# Configure Secure Node-Red basically

**URL:** <https://discourse.nodered.org/t/configure-secure-node-red-basically/95653>\
**Category:** General\
**Tags:** node-red-dashboard, security\
**Created:** [26 February 2025 02:53 UTC](https://discourse.nodered.org/t/configure-secure-node-red-basically/95653 "2025-02-26T02:53:37Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![muksidin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/muksidin/32/99111_2.png) [@muksidin](https://discourse.nodered.org/u/muksidin)\
**Post date:** [26 February 2025 02:53 UTC](https://discourse.nodered.org/t/configure-secure-node-red-basically/95653/1 "2025-02-26T02:53:37Z")

</div>

Hello, i am new in node-red. So for basic security, i imagine for node-red dashboard make public without password and for node-red editor make secured by enable user and password login.  
Is it possible to make this.

Thanks

Muksidin

---

<div class="post-metadata">

**Author:** ![Sean-McG](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/sean-mcg/32/54677_2.png) [@Sean-McG](https://discourse.nodered.org/u/Sean-McG)\
**Post date:** [26 February 2025 03:35 UTC](https://discourse.nodered.org/t/configure-secure-node-red-basically/95653/2 "2025-02-26T03:35:40Z")

</div>

Hi,

Welcome to the forum @muksidin, what exactly do you mean by "make public" ?

If you are thinking of making it accessible to the internet - **Stop right there** and take a look at this -

See this FAQ post for advice on how to safely access node-red over the internet.

> [@Safely accessing Node-RED over the Internet](https://discourse.nodered.org/t/safely-accessing-node-red-over-the-internet/45024):
>
> Update 2025-02-19 The best advice for most people doing home automation is still: Don't expose Node-RED to the outside world! Where you really have to have some outside access, keep it as hands-off and restricted as possible. For example, using a Telegram bot. Also keep it as minimal as possible, e.g. Don't expose the Editor - EVER! If you want to provide remote control of your heating or the precious plants in your greenhouse, provide explicit controls with strong limits. Don't expose ever…

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [26 February 2025 11:49 UTC](https://discourse.nodered.org/t/configure-secure-node-red-basically/95653/3 "2025-02-26T11:49:25Z")

</div>

Basically, don't make the Editor accessible from the Internet.

If you need remote access to the Editor, use a 3rd-party security proxy such as Cloudflare Zero Trust.

In fact, best to make Dashboard also only available via the secure proxy.

CF ZT allows you up to 50 users on the free tier so should be more than enough for the Editor.

---

<div class="post-metadata">

**Author:** ![muksidin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/muksidin/32/99111_2.png) [@muksidin](https://discourse.nodered.org/u/muksidin)\
**Post date:** [3 March 2025 19:28 UTC](https://discourse.nodered.org/t/configure-secure-node-red-basically/95653/4 "2025-03-03T19:28:31Z")

</div>

**make public** means the dashboard can be accessed without entering a password. so anyone can access it

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [3 March 2025 20:28 UTC](https://discourse.nodered.org/t/configure-secure-node-red-basically/95653/5 "2025-03-03T20:28:37Z")

</div>

> [@muksidin](#):
>
> **make public** means the dashboard can be accessed without entering a password.

Do you mean anyone in the world with internet access?

---

<div class="post-metadata">

**Author:** ![muksidin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/muksidin/32/99111_2.png) [@muksidin](https://discourse.nodered.org/u/muksidin)\
**Post date:** [3 March 2025 22:34 UTC](https://discourse.nodered.org/t/configure-secure-node-red-basically/95653/6 "2025-03-03T22:34:45Z")

</div>

No, i configure for local network. So here, for access the editor need authentication and for dashboard no need or other words freely access.

---

<div class="post-metadata">

**Author:** ![jbudd](https://avatars.discourse-cdn.com/v4/letter/j/5f8ce5/32.png) [@jbudd](https://discourse.nodered.org/u/jbudd)\
**Post date:** [3 March 2025 23:44 UTC](https://discourse.nodered.org/t/configure-secure-node-red-basically/95653/7 "2025-03-03T23:44:53Z")

</div>

The documentation has a section on securing node-red.  
From what you say above, the relevant bit for you is [https://nodered.org/docs/user-guide/runtime/securing-node-red#editor--admin-api-security](https://nodered.org/docs/user-guide/runtime/securing-node-red#editor--admin-api-security)

In your settings.js file is a section like this

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/a/8/a871b0c71e5ca1a75644e661e6fd7e6b5f24fa5e.png)

Uncomment (remove the leading // characters) from the 8 lines starting from `//adminAuth: {`  
You may wish to change the username from "admin" to something else.  
Replace the stuff between `password: "` and `"` at the end of that line with a password hash that you create (see the documentation linked above for how).

Now restart node-red.  
It will not ask for the password every time.

---

<div class="post-metadata">

**Author:** ![muksidin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/muksidin/32/99111_2.png) [@muksidin](https://discourse.nodered.org/u/muksidin)\
**Post date:** [6 March 2025 14:50 UTC](https://discourse.nodered.org/t/configure-secure-node-red-basically/95653/8 "2025-03-06T14:50:07Z")

</div>

Thanks for your answer guys. 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [20 March 2025 14:50 UTC](https://discourse.nodered.org/t/configure-secure-node-red-basically/95653/9 "2025-03-20T14:50:12Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
