# API autentication with sso login

**URL:** <https://hub.mender.io/t/api-autentication-with-sso-login/3469>\
**Category:** General Discussions\
**Tags:** api, authentication\
**Created:** [April 7, 2021, 10:06am UTC](https://hub.mender.io/t/api-autentication-with-sso-login/3469 "2021-04-07T10:06:12Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![profff](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/profff/32/1117_2.png) [@profff](https://hub.mender.io/u/profff)\
**Post date:** [April 7, 2021, 10:06am UTC](https://hub.mender.io/t/api-autentication-with-sso-login/3469/1 "2021-04-07T10:06:12Z")

</div>

hi all I’m using my google account to get connected to mender UI  
I’m about to try to setup a pre-authorization process and try to get access to rest API  
but how can I do when using a google account when trying to get the JWT even if I enter my google account pass it will not work as sso auth dont work like this …  
if anyone has an idea how to get this working ?

---

<div class="post-metadata">

**Author:** ![drewmoseley](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/drewmoseley/32/47_2.png) [@drewmoseley](https://hub.mender.io/u/drewmoseley)\
**Post date:** [April 7, 2021, 1:33pm UTC](https://hub.mender.io/t/api-autentication-with-sso-login/3469/2 "2021-04-07T13:33:55Z")

</div>

Can you share specific commands you are executing that are not working?

Drew

---

<div class="post-metadata">

**Author:** ![profff](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/profff/32/1117_2.png) [@profff](https://hub.mender.io/u/profff)\
**Post date:** [April 7, 2021, 2:04pm UTC](https://hub.mender.io/t/api-autentication-with-sso-login/3469/3 "2021-04-07T14:04:30Z")

</div>

```auto
$ MENDER_SERVER_URI='https://hosted.mender.io'
$ MENDER_SERVER_USER='myemail'
$ JWT=$(curl -X POST -u $MENDER_SERVER_USER $MENDER_SERVER_URI/api/management/v1/useradm/auth/login)

```

but as my account is google linked one ( and not a mender sub)

```auto
$ source env.sh
Enter host password for user '<myemail>':
  % Total % Received % Xferd Average Speed Time Time Time Current
                                 Dload Upload Total Spent Left Speed
100 76 100 76 0 0 110 0 --:--:-- --:--:-- --:--:-- 110
$ echo $JWT
{"error":"unauthorized","request_id":"10f8b728-31fa-455c-aa60-33ccc8202e77"}

```

i have tested with a blank new account created on mender ui and it work great except I cant attach it to my existing organization ( I supressed the second account and tried to create a new used under my first account organisation and I get :

> There was an error creating the user. internal error [Request ID: 1c9a3fea]

---

<div class="post-metadata">

**Author:** ![profff](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/profff/32/1117_2.png) [@profff](https://hub.mender.io/u/profff)\
**Post date:** [April 7, 2021, 4:15pm UTC](https://hub.mender.io/t/api-autentication-with-sso-login/3469/4 "2021-04-07T16:15:59Z")

</div>

ok I found another solution by adding another non pre existing user

---

<div class="post-metadata">

**Author:** ![drewmoseley](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/drewmoseley/32/47_2.png) [@drewmoseley](https://hub.mender.io/u/drewmoseley)\
**Post date:** [April 7, 2021, 11:49pm UTC](https://hub.mender.io/t/api-autentication-with-sso-login/3469/5 "2021-04-07T23:49:47Z")

</div>

OK. I’m not sure how the Google account linking works. It may indeed be a limitation that 2FA based Google accounts cannot use the API.

@tranchitella can you comment?

Drew

---

<div class="post-metadata">

**Author:** ![tranchitella](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/tranchitella/32/606_2.png) [@tranchitella](https://hub.mender.io/u/tranchitella)\
**Post date:** [April 8, 2021, 3:49am UTC](https://hub.mender.io/t/api-autentication-with-sso-login/3469/6 "2021-04-08T03:49:13Z")

</div>

@profff what you found out is correct: you cannot use OAuth 2.0 users (Google/GitHub) to get programmatic access to the APIs. You need to create a standard/password-based user in your tenant and use that to authenticate before consuming the APIs end-point.

If you still have issues with your users, feel free to reach the support by email, and we’ll fix it: an email address can be linked to a single tenant only; if you have multiple trial tenants adding the same email address as a user can fail.

---

<div class="post-metadata">

**Author:** ![profff](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/profff/32/1117_2.png) [@profff](https://hub.mender.io/u/profff)\
**Post date:** [April 8, 2021, 8:06am UTC](https://hub.mender.io/t/api-autentication-with-sso-login/3469/7 "2021-04-08T08:06:42Z")

</div>

thank’s all for your help

---

<div class="post-metadata">

**Author:** ![kbroughton](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/kbroughton/32/1817_2.png) [@kbroughton](https://hub.mender.io/u/kbroughton)\
**Post date:** [March 24, 2023, 2:21pm UTC](https://hub.mender.io/t/api-autentication-with-sso-login/3469/8 "2023-03-24T14:21:20Z")

</div>

@tranchitella Is this still the case in March 2023?  
“you cannot use OAuth 2.0 users (Google/GitHub) to get programmatic access to the APIs.”

---

<div class="post-metadata">

**Author:** ![tranchitella](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/tranchitella/32/606_2.png) [@tranchitella](https://hub.mender.io/u/tranchitella)\
**Post date:** [March 25, 2023, 3:57am UTC](https://hub.mender.io/t/api-autentication-with-sso-login/3469/9 "2023-03-25T03:57:57Z")

</div>

Correct @kbroughton
