# Api Error: "Invalid key supplied"

**URL:** https://community.xibo.org.uk/t/api-error-invalid-key-supplied/31518
**Category:** CMS Features and Functionality
**Created:** [April 10, 2024, 1:17pm UTC](https://community.xibo.org.uk/t/api-error-invalid-key-supplied/31518 "2024-04-10T13:17:44Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![sasch90](https://community.xibo.org.uk/user_avatar/community.xibo.org.uk/sasch90/32/13311_2.png) [@sasch90](https://community.xibo.org.uk/u/sasch90)
#### Post date: [April 10, 2024, 1:17pm UTC](https://community.xibo.org.uk/t/api-error-invalid-key-supplied/31518/1 "2024-04-10T13:17:44Z")

</div>

To be completed by the original poster:

# CMS Version

4.0.9

# Issue

Does anyone knows what “key” the CMS mean? I tried the (little bit outdated) manual of [Getting Started with Postman | Xibo Digital Signage](https://xibosignage.com/docs/developer/cms-api/getting-started-with-postman)

and the CMS shows this Error on the Logs:

 ![Bildschirmfoto 2024-04-10 um 13.20.56](https://community.xibo.org.uk/uploads/default/original/2X/2/2226b30e23bf8618d400394792219db3542895bd.png)

---

<div class="post-metadata">

### Author: ![ProServ](https://community.xibo.org.uk/user_avatar/community.xibo.org.uk/proserv/32/9355_2.png) [@ProServ](https://community.xibo.org.uk/u/ProServ)
#### Post date: [April 10, 2024, 8:52pm UTC](https://community.xibo.org.uk/t/api-error-invalid-key-supplied/31518/2 "2024-04-10T20:52:38Z")

</div>

This documentation, though in need of updating, is still up to date.

Having used it, I haven’t had any major problems.

Have you created a new application, like this?

 ![image](https://community.xibo.org.uk/uploads/default/original/2X/2/2507d1f49f70a9074f6b38e6ac343f5455ff4fce.png)

Can you give us the API request you want?

What are you using to test the API?

Did you ask for an authorisation key before sending your GET/POST?

---

<div class="post-metadata">

### Author: ![sasch90](https://community.xibo.org.uk/user_avatar/community.xibo.org.uk/sasch90/32/13311_2.png) [@sasch90](https://community.xibo.org.uk/u/sasch90)
#### Post date: [April 16, 2024, 1:24pm UTC](https://community.xibo.org.uk/t/api-error-invalid-key-supplied/31518/3 "2024-04-16T13:24:55Z")

</div>

Hey, thank you for the reply. I created the app, checked “Authorisation Code” and “Is Credential”  
Then i added like in the screenshot to Postman (also tried it with [make.com](http://make.com))

 ![image](https://community.xibo.org.uk/uploads/default/original/2X/9/9a0f14ab478124946ed3a4153727000c4c3b9763.png)

and if i click on: “Get New Access Token” it opens a browser window:

 ![image](https://community.xibo.org.uk/uploads/default/original/2X/6/62d8217aaa5b1dfd3228072e75994f77df9a31fe.jpeg)

and throws the errors shown in the first post.  
Maybe is this an error with the .key files in my (self hosted) cms?

---

<div class="post-metadata">

### Author: ![ProServ](https://community.xibo.org.uk/user_avatar/community.xibo.org.uk/proserv/32/9355_2.png) [@ProServ](https://community.xibo.org.uk/u/ProServ)
#### Post date: [April 16, 2024, 4:45pm UTC](https://community.xibo.org.uk/t/api-error-invalid-key-supplied/31518/4 "2024-04-16T16:45:33Z")

</div>

Try with this exemple:

 ![image](https://community.xibo.org.uk/uploads/default/original/2X/2/23e86f20f49194bb3c2fd8674e949953162e13f5.png)

Don’t forget to set your variables: [Store and reuse values using variables | Postman Learning Center](https://learning.postman.com/docs/sending-requests/variables/variables/)

Like this:

 ![image](https://community.xibo.org.uk/uploads/default/original/2X/9/9c558be35c39224646502ac4f1ad52ae336231d9.png)

---

<div class="post-metadata">

### Author: ![ProServ](https://community.xibo.org.uk/user_avatar/community.xibo.org.uk/proserv/32/9355_2.png) [@ProServ](https://community.xibo.org.uk/u/ProServ)
#### Post date: [April 16, 2024, 4:58pm UTC](https://community.xibo.org.uk/t/api-error-invalid-key-supplied/31518/5 "2024-04-16T16:58:23Z")

</div>

> [@sasch90](#):
>
> i click on: “Get New Access Token”

You try to get an OAuth 2.0 token.  
Xibo’s API don’t work with this token.

