# 用户 API 密钥规范

**URL:** <https://meta.discourse.org/t/user-api-keys-specification/48536>\
**Category:** Integrations\
**Tags:** rest-api, reference\
**Created:** [2016年八月12日 02:11 UTC](https://meta.discourse.org/t/user-api-keys-specification/48536 "2016-08-12T02:11:53Z")\
**Posts on this page:** 1\
**Showing post:** 25

<div class="post-metadata">

**Author:** ![Alan\_Murphy](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/alan_murphy/32/139391_2.png) [@Alan\_Murphy](https://meta.discourse.org/u/Alan_Murphy)\
**Post date:** [2019年八月9日 09:09 UTC](https://meta.discourse.org/t/user-api-keys-specification/48536/25 "2019-08-09T09:09:47Z")

</div>

我认为不需要为每个用户单独分配一个密钥……一个管理员密钥就足以满足我的需求。

通过 Postman 调用 API 完全没有问题。例如，使用 api-key 作为请求头发起对 /notifications.json?username=alanmurphy 的 GET 请求，可以正常返回数据。

如果我在 Discourse 安装的控制台中触发该请求，同样可以正常获取数据，如下所示：

var xhr = new XMLHttpRequest();  
xhr.addEventListener(“readystatechange”, function () {  
if (this.readyState === 4) {  
console.log(this.responseText);  
}  
});  
xhr.open(“GET”, “https://\*\*\*\*\*\*\*\*\*\*.com/notifications.json?username=alanmurphy”);  
xhr.setRequestHeader(“api-key”, “d06ca53322d1fbaf383a6394d6c229e56871342d2cad953a0fe26c19df7645ba”);  
xhr.setRequestHeader(“api-userame”, “system”);  
xhr.send();

一切正常：+1:

但是，如果我从希望联系 Discourse 的子域名发起该请求，系统会提示被 CORS 策略阻止：请求头字段 api-key 未被 Access-Control-Allow-Headers 允许。

允许的请求头包括：

Content-Type, Cache-Control, X-Requested-With, X-CSRF-Token, Discourse-Visible, User-Api-Key, User-Api-Client-Id

如果能得到关于跨域请求应传递哪些认证参数以及这些参数获取位置的指导，将非常有帮助。

附：我的 Discourse 已配置为允许来自该域名的跨域请求，因此我认为问题纯粹出在请求头上。

谢谢

---

_[View the full topic](https://meta.discourse.org/t/user-api-keys-specification/48536)._
