Updated on 2026-02-26 GMT+08:00

Authentication

API call requests can be authenticated using tokens.

Token-based Authentication

The validity period of a token is 24 hours. When using a token for authentication, cache it to prevent frequently calling the IAM API used to obtain a user token.

A token specifies certain permissions in a computer system. During API authentication using a token, the token is added to requests to get permissions for calling the API.

When calling the API to obtain a user token, you must set auth.scope in the request body to project.

In Making an API Request, the process of calling the API used to obtain a user token is described.

{
	"auth": {
		"identity": {
			"methods": [
				"password"
			],
			"password": {
				"user": {
					"name": "user_name",
					"password": "user_password",
					"domain": {
						"name": "domain_name"
					}
				}
			}
		},
		"scope": {
			"project": {
				"name": "project_name"
			}
		}
	}
}

After a token is obtained, the X-Auth-Token header must be added to requests to specify the token when calling other APIs. For example, if the token is ABCDEFJ...., add X-Auth-Token: ABCDEFJ.... to a request as follows:

GET https://modelarts.ap-southeast-1.myhuaweicloud.com/v1/{project_id}/services
Content-Type: application/json
X-Auth-Token: ABCDEFJ....