# How to pass the token to the \[http in\] node?

**URL:** <https://discourse.nodered.org/t/how-to-pass-the-token-to-the-http-in-node/69293>\
**Category:** Developing Nodes\
**Tags:** security\
**Created:** [20 October 2022 03:51 UTC](https://discourse.nodered.org/t/how-to-pass-the-token-to-the-http-in-node/69293 "2022-10-20T03:51:10Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![stephenwang1011](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/stephenwang1011/32/69420_2.png) [@stephenwang1011](https://discourse.nodered.org/u/stephenwang1011)\
**Post date:** [20 October 2022 03:51 UTC](https://discourse.nodered.org/t/how-to-pass-the-token-to-the-http-in-node/69293/1 "2022-10-20T03:51:11Z")

</div>

Hi team,  
I set the adminAuth

```auto
     adminAuth: {
        type: "credentials",
        sessionExpiryTime: 7200,
        users: [

         {
            username: "ne323nqa",
            password: "$2b$08$1aRZsE3232j0wg73rlS1oB.K.QcV0uQsdGm1W4GUj2QkD4NVqe5ZdMxu", 
            permissions: "*"
        }

     ],

```

And also set the httpNodeAuth

```auto
   httpNodeAuth: {user:"ne323nqa",pass:"$2b$08$1aRZsE3232j0wg73rlS1oB.K.QcV0uQsdGm1W4GUj2QkD4NVqe5ZdMxu"},

```

But when I used the admin API [/auth/token] to produce an access token and the pass to the [http in] node, it told me that Unauthorized.  
And I used the postman to call the API[http in], I also set the header :Authorization, but it didn't work, still said Unauthorized.

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/5/0/507613cdf21e909965b9502da08c67211d961344.png)

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/c/8/c8c7b6f7ca0533c1de48f2ac32cd31380ff16e22.png)

---

<div class="post-metadata">

**Author:** ![stephenwang1011](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/stephenwang1011/32/69420_2.png) [@stephenwang1011](https://discourse.nodered.org/u/stephenwang1011)\
**Post date:** [20 October 2022 07:20 UTC](https://discourse.nodered.org/t/how-to-pass-the-token-to-the-http-in-node/69293/2 "2022-10-20T07:20:00Z")

</div>

This is my http in node

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/6/1/61cb7a0eb57d1a8f1cac41a20d706dea8c4c0485.png)

---

<div class="post-metadata">

**Author:** ![stephenwang1011](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/stephenwang1011/32/69420_2.png) [@stephenwang1011](https://discourse.nodered.org/u/stephenwang1011)\
**Post date:** [20 October 2022 07:46 UTC](https://discourse.nodered.org/t/how-to-pass-the-token-to-the-http-in-node/69293/3 "2022-10-20T07:46:19Z")

</div>

IF I used the basic auth, I can call the api from postman:

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/8/a/8a80d9a64e27fc6d8a5dffc3a229327fb53404c2.png)

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [20 October 2022 08:01 UTC](https://discourse.nodered.org/t/how-to-pass-the-token-to-the-http-in-node/69293/4 "2022-10-20T08:01:42Z")

</div>

The `adminAuth` security only applies to the editor and admin apis of Node-RED. It does not apply to the routes created in the flow, such as the HTTP In nodes.

The only built-in security we provide for the HTTP In nodes is the `httpNodeAuth` basic authentication option.

---

<div class="post-metadata">

**Author:** ![stephenwang1011](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/stephenwang1011/32/69420_2.png) [@stephenwang1011](https://discourse.nodered.org/u/stephenwang1011)\
**Post date:** [20 October 2022 08:54 UTC](https://discourse.nodered.org/t/how-to-pass-the-token-to-the-http-in-node/69293/5 "2022-10-20T08:54:23Z")

</div>

Thanks knolleary,  
I will use basic auth instead

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [20 October 2022 18:10 UTC](https://discourse.nodered.org/t/how-to-pass-the-token-to-the-http-in-node/69293/6 "2022-10-20T18:10:33Z")

</div>

Or use external auth if you want more. Lots of people have written about using something like NGINX as a reverse proxy and configuring the auth there since there are lots of tools and articles on doing that.

---

<div class="post-metadata">

**Author:** ![stephenwang1011](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/stephenwang1011/32/69420_2.png) [@stephenwang1011](https://discourse.nodered.org/u/stephenwang1011)\
**Post date:** [21 October 2022 01:23 UTC](https://discourse.nodered.org/t/how-to-pass-the-token-to-the-http-in-node/69293/7 "2022-10-21T01:23:03Z")

</div>

Thanks, will do that

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [4 November 2022 01:23 UTC](https://discourse.nodered.org/t/how-to-pass-the-token-to-the-http-in-node/69293/8 "2022-11-04T01:23:28Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
