# {'message': 'forbidden.'} What am I doing wrong?

**URL:** <https://forum.alpaca.markets/t/message-forbidden-what-am-i-doing-wrong/8692>\
**Category:** Alpaca Market Data\
**Created:** [March 9, 2022, 5:17am UTC](https://forum.alpaca.markets/t/message-forbidden-what-am-i-doing-wrong/8692 "2022-03-09T05:17:43Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Midi](https://avatars.discourse-cdn.com/v4/letter/m/dbc845/32.png) [@Midi](https://forum.alpaca.markets/u/Midi)\
**Post date:** [March 9, 2022, 5:17am UTC](https://forum.alpaca.markets/t/message-forbidden-what-am-i-doing-wrong/8692/1 "2022-03-09T05:17:43Z")

</div>

```auto
import requests
import json

endpoint = "https://data.sandbox.alpaca.markets/v2"
headers = json.loads(open("key.txt",'r').read())

symbol = "MSFT"
bar_url = endpoint + "/stocks/{}/bars".format(symbol)
params = {"start" : "2022-01-01",
          "limit" : 600,
          "timeframe" : "1Hour"}

r = requests.get(bar_url, headers = headers, params = params)

data = r.json()

```

I have also tried this with url

```auto
https://data.alpaca.markets/v2

```

Additionally I have regenerated my key several times and made sure the correct key was brought over.

Every time I get the error: {‘message’: ‘forbidden.’}  
Can someone please tell me what im doing wrong here?

---

<div class="post-metadata">

**Author:** ![oleg.rakhmatulin](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.alpaca.markets/oleg.rakhmatulin/32/559_2.png) [@oleg.rakhmatulin](https://forum.alpaca.markets/u/oleg.rakhmatulin)\
**Post date:** [March 9, 2022, 9:54am UTC](https://forum.alpaca.markets/t/message-forbidden-what-am-i-doing-wrong/8692/2 "2022-03-09T09:54:58Z")

</div>

You have to provide the secret id/key in HTTP request headers. Read more information [here](https://alpaca.markets/docs/api-references/trading-api/). This info is placed into the Trading API section of the new documentation but the authentication process is the same for all REST APIs provided by Alpaca.

---

<div class="post-metadata">

**Author:** ![Midi](https://avatars.discourse-cdn.com/v4/letter/m/dbc845/32.png) [@Midi](https://forum.alpaca.markets/u/Midi)\
**Post date:** [March 10, 2022, 4:06am UTC](https://forum.alpaca.markets/t/message-forbidden-what-am-i-doing-wrong/8692/3 "2022-03-10T04:06:20Z")

</div>

Hi Oleg, isn’t that what im doing? the key.txt file contains json with my key and ID which are assigned to the headers variable. If this is incorrect, can you show me in code how to fix this issue? I am new to alpacas api.

Thank you

_ **key.txt** _

```auto
{
"APCA_API_KEY_ID" : "XXXXXXXXXXXXX",
"APCA_API_SECRET_KEY" : "XXXXXXXXXXXXXXXXXXXXXXX"
}

```

---

<div class="post-metadata">

**Author:** ![oleg.rakhmatulin](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.alpaca.markets/oleg.rakhmatulin/32/559_2.png) [@oleg.rakhmatulin](https://forum.alpaca.markets/u/oleg.rakhmatulin)\
**Post date:** [March 11, 2022, 1:57pm UTC](https://forum.alpaca.markets/t/message-forbidden-what-am-i-doing-wrong/8692/4 "2022-03-11T13:57:56Z")

</div>

I’m not a Python developer. Your code looks fine but I’m not sure how headers passed into the `requests.get` function. Why not just check how it works with the official Python SDK?

---

<div class="post-metadata">

**Author:** ![Midi](https://avatars.discourse-cdn.com/v4/letter/m/dbc845/32.png) [@Midi](https://forum.alpaca.markets/u/Midi)\
**Post date:** [March 11, 2022, 6:30pm UTC](https://forum.alpaca.markets/t/message-forbidden-what-am-i-doing-wrong/8692/5 "2022-03-11T18:30:09Z")

</div>

So looked at it appears according to this it’s just expecting a dictionary  
[https://docs.python-requests.org/en/master/user/quickstart/](https://docs.python-requests.org/en/master/user/quickstart/)

I updated my code to directly pass the key values to the headers parameter and im still getting the same error

```auto
import requests
import json

endpoint = "https://data.alpaca.markets/v2"
headers = json.loads(open("key.txt",'r').read())

symbol = "MSFT"
bar_url = endpoint + "/stocks/{}/bars".format(symbol)
params = {"start" : "2022-01-01",
          "limit" : 600,
          "timeframe" : "1Hour"}

r = requests.get(bar_url, headers = {'APCA_API_KEY_ID':'XXXXXXXX','APCA_API_SECRET_KEY':'XXXXXXXXX'}, params = params)

data = r.json()

```

How confident are you that it’s the headers?

---

<div class="post-metadata">

**Author:** ![oleg.rakhmatulin](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.alpaca.markets/oleg.rakhmatulin/32/559_2.png) [@oleg.rakhmatulin](https://forum.alpaca.markets/u/oleg.rakhmatulin)\
**Post date:** [March 12, 2022, 7:44am UTC](https://forum.alpaca.markets/t/message-forbidden-what-am-i-doing-wrong/8692/6 "2022-03-12T07:44:17Z")

</div>

You should use dashes instead of underscores in header names. Read the [documentation](https://alpaca.markets/docs/api-references/trading-api/#authentication) carefully.

---

<div class="post-metadata">

**Author:** ![Midi](https://avatars.discourse-cdn.com/v4/letter/m/dbc845/32.png) [@Midi](https://forum.alpaca.markets/u/Midi)\
**Post date:** [March 14, 2022, 1:41pm UTC](https://forum.alpaca.markets/t/message-forbidden-what-am-i-doing-wrong/8692/7 "2022-03-14T13:41:37Z")

</div>

I can’t believe it that worked. Thank you!

---

<div class="post-metadata">

**Author:** ![jonathan.j.heath](https://avatars.discourse-cdn.com/v4/letter/j/f05b48/32.png) [@jonathan.j.heath](https://forum.alpaca.markets/u/jonathan.j.heath)\
**Post date:** [January 22, 2023, 10:18pm UTC](https://forum.alpaca.markets/t/message-forbidden-what-am-i-doing-wrong/8692/8 "2023-01-22T22:18:52Z")

</div>

I am getting this error code as well with the exact same code. I have dashes instead of underscores. What else could be wrong?
