# Will there be external TAP access to RSP DP0.2 tables?

**URL:** <https://www.rubin.community/t/will-there-be-external-tap-access-to-rsp-dp0-2-tables/6660>\
**Category:** Support\
**Tags:** dp0\
**Created:** [June 3, 2022, 1:51pm UTC](https://www.rubin.community/t/will-there-be-external-tap-access-to-rsp-dp0-2-tables/6660 "2022-06-03T13:51:39Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![mwv](https://avatars.discourse-cdn.com/v4/letter/m/e79b87/32.png) [@mwv](https://www.rubin.community/u/mwv)\
**Post date:** [June 3, 2022, 1:51pm UTC](https://www.rubin.community/t/will-there-be-external-tap-access-to-rsp-dp0-2-tables/6660/1 "2022-06-03T13:51:39Z")

</div>

For DP0.2 will it be possible to access the RSP through TAP from an external site. E.g., directly running a TAP client (e.g., `pyvo.dal.TAPService`) from my laptop or NERSC?

---

<div class="post-metadata">

**Author:** ![mwv](https://avatars.discourse-cdn.com/v4/letter/m/e79b87/32.png) [@mwv](https://www.rubin.community/u/mwv)\
**Post date:** [June 3, 2022, 1:53pm UTC](https://www.rubin.community/t/will-there-be-external-tap-access-to-rsp-dp0-2-tables/6660/2 "2022-06-03T13:53:07Z")

</div>

I am asking about the opposite direction of access from the following two posts, which were about accessing an external TAP service _from_ the RSP:

> [@Accessing External TAP Services from an RSP Jupyter Notebook](http://www.rubin.community/t/accessing-external-tap-services-from-an-rsp-jupyter-notebook/6584):
>
> Informational: At today’s (20 May 2022) DP0 Delegates working meeting, there was a question on whether it was possible to access and query external TAP services from within an RSP Jupyter notebook. In particular, the question was whether it was possible to query the PanSTARRS1 TAP service from within an RSP Juptyer notebook from [https://data.lsst.cloud](https://data.lsst.cloud). Fortunately, this was previously asked (and answered!) by Robert Nikutta in a Community Forum post in July 2021 ([link](http://www.rubin.community/t/how-can-i-query-external-tap-services/5726). Basically, although …

> [@How can I query external TAP services?](http://www.rubin.community/t/how-can-i-query-external-tap-services/5726):
>
> Hi team, how could one define an external TAP service URL, and query for data there? I was hoping that the get\_tap\_service() method from rubin\_jupyter\_utils.lab.notebook method would accept an argument to define a TAP URL, but it does not appear to be the case. Is there another way? Thank you, Robert

---

<div class="post-metadata">

**Author:** ![DouglasLTucker](https://sea2.discourse-cdn.com/flex002/user_avatar/www.rubin.community/douglasltucker/32/1341_2.png) [@DouglasLTucker](https://www.rubin.community/u/DouglasLTucker)\
**Post date:** [June 3, 2022, 3:59pm UTC](https://www.rubin.community/t/will-there-be-external-tap-access-to-rsp-dp0-2-tables/6660/3 "2022-06-03T15:59:29Z")

</div>

For DP0.1, I was able to access the RSP TAP services using TOPCAT on my laptop; so I believe this will be the case. Let me revisit this question in full a little later today…

---

<div class="post-metadata">

**Author:** ![mwv](https://avatars.discourse-cdn.com/v4/letter/m/e79b87/32.png) [@mwv](https://www.rubin.community/u/mwv)\
**Post date:** [June 3, 2022, 5:28pm UTC](https://www.rubin.community/t/will-there-be-external-tap-access-to-rsp-dp0-2-tables/6660/4 "2022-06-03T17:28:56Z")

</div>

I get

```auto
DALServiceError: 401 Client Error: Unauthorized for url: https://data.lsst.cloud/api/tap/sync

```

When I try to do it from external to the RSP.

