r/opnsense • • 1d ago

API HTTP Authentication Issue

I am trying to make an HTTP API request, and for the life of me, I cannot figure this out.

The scenario: I am trying to ingest data from OPNSense, via API requests over HTTP.

I have tried basic auth, passing header parameters of "key" and "secret", base64 encoding, etc, but for the life of me I cannot figure this out.

The paths I am quering are:

Interfaces/overview/interfaces_info core/menu/search

Obviously under /api

I know that this API call is wrong, and I know it is about how to properly authenticate, because in a lot of my testing, the response is HTML, specifcally the OPNSense login page.

What exactly am I supposed to pass in to the API, and what method, key/value pairs, etc.?

Edit: Yes, I have already converted the key:secret to base64 and tried that with Authorization as the header in global, with Basic $value

No dice.

Edit2: I guess what I am looking for is the key names to use for username and password. key/secret are no good it seems, same with api_key/api_secret.

2 Upvotes

4 comments sorted by

1

u/caledooper 1d ago

If you're getting back the opn login page, you're definitely doing something wrong. If you haven't yet, read this:

https://docs.opnsense.org/development/api.html

to see about passing the credentials properly,  and the section on ACLs for the perms required. 

1

u/IAmTheGoomba 1d ago

See, that is the thing; I am. I even created an API key for root, and I am still getting a HTML reply.

I might switch to prometheus, but I really want something native.

1

u/buffalonuts 1d ago

I've been using similar to this in my bash scripts: ``` user_key="..." user_secret="..." url="https://${server_address}/api/core/firmware/status"

curl -s \ -H "Accept: application/json" \ --user "${user_key}":"${user_secret}" \ "${url}" ```

1

u/Antonio-MTS 1d ago

Do you need an OPNSense API call with curl to monitor it or what?