# What's the correct \`content-type\` when editing posts?

**URL:** <https://meta.discourse.org/t/whats-the-correct-content-type-when-editing-posts/199921>\
**Category:** Development\
**Tags:** rest-api\
**Created:** [August 10, 2021, 10:02am UTC](https://meta.discourse.org/t/whats-the-correct-content-type-when-editing-posts/199921 "2021-08-10T10:02:11Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![david](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/david/32/157490_2.png) [@david](https://meta.discourse.org/u/david)\
**Post date:** [August 10, 2021, 10:12am UTC](https://meta.discourse.org/t/whats-the-correct-content-type-when-editing-posts/199921/2 "2021-08-10T10:12:46Z")

</div>

> [@pedroleaoc](#):
>
> ```plaintext
> header = CaseInsensitiveDict()
> header["Authorization"] = '{"api-key": "longapikey", "api-username": "myusername"}'
> 
> ```

You need to send the Api-Key and Api-Username as their own headers, not in the `Authorization` header. Something like this should work better:

```plaintext
header = CaseInsensitiveDict()
header["Api-Key"] = 'longapikey'
header["Api-Username"] = 'myusername'

```

This looks like the same issue as your previous topic:

> [@Getting \["BAD CSRF"\] when updating topic via API \[python\]](https://meta.discourse.org/t/getting-bad-csrf-when-updating-topic-via-api-python/199857/3):
>
> You are right, that’s something the tool I am using to test the API is doing and it works and that’s a problem on itself apparently: header1 = CaseInsensitiveDict() header1["Authorization"] = '{"api-key": "longapikey", "api-username": "myusername"}' header2 = {"api-key": "longapikey", "api-username": "myusername"} r = requests.get(url, headers= HEADER) When HEADER == header1, it works, when == header2, I get: {"errors":["You are not permitted to view the requested resource. The API username…

---

_[View the full topic](https://meta.discourse.org/t/whats-the-correct-content-type-when-editing-posts/199921)._
