# What does this ERROR code means "UNAUTHENTICATED\_API\_CALL"?

**URL:** <https://community.rapyd.net/t/what-does-this-error-code-means-unauthenticated-api-call/4176>\
**Category:** 🙋🏽‍♀️🙋🏽‍♂️ Ask Questions\
**Created:** [June 13, 2022, 7:52am UTC](https://community.rapyd.net/t/what-does-this-error-code-means-unauthenticated-api-call/4176 "2022-06-13T07:52:02Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![jy967845](https://avatars.discourse-cdn.com/v4/letter/j/3be4f8/32.png) [@jy967845](https://community.rapyd.net/u/jy967845)\
**Post date:** [June 13, 2022, 7:52am UTC](https://community.rapyd.net/t/what-does-this-error-code-means-unauthenticated-api-call/4176/1 "2022-06-13T07:52:02Z")

</div>

Hello,  
I am getting this error code on Create Customer API.  
I did not find explanation for this Error Code.

I am not getting what I am doing wrong, Incorrect api Creadetails or account verification or incorrect api url??

---

<div class="post-metadata">

**Author:** ![aviarviv](https://avatars.discourse-cdn.com/v4/letter/a/b4bc9f/32.png) [@aviarviv](https://community.rapyd.net/u/aviarviv)\
**Post date:** [June 13, 2022, 9:27am UTC](https://community.rapyd.net/t/what-does-this-error-code-means-unauthenticated-api-call/4176/3 "2022-06-13T09:27:05Z")

</div>

This error means that one of your headers in the request is wrong.  
Could be the access\_key, signature, or the salt

---

<div class="post-metadata">

**Author:** ![CharlesDorsett](https://sea2.discourse-cdn.com/flex016/user_avatar/community.rapyd.net/charlesdorsett/32/47_2.png) [@CharlesDorsett](https://community.rapyd.net/u/CharlesDorsett)\
**Post date:** [June 13, 2022, 12:59pm UTC](https://community.rapyd.net/t/what-does-this-error-code-means-unauthenticated-api-call/4176/4 "2022-06-13T12:59:11Z")

</div>

This error drove me crazy when I was first learning the system. Basically it means that the request was malformed. It can come up in several contexts (maybe more):

- One or more of the header fields is missing or has an invalid value (as @aviarviv pointed out).
- There is an error in the calculation of the signature (possibly the body contains whitespace, or the body is represented by {} instead of being blank).
- The HTTP verb is not correct.

Check the API Reference carefully. Once you get the hang of it, you will hardly ever see this error. I’m sorry the error does not provide more helpful instructions.

---

<div class="post-metadata">

**Author:** ![NotWilliamShatner](https://avatars.discourse-cdn.com/v4/letter/n/59ef9b/32.png) [@NotWilliamShatner](https://community.rapyd.net/u/NotWilliamShatner)\
**Post date:** [June 22, 2022, 7:33pm UTC](https://community.rapyd.net/t/what-does-this-error-code-means-unauthenticated-api-call/4176/5 "2022-06-22T19:33:37Z")

</div>

I am getting this same error now, while orking through the `access-payments` sample, using Node.js for the back-end server.

```auto
Error: Network response was not OK. Check logs in the console.
{
    "message": {
        "error_code": "UNAUTHENTICATED_API_CALL",
        "status": "ERROR",
        "message": "access_key header is not valid",
        "response_code": "UNAUTHENTICATED_API_CALL",
        "operation_id": "e51d6e12-25b1-439b-ba84-85d5d3adb67c"
    }
}

```

I traced the server side code and I do see my access key and secret values when looking at the `this` object fields, from a breakpoint set in the constructor for the `RapydService` object:

```auto
  constructor() {
    this._accessKey = config.accessKey;
    this._secretKey = config.secretKey;
    this._baseUrl = config.baseRapydApiUrl;

```

I didn’t see any instructions in the `access-sample` readme regarding signature calculations or creating a `salt`, so I assumed the sample code did that for me?

Any help would be appreciated because I am not sure what to try next to fix this.

---

<div class="post-metadata">

**Author:** ![Community\_Team](https://avatars.discourse-cdn.com/v4/letter/c/46a35a/32.png) [@Community\_Team](https://community.rapyd.net/u/Community_Team)\
**Post date:** [June 22, 2022, 8:25pm UTC](https://community.rapyd.net/t/what-does-this-error-code-means-unauthenticated-api-call/4176/6 "2022-06-22T20:25:48Z")

</div>

Thanks @NotWilliamShatner,

Per our own @Community_Team,

> This is a node.js example The utilities.js file implements the signature calculation. You can refer to this at [GitHub - RapydPayments/rapyd-request-signatures: When you send a request, you calculate the signature and insert the result into the signature header. When the platform receives the request, it performs the same signature calculation. If the resulting values do not match, the request is rejected.](https://github.com/RapydPayments/rapyd-request-signatures)

He also follows this here: [https://youtu.be/IUqDc4Siq70?t=455](https://youtu.be/IUqDc4Siq70?t=455)

---

<div class="post-metadata">

**Author:** ![CharlesDorsett](https://sea2.discourse-cdn.com/flex016/user_avatar/community.rapyd.net/charlesdorsett/32/47_2.png) [@CharlesDorsett](https://community.rapyd.net/u/CharlesDorsett)\
**Post date:** [June 23, 2022, 7:35am UTC](https://community.rapyd.net/t/what-does-this-error-code-means-unauthenticated-api-call/4176/7 "2022-06-23T07:35:51Z")

</div>

I assume you are doing your development in the sandbox. You have to use the sandbox access key and secret key, and not the production keys. You get both from the Client Portal (when you are logged in as account owner), and you select one or the other with the Sandbox toggle at the lower left of the screen.

