# Is it possible to open the node-red editor via an url by sending a flow id as a parameter in addition to the access token?

**URL:** <https://discourse.nodered.org/t/is-it-possible-to-open-the-node-red-editor-via-an-url-by-sending-a-flow-id-as-a-parameter-in-addition-to-the-access-token/87581>\
**Category:** General\
**Tags:** editor\
**Created:** [29 April 2024 09:18 UTC](https://discourse.nodered.org/t/is-it-possible-to-open-the-node-red-editor-via-an-url-by-sending-a-flow-id-as-a-parameter-in-addition-to-the-access-token/87581 "2024-04-29T09:18:45Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Fitspade](https://avatars.discourse-cdn.com/v4/letter/f/7ea924/32.png) [@Fitspade](https://discourse.nodered.org/u/Fitspade)\
**Post date:** [29 April 2024 09:18 UTC](https://discourse.nodered.org/t/is-it-possible-to-open-the-node-red-editor-via-an-url-by-sending-a-flow-id-as-a-parameter-in-addition-to-the-access-token/87581/1 "2024-04-29T09:18:45Z")

</div>

**Introduction to the problem:**

We use the node-red API to display the list of flows in our application.  
In our application, I would like to open the node-red editor in an iframe when we click on a flow located in this list.  
But I don't want the user to have to log in and I would like the editor to open on the tab of the selected flow.

So that the user does not have to log in, I found in the node-red documentation that we can send the access token via the url:  
`https://test-server.com/concoord/admin/?access_token=<ACCESS_TOKEN>`

I then tried to add at the same time in the url:  
`/#flow/<FLOW_ID>`  
Or  
`?flow_id=<FLOW_ID>`  
before and after the access\_token in the url but nothing seems to work and I couldn't find anything in the documentation.

Do you have any idea if it is possible to send the access\_token and a flow\_id in the url at the same time?

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [29 April 2024 10:38 UTC](https://discourse.nodered.org/t/is-it-possible-to-open-the-node-red-editor-via-an-url-by-sending-a-flow-id-as-a-parameter-in-addition-to-the-access-token/87581/2 "2024-04-29T10:38:10Z")

</div>

You can copy the URL to any flow or node using the info panel

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/0/8/08f3e2b915fed7024f1aef7a5905fd641baae4e7.png)

Then as with any URL you can append query parameters

`https://my-flows/#flow/629274ae73ff8efb?access_token=<ACCESS_TOKEN>`

Does that not work?

---

<div class="post-metadata">

**Author:** ![Fitspade](https://avatars.discourse-cdn.com/v4/letter/f/7ea924/32.png) [@Fitspade](https://discourse.nodered.org/u/Fitspade)\
**Post date:** [29 April 2024 12:01 UTC](https://discourse.nodered.org/t/is-it-possible-to-open-the-node-red-editor-via-an-url-by-sending-a-flow-id-as-a-parameter-in-addition-to-the-access-token/87581/3 "2024-04-29T12:01:12Z")

</div>

Thanks for your response! But no unfortunately it doesn't work, it sends me to the login page.  
I wondered if it wasn't possible to also send the flow id as a query parameter? But I couldn't find anything about it.

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [29 April 2024 12:21 UTC](https://discourse.nodered.org/t/is-it-possible-to-open-the-node-red-editor-via-an-url-by-sending-a-flow-id-as-a-parameter-in-addition-to-the-access-token/87581/4 "2024-04-29T12:21:27Z")

</div>

So are you saying

`https://test-server.com/concoord/admin/?access_token=<ACCESS_TOKEN>` opens the editor and logs in BUT `https://test-server.com/concoord/admin/#flow/629274ae73ff8efb/?access_token=<ACCESS_TOKEN>` does not?

If so, then you will have to raise an issue but I am surprised this is the case. Maybe give it another go? Pay attention to the slashes and other formatting of the URL as i have written above.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [29 April 2024 12:32 UTC](https://discourse.nodered.org/t/is-it-possible-to-open-the-node-red-editor-via-an-url-by-sending-a-flow-id-as-a-parameter-in-addition-to-the-access-token/87581/5 "2024-04-29T12:32:14Z")

</div>

> [@Steve-Mcl](#):
>
> [https://test-server.com/concoord/admin/?access\_token=](https://test-server.com/concoord/admin/?access_token=)\<ACCESS\_TOKEN\>

It lets you put the access token on the URL?

That would seem to be extremely insecure.

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [29 April 2024 12:38 UTC](https://discourse.nodered.org/t/is-it-possible-to-open-the-node-red-editor-via-an-url-by-sending-a-flow-id-as-a-parameter-in-addition-to-the-access-token/87581/6 "2024-04-29T12:38:18Z")

</div>

Potentially yes. It depends how the tokens are verified in the users configuration. If verified against a static value - absolutely - but correct implementations would validate the token and age when the callback is executed.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [29 April 2024 12:48 UTC](https://discourse.nodered.org/t/is-it-possible-to-open-the-node-red-editor-via-an-url-by-sending-a-flow-id-as-a-parameter-in-addition-to-the-access-token/87581/7 "2024-04-29T12:48:03Z")

</div>

Hmm, but that is highly insecure if done over open networks. Even with HTTP, the URL is in the clear and can easily be intercepted. It will also be recorded in various logs and proxies.

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [29 April 2024 12:57 UTC](https://discourse.nodered.org/t/is-it-possible-to-open-the-node-red-editor-via-an-url-by-sending-a-flow-id-as-a-parameter-in-addition-to-the-access-token/87581/8 "2024-04-29T12:57:23Z")

</div>

Not disagreeing. It is a feature that has been around for about 9 years. The OP has chosen to use this 🤷

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [29 April 2024 13:34 UTC](https://discourse.nodered.org/t/is-it-possible-to-open-the-node-red-editor-via-an-url-by-sending-a-flow-id-as-a-parameter-in-addition-to-the-access-token/87581/9 "2024-04-29T13:34:02Z")

</div>

In a URL, the search component (`#flow/123`) has to come _after_ the query component (`?access_token=...`)

However, I'm not sure Node-RED preserves the search component when it clears the query component, so it may not be possible to do what you want.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [29 April 2024 15:12 UTC](https://discourse.nodered.org/t/is-it-possible-to-open-the-node-red-editor-via-an-url-by-sending-a-flow-id-as-a-parameter-in-addition-to-the-access-token/87581/10 "2024-04-29T15:12:24Z")

</div>

> [@Steve-Mcl](#):
>
> Not disagreeing. It is a feature that has been around for about 9 years. The OP has chosen to use this 🤷

Another good reason not to expose the Admin endpoints direct over the Internet!

---

<div class="post-metadata">

**Author:** ![Fitspade](https://avatars.discourse-cdn.com/v4/letter/f/7ea924/32.png) [@Fitspade](https://discourse.nodered.org/u/Fitspade)\
**Post date:** [6 May 2024 16:02 UTC](https://discourse.nodered.org/t/is-it-possible-to-open-the-node-red-editor-via-an-url-by-sending-a-flow-id-as-a-parameter-in-addition-to-the-access-token/87581/11 "2024-05-06T16:02:32Z")

</div>

Thank you for all your answers!  
But actually, I don't think it's possible to do what I want. To solve the problem, I therefore make a first invisible iframe which will take care of receiving the access token and then a second visible iframe which will open the flow selected in my list.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [20 May 2024 16:03 UTC](https://discourse.nodered.org/t/is-it-possible-to-open-the-node-red-editor-via-an-url-by-sending-a-flow-id-as-a-parameter-in-addition-to-the-access-token/87581/12 "2024-05-20T16:03:26Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
