/5_2.png) [@gmillard](https://forum.mautic.org/u/gmillard)\
**Post date:** [December 31, 2015, 8:37pm UTC](https://forum.mautic.org/t/newbie-authentication-issue/3111/3 "2015-12-31T20:37:30Z")

</div>

A couple things to check. First, ensure that the client key and secret are configured to be OAuth2 credentials. You have the option to generate OAuth1a or OAuth2 keys and they of course have to match the version used by the script.

Also, I don’t think you need the /api on the end of $mauticBaseUrl. Try changing it to just [https://my-domain.mautic.com](https://my-domain.mautic.com) to see what happens.

---

<div class="post-metadata">

**Author:** ![pth](https://avatars.discourse-cdn.com/v4/letter/p/e5b9ba/32.png) [@pth](https://forum.mautic.org/u/pth)\
**Post date:** [January 4, 2016, 4:31pm UTC](https://forum.mautic.org/t/newbie-authentication-issue/3111/4 "2016-01-04T16:31:12Z")

</div>

Hi Alan,

That’s helped thank you.

However, I am now seeing “XMLHttpRequest cannot load [https://mydomain.mautic.com//oauth/v2/authorize?client\_id=1\_37qat7ob9uio44co…st%3A8888&state=5f8497fdbd49a69fdc068edc9d2c1e91&scope=&response\_type=code](https://mydomain.mautic.com//oauth/v2/authorize?client_id=1_37qat7ob9uio44co%E2%80%A6st%3A8888&state=5f8497fdbd49a69fdc068edc9d2c1e91&scope=&response_type=code). No ‘Access-Control-Allow-Origin’ header is present on the requested resource. Origin ‘[http://localhost:8888](http://localhost:8888)’ is therefore not allowed access. The response had HTTP status code 404.”

The API credentials Redirect URI is set as “[http://localhost:8888](http://localhost:8888),[https://localhost:8888](https://localhost:8888)” and I’ve tried setting callback for  
settings as both ‘[http://localhost:8888](http://localhost:8888)’, and ‘[http://localhost:8888/downloads/](http://localhost:8888/downloads/)’. I would presume the former should work.

If you can help again that would be much appreciated.

Thanks in advance for your time.

best regards,  
Paul

---

<div class="post-metadata">

**Author:** ![escopecz](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/escopecz/32/370_2.png) [@escopecz](https://forum.mautic.org/u/escopecz)\
**Post date:** [January 6, 2016, 8:12am UTC](https://forum.mautic.org/t/newbie-authentication-issue/3111/5 "2016-01-06T08:12:10Z")

</div>

You are experiencing CORS. Lear about what it is for example at

[https://developer.mozilla.org/en-US/docs/Web/HTTP/Access\_control\_CORS](https://developer.mozilla.org/en-US/docs/Web/HTTP/Access_control_CORS)

Your server probably sets a header in response which doesn’t allow to process response under another domain.

---

<div class="post-metadata">

**Author:** ![mbrinson](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/mbrinson/32/116_2.png) [@mbrinson](https://forum.mautic.org/u/mbrinson)\
**Post date:** [November 11, 2016, 8:52pm UTC](https://forum.mautic.org/t/newbie-authentication-issue/3111/6 "2016-11-11T20:52:46Z")

</div>

Thanks for that info escopecz. I’m running into this same issue and I’m running mautic on nginx.

I read through that page you linked so as best I could, but I couldn’t find any solution being offered. Do you have any hints as to where I should focus to get around this? A configuration change to my nginx environment?

---

<div class="post-metadata">

**Author:** ![silavapi](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/silavapi/32/7424_2.png) [@silavapi](https://forum.mautic.org/u/silavapi)\
**Post date:** [February 2, 2020, 10:54pm UTC](https://forum.mautic.org/t/newbie-authentication-issue/3111/7 "2020-02-02T22:54:39Z")

</div>


