作为Booking.com联盟成员调用API时遇401 Authorization Required错误求助
Hey there, let's walk through the most common reasons you're seeing this Authorization Required 401 error when calling the Booking.com API, and how to fix them:
Double-check your Basic Auth formatting
Basic Auth requires combining your API username and password with a colon (username:password), then encoding that entire string in Base64. Common mistakes here include:- Forgetting the colon separator between username and password
- Including extra spaces or line breaks in the Base64-encoded string
- Accidentally URL-encoding the string (you don't need to do this—just encode the raw
user:passpair directly)
Verify your encoded string manually to make sure it matches what's being sent in yourAuthorization: Basic <encoded-value>header.
Confirm you're using the correct API credentials
Make sure you're using the exclusive API credentials from your Booking.com affiliate account, not your regular Booking.com user login details. Affiliate API credentials are usually found in your dedicated affiliate management dashboard—double-check for typos, case sensitivity, or missing special characters in your username/password.Validate your request header setup
- Ensure the header is spelled exactly
Authorization(some tools might auto-generate lowercase variants, which can cause issues with strict servers) - Check that no other conflicting authentication headers are being added automatically by your dev tool or framework (e.g., some libraries might inject OAuth headers if misconfigured)
- Ensure the header is spelled exactly
Verify endpoint and API version compatibility
You're calling the v2.0 JSON endpointhttps://distribution-xml.booking.com/2.0/json/hotels, which should support Basic Auth per Booking's docs. But confirm that your affiliate account has access to this specific API version and endpoint—sometimes access is restricted based on your affiliate tier or agreement.Check IP whitelisting rules
Many Booking.com affiliate APIs require your request's source IP to be added to an allowed IP whitelist. If your server or local dev IP isn't listed in your affiliate dashboard's security settings, you'll get a 401 even with correct credentials.
A quick way to isolate the issue is to test with a simple curl command, which eliminates any framework-specific configuration issues:
curl -u "your_api_username:your_api_password" "https://distribution-xml.booking.com/2.0/json/hotels?hotel_ids=10004"
If this curl request works, the problem is likely in how your application is constructing the request header.
内容的提问来源于stack exchange,提问作者persia

