SharePoint 2010 REST API认证授权方法及Postman实操步骤咨询
Hey there, let's break down how to handle authentication and authorization for SharePoint 2010 REST API calls, plus walk through exactly how to set this up in Postman. SharePoint 2010 supports two primary auth methods for REST access, so we'll cover both below.
Supported Authentication Methods
SharePoint 2010 leans on two main mechanisms for REST API authentication:
- NTLM (Windows Authentication): The go-to for on-premises farms integrated with Active Directory.
- Form-Based Authentication (FBA): Used when SharePoint is configured with custom identity providers (like ASP.NET Membership systems).
1. NTLM Authentication with Postman
This is the simplest flow for AD-connected environments. Here's how to configure Postman to use it:
Step-by-Step Setup
- Open Postman and create a new request (start with a GET for testing—e.g., fetching a list).
- Enter your SharePoint 2010 REST endpoint. For example:
http://your-sharepoint-site/_vti_bin/listdata.svc/YourTargetList - Navigate to the Authorization tab.
- From the Type dropdown, select NTLM Authentication.
- Fill in your credentials correctly:
- Username: Use the format
DOMAIN\your-username(e.g.,CONTOSO\jdoe) - Password: Your Active Directory account password
- Domain: Your AD domain name (can leave blank if it's already included in the username)
- Username: Use the format
- Optional but recommended: Head to the Headers tab and add an
Acceptheader to get JSON responses:Key: Accept Value: application/json;odata=verbose - Click Send. If authentication works, you'll get a valid response with your list data (JSON or XML, depending on your header).
Quick Troubleshooting
- Double-check the username format—missing the domain or using wrong slashes is a common pitfall.
- Ensure Postman can reach the SharePoint server (no proxy blocks or network restrictions).
2. Form-Based Authentication (FBA) with Postman
FBA requires first grabbing authentication cookies from the SharePoint login page, then attaching those cookies to your REST requests. Here's the play-by-play:
Step 1: Retrieve Auth Cookies
- Create a new POST request in Postman.
- Enter your SharePoint FBA login page URL (adjust if your farm uses a custom path):
http://your-sharepoint-site/_forms/default.aspx?ReturnUrl=/_layouts/15/Authenticate.aspx?Source=%2F - Go to the Body tab, select form-data, and add these key-value pairs:
ctl00$PlaceHolderMain$login$UserName: Your FBA usernamectl00$PlaceHolderMain$login$Password: Your FBA passwordctl00$PlaceHolderMain$login$LoginButton:Log In
- Add a Content-Type header in the Headers tab:
Key: Content-Type Value: application/x-www-form-urlencoded - Click Send. After a successful login, check the Cookies tab in the response—you'll see two critical cookies:
FedAuthandrtFa.
Step 2: Attach Cookies to REST Requests
- Create your target REST request (e.g., GET to
http://your-sharepoint-site/_vti_bin/listdata.svc/YourTargetList). - Go to the Cookies tab in Postman, click Add Cookie, and paste the values for
FedAuthandrtFaone by one.- Make sure the Domain matches your SharePoint site's domain (e.g.,
your-sharepoint-site).
- Make sure the Domain matches your SharePoint site's domain (e.g.,
- Add the
Acceptheader (same as NTLM step) if you want formatted JSON responses. - Click Send—your request will be authenticated using the FBA cookies, and you'll receive the expected data.
Key SharePoint 2010 REST Notes
- Remember: SharePoint 2010's REST endpoint is always
/_vti_bin/listdata.svc(later versions use/_api, so don't mix these up). - Test with a simple GET request first to confirm auth works before moving to write operations (POST/PUT/DELETE).
- For write operations, you'll need extra headers like
X-HTTP-MethodandIf-Match—but that's a separate topic from authentication.
内容的提问来源于stack exchange,提问作者Clinton Prakash
相关产品推荐
相关产品推荐

