# Cannot authenticate using Cookie Authentication

**URL:** <https://community.weweb.io/t/cannot-authenticate-using-cookie-authentication/5800>\
**Category:** How do I?\
**Tags:** authentication\
**Created:** [December 7, 2023, 2:47pm UTC](https://community.weweb.io/t/cannot-authenticate-using-cookie-authentication/5800 "2023-12-07T14:47:57Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jerome1](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/jerome1/32/6398_2.png) [@Jerome1](https://community.weweb.io/u/Jerome1)\
**Post date:** [December 7, 2023, 2:47pm UTC](https://community.weweb.io/t/cannot-authenticate-using-cookie-authentication/5800/1 "2023-12-07T14:47:57Z")

</div>

Hi,  
We have a Rest API using Cookie Authentication similar to [this](https://swagger.io/docs/specification/authentication/cookie-authentication/).  
I created a workflow that includes 2 requests, for which I selected “Proxy the request to bypass CORS issues”:

- Login to our server, sending the user/password credentials. The request succeed. This means the JSESSIONID cookie is set in the response (weweb server side)
- Fetch a collection. I see in the browser dev tools that the “credentials”: “include” is set, which make me think the cookies should be sent with the request. The request fails as 401 (Unauthorized).

Is it expected?  
Another solution would be to get the JSESSIONID cookie from the login response, and use it in the fectch collection. Unfortunatly this is not returned in the weweb response.  
Any hints?

---

<div class="post-metadata">

**Author:** ![Jerome1](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/jerome1/32/6398_2.png) [@Jerome1](https://community.weweb.io/u/Jerome1)\
**Post date:** [December 8, 2023, 1:00pm UTC](https://community.weweb.io/t/cannot-authenticate-using-cookie-authentication/5800/2 "2023-12-08T13:00:06Z")

</div>

Any help on this? This is critical for us to authenticate to our API.

---

<div class="post-metadata">

**Author:** ![Quentin](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/quentin/32/6_2.png) [@Quentin](https://community.weweb.io/u/Quentin)\
**Post date:** [December 8, 2023, 3:46pm UTC](https://community.weweb.io/t/cannot-authenticate-using-cookie-authentication/5800/3 "2023-12-08T15:46:48Z")

</div>

Are you sending the cookie using the send credentials toggle?

 ![CleanShot 2023-12-08 at 16.45.30](https://us1.discourse-cdn.com/flex016/uploads/weweb/original/2X/7/7f914c74b604f11bb5c6161365c537cbbb2de628.png)

---

<div class="post-metadata">

**Author:** ![Jerome1](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/jerome1/32/6398_2.png) [@Jerome1](https://community.weweb.io/u/Jerome1)\
**Post date:** [December 8, 2023, 5:50pm UTC](https://community.weweb.io/t/cannot-authenticate-using-cookie-authentication/5800/4 "2023-12-08T17:50:28Z")

</div>

Nop. Since I enabled “Proxy the request to bypass CORS issues” this toggle is not visible.

---

<div class="post-metadata">

**Author:** ![Jerome1](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/jerome1/32/6398_2.png) [@Jerome1](https://community.weweb.io/u/Jerome1)\
**Post date:** [December 12, 2023, 10:51am UTC](https://community.weweb.io/t/cannot-authenticate-using-cookie-authentication/5800/5 "2023-12-12T10:51:34Z")

</div>

Any other thoughts about this?  
We need to know if this kind of authentication is possible with weweb, or not.  
We don’t see how we could workaround this.  
Please advice. Thanks!
