Guide

Authentication

@auth bearer {{token}}
@auth basic {{user}} {{secret(password)}}
@auth jwt {{token}}
@auth apikey X-API-Key {{key}}
@auth oauth2 client_credentials token_url={{idp}}/token client_id=app client_secret={{secret(clientSecret)}}

An @auth line before the first request applies to the whole file. OAuth 2 tokens are fetched once and reused until they expire.

In the app: the Auth tab of the request, which writes the same @auth line. A header you type by hand always wins.

@needs and @auth lines in the file, which the Auth tab writes for you
@needs and @auth lines in the file, which the Auth tab writes for you

Back: Secrets Next: Scripts and assertions