使用POSTMAN提交revcontent登录表单失败,请求遭拒绝
I’ve run into this exact issue before when trying to simulate form logins with Postman—browsers work fine, but API clients get blocked. Let’s break down why this is happening and how to fix it:
1. You’re Missing Critical Hidden Form Fields
Looking at the login form you shared, there are two hidden inputs you haven’t included in your Postman request, and the site is almost certainly validating these:
rv_tsvm: This is a dynamic validation token (similar to a CSRF token) that changes every time the login page loadsdesk: A static hidden field set tofalse
How to Get the rv_tsvm Value:
- Open your browser’s DevTools (F12) and navigate to the login page
- Go to the Elements tab, find the
<input type="hidden" name="rv_tsvm">element, and copy itsvalueattribute - Add both fields to your Postman request body:
rv_tsvm: [paste the copied token here] desk: false
Note: The rv_tsvm token is one-time use—you’ll need to grab a fresh value every time you send a new login request.
2. Match Browser Request Headers
Websites often block requests that don’t look like they’re coming from a real browser. Add these headers to your Postman request to mimic a browser:
User-Agent: Copy your browser’s actual User-Agent string (find it in DevTools > Network tab, check the login request’s headers)Referer: Set this tohttps://www.revcontent.com/login(tells the server the request originated from the login page)Accept: Use a value matching your browser’s, e.g.,text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
3. Use the Correct Body Encoding
The form uses accept-charset="utf-8" and is a standard POST form, so in Postman:
- Go to the Body tab
- Select
x-www-form-urlencoded(notform-dataorraw) - Add all your fields here:
name,password,login,rv_tsvm, anddesk
Step-by-Step Test Plan
- Refresh the login page in your browser and grab the latest
rv_tsvmtoken - Configure your Postman POST request to
https://www.revcontent.com/login - In the Body tab (x-www-form-urlencoded), add all 5 fields with their correct values
- Paste in the browser-matching headers
- Send the request—this should now work like your browser login does
内容的提问来源于stack exchange,提问作者Dinesh Ahuja

