# Postman Authorization

**URL:** <https://community.sendbird.com/t/postman-authorization/3186>\
**Category:** JavaScript\
**Tags:** sendbird-call, react-js, chatsdk\
**Created:** [October 6, 2021, 10:26pm UTC](https://community.sendbird.com/t/postman-authorization/3186 "2021-10-06T22:26:17Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![rburton](https://avatars.discourse-cdn.com/v4/letter/r/ec9cab/32.png) [@rburton](https://community.sendbird.com/u/rburton)\
**Post date:** [October 6, 2021, 10:26pm UTC](https://community.sendbird.com/t/postman-authorization/3186/1 "2021-10-06T22:26:17Z")

</div>

I am trying to use Postman to exercise the API. I create a request and select Authorization-\>Basic. I enter my email address and password. When I run the request I still get  
{

```
"message": "Invalid value: \"Api-Token. Api-Token is missing.\".",

"code": 400401,

"error": true

```

}  
for a response. Has anyone tried to do something similar?

---

<div class="post-metadata">

**Author:** ![Tyler](https://sea2.discourse-cdn.com/flex020/user_avatar/community.sendbird.com/tyler/32/810_2.png) [@Tyler](https://community.sendbird.com/u/Tyler)\
**Post date:** [October 7, 2021, 4:25am UTC](https://community.sendbird.com/t/postman-authorization/3186/2 "2021-10-07T04:25:13Z")

</div>

Hi @rburton,

Authorization doesn’t work that way for Sendbird. You’ll need to create a header with the key of `Api-Token` and the value of your API Token.

---

<div class="post-metadata">

**Author:** ![rburton](https://avatars.discourse-cdn.com/v4/letter/r/ec9cab/32.png) [@rburton](https://community.sendbird.com/u/rburton)\
**Post date:** [October 7, 2021, 10:01pm UTC](https://community.sendbird.com/t/postman-authorization/3186/3 "2021-10-07T22:01:42Z")

</div>

@Tyler,  
This is what I read in the documentation. Where are you looking? Anyway the ‘token’ is the base64 encoded value of email:password? Thank you.

---

<div class="post-metadata">

**Author:** ![Tyler](https://sea2.discourse-cdn.com/flex020/user_avatar/community.sendbird.com/tyler/32/810_2.png) [@Tyler](https://community.sendbird.com/u/Tyler)\
**Post date:** [October 7, 2021, 10:09pm UTC](https://community.sendbird.com/t/postman-authorization/3186/4 "2021-10-07T22:09:57Z")

</div>

Hi,

That portion of our documentation is outdated and we are in the process of updating it. We do not support basic authentication for the Organization API any longer.

---

<div class="post-metadata">

**Author:** ![rburton](https://avatars.discourse-cdn.com/v4/letter/r/ec9cab/32.png) [@rburton](https://community.sendbird.com/u/rburton)\
**Post date:** [October 7, 2021, 10:21pm UTC](https://community.sendbird.com/t/postman-authorization/3186/5 "2021-10-07T22:21:58Z")

</div>

Thank you. So is the “token” base64 encoded email + ‘:’ + password?

---

<div class="post-metadata">

**Author:** ![Tyler](https://sea2.discourse-cdn.com/flex020/user_avatar/community.sendbird.com/tyler/32/810_2.png) [@Tyler](https://community.sendbird.com/u/Tyler)\
**Post date:** [October 7, 2021, 10:37pm UTC](https://community.sendbird.com/t/postman-authorization/3186/6 "2021-10-07T22:37:03Z")

</div>

For the Organization API, you must pass the `SENDBIRDORGANIZATIONAPITOKEN` header with the token from your dashboard:

> **[Organization API | Chat Platform API | Sendbird Docs](https://sendbird.com/docs/chat/v3/platform-api/guides/organization-api#-3-http-headers)**
>
> Learn how to create, list, view, and delete an application in your Sendbird organization.

 ![XBVbZz4h](https://us1.discourse-cdn.com/flex020/uploads/sendbird/original/2X/b/b59bc1638e6db19dc8d655267eb2a5e1c7135752.png)

For Platform API, you must pass the `Api-Token` header, with an Api Token from your Dashboard:

> **[Prepare to use API | Chat Platform API | Sendbird Docs](https://sendbird.com/docs/chat/v3/platform-api/getting-started/prepare-to-use-api#2-headers)**
>
> Learn how to use and authenticate Sendbird Chat Platform API.

