200-901 Cisco Platforms and Development Practice Question
A developer is building a Python script to create a new network in a Cisco Meraki organization. The developer must authenticate to the Dashboard API. Which HTTP header is used to pass the API key?
⚠ Common exam trap
The trap here is assuming that all REST APIs use standard OAuth or Basic authentication headers, overlooking Meraki's custom header requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
X-Cisco-Meraki-API-Key
The Meraki Dashboard API authenticates requests using an API key passed in the X-Cisco-Meraki-API-Key HTTP header. This is a custom header specific to Meraki, and it must be present in all API calls. Other authentication schemes like Bearer tokens or Basic auth are not used. Understanding the correct header is essential for successful API integration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
X-Cisco-Meraki-API-Key
Why this is correct
The Meraki Dashboard API requires the API key in a custom HTTP header named X-Cisco-Meraki-API-Key. This header must be included in every request for authentication. The key is generated in the Meraki Dashboard under Organization > Settings. Using this header allows the API to identify the organization and authorize the action, such as creating a network.
- ✗
Authorization: Bearer <token>
Why it's wrong here
The Meraki Dashboard API does not use OAuth 2.0 bearer tokens. While many REST APIs use the Authorization header with a Bearer token, Meraki uses a custom header for its API key. Using a Bearer token would result in a 401 Unauthorized error because the API expects the key in X-Cisco-Meraki-API-Key.
- ✗
Authorization: Basic <base64-encoded-credentials>
Why it's wrong here
Basic authentication encodes a username and password, but the Meraki Dashboard API uses an API key, not user credentials. Basic auth is not supported for Meraki API access. Attempting to use it would fail authentication. The correct method is to include the API key in the X-Cisco-Meraki-API-Key header.
- ✗
X-Api-Key
Why it's wrong here
X-Api-Key is a common header for API keys in some services, but Meraki specifically requires X-Cisco-Meraki-API-Key. Using X-Api-Key would not authenticate the request and would likely return a 401 error. The Meraki documentation explicitly states the header name, so developers must follow it precisely.
Go deeper
Related to this question
About these practice questions
One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.