# Exposing a HTTP node without SSL in secured NR

**URL:** <https://discourse.nodered.org/t/exposing-a-http-node-without-ssl-in-secured-nr/5300>\
**Category:** General\
**Created:** [29 November 2018 14:15 UTC](https://discourse.nodered.org/t/exposing-a-http-node-without-ssl-in-secured-nr/5300 "2018-11-29T14:15:23Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![lius](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/lius/32/12679_2.png) [@lius](https://discourse.nodered.org/u/lius)\
**Post date:** [29 November 2018 14:15 UTC](https://discourse.nodered.org/t/exposing-a-http-node-without-ssl-in-secured-nr/5300/1 "2018-11-29T14:15:23Z")

</div>

Dear Node-RED friends,  
Is it possible to expose an HTTP node in a secured Node-RED environment? Basically, I want to have all of NR's APIs and UI SSL-secured, but I need to make one particular endpoint available for a device that's incapable of connecting to https:// URLs.  
Any hint is highly appreciated!  
Thanks in advance!

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [29 November 2018 19:45 UTC](https://discourse.nodered.org/t/exposing-a-http-node-without-ssl-in-secured-nr/5300/2 "2018-11-29T19:45:05Z")

</div>

> [@lius](#):
>
> Dear Node-RED friends,  
> Is it possible to expose an HTTP node in a secured Node-RED environment? Basically, I want to have all of NR's APIs and UI SSL-secured, but I need to make one particular endpoint available for a device that's incapable of connecting to https:// URLs.  
> Any hint is highly appreciated!  
> Thanks in advance!

Node-RED uses ExpressJS to provide its endpoints. The default endpoints are either https or http, I don't believe it is possible to mix. As far as I am aware, to do what you want would require a custom node writing that creates a new ExpressJS endpoint - that would need to use a different port number.

---

<div class="post-metadata">

**Author:** ![lius](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/lius/32/12679_2.png) [@lius](https://discourse.nodered.org/u/lius)\
**Post date:** [30 November 2018 07:28 UTC](https://discourse.nodered.org/t/exposing-a-http-node-without-ssl-in-secured-nr/5300/3 "2018-11-30T07:28:21Z")

</div>

Thank you, @TotallyInformation! I'll give this a try then.
