# How to access auth\_token

**URL:** <https://discourse.nodered.org/t/how-to-access-auth-token/77238>\
**Category:** General\
**Tags:** security\
**Created:** [4 April 2023 10:34 UTC](https://discourse.nodered.org/t/how-to-access-auth-token/77238 "2023-04-04T10:34:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![sabir](https://avatars.discourse-cdn.com/v4/letter/s/b5e925/32.png) [@sabir](https://discourse.nodered.org/u/sabir)\
**Post date:** [4 April 2023 10:34 UTC](https://discourse.nodered.org/t/how-to-access-auth-token/77238/1 "2023-04-04T10:34:37Z")

</div>

I saw this PR is merged [Feature add: Store external token when authenticate if provided by ArFe · Pull Request #3460 · node-red/node-red · GitHub](https://github.com/node-red/node-red/pull/3460).  
Now I'm able to authenticate with external api and set the token which api returns in response .

Now How can I access the token?  
what I'm trying to achieve to is I have created some custom nodes which takes some fields from the user and under the hood call the api and that api need token, and we have returned at authentication time and stored it, Now I wanted to access the token in custom-node.js file.  
@ArFe

---

<div class="post-metadata">

**Author:** ![ArFe](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/arfe/32/57427_2.png) [@ArFe](https://discourse.nodered.org/u/ArFe)\
**Post date:** [5 April 2023 02:22 UTC](https://discourse.nodered.org/t/how-to-access-auth-token/77238/2 "2023-04-05T02:22:42Z")

</div>

Hi sabir,

I wouldn't be able to tell you. I'm not sure it can be done, even more easily.

The token on that PR is for authenticating the interface, or the user to the interface, not anything else.  
It makes sure the user has the rights to read/write to the flow via an external entity.

In any case, the user isn't always logged in to make your request succeed with a valid token.  
So, what is the problem you're trying to solve that storing a token manually on the http request flow won't fix?

---

<div class="post-metadata">

**Author:** ![sabir](https://avatars.discourse-cdn.com/v4/letter/s/b5e925/32.png) [@sabir](https://discourse.nodered.org/u/sabir)\
**Post date:** [5 April 2023 04:03 UTC](https://discourse.nodered.org/t/how-to-access-auth-token/77238/3 "2023-04-05T04:03:24Z")

</div>

Hii, thanks for the reply,  
Currently the way I'm storing the token is: Once we verify the token or in after authenticating what I'm doing is in settings.js `global.token = response.data.token` and then in custom-node.js file I fetch the token via `token.global` and pass it to the external api call, which is used by custom node.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [4 June 2023 04:03 UTC](https://discourse.nodered.org/t/how-to-access-auth-token/77238/4 "2023-06-04T04:03:42Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
