# Custom Admin API with authentication

**URL:** <https://discourse.nodered.org/t/custom-admin-api-with-authentication/27051>\
**Category:** General\
**Created:** [21 May 2020 20:57 UTC](https://discourse.nodered.org/t/custom-admin-api-with-authentication/27051 "2020-05-21T20:57:43Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [21 May 2020 21:23 UTC](https://discourse.nodered.org/t/custom-admin-api-with-authentication/27051/4 "2020-05-21T21:23:30Z")

</div>

The `needsPermission` function returns a middleware that handles the request before it reaches your `test.get` function. That middleware checks if the user making the request has the required permission.

> [@ashish-y](#):
>
> I guess my question is where do I define scope of this new permission?

You don't have to predefined the permission anywhere. As long as the permission string takes the form `XYZ.read` or `XYZ.write` then it will work as expected.

As per [the docs](https://nodered.org/docs/user-guide/runtime/securing-node-red#user-permissions) users either have the permission `read` or `*`. If it is `read` then they are allowed to access anything with a `XYZ.read` permission. If it's `*` then they can access everything.

The reason for the `XYZ` part of the permission is to identify the type of resource being accessed - which allows for some finer-grained permissions. For example, a user couple have a permission of `["read", "inject.write"]` - this would allow them read-only access to the editor, but would be able to trigger any inject nodes.

---

_[View the full topic](https://discourse.nodered.org/t/custom-admin-api-with-authentication/27051)._
