Example: Authenticated JSON POST (GitHub API)
curl -X POST https://api.github.com/repos/octocat/hello-world/issues \
-H 'Authorization: Bearer ***' \
-H 'Accept: application/vnd.github.v3+json' \
-H 'Content-Type: application/json' \
-d '{"title":"Weekly sync","body":"agenda TBD"}'
Accepthere selects an API version, not a media type — GitHub's v3 header is required for stable JSON.- No
--compressed? GitHub sends one anyway; the converter injects it only when the source had it, so output stays honest. - In Python:
requests.post(url, headers={...}, json={"title": ...})— neverdata="{\"title\"...}"stringly JSON; that's the bug from this guide.
FAQ
Why does GitHub want Accept: application/vnd.github.v3+json instead of application/json? The vendor media type pins the API representation version. Plain application/json gets you the default version, which can shift under you.
Should the bearer token ever be in the URL? No. Query-string tokens are logged at every intermediary; header tokens aren't. See GET with a body for the same logging argument.