# Trouble using the Ghost admin API

**URL:** <https://forum.ghost.org/t/trouble-using-the-ghost-admin-api/12782>\
**Category:** Developer help\
**Created:** [March 17, 2020, 12:00pm UTC](https://forum.ghost.org/t/trouble-using-the-ghost-admin-api/12782 "2020-03-17T12:00:06Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![adriaan\_pelzer](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/adriaan_pelzer/32/6877_2.png) [@adriaan\_pelzer](https://forum.ghost.org/u/adriaan_pelzer)\
**Post date:** [March 17, 2020, 12:00pm UTC](https://forum.ghost.org/t/trouble-using-the-ghost-admin-api/12782/1 "2020-03-17T12:00:06Z")

</div>

I’ve been trying to use the Ghost Admin API (self-hosted) by two means:

1. HTTP to the REST api directly
2. Using the SDK (@tryghost/admin-api)

I’ve created a custom integration, and I’m trying to use the admin api key. I get 403 responses in both cases. Is this supposed to work, or am I missing a key negotiation step (i.e. OAuth or similar)?

---

<div class="post-metadata">

**Author:** ![Kevin](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/kevin/32/32_2.png) [@Kevin](https://forum.ghost.org/u/Kevin)\
**Post date:** [March 17, 2020, 12:07pm UTC](https://forum.ghost.org/t/trouble-using-the-ghost-admin-api/12782/2 "2020-03-17T12:07:05Z")

</div>

For token auth you need to generate JWTs. The `@tryghost/admin-api` should do that for you though. If you provide the full error response that would be useful as the error message will tell you what’s wrong.

[https://ghost.org/docs/api/v3/admin/#authentication](https://ghost.org/docs/api/v3/admin/#authentication)

---

<div class="post-metadata">

**Author:** ![adriaan\_pelzer](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/adriaan_pelzer/32/6877_2.png) [@adriaan\_pelzer](https://forum.ghost.org/u/adriaan_pelzer)\
**Post date:** [March 17, 2020, 2:08pm UTC](https://forum.ghost.org/t/trouble-using-the-ghost-admin-api/12782/3 "2020-03-17T14:08:32Z")

</div>

{  
“message”: “Request failed with status code 403”,  
“name”: “Error”,  
“stack”: “Error: Request failed with status code 403\n at createError (/Users/adriaan/clause-blog/process-content/node\_modules/axios/lib/core/createError.js:16:15)\n at settle (/Users/adriaan/clause-blog/process-content/node\_modules/axios/lib/core/settle.js:17:12)\n at IncomingMessage.handleStreamEnd (/Users/adriaan/clause-blog/process-content/node\_modules/axios/lib/adapters/http.js:236:11)\n at IncomingMessage.emit (events.js:203:15)\n at endReadableNT (\_stream\_readable.js:1129:12)\n at process.\_tickCallback (internal/process/next\_tick.js:63:19)”  
}

---

<div class="post-metadata">

**Author:** ![Kevin](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/kevin/32/32_2.png) [@Kevin](https://forum.ghost.org/u/Kevin)\
**Post date:** [March 17, 2020, 2:24pm UTC](https://forum.ghost.org/t/trouble-using-the-ghost-admin-api/12782/4 "2020-03-17T14:24:48Z")

</div>

@adriaan_pelzer that’s the generic error from the request library, are you able to get the response data that’s coming from Ghost’s API?

---

<div class="post-metadata">

**Author:** ![adriaan\_pelzer](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/adriaan_pelzer/32/6877_2.png) [@adriaan\_pelzer](https://forum.ghost.org/u/adriaan_pelzer)\
**Post date:** [March 17, 2020, 2:46pm UTC](https://forum.ghost.org/t/trouble-using-the-ghost-admin-api/12782/5 "2020-03-17T14:46:01Z")

</div>

@Kevin That is the response from the admin-api module; it’s the entire error being thrown, nothing omitted.

I have reverted to using sessions, as the front end does.  
It would be good, however, to get this working at some point.

Could you point me to ghost docs or an example detailing getting a JWT token, as that could be another viable route.

---

<div class="post-metadata">

**Author:** ![adriaan\_pelzer](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/adriaan_pelzer/32/6877_2.png) [@adriaan\_pelzer](https://forum.ghost.org/u/adriaan_pelzer)\
**Post date:** [March 17, 2020, 2:47pm UTC](https://forum.ghost.org/t/trouble-using-the-ghost-admin-api/12782/6 "2020-03-17T14:47:29Z")

</div>

@Kevin Apologies - just noticed you’ve already sent the JWT docs in the first response. That should suffice, thanks!