You need to get a Token by Send a Request “POST”.  
After that, you can set this “bearer token” to your collection:

 ![image](https://community.xibo.org.uk/uploads/default/original/2X/5/58125eaa249eaa6294218fbf5c6262c30160e2c4.png)

Or to your header requests:

 ![image](https://community.xibo.org.uk/uploads/default/original/2X/1/1951b34ffa24e5e4634358da33cf5e4aec965067.png)

---

<div class="post-metadata">

### Author: ![sasch90](https://community.xibo.org.uk/user_avatar/community.xibo.org.uk/sasch90/32/13311_2.png) [@sasch90](https://community.xibo.org.uk/u/sasch90)
#### Post date: [April 16, 2024, 6:28pm UTC](https://community.xibo.org.uk/t/api-error-invalid-key-supplied/31518/6 "2024-04-16T18:28:13Z")

</div>

I tried it all. The answer is always a Error with 500 Code:

> {“error”:0,“message”:“API configuration problem, consult your administrator”}

and xibo doesn’t say why.  
I think there is a faulty configuration in my CMS

* * *

another question. At the screenshot in the manual is “Oauth 2.0 on the top”  
[![](https://xibosignage.com/img/developer/0cb838b8dc040e9dc972ca55136fe284f9e91f3c_2_307x500.png) ](https://xibosignage.com/img/developer/0cb838b8dc040e9dc972ca55136fe284f9e91f3c_2_307x500.png)

---

<div class="post-metadata">

### Author: ![ProServ](https://community.xibo.org.uk/user_avatar/community.xibo.org.uk/proserv/32/9355_2.png) [@ProServ](https://community.xibo.org.uk/u/ProServ)
#### Post date: [April 16, 2024, 6:31pm UTC](https://community.xibo.org.uk/t/api-error-invalid-key-supplied/31518/7 "2024-04-16T18:31:45Z")

</div>

> [@sasch90](#):
>
> At the screenshot in the manual is “Oauth 2.0 on the top”

I think it’s a bad information.

But I could be wrong.

@dan, can you confirm that you can’t request API authorisation with an OAuth 2.0 token?

---

<div class="post-metadata">

### Author: ![sasch90](https://community.xibo.org.uk/user_avatar/community.xibo.org.uk/sasch90/32/13311_2.png) [@sasch90](https://community.xibo.org.uk/u/sasch90)
#### Post date: [April 16, 2024, 6:51pm UTC](https://community.xibo.org.uk/t/api-error-invalid-key-supplied/31518/8 "2024-04-16T18:51:46Z")

</div>

I am a Step forward. The documentation [here](https://xibosignage.com/docs/setup/xibo-on-a-web-server#content-after-installation) says:

> The CMS requires a pub/private RSA keypair and an encryption key to be saved in the library folder.

But my Library is at another place. So i created the files and put it in the [cms]/library folder. But this was the error. Now i understand. The documentation menans not **the** Library folder. It means **my** library Folder. Just like in the settings. Now i try again 🙂 because the error is now another one:  
{  
“error”: “invalid\_client”,  
“error\_description”: “Client authentication failed”,  
“message”: “Client authentication failed”  
}

complicated world 🤯 😅

---

<div class="post-metadata">

### Author: ![ProServ](https://community.xibo.org.uk/user_avatar/community.xibo.org.uk/proserv/32/9355_2.png) [@ProServ](https://community.xibo.org.uk/u/ProServ)
#### Post date: [April 16, 2024, 7:05pm UTC](https://community.xibo.org.uk/t/api-error-invalid-key-supplied/31518/9 "2024-04-16T19:05:02Z")

</div>

I thought you were using Xibo for Docker with a reverse proxy.

It’s so easy to use Docker.

Take a screenshot to your Postman code snippet like that:

 ![image](https://community.xibo.org.uk/uploads/default/original/2X/7/7d7fb71eac84875b4563e418ab4d01bcf0eac45a.png)

---

<div class="post-metadata">

### Author: ![sasch90](https://community.xibo.org.uk/user_avatar/community.xibo.org.uk/sasch90/32/13311_2.png) [@sasch90](https://community.xibo.org.uk/u/sasch90)
#### Post date: [April 16, 2024, 7:23pm UTC](https://community.xibo.org.uk/t/api-error-invalid-key-supplied/31518/10 "2024-04-16T19:23:20Z")

</div>

its a self hosted CMS with PHP

---

<div class="post-metadata">

### Author: ![ProServ](https://community.xibo.org.uk/user_avatar/community.xibo.org.uk/proserv/32/9355_2.png) [@ProServ](https://community.xibo.org.uk/u/ProServ)
#### Post date: [April 16, 2024, 7:27pm UTC](https://community.xibo.org.uk/t/api-error-invalid-key-supplied/31518/11 "2024-04-16T19:27:39Z")

</div>

Please uncheck “Authorization” and “Cookie” under “Headers” tab.

