# Question About Lookup Field and REST API

**URL:** <https://forum.kintone.dev/t/question-about-lookup-field-and-rest-api/168>\
**Category:** General\
**Created:** [September 20, 2018, 5:22am UTC](https://forum.kintone.dev/t/question-about-lookup-field-and-rest-api/168 "2018-09-20T05:22:02Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![legacy\_user](https://yyz1.discourse-cdn.com/flex035/user_avatar/forum.kintone.dev/legacy_user/32/25_2.png) [@legacy\_user](https://forum.kintone.dev/u/legacy_user)\
**Post date:** [September 20, 2018, 5:22am UTC](https://forum.kintone.dev/t/question-about-lookup-field-and-rest-api/168/1 "2018-09-20T05:22:02Z")

</div>

Dear Developers,

Currently I’m creating a Kintone App which using a Lookup and REST API, and then I encountered the same problem as below post:

[https://developer.kintone.io/hc/en-us/community/posts/360000665873-Is-there-any-way-to-work-with-Lookup-fields-](https://developer.kintone.io/hc/en-us/community/posts/360000665873-Is-there-any-way-to-work-with-Lookup-fields-)&nbsp;

And thus my problem has been solved, by following the latest reply of that post, which he said&nbsp;by using an X-Cybozu-Authorization included on Headers instead of X-Cybozu-API-Token― now I am able to create a record on an app using REST API where there’s a Lookup field placed

However,

As below post stated:

[https://developer.kintone.io/hc/en-us/articles/229868687-Using-API-Token-authentication](https://developer.kintone.io/hc/en-us/articles/229868687-Using-API-Token-authentication)&nbsp;

that “(…) there is also a risk of the user credentials being leaked from that system.” means that using API Token instead of User API Token probably is the best way to authorize a request API

My question is

Is there any way for me to be able to POST using REST API to an app where a Lookup field used― by using API Token (X-Cybozu-API-Token) instead of using User API Token (X-Cybozu-Authorization) ?

Any answer would be appreciated

Thanks

Afief

---

<div class="post-metadata">

**Author:** ![legacy\_user](https://yyz1.discourse-cdn.com/flex035/user_avatar/forum.kintone.dev/legacy_user/32/25_2.png) [@legacy\_user](https://forum.kintone.dev/u/legacy_user)\
**Post date:** [September 21, 2018, 7:46pm UTC](https://forum.kintone.dev/t/question-about-lookup-field-and-rest-api/168/2 "2018-09-21T19:46:02Z")

</div>

Hi Afief,

&nbsp;

Unfortunately, you&nbsp;can not&nbsp;use POST with API token for lookup fields as the API docs says below.

&nbsp;

▼ Kintone REST API Overview Under API Token Authentication  
[https://developer.kintone.io/hc/en-us/articles/212495188-Kintone-REST-API-Overview](https://forum.kintone.dev/hc/en-us/articles/212495188-Kintone-REST-API-Overview)

“\*values of Lookup fields cannot be created/updated with REST API”

&nbsp;

Therefore, you may need to use a user or session authorization instead.

&nbsp;

Thanks.  
Junko

---

<div class="post-metadata">

**Author:** ![legacy\_user](https://yyz1.discourse-cdn.com/flex035/user_avatar/forum.kintone.dev/legacy_user/32/25_2.png) [@legacy\_user](https://forum.kintone.dev/u/legacy_user)\
**Post date:** [September 24, 2018, 1:31am UTC](https://forum.kintone.dev/t/question-about-lookup-field-and-rest-api/168/3 "2018-09-24T01:31:00Z")

</div>

Hi Junko

Yes, I think that there’s no other way except using user authorization, I may do some other way so that I could use a newly created user authorization for that

You helped me a lot, for that matter I appreciate it so much

Again, thank you,

Afief
