POSTMAN Digest authentication not working

1.6k Views Asked by At

I am trying to access a REST API (Shopware to be specific), which is hosted externally. When I log in to the frontend in the browser, I first need to enter a set of credentials in the browser authentication pop up. And then the application opens and I need to enter the application credentials.

I assumed the authentication for the API would also be similar.

This is how I see this set up: (sorry for the crude image) Set up pic

So first, I use HTTP Basic auth and pass my browser credentials to the server. I get the following response:

{
    "success": false,
    "message": "Invalid or missing auth"
} 

But in the Response header I get

Basic realm="<Realm B>", Digest realm="<Realm B>", domain="/", nonce="<nonce>", opaque="<opaque value>", algorithm="MD5", qop="auth"
  1. Does this response mean that both Basic and Digest are supported for Realm B and the client can use any one of these?

I tried to authenticate again with Digest Auth chosen in postman,and using the realm B, nonce, opaque and qop values provided in the previous request. But I still get a 401 Unauthorized error.

What am I missing? How does this two factor auth work via Postman? Thanks in advance for your help.

0

There are 0 best solutions below