---

<div class="post-metadata">

**Author:** ![ktl](https://sea2.discourse-cdn.com/flex002/user_avatar/www.rubin.community/ktl/32/1373_2.png) [@ktl](https://www.rubin.community/u/ktl)\
**Post date:** [June 3, 2022, 5:40pm UTC](https://www.rubin.community/t/will-there-be-external-tap-access-to-rsp-dp0-2-tables/6660/5 "2022-06-03T17:40:11Z")

</div>

You will need to provide a token in some way (authorization header or as username/password) to access TAP from outside the RSP. See [SQR-039: Discussion of authentication and authorization for Science Platform](https://sqr-039.lsst.io/#api-authentication).

As Douglas says, this works today (via [https://data.lsst.cloud/auth/tokens/](https://data.lsst.cloud/auth/tokens/)), but I’m not sure it’s as “pretty” as we would like, so there isn’t full documentation for it yet.

---

<div class="post-metadata">

**Author:** ![mwv](https://avatars.discourse-cdn.com/v4/letter/m/e79b87/32.png) [@mwv](https://www.rubin.community/u/mwv)\
**Post date:** [June 3, 2022, 5:57pm UTC](https://www.rubin.community/t/will-there-be-external-tap-access-to-rsp-dp0-2-tables/6660/6 "2022-06-03T17:57:00Z")

</div>

Thanks for the pointer to that SQR document, @ktl, I’ll try it out.

@frossie Are there any performance limitations I should anticipate? Or, “How can I be a nice DP0 Delegate and not break things?”

---

<div class="post-metadata">

**Author:** ![DouglasLTucker](https://sea2.discourse-cdn.com/flex002/user_avatar/www.rubin.community/douglasltucker/32/1341_2.png) [@DouglasLTucker](https://www.rubin.community/u/DouglasLTucker)\
**Post date:** [June 3, 2022, 8:02pm UTC](https://www.rubin.community/t/will-there-be-external-tap-access-to-rsp-dp0-2-tables/6660/7 "2022-06-03T20:02:58Z")

</div>

Sorry for the delay. I had to dig into the code a bit…

Anyway, @MelissaGraham pointed me to this useful piece Rubin DP0 Delegate documenation:  
[https://data.lsst.cloud/api-aspect](https://data.lsst.cloud/api-aspect) .

Once you have your data.lsst.cloud TAP service token, you can either use it other TAP access services. I will give two cases: (1) via TOPCAT and (2) via a NOIRLAB DataLab Jupyter Notebook.

_ **TOPCAT** _

1. Start up TOPCAT.  
(see [http://www.star.bris.ac.uk/~mbt/topcat/](http://www.star.bris.ac.uk/~mbt/topcat/) )

2. Click on 'Table Access Protocal (TAP) Query under the “VO” menu.  

3. Fill in `https://data.lsst.cloud/api/tap` in the “TAP URL” window and click the “Use Service” button.  

4. Fill in your security token under “User” in the Authentication window that pops up. Leave the “Password” blank. Click OK.  

5. Now you have access to the RSP TAP service from TOPCAT.  

_ **NOIRLAB Data Lab** _

Here, basically you want to use the basic `pyvo` commands, not the specialized DataLab convenience functions.

1. Go to the NOIRLAB DataLab ( [https://datalab.noirlab.edu/](https://datalab.noirlab.edu/) ) and launch a Jupyter Notebook.

2. At the very minumun, import the `pyvo` and `requests` python modules:

```auto
import pyvo
import requests

```

1. Define the data.lsst.cloud TAP server URL and your security token:

```auto
tap_url = 'https://data.lsst.cloud/api/tap'
token = 'yy-xxxxxx' # insert your own RSP TAP server security token here.

```

1. Set up appropriate authorization to access the RSP TAP server:

```auto
s = requests.Session()
s.headers["Authorization"] = "Bearer " + token
auth = pyvo.auth.authsession.AuthSession()
auth.credentials.set("lsst-token", s)
auth.add_security_method_for_url(tap_url, "lsst-token")
auth.add_security_method_for_url(tap_url + "/sync", "lsst-token")
auth.add_security_method_for_url(tap_url + "/async", "lsst-token")
auth.add_security_method_for_url(tap_url + "/tables", "lsst-token")

```

1. Access the RSP TAP servics:

```auto
tap = pyvo.dal.TAPService(tap_url, auth)

```

1. Run a query:

```auto
query = "SELECT * FROM tap_schema.schemas"
results = tap.run_sync(query)
results.to_table()

```

Below, I have screenshots of a full Jupyter notebook running the above in the NOIRLAB DataLab (well, with my security token changed to a generic `yy-XXXXX`):

