# REST API v2 Error

**URL:** <https://community.gravityforms.com/t/rest-api-v2-error/2365>\
**Category:** Get Help\
**Tags:** api, rest-api, has-ticket\
**Created:** [July 30, 2019, 6:34pm UTC](https://community.gravityforms.com/t/rest-api-v2-error/2365 "2019-07-30T18:34:04Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![user5d4088ed6a5bf650](https://avatars.discourse-cdn.com/v4/letter/u/73ab20/32.png) [@user5d4088ed6a5bf650](https://community.gravityforms.com/u/user5d4088ed6a5bf650)\
**Post date:** [July 30, 2019, 6:34pm UTC](https://community.gravityforms.com/t/rest-api-v2-error/2365/1 "2019-07-30T18:34:04Z")

</div>

I am trying to integrate Gravity Forms with integromat and when I enter in the information for the API I get an error saying “Sorry, you are not allowed to do that.”. Integromat says the error comes from GF. Does anyone have any ideas about fixing that?

---

<div class="post-metadata">

**Author:** ![chrishajer](https://sea2.discourse-cdn.com/flex020/user_avatar/community.gravityforms.com/chrishajer/32/88_2.png) [@chrishajer](https://community.gravityforms.com/u/chrishajer)\
**Post date:** [July 30, 2019, 7:03pm UTC](https://community.gravityforms.com/t/rest-api-v2-error/2365/2 "2019-07-30T19:03:27Z")

</div>

The best place to get assistance for this is to open a support ticket [https://www.gravityforms.com/open-support-ticket/](https://www.gravityforms.com/open-support-ticket/) but I will leave this open in case someone wants to share their experience.

---

<div class="post-metadata">

**Author:** ![user5d4088ed6a5bf650](https://avatars.discourse-cdn.com/v4/letter/u/73ab20/32.png) [@user5d4088ed6a5bf650](https://community.gravityforms.com/u/user5d4088ed6a5bf650)\
**Post date:** [August 13, 2019, 3:06pm UTC](https://community.gravityforms.com/t/rest-api-v2-error/2365/3 "2019-08-13T15:06:51Z")

</div>

Chris,

I no longer have the email that was associated with paypal. I have the token though. Is there a way I can still submit a ticket?

---

<div class="post-metadata">

**Author:** ![chrishajer](https://sea2.discourse-cdn.com/flex020/user_avatar/community.gravityforms.com/chrishajer/32/88_2.png) [@chrishajer](https://community.gravityforms.com/u/chrishajer)\
**Post date:** [August 13, 2019, 3:15pm UTC](https://community.gravityforms.com/t/rest-api-v2-error/2365/4 "2019-08-13T15:15:43Z")

</div>

I recommend contacting us here in that case and explaining the issue with your license email:

> **[Contact Gravity Forms | Premium Form Plugin For WordPress](https://www.gravityforms.com/contact-us/)**
>
> Have a few questions about Gravity Forms before you buy? Need support? We're here to help you get the most out of our premiere WordPress form solution.

---

<div class="post-metadata">

**Author:** ![beardedfriend](https://sea2.discourse-cdn.com/flex020/user_avatar/community.gravityforms.com/beardedfriend/32/1573_2.png) [@beardedfriend](https://community.gravityforms.com/u/beardedfriend)\
**Post date:** [May 3, 2020, 6:47am UTC](https://community.gravityforms.com/t/rest-api-v2-error/2365/5 "2020-05-03T06:47:21Z")

</div>

I’m having the same issue

> I am trying to integrate Gravity Forms with integromat and when I enter in the information for the API I get an error saying “Sorry, you are not allowed to do that.”

Following these instructions [https://support.integromat.com/hc/en-us/articles/360019074073](https://support.integromat.com/hc/en-us/articles/360019074073)

Was there a conflicting plugin involved? I’ve tried disabling the ones I _think_ could cause issues.

---

<div class="post-metadata">

**Author:** ![chrishajer](https://sea2.discourse-cdn.com/flex020/user_avatar/community.gravityforms.com/chrishajer/32/88_2.png) [@chrishajer](https://community.gravityforms.com/u/chrishajer)\
**Post date:** [May 4, 2020, 2:48am UTC](https://community.gravityforms.com/t/rest-api-v2-error/2365/6 "2020-05-04T02:48:21Z")

</div>

Hi Robey. I recommend testing with logging for the Gravity Forms API enabled to see what the actual issue with the API authentication.

Here’s how you can enable logging in Gravity Forms:

> **[Logging and Debugging - Gravity Forms Documentation](https://docs.gravityforms.com/logging-and-debugging/#enabling-logging)**
>
> For quite a while, enabling logging within Gravity Forms has been a go-to method for debugging any issues within Gravity Forms. As of Gravity Forms version 2.2, logging functionality has been moved from a separate add-on to becoming a core feature of...

