You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用POSTMAN提交revcontent登录表单失败,请求遭拒绝

Fix: Postman Login Request Returns "The action you have requested is not allowed"

I’ve run into this exact issue before when trying to simulate form logins with Postman—browsers work fine, but API clients get blocked. Let’s break down why this is happening and how to fix it:

1. You’re Missing Critical Hidden Form Fields

Looking at the login form you shared, there are two hidden inputs you haven’t included in your Postman request, and the site is almost certainly validating these:

  • rv_tsvm: This is a dynamic validation token (similar to a CSRF token) that changes every time the login page loads
  • desk: A static hidden field set to false

How to Get the rv_tsvm Value:

  • Open your browser’s DevTools (F12) and navigate to the login page
  • Go to the Elements tab, find the <input type="hidden" name="rv_tsvm"> element, and copy its value attribute
  • Add both fields to your Postman request body:
    rv_tsvm: [paste the copied token here]
    desk: false
    

Note: The rv_tsvm token is one-time use—you’ll need to grab a fresh value every time you send a new login request.

2. Match Browser Request Headers

Websites often block requests that don’t look like they’re coming from a real browser. Add these headers to your Postman request to mimic a browser:

  • User-Agent: Copy your browser’s actual User-Agent string (find it in DevTools > Network tab, check the login request’s headers)
  • Referer: Set this to https://www.revcontent.com/login (tells the server the request originated from the login page)
  • Accept: Use a value matching your browser’s, e.g., text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8

3. Use the Correct Body Encoding

The form uses accept-charset="utf-8" and is a standard POST form, so in Postman:

  • Go to the Body tab
  • Select x-www-form-urlencoded (not form-data or raw)
  • Add all your fields here: name, password, login, rv_tsvm, and desk

Step-by-Step Test Plan

  1. Refresh the login page in your browser and grab the latest rv_tsvm token
  2. Configure your Postman POST request to https://www.revcontent.com/login
  3. In the Body tab (x-www-form-urlencoded), add all 5 fields with their correct values
  4. Paste in the browser-matching headers
  5. Send the request—this should now work like your browser login does

内容的提问来源于stack exchange,提问作者Dinesh Ahuja

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.29 07:17:35