# Authentication failing / Out-of-date documentation

**URL:** <https://community.prismic.io/t/authentication-failing-out-of-date-documentation/5670>\
**Category:** Developing with Prismic\
**Tags:** graphql\
**Created:** [June 8, 2021, 11:47am UTC](https://community.prismic.io/t/authentication-failing-out-of-date-documentation/5670 "2021-06-08T11:47:31Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![jayden.wise](https://avatars.discourse-cdn.com/v4/letter/j/22d042/32.png) [@jayden.wise](https://community.prismic.io/u/jayden.wise)\
**Post date:** [June 8, 2021, 11:47am UTC](https://community.prismic.io/t/authentication-failing-out-of-date-documentation/5670/1 "2021-06-08T11:47:31Z")

</div>

While following along with the example project found on the [React with GraphQL](https://prismic.io/docs/technologies/react-with-graphql) page, it details a process called [Introspection Fragment matching with GraphQL](https://prismic.io/docs/technologies/introspection-fragment-matching-with-graphql).  
My first question is, is this file necessary/does it bring any benefit to the project?

I ask because both the sample project and the Introspection fragment matching page I linked above seem to both be out-of-date and using the old version 1 API.  
As my repo is private I also need to adjust the sample given, in order to attach some headers to the fetch request..  
I have tried following the sample given on this page - [Introduction To The Content Query API](https://prismic.io/docs/technologies/introduction-to-the-content-query-api) to test using an access token and it has not worked. To quote the page

## The Access Token

If you've set your repository to private, then you'll need to provide an access token in order to retrieve your content. To do this you will need to use the access\_token parameter and provide your token.

```auto
https://your-repo-name.cdn.prismic.io/api/v2/documents/search?ref=Your_Ref&access_token=${MY_ACCESS_TOKEN}

```

This does not work, I receive a 403 Forbidden. I also tried with replacing the Your\_ref with "master", (even though this is not documented) to no success.

I have also tried following the example in the following page - [Intro to the GraphQL API](https://prismic.io/docs/technologies/intro-to-the-graphql-api).

Supposedly all you need to do is query the `https://your-repo-name.prismic.io/graphql` endpoint with a "Authorization" header and a "Prismic-Ref" header. I receive a 'Invalid access token' error.

And just to be clear, I only have a single permanent access token which I have been using when required.  
Any help is appreciated. Thanks for reading!

---

<div class="post-metadata">

**Author:** ![Phil](https://dub1.discourse-cdn.com/flex013/user_avatar/community.prismic.io/phil/32/14_2.png) [@Phil](https://community.prismic.io/u/Phil)\
**Post date:** [June 15, 2021, 9:08am UTC](https://community.prismic.io/t/authentication-failing-out-of-date-documentation/5670/4 "2021-06-15T09:08:52Z")

</div>

Hey Jayden,

You can find the master ref if you visit your projects API browser at:

```auto
https://your-repo-name.prismic.io/api/v2

```

You can see my example here:

```auto
https://new-test-phil.cdn.prismic.io/api/v2/documents/search?ref=YMhoxBAAACUA03AJ&access_token=MTYyMzc1MDQyODMyMi5ZTWhwREJBQUFDUUEwM0Za.EO-_ve-_ve-_vUxxEhNx77-9Nu-_vWrvv71J77-977-9be-_vRjvv73vv71H77-9P--_vXTvv71TaUZP#format=json

```