---

<div class="post-metadata">

**Author:** ![Olamihybr](https://avatars.discourse-cdn.com/v4/letter/o/50afbb/32.png) [@Olamihybr](https://community.rapyd.net/u/Olamihybr)\
**Post date:** [August 19, 2022, 9:20pm UTC](https://community.rapyd.net/t/what-does-this-error-code-means-unauthenticated-api-call/4176/10 "2022-08-19T21:20:14Z")

</div>

Hi @Community_Team

I am running crazy here. I keep getting the same error I followed the YouTube video directions on how to request signatures, used the secret and access key I was given but I keep getting this 😰

```
},
"body": {
    "status": {
        "error_code": "UNAUTHENTICATED_API_CALL",
        "status": "ERROR",
        "message": "access_key header is not valid",
        "response_code": "UNAUTHENTICATED_API_CALL",
        "operation_id": "6d96331b-8a24-419c-82c7-d52c9eeb8438"
    }
}

```

}

---

<div class="post-metadata">

**Author:** ![Olamihybr](https://avatars.discourse-cdn.com/v4/letter/o/50afbb/32.png) [@Olamihybr](https://community.rapyd.net/u/Olamihybr)\
**Post date:** [August 19, 2022, 9:43pm UTC](https://community.rapyd.net/t/what-does-this-error-code-means-unauthenticated-api-call/4176/11 "2022-08-19T21:43:33Z")

</div>

could it be because I have not activated my account?

---

<div class="post-metadata">

**Author:** ![Olamihybr](https://avatars.discourse-cdn.com/v4/letter/o/50afbb/32.png) [@Olamihybr](https://community.rapyd.net/u/Olamihybr)\
**Post date:** [August 19, 2022, 9:54pm UTC](https://community.rapyd.net/t/what-does-this-error-code-means-unauthenticated-api-call/4176/12 "2022-08-19T21:54:47Z")

</div>

NO worried. I’ve sorted it out. Madness over, I was using production credentials instead. The toggle button confused me

---

<div class="post-metadata">

**Author:** ![Community\_Team](https://avatars.discourse-cdn.com/v4/letter/c/46a35a/32.png) [@Community\_Team](https://community.rapyd.net/u/Community_Team)\
**Post date:** [August 19, 2022, 10:06pm UTC](https://community.rapyd.net/t/what-does-this-error-code-means-unauthenticated-api-call/4176/13 "2022-08-19T22:06:50Z")

</div>

Thanks @Olamihybr,

Just confirming you have your [Sandbox access and secret key](https://docs.rapyd.net/client-portal/docs/developers) with the Sandbox request URL.

`https://sandboxapi.rapyd.net/v1/data/countries`

Are you making your request in Node.js?

If you haven’t made any test request yet, here’s a simple [guide of making a request in Postman with your Sandbox credentials](https://community.rapyd.net/t/set-your-api-keys-in-postman-rapyd-sandbox-environment/1055).

Here’s a comment with more resources, however these may be address a different error related to when the The API received a request, but the signature did not match.

> [@Issue in creating signature in Go Lang](https://community.rapyd.net/t/issue-in-creating-signature-in-go-lang/1627/2):
>
> Hi @Abdul_Waheed, From the error response, this may be due to a couple things: All spaces and other whitespace outside of strings must be removed. Numbers should be sent in strings, not as integers/numbers. Here are some resources that may help: [Rapyd API Request Signatures and How to Calculate](https://community.rapyd.net/t/rapyd-api-request-signatures-and-how-to-calculate/1256)[Verify Webhook Signature? - #2 by Minh\_Nguy\_n\_Van](https://community.rapyd.net/t/verify-webhook-signature/1383/2)[How to verify Webhook Signature with PHP script](https://community.rapyd.net/t/how-to-verify-webhook-signature-with-php-script/1382)[https://youtu.be/yL5TK4JfP7s](https://youtu.be/yL5TK4JfP7s) I would also take a look around your body and and how it may not be pa…

---

<div class="post-metadata">

**Author:** ![Community\_Team](https://avatars.discourse-cdn.com/v4/letter/c/46a35a/32.png) [@Community\_Team](https://community.rapyd.net/u/Community_Team)\
**Post date:** [December 21, 2022, 5:52pm UTC](https://community.rapyd.net/t/what-does-this-error-code-means-unauthenticated-api-call/4176/14 "2022-12-21T17:52:11Z")

</div>

A post was split to a new topic: [Client Portal Sandbox / Production Switch](https://community.rapyd.net/t/client-portal-sandbox-production-switch/58256)

---

<div class="post-metadata">

**Author:** ![drew.harris](https://sea2.discourse-cdn.com/flex016/user_avatar/community.rapyd.net/drew.harris/32/1259_2.png) [@drew.harris](https://community.rapyd.net/u/drew.harris)\
**Post date:** [April 4, 2023, 3:37pm UTC](https://community.rapyd.net/t/what-does-this-error-code-means-unauthenticated-api-call/4176/15 "2023-04-04T15:37:08Z")

</div>