 ![Screen Shot 2022-06-03 at 3.00.55 PM](https://us1.discourse-cdn.com/flex002/uploads/rubin/original/2X/c/c7a9dae1666effd0fd81cd6cb82f2c901208574b.png)  
 ![Screen Shot 2022-06-03 at 3.01.12 PM](https://us1.discourse-cdn.com/flex002/uploads/rubin/original/2X/4/4df9580039ffe719bef966c800564ded47ee74bc.png)

* * *

I hope this helps! Apologies for the gory details, but I hope to be able to go back to this and remind myself how this works in the future(!).

Thanks!

---

<div class="post-metadata">

**Author:** ![ktl](https://sea2.discourse-cdn.com/flex002/user_avatar/www.rubin.community/ktl/32/1373_2.png) [@ktl](https://www.rubin.community/u/ktl)\
**Post date:** [June 3, 2022, 9:58pm UTC](https://www.rubin.community/t/will-there-be-external-tap-access-to-rsp-dp0-2-tables/6660/8 "2022-06-03T21:58:44Z")

</div>

Oh, it is “official”, then.

For notebook steps 4+5, I found it simpler to do:

```auto
cred = pyvo.auth.CredentialStore()
cred.set_password("x-oauth-basic", token)
tap = pyvo.dal.TAPService(tap_url, session=cred.get("ivo://ivoa.net/sso#BasicAA"))

```

(and no need to import `requests`)

---

<div class="post-metadata">

**Author:** ![mwv](https://avatars.discourse-cdn.com/v4/letter/m/e79b87/32.png) [@mwv](https://www.rubin.community/u/mwv)\
**Post date:** [June 4, 2022, 6:33pm UTC](https://www.rubin.community/t/will-there-be-external-tap-access-to-rsp-dp0-2-tables/6660/9 "2022-06-04T18:33:14Z")

</div>

Thanks, all! I tried @ktl 's solution and it works perfectly.

---

<div class="post-metadata">

**Author:** ![mwv](https://avatars.discourse-cdn.com/v4/letter/m/e79b87/32.png) [@mwv](https://www.rubin.community/u/mwv)\
**Post date:** [June 4, 2022, 6:37pm UTC](https://www.rubin.community/t/will-there-be-external-tap-access-to-rsp-dp0-2-tables/6660/10 "2022-06-04T18:37:30Z")

</div>

Thanks, @DouglasLTucker I appreciate the gory details for exactly the purpose of providing a good detailed answer for people searching this in the future (which will likely include us). I wasn’t familiar with using `requests` and appreciate learning about building the auth by specifying what to do for the different parts of the TAP service.

---

<div class="post-metadata">

**Author:** ![gpdf](https://sea2.discourse-cdn.com/flex002/user_avatar/www.rubin.community/gpdf/32/65_2.png) [@gpdf](https://www.rubin.community/u/gpdf)\
**Post date:** [July 6, 2022, 10:58pm UTC](https://www.rubin.community/t/will-there-be-external-tap-access-to-rsp-dp0-2-tables/6660/11 "2022-07-06T22:58:49Z")

</div>

@mwv I would prefer @ktl’s more concise recipe be propagated. It’s the result of some recent work on improving Python interfaces to authenticated IVOA services, and it’ll be more robust than enumerating specific endpoints (which could very well change over time - they are not required by the standard to keep those names).

---

<div class="post-metadata">

**Author:** ![mwv](https://avatars.discourse-cdn.com/v4/letter/m/e79b87/32.png) [@mwv](https://www.rubin.community/u/mwv)\
**Post date:** [July 6, 2022, 11:18pm UTC](https://www.rubin.community/t/will-there-be-external-tap-access-to-rsp-dp0-2-tables/6660/12 "2022-07-06T23:18:46Z")

</div>

Yep. Here’s what I wrote up and circulated to DESC as a simple example test of NOIRLab and RSP TAP services.

[test\_rsp\_tap\_service.py](https://www.rubin.community/uploads/short-url/5L2Q7f77RqNC9gT1ekVY2A1JOHG.py) (1.5 KB)
