Python HTTP认证添加额外参数及群晖NAS认证报错排查
Hey there, let's work through this Synology authentication issue together. Error code 101 ("Invalid Parameters") usually means your Python request is missing or sending incorrect parameters compared to what the NAS expects—and since it works in the browser, we can use that as our reference point.
Step 1: Diagnose the Error 101 Issue
First, you need to compare what your browser sends vs. what your Python code sends. Here's how to do that:
- Open your browser's dev tools (press F12), go to the Network tab.
- Perform the login in the browser, then find the auth request (it’s usually sent to
/webapi/auth.cgi). - Check the Payload or Form Data section to see every parameter the browser sends. Synology's auth API typically requires these core parameters:
api: Should beSYNO.API.Authversion: Usually6(double-check your NAS's API version in its documentation)method: Set tologinaccount: Your NAS usernamepasswd: Your NAS passwordsession: The service you're authenticating for (e.g.,FileStation,DownloadStation)format:cookieorsid(depends on how you want to handle the session)
Common mistakes that trigger error 101:
- Typos in parameter names (they’re case-sensitive!)
- Missing one of the required core parameters
- Sending data as JSON instead of form-encoded (Synology's auth API usually expects
application/x-www-form-urlencoded) - Forgetting to specify the target service via the
sessionparameter
Example Working Python Code
Here’s a corrected request using the requests library, matching what the browser sends:
import requests # Replace with your NAS details NAS_IP = "192.168.1.100" NAS_PORT = 5000 USERNAME = "your_nas_username" PASSWORD = "your_nas_password" TARGET_SERVICE = "FileStation" auth_url = f"http://{NAS_IP}:{NAS_PORT}/webapi/auth.cgi" payload = { "api": "SYNO.API.Auth", "version": 6, "method": "login", "account": USERNAME, "passwd": PASSWORD, "session": TARGET_SERVICE, "format": "cookie" } # Send the request as form-encoded (default for requests.post with data=) response = requests.post(auth_url, data=payload) print(response.json())
Step 2: Adding Extra Parameters to Your Auth Request
Adding extra parameters is straightforward—just include them in your payload dictionary (or request headers, if the parameter belongs there):
Adding Payload Parameters
If your NAS's API supports extra parameters (like remember_me for persistent sessions or otp_code for 2FA), just add them to the payload dict:
payload = { # Core parameters here... "remember_me": 1, # Keep session active after closing the client "otp_code": "123456" # Required if 2FA is enabled on your NAS }
Adding Header Parameters
Some parameters might need to go in the request headers (like mimicking a browser's User-Agent to avoid being blocked):
headers = { "User-Agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36" } response = requests.post(auth_url, data=payload, headers=headers)
Extra Tips
- If your password is encrypted in the browser (check the payload), replicate that encryption method in your Python code (e.g., base64 encoding if that’s what the browser uses).
- If you get a session ID (
sid) in the response, use it in subsequent requests by including it in the headers or as a_sidparameter.
内容的提问来源于stack exchange,提问作者Eric

