# How secure is opening up a public endpoint

**URL:** <https://discourse.nodered.org/t/how-secure-is-opening-up-a-public-endpoint/49810>\
**Category:** General\
**Created:** [16 August 2021 22:14 UTC](https://discourse.nodered.org/t/how-secure-is-opening-up-a-public-endpoint/49810 "2021-08-16T22:14:16Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![CybrPimp](https://avatars.discourse-cdn.com/v4/letter/c/a698b9/32.png) [@CybrPimp](https://discourse.nodered.org/u/CybrPimp)\
**Post date:** [16 August 2021 22:14 UTC](https://discourse.nodered.org/t/how-secure-is-opening-up-a-public-endpoint/49810/1 "2021-08-16T22:14:16Z")

</div>

We want to be able to open up a public endpoint (HTTP In Node) to be a webhook to receive post data from Zapier, but I want to make sure it is secure.

You can get a list of the [Zapier server IP list](https://community.zapier.com/general-questions-3/zapier-server-ip-list-1919) but this is constantly changing and right now I don't have time to develop a custom solution to update the IP list and lockdown to Zapier's IPs.

So I would like to know how secure is NodeRed if I were to open up the port 1880 to the internet?

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [16 August 2021 22:36 UTC](https://discourse.nodered.org/t/how-secure-is-opening-up-a-public-endpoint/49810/2 "2021-08-16T22:36:03Z")

</div>

As long as you have setup `adminAuth` to secure the editor (and don't allow anonymous access) and `https` in your settings file, then it's no different to any web server application.

You still have to be mindful as to what http routes you expose and what, if any, security you need to apply to them.

I'm sure others will share their thoughts as to putting it behind some sort of reverse proxy like nginx for even more peace of mind.

---

<div class="post-metadata">

**Author:** ![sammachin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/sammachin/32/5121_2.png) [@sammachin](https://discourse.nodered.org/u/sammachin)\
**Post date:** [17 August 2021 14:35 UTC](https://discourse.nodered.org/t/how-secure-is-opening-up-a-public-endpoint/49810/3 "2021-08-17T14:35:55Z")

</div>

You might also want to look at sending some kind of credentials with the webhook from zapier (that you can then periodically change) Just in case someone discovers your endpoint and sends it data.  
Although this will depend a bit on your use case.  
BTW I've built a Zapier node and coresponding package, this implements the token functionality as above but its no more or less secure than creating your own webhook really [node-red-contrib-zapier (node) - Node-RED](https://flows.nodered.org/node/node-red-contrib-zapier)

---

<div class="post-metadata">

**Author:** ![CybrPimp](https://avatars.discourse-cdn.com/v4/letter/c/a698b9/32.png) [@CybrPimp](https://discourse.nodered.org/u/CybrPimp)\
**Post date:** [18 August 2021 12:11 UTC](https://discourse.nodered.org/t/how-secure-is-opening-up-a-public-endpoint/49810/4 "2021-08-18T12:11:55Z")

</div>

Thanks, gentlemen! Very helpful.

@knolleary @sammachin

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [17 October 2021 12:12 UTC](https://discourse.nodered.org/t/how-secure-is-opening-up-a-public-endpoint/49810/5 "2021-10-17T12:12:23Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
