# Http request node - Authentication

**URL:** <https://discourse.nodered.org/t/http-request-node-authentication/88168>\
**Category:** General\
**Tags:** security\
**Created:** [22 May 2024 10:37 UTC](https://discourse.nodered.org/t/http-request-node-authentication/88168 "2024-05-22T10:37:15Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![jttjtt](https://avatars.discourse-cdn.com/v4/letter/j/278dde/32.png) [@jttjtt](https://discourse.nodered.org/u/jttjtt)\
**Post date:** [22 May 2024 10:37 UTC](https://discourse.nodered.org/t/http-request-node-authentication/88168/1 "2024-05-22T10:37:15Z")

</div>

Hello,  
i am not sure if it is possible to send authentication username and password to http-request node. So when I have more nodes of this type, if I can manage the username and password from a global variable for example. Thanks.

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [22 May 2024 10:50 UTC](https://discourse.nodered.org/t/http-request-node-authentication/88168/2 "2024-05-22T10:50:15Z")

</div>

it is possible to include the username and password in the URL `http://user:pass@wherever.com`.  
The HTTP node extracts them and uses the with auth type (basic/digest) you set on node.

Alternatively, depending on the auth type, you can probably set the `Authorization` header yourself (either in the HTTP node edit dialog or via a change/function node before the HTP request.

_basic auth example_

```auto
const user = flow.get('user')
const pass = flow.get('pass')
msg.headers = msg.headers || {}
msg.headers.Authorization = "Basic " + Buffer.from(`${user}:${password}`).toString("base64");

```

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [22 May 2024 10:51 UTC](https://discourse.nodered.org/t/http-request-node-authentication/88168/3 "2024-05-22T10:51:20Z")

</div>

Alternatively, you can use Env Vars for setting the username and password.

See [Using environment variables : Node-RED](https://nodered.org/docs/user-guide/environment-variables#setting-a-node-property)

---

<div class="post-metadata">

**Author:** ![E1cid](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/e1cid/32/77971_2.png) [@E1cid](https://discourse.nodered.org/u/E1cid)\
**Post date:** [22 May 2024 11:06 UTC](https://discourse.nodered.org/t/http-request-node-authentication/88168/4 "2024-05-22T11:06:01Z")

</div>

Here is an example of basic authorization in a change node.

```auto
[{"id":"bba0f53aec84ae5f","type":"change","z":"b779de97.b1b46","name":"","rules":[{"t":"set","p":"user","pt":"msg","to":"user","tot":"global"},{"t":"set","p":"password","pt":"msg","to":"password","tot":"global"},{"t":"set","p":"headers","pt":"msg","to":"{}","tot":"json"},{"t":"set","p":"headers.Authorization","pt":"msg","to":"\"Basic \" & $base64decode($$.user & \":\" & $$.password)","tot":"jsonata"}],"action":"","property":"","from":"","to":"","reg":false,"x":200,"y":5240,"wires":[[]]}]

```

 ![chrome_screenshot_22 May 2024 12_05_05 BST](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/d/6/d6bc43d598b248fbf2d92a8e51d5a9db31815eef.png)

---

<div class="post-metadata">

**Author:** ![jttjtt](https://avatars.discourse-cdn.com/v4/letter/j/278dde/32.png) [@jttjtt](https://discourse.nodered.org/u/jttjtt)\
**Post date:** [22 May 2024 11:16 UTC](https://discourse.nodered.org/t/http-request-node-authentication/88168/5 "2024-05-22T11:16:08Z")

</div>

Thanks all for great and fast help. I think, I will use the Change node, which will do, what I need. Great. Thanks.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [23 May 2024 09:58 UTC](https://discourse.nodered.org/t/http-request-node-authentication/88168/6 "2024-05-23T09:58:36Z")

</div>

> [@Steve-Mcl](#):
>
> it is possible to include the username and password in the URL `http://user:pass@wherever.com`.  
> The HTTP node extracts them and uses the with auth type (basic/digest) you set on node.

Please lets use `https` in any logon examples. And please note that even with https, you are leaking your id and password to the Internet. This is HIGHLY INSECURE.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [6 June 2024 09:59 UTC](https://discourse.nodered.org/t/http-request-node-authentication/88168/7 "2024-06-06T09:59:14Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
