# Curl. Bad request. No token or api key provided. On login

**URL:** <https://community.dreamfactory.com/t/curl-bad-request-no-token-or-api-key-provided-on-login/3618>\
**Category:** uncategorized\
**Created:** [February 3, 2017, 11:41pm UTC](https://community.dreamfactory.com/t/curl-bad-request-no-token-or-api-key-provided-on-login/3618 "2017-02-03T23:41:35Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![adrianblakey](https://avatars.discourse-cdn.com/v4/letter/a/a183cd/32.png) [@adrianblakey](https://community.dreamfactory.com/u/adrianblakey)\
**Post date:** [February 3, 2017, 11:41pm UTC](https://community.dreamfactory.com/t/curl-bad-request-no-token-or-api-key-provided-on-login/3618/1 "2017-02-03T23:41:35Z")

</div>

Any ideas why this does not work?

DreamFactory 2.4.2 RHEL 6.8

curl -i -k -X POST [https://host/api/v2/mongodb/user/session](https://host/api/v2/mongodb/user/session) -d ‘{ “email” : "me@some.org", “password” : “password” }’ -H 'Content-Type: application/json’  
HTTP/1.1 400 Bad Request  
Date: Fri, 03 Feb 2017 23:38:02 GMT  
Server: Apache  
X-Frame-Options: SAMEORIGIN  
Vary: Cookie  
X-Powered-By: PHP/7.0.15  
Cache-Control: no-cache  
Content-Length: 92  
Connection: close  
Content-Type: application/json

{“error”:{“context”:null,“message”:“Bad request. No token or api key provided.”,“code”:400}}+ exit

For refn - this does.

curl -s -k [https://me%40some.org:password@host/api/v2/mongodb](https://me%40some.org:password@host/api/v2/mongodb)  
++ local ‘RESULT={“resource”:[{“name”:"\_schema"},{“name”:"\_table"}]}’

---

<div class="post-metadata">

**Author:** ![Jedi](https://yyz1.discourse-cdn.com/flex035/user_avatar/community.dreamfactory.com/jedi/32/1058_2.png) [@Jedi](https://community.dreamfactory.com/u/Jedi)\
**Post date:** [February 6, 2017, 7:02pm UTC](https://community.dreamfactory.com/t/curl-bad-request-no-token-or-api-key-provided-on-login/3618/2 "2017-02-06T19:02:23Z")

</div>

because you’re not logging in with that call.  
you’re accessing the mongodb service and trying to append user/session to the end of it. Mongodb service requires an api key and/or session token to operate.  
If you want to use sessions, you need to POST user/session first. Then take the session token and use it in your subsequent calls (which will need both a token and an api key)
