---
title: "I get the error {“code”:”1002″,”message”:”Authorization error: Full authentication is required to access this resource »}. What should I do?"
description: "The message {&quot;code&quot;: &quot;1002″, &quot;message&quot;: &quot;Authorization error: Full authentication is required to access this resource&quot;} indicates an Authentication problem. To use API-money, it's needed to be able to"
---

[Skip to content](https://ressources.w-ha.com/en/support/api-money/i-get-the-error-code-1002-message-authorization-error-full-authentication-is-required-to-access-this-resource-what-should-i-do#main-content)

- [English](https://ressources.w-ha.com/en/support/api-money/i-get-the-error-code-1002-message-authorization-error-full-authentication-is-required-to-access-this-resource-what-should-i-do)
- [Français](https://ressources.w-ha.com/support/api-money/jobtiens-lerreur-code1002messageauthorization-error-full-authentication-is-required-to-access-this-resource)

English

Show submenu for translations

![logo-wha-bleu-fonce-1.png\]](https://ressources.w-ha.com/hs-fs/hubfs/logo-wha-bleu-fonce-1.png?height=50&name=logo-wha-bleu-fonce-1.png)

Open main navigation

Close main navigation

- - [English](https://ressources.w-ha.com/en/support/api-money/i-get-the-error-code-1002-message-authorization-error-full-authentication-is-required-to-access-this-resource-what-should-i-do)
    - [Français](https://ressources.w-ha.com/support/api-money/jobtiens-lerreur-code1002messageauthorization-error-full-authentication-is-required-to-access-this-resource)

  English
  
  Show submenu for translations
- [W-HA website](https://www.w-ha.com/)

[W-HA website](https://www.w-ha.com/)

 How can we help you ?

- There are no suggestions because the search field is empty.

1. [W-HA Support Center](https://ressources.w-ha.com/en/support?hsLang=en)
2. [API-money](https://ressources.w-ha.com/en/support/api-money?hsLang=en)
3. [Technical](https://ressources.w-ha.com/en/support/api-money?hsLang=en#technical)

# I get the error {“code”:”1002″,”message”:”Authorization error: Full authentication is required to access this resource »}. What should I do?

The message {"code": "1002″, "message": "Authorization error: Full authentication is required to access this resource"} indicates an **Authentication problem.**

To use API-money, it's needed to be able to authenticate the user who initiated the request.

 

You can start with a simple **GET** request, without a **"body"**, such as :

> **GET /accounts**

This will also enable you to retrieve your **Partner account identifier**, already created in the system (cf. doc : [https://www.api-money.com/docs/#Accountservices-Createanaccount-Standard](https://www.api-money.com/docs/#Accountservices-Listofaccounts) & [https://www.api-money.com/docs/#Overview-Authentication](https://www.api-money.com/docs/#Overview-Authentication)).

Below is a detailed example of query construction, with the following test parameters:

– sandbox URL : [https://test-emoney-services.w-ha.com/dashboard/#/login](https://test-emoney-services.w-ha.com/dashboard/#/login)  
– api\_access\_key : k1rXpphkRG!2-Fox  
– api\_secret\_key : E0!oYfVpA6-noiqGr-pT7AJ2ybT4r7lx  
– version : 1

 

**1°) First step : “StringToSign”**

The first step is to construct the **"message"** to be signed.

StringToSign = api\_access\_key:timestamp:version:

Example :

***\> StringToSign = k1rXpphkRG!2-Fox:timestamp:1:***

(above the :timestamp: value must contain a timestamp of a sequence of digits, like this :1672650133163: )

 

Note:

The timestamp (unix) designates the number of seconds elapsed since January 1, 1970 at midnight UTC (cf. [http://www.timestamp.fr](http://www.timestamp.fr/)).

In API-money requests, you must indicate the timestamp (in milliseconds) corresponding to the moment your request is sent to the API-money platform.

 

**2°) Second step: “Sign”**

The second step consists of encoding the **"Sign"** in HMCA (SHA256) using the **"message"** to be signed (StringToSign) and the secret key (api\_secret\_key).  
HMAC encoding ensures message integrity.

