# Authentication with download

**URL:** <https://discourse.julialang.org/t/authentication-with-download/58790>\
**Category:** Web Stack\
**Created:** [April 7, 2021, 7:37pm UTC](https://discourse.julialang.org/t/authentication-with-download/58790 "2021-04-07T19:37:06Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![robertdj](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/robertdj/32/103_2.png) [@robertdj](https://discourse.julialang.org/u/robertdj)\
**Post date:** [April 7, 2021, 7:37pm UTC](https://discourse.julialang.org/t/authentication-with-download/58790/1 "2021-04-07T19:37:06Z")

</div>

I would like to authenticate against an API that use Active Directory. It is possible with `curl` and  
I’m hoping that the new `Downloads.download` can handle this since it’s based on `libcurl`. But I can’t see from the docs how to include authentication.

Has anyone succeeded with such an authentication?

(In the past I haven’t succeeded – like [GSSAPI / Kerberos in Julia?](https://discourse.julialang.org/t/gssapi-kerberos-in-julia/48548) and [Ntlm authentication for HTTP requests](https://discourse.julialang.org/t/ntlm-authentication-for-http-requests/26488))

---

<div class="post-metadata">

**Author:** ![fredrikekre](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/fredrikekre/32/1688_2.png) [@fredrikekre](https://discourse.julialang.org/u/fredrikekre)\
**Post date:** [April 7, 2021, 8:34pm UTC](https://discourse.julialang.org/t/authentication-with-download/58790/2 "2021-04-07T20:34:53Z")

</div>

Most services allow you to authenticate with a Authorization header. You can pass headers to `Downloads.download` like this:

```julia
Download.download(url, filename; headers = Dict("Authorization" => "XXXX"))

```

---

<div class="post-metadata">

**Author:** ![robertdj](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/robertdj/32/103_2.png) [@robertdj](https://discourse.julialang.org/u/robertdj)\
**Post date:** [April 8, 2021, 8:33am UTC](https://discourse.julialang.org/t/authentication-with-download/58790/3 "2021-04-08T08:33:43Z")

</div>

Yes, most services do 🙂

The problem is that Active Directory expects things in a certain way and I haven’t found docs for it.  
With `curl` this works:

```julia
curl --ntlm -u : --negotiate <url>

```

The `-u :` means that it should rely on my Windows user/Kerberos ticket.  
Without `--negotiate` it fails. Running verbose (with `-v`) reveals that “Authorization: Negotiate \<very long string\>” when it works and “Authorization: NTLM \<short string\>” when it doesn’t work.  
I don’t know how the strings are generated.

Is it possible to use a counterpart to `--negotiate` in `Downloads.download`? Or does anyone know how to construct the custom header?