 ![MqCj55uA](https://us1.discourse-cdn.com/flex020/uploads/sendbird/original/2X/a/aff8fc5890311a7d04cc16bcaaa9e1826a98ff1d.png)

---

<div class="post-metadata">

**Author:** ![rburton](https://avatars.discourse-cdn.com/v4/letter/r/ec9cab/32.png) [@rburton](https://community.sendbird.com/u/rburton)\
**Post date:** [October 8, 2021, 1:01am UTC](https://community.sendbird.com/t/postman-authorization/3186/7 "2021-10-08T01:01:26Z")

</div>

What is the “Organization API”?

---

<div class="post-metadata">

**Author:** ![rburton](https://avatars.discourse-cdn.com/v4/letter/r/ec9cab/32.png) [@rburton](https://community.sendbird.com/u/rburton)\
**Post date:** [October 8, 2021, 1:09am UTC](https://community.sendbird.com/t/postman-authorization/3186/8 "2021-10-08T01:09:34Z")

</div>

I see the Master Api Token but I don’t seem to be able to access it. Is there another password other than the one I use to login to the dashboard?

---

<div class="post-metadata">

**Author:** ![Tyler](https://sea2.discourse-cdn.com/flex020/user_avatar/community.sendbird.com/tyler/32/810_2.png) [@Tyler](https://community.sendbird.com/u/Tyler)\
**Post date:** [October 8, 2021, 12:49pm UTC](https://community.sendbird.com/t/postman-authorization/3186/9 "2021-10-08T12:49:40Z")

</div>

The Organization API is the API used to manage your organization: [Organization API | Chat Platform API | Sendbird Docs](https://sendbird.com/docs/chat/v3/platform-api/guides/organization-api#1-organization-api)

The Master API token should be visible using the password you used to sign in as long as you’re the owner or an admin.

---

<div class="post-metadata">

**Author:** ![rburton](https://avatars.discourse-cdn.com/v4/letter/r/ec9cab/32.png) [@rburton](https://community.sendbird.com/u/rburton)\
**Post date:** [October 8, 2021, 1:53pm UTC](https://community.sendbird.com/t/postman-authorization/3186/10 "2021-10-08T13:53:25Z")

</div>

If I am using Postman should I delve into the Organization API? As an organization we primarily use the JavaScript SDK to send/receive messages. II am interested in using Postman to exercise some requests that normally would use the JavaScript SDK.

I guess I am not the owner or admin because my password doesn’t seem to work. Is there a way to tell if I am an owner or admin?

---

<div class="post-metadata">

**Author:** ![Tyler](https://sea2.discourse-cdn.com/flex020/user_avatar/community.sendbird.com/tyler/32/810_2.png) [@Tyler](https://community.sendbird.com/u/Tyler)\
**Post date:** [October 8, 2021, 2:26pm UTC](https://community.sendbird.com/t/postman-authorization/3186/11 "2021-10-08T14:26:53Z")

</div>

The Organization API is utilized to manage the organization, such as creation applications programatically. The Javascript SDK would not have any ability to interaction with that API. Since you’re looking to make calls that the Javascript SDK would, you would want to utilize the Platform API.

I checked your role within your organization and you are neither an Admin or Owner and so you would need to request that token from someone within your organization that does have that access.

---

<div class="post-metadata">

**Author:** ![rburton](https://avatars.discourse-cdn.com/v4/letter/r/ec9cab/32.png) [@rburton](https://community.sendbird.com/u/rburton)\
**Post date:** [October 8, 2021, 8:03pm UTC](https://community.sendbird.com/t/postman-authorization/3186/12 "2021-10-08T20:03:42Z")

</div>

Sorry to be such a pain. I entered the Api-Token, and now I get another failed response:  
{

```
"message": "Not authorized. \"The delivery receipt feature is not enabled.\".",

"code": 400108,

"error": true

```

}

---

<div class="post-metadata">

**Author:** ![Tyler](https://sea2.discourse-cdn.com/flex020/user_avatar/community.sendbird.com/tyler/32/810_2.png) [@Tyler](https://community.sendbird.com/u/Tyler)\
**Post date:** [October 8, 2021, 8:13pm UTC](https://community.sendbird.com/t/postman-authorization/3186/13 "2021-10-08T20:13:14Z")

</div>

What endpoint did you call? It looks like it has something to do with delivery receipts, which is not enabled on the application you’re accessing. This can be seen by going to Settings \> Features

---

<div class="post-metadata">

**Author:** ![rburton](https://avatars.discourse-cdn.com/v4/letter/r/ec9cab/32.png) [@rburton](https://community.sendbird.com/u/rburton)\
**Post date:** [October 8, 2021, 8:30pm UTC](https://community.sendbird.com/t/postman-authorization/3186/14 "2021-10-08T20:30:20Z")

</div>

I am just copying the URL that chows up in the network tab (in the Chrome debugger) of our application that uses JavaScript SDK. It apparently works. At least it returns a 200 HTTP status code.