---

<div class="post-metadata">

**Author:** ![omnibrand](https://sea2.discourse-cdn.com/flex020/user_avatar/community.gravityforms.com/omnibrand/32/1646_2.png) [@omnibrand](https://community.gravityforms.com/u/omnibrand)\
**Post date:** [May 15, 2020, 2:32am UTC](https://community.gravityforms.com/t/rest-api-v2-error/2365/7 "2020-05-15T02:32:18Z")

</div>

I’ve also opened a ticket for this issue; but thought I’d add my logging results here:

> 2020-05-15 2:16:55.470037 - DEBUG → GF\_REST\_Authentication::authenticate(): Running.  
> 2020-05-15 2:16:55.470140 - DEBUG → GF\_REST\_Authentication::perform\_basic\_authentication(): Running.  
> 2020-05-15 2:16:55.470174 - ERROR → GF\_REST\_Authentication::perform\_basic\_authentication(): Aborting; credentials not found.  
> 2020-05-15 2:16:55.470197 - DEBUG → GF\_REST\_Authentication::perform\_oauth\_authentication(): Running.  
> 2020-05-15 2:16:55.470231 - ERROR → GF\_REST\_Authentication::perform\_oauth\_authentication(): Aborting; OAuth parameters not found.  
> 2020-05-15 2:16:55.567249 - DEBUG → GF\_REST\_Controller::current\_user\_can\_any(): method: GET; route: /gf/v2/forms; capability: “gravityforms\_edit\_forms”; result: false.

---

<div class="post-metadata">

**Author:** ![chrishajer](https://sea2.discourse-cdn.com/flex020/user_avatar/community.gravityforms.com/chrishajer/32/88_2.png) [@chrishajer](https://community.gravityforms.com/u/chrishajer)\
**Post date:** [May 15, 2020, 3:19am UTC](https://community.gravityforms.com/t/rest-api-v2-error/2365/8 "2020-05-15T03:19:56Z")

</div>

Hi Carl. If you have not received it already, this is the reply from Richard:

> Some hosting environments don’t pass the basic authentication headers from incoming requests to PHP. As they are not included in the request which is available to the WordPress and Gravity Forms REST APIs the request will fail authentication.

> WordPress have had reports of this issue with their basic auth plugin for a few years now: [https://github.com/WP-API/Basic-Auth/issues/35](https://github.com/WP-API/Basic-Auth/issues/35)

> As you can see in that issue some have found making a change to the htaccess file resolves the issue.

> There is also this issue where an engineer at WPEngine confirms it is a hosting issue which the host can resolve by making a change to the Apache configuration on the server hosting the site: [All authentication methods use "Authorization" header, which is unreliable · Issue #2512 · WP-API/WP-API · GitHub](https://github.com/WP-API/WP-API/issues/2512#issuecomment-280539514)

---

<div class="post-metadata">

**Author:** ![omnibrand](https://sea2.discourse-cdn.com/flex020/user_avatar/community.gravityforms.com/omnibrand/32/1646_2.png) [@omnibrand](https://community.gravityforms.com/u/omnibrand)\
**Post date:** [May 15, 2020, 3:38am UTC](https://community.gravityforms.com/t/rest-api-v2-error/2365/9 "2020-05-15T03:38:59Z")

</div>

Good day Chris,

Received yes; thanks.

Fortunately, they’re my own servers; so I’m looking my options. For everyone’s reference, the primary options at this point seem to be:

1. Modify .htaccess adding something like:

> IfModule mod\_rewrite.c\>  
> RewriteEngine On  
> RewriteBase /  
> RewriteRule ^index.php$ - [E=HTTP\_AUTHORIZATION:%{HTTP:Authorization},L]  
> RewriteCond %{REQUEST\_FILENAME} !-f  
> RewriteCond %{REQUEST\_FILENAME} !-d  
> RewriteRule . /index.php [L]

1. Add the following to your Apache config:

> SetEnvIf Authorization “(.\*)” HTTP\_AUTHORIZATION=$1

1. If you are using mod\_proxycgi and Apache 2.4.13+ there is also a [CGIPassAuth] directive that can be used within your main apache config file or .htaccess `CGIPassAuth` on.  
[https://httpd.apache.org/docs/current/en/mod/core.html#cgipassauth](http://CGIPassAuth)

2. If you use mod\_fastcgi configure your virtual host fastcgi configuration to use the “-pass-header Authorization” flag:

> \<IfModule mod\_fastcgi.c\>  
> SetHandler php7-fcgi .php|  
> Action php7-fcgi /php7-fcgi virtual|  
> Alias /php7-fcgi /usr/lib/cgi-bin/php7-fcgi|  
> FastCgiExternalServer /usr/lib/cgi-bin/php7-fcgi -socket /var/run/php/php7.0-fpm.sock -pass-header Authorization  
> \</IfModule\>

---

<div class="post-metadata">

**Author:** ![richardw8k](https://sea2.discourse-cdn.com/flex020/user_avatar/community.gravityforms.com/richardw8k/32/2354_2.png) [@richardw8k](https://community.gravityforms.com/u/richardw8k)\
**Post date:** [January 4, 2022, 5:12pm UTC](https://community.gravityforms.com/t/rest-api-v2-error/2365/10 "2022-01-04T17:12:30Z")

</div>