Sign = HMAC-SHA256(StringToSign, api\_secret\_key)  
Sign = HMAC-SHA256(*k1rXpphkRG!2-Fox:1672650133163:1:, E0!oYfVpA6-noiqGr-pT7AJ2ybT4r7lx)*

Example :

***\> Sign = fdc93dee9a203b2a544e7bcc5f34918e89c547c2ee5503071482a9fbfb3e4e8e***

You can check your HMAC calculation using, for example, the tool: [https://www.freeformatter.com/hmac-generator.html#ad-output](https://www.freeformatter.com/hmac-generator.html#ad-output)

 

**3°) Third step: Request (in theory)**

All that remains is to generate and send the request to the platform URL:

> **GET /accounts**

Header parameter:

Authorization: AUTH api\_access\_key:timestamp:version:Sign

Example :

***\>* *URL endpoint : GET /accounts*  
*\> Header : Authorization :* *AUTH k1rXpphkRG!2-Fox:1672650133163:1:fdc93dee9a203b2a544e7bcc5f34918e89c547c2ee5503071482a9fbfb3e4e8e***

 

**4°) Fourth step: the Request (in practice)**

To check that the request is working properly, you can **run the following CURL** command with your own credentials and add your timestamp and your Sign (encoded HMAC SHA256):

> **curl –location –request GET ‘https://test-emoney-services.w-ha.com/api/accounts’ \\**  
> **–header ‘Authorization: AUTH odzAr67enYtX7vDdiLwdMYOTh6R4ZQUz:\[Timestamp\]:1:\[Sign\]’**

 

**WARNING:** once the request has been prepared, it is **only valid for 1 hour** (the timestamp must not be more than 5 minutes old at time T of the request) in the test environment (sandbox)!

 

**You should get a result like :**

> **\[**
> 
>     **{**
> 
>         **“id”: “AB-0895358735216643”,**
> 
>         **“type”: “BUSINESS”,**
> 
>         **“status”: “ACTIVE”,**
> 
>         **“tag”: “account\_type1”,**
> 
>         **“creation\_date”: “2022-12-23T14:40:26+0100”,**
> 
>         **“kyc\_level”: “LEVEL\_1”**
> 
>     **},**
> 
>     **{**
> 
>         **“id”: “AS-5205597398211593”,**
> 
>         **“type”: “STANDARD”,**
> 
>         **“status”: “ACTIVE”,**
> 
>         **“tag”: “account\_type1”,**
> 
>         **“creation\_date”: “2022-12-23T14:20:37+0100”,**
> 
>         **“kyc\_level”: “LEVEL\_1”**
> 
>     **}**
> 
> **\]**
> 
> *.json*

 

- [API-money](https://ressources.w-ha.com/en/support/api-money?hsLang=en#main-content)

    - [Support request](https://ressources.w-ha.com/en/support/api-money?hsLang=en#support-request)
    - [Start-up](https://ressources.w-ha.com/en/support/api-money?hsLang=en#start-up)
    - [Features](https://ressources.w-ha.com/en/support/api-money?hsLang=en#features)
    - [Technical](https://ressources.w-ha.com/en/support/api-money?hsLang=en#technical)
    - [Dashboard](https://ressources.w-ha.com/en/support/api-money?hsLang=en#dashboard)
    - [KYC / KYB](https://ressources.w-ha.com/en/support/api-money?hsLang=en#kyc-kyb)
- [Internet + Box](https://ressources.w-ha.com/en/support/internet-box?hsLang=en#main-content)

    - [API](https://ressources.w-ha.com/en/support/internet-box?hsLang=en#api)
    - [KIT](https://ressources.w-ha.com/en/support/internet-box?hsLang=en#kit)
- [Internet + Mobile](https://ressources.w-ha.com/en/support/internet-mobile?hsLang=en#main-content)

    - [MSCA](https://ressources.w-ha.com/en/support/internet-mobile?hsLang=en#msca)

[![Chill listening crop-3](https://ressources.w-ha.com/hs-fs/hubfs/logo-wha-bleu-fonce-1.png?width=178&height=50&name=logo-wha-bleu-fonce-1.png "Chill listening crop-3")](http://www.w-ha.com)

Copyright © 2026, W-HA