---

<div class="post-metadata">

### Author: ![sasch90](https://community.xibo.org.uk/user_avatar/community.xibo.org.uk/sasch90/32/13311_2.png) [@sasch90](https://community.xibo.org.uk/u/sasch90)
#### Post date: [April 16, 2024, 7:30pm UTC](https://community.xibo.org.uk/t/api-error-invalid-key-supplied/31518/12 "2024-04-16T19:30:11Z")

</div>

done 🙂 same response

---

<div class="post-metadata">

### Author: ![sasch90](https://community.xibo.org.uk/user_avatar/community.xibo.org.uk/sasch90/32/13311_2.png) [@sasch90](https://community.xibo.org.uk/u/sasch90)
#### Post date: [April 16, 2024, 7:31pm UTC](https://community.xibo.org.uk/t/api-error-invalid-key-supplied/31518/13 "2024-04-16T19:31:55Z")

</div>

would be so great to get the access token from the CMS in the UI. So much hours for that ☹

---

<div class="post-metadata">

### Author: ![ProServ](https://community.xibo.org.uk/user_avatar/community.xibo.org.uk/proserv/32/9355_2.png) [@ProServ](https://community.xibo.org.uk/u/ProServ)
#### Post date: [April 16, 2024, 7:33pm UTC](https://community.xibo.org.uk/t/api-error-invalid-key-supplied/31518/14 "2024-04-16T19:33:21Z")

</div>

Take a screenshot to your Application Profil, like this:

 ![image](https://community.xibo.org.uk/uploads/default/original/2X/7/731074b5bb4548e72533718d53d48b0312b2dd7b.png)

And under Sharing tab

 ![image](https://community.xibo.org.uk/uploads/default/original/2X/c/c1559fafd84bccdfb314e77faa8dc611a865e0fc.png)

---

<div class="post-metadata">

### Author: ![sasch90](https://community.xibo.org.uk/user_avatar/community.xibo.org.uk/sasch90/32/13311_2.png) [@sasch90](https://community.xibo.org.uk/u/sasch90)
#### Post date: [April 16, 2024, 7:39pm UTC](https://community.xibo.org.uk/t/api-error-invalid-key-supplied/31518/15 "2024-04-16T19:39:08Z")

</div>

![Bildschirmfoto 2024-04-16 um 21.37.13](https://community.xibo.org.uk/uploads/default/original/2X/b/b69dc4bd532c72036d94db954f2e8af650510cbb.png)  
 ![screen1](https://community.xibo.org.uk/uploads/default/original/2X/d/d3f6a6ae8649a6ad4fbbb90e6d164e042d8d7de5.jpeg)

---

<div class="post-metadata">

### Author: ![ProServ](https://community.xibo.org.uk/user_avatar/community.xibo.org.uk/proserv/32/9355_2.png) [@ProServ](https://community.xibo.org.uk/u/ProServ)
#### Post date: [April 16, 2024, 7:52pm UTC](https://community.xibo.org.uk/t/api-error-invalid-key-supplied/31518/16 "2024-04-16T19:52:06Z")

</div>

I think I’ve give the wrong information

Try with all 3 boxes checked, or at a minimum the first 2.

![image](https://community.xibo.org.uk/uploads/default/original/2X/9/922341be50bf1cd9a72f15320f779fd40af9743d.png)

---

<div class="post-metadata">

### Author: ![sasch90](https://community.xibo.org.uk/user_avatar/community.xibo.org.uk/sasch90/32/13311_2.png) [@sasch90](https://community.xibo.org.uk/u/sasch90)
#### Post date: [April 16, 2024, 7:56pm UTC](https://community.xibo.org.uk/t/api-error-invalid-key-supplied/31518/17 "2024-04-16T19:56:44Z")

</div>

if i check all the 3 checkboxes, there is a new error (500) and its translated into german:

{  
“success”: false,  
“error”: 500,  
“message”: “Unerwarteter Fehler, bitte den Support kontaktieren.”  
}

something like: “unexpected error”

---

<div class="post-metadata">

### Author: ![ProServ](https://community.xibo.org.uk/user_avatar/community.xibo.org.uk/proserv/32/9355_2.png) [@ProServ](https://community.xibo.org.uk/u/ProServ)
#### Post date: [April 16, 2024, 8:01pm UTC](https://community.xibo.org.uk/t/api-error-invalid-key-supplied/31518/18 "2024-04-16T20:01:32Z")

</div>

And with the last box unchecked “Is Confidential”?

---

<div class="post-metadata">

### Author: ![sasch90](https://community.xibo.org.uk/user_avatar/community.xibo.org.uk/sasch90/32/13311_2.png) [@sasch90](https://community.xibo.org.uk/u/sasch90)
#### Post date: [April 16, 2024, 8:32pm UTC](https://community.xibo.org.uk/t/api-error-invalid-key-supplied/31518/19 "2024-04-16T20:32:26Z")

</div>

{  
“error”: “invalid\_client”,  
“error\_description”: “Client authentication failed”,  
“message”: “Client authentication failed”  
}

---

<div class="post-metadata">

### Author: ![ProServ](https://community.xibo.org.uk/user_avatar/community.xibo.org.uk/proserv/32/9355_2.png) [@ProServ](https://community.xibo.org.uk/u/ProServ)
#### Post date: [April 16, 2024, 10:02pm UTC](https://community.xibo.org.uk/t/api-error-invalid-key-supplied/31518/20 "2024-04-16T22:02:51Z")

</div>

Strange,

Please let me add a New instance for testing that.

[Next page](https://community.xibo.org.uk/t/api-error-invalid-key-supplied/31518.md?page=2)
