API:Login/id

MediaWiki API mungkin mengharuskan aplikasi atau klien Anda memberikan kredensial pengguna yang diautentikasi dan login untuk (a) informasi kueri atau tindakan mengubah data (b) membuat kueri besar dengan permintaan per batas yang lebih tinggi.

Dua metode untuk mengotentikasi
Ada dua cara untuk mengotentikasi ke API Tindakan MediaWiki:

Metode 1. login
Bot dan aplikasi non-interaktif lainnya harus menggunakan konsumen OAuth khusus pemilik jika tersedia karena lebih aman. Jika tidak tersedia atau tidak berlaku untuk klien, tindakan  bisa digunakan dengan bot password.

Method 2. clientlogin
Interactive applications such as custom editors or patrolling applications that provide a service without intending to fully replace the website or mobile apps that aim to completely replace access to the web-based user interface should use the  action. However, one should prefer using if it is available for authenticating the tool, as it is easier and more secure. This module is available since MediaWiki 1.27.

Permintaan POST
Obtain token login in the request above via.

Example 2: Process for a wiki with special authentication extensions
A wiki with special authentication extensions such as (captchas),,  (two factor authentication), may have a more complicated authentication process. Specific fields might also be required in that case, the description of which could be fetched from the query.

Step 3: Two-factor authentication
Note: In certain cases it's possible to receive a  response, for example if the OpenID Connect extension had no mapping for the OpenID account to any local user. In this case the client might restart the login process from the beginning or might switch to account creation, in either case passing the loginpreservestate or createpreservestate parameter to preserve some state.

Additional notes

 * On wikis that allow anonymous editing, it's possible to edit through the API without logging in, but it's highly recommended that you do log in. On private wikis, logging in is required to use any API functionality.
 * It is recommended to create a separate user account for your application. This is especially important if your application is carrying out automated editing or invoking large or performance-intensive queries. With that, it is easy to track changes made by the application and apply special rights to the application's account.
 * If you are sending a request that should be made by a logged-in user, add  parameter to the request you are sending in order to check whether the user is logged in. If the user is not logged-in, an   error code will be returned.
 * To check if an account has bot rights, add  parameter to the request. If the account does not have bot rights, an   error code will be returned.