# Multiple instances authentication

**URL:** <https://discourse.nodered.org/t/multiple-instances-authentication/33819>\
**Category:** General\
**Created:** [6 October 2020 08:13 UTC](https://discourse.nodered.org/t/multiple-instances-authentication/33819 "2020-10-06T08:13:54Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![FStefanni](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/fstefanni/32/23624_2.png) [@FStefanni](https://discourse.nodered.org/u/FStefanni)\
**Post date:** [6 October 2020 08:13 UTC](https://discourse.nodered.org/t/multiple-instances-authentication/33819/1 "2020-10-06T08:13:55Z")

</div>

Hi,

I have the following scenario.  
I have one server, running two node-red instances, e.g. [myserver.net/nodered1](http://myserver.net/nodered1) and [myserver.net/nodered2](http://myserver.net/nodered2).  
Both instances use the builtin user-password authentication.  
I would like to open and edit both node-red editor instances into two tabs of the same browser.

Unfortunatly, both instances will store into the browser local storage the "auth-tokens", and therefore,  
the second instance will overwrite the auth token of the first.  
E.g. if I first do login on nodered1, and then on nodered2, nodered2 will work fine, but to successfully deploy or work with nodered1, I have to re-do login, but this will overwrite the nodered2 token, and so on.

Question: is there a way to prevent this overwrite? E.g. a simple settings.js option to customize where/how the auth token is stored.

Regards

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [6 October 2020 08:18 UTC](https://discourse.nodered.org/t/multiple-instances-authentication/33819/2 "2020-10-06T08:18:54Z")

</div>

Hi @FStefanni

this is a known issue that was recently raised with the auth mechanism we have - you can't have two instances on the same domain. [https://github.com/node-red/node-red/issues/2657](https://github.com/node-red/node-red/issues/2657)

There's no workaround - we need to change how the auth works in the editor.

---

<div class="post-metadata">

**Author:** ![FStefanni](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/fstefanni/32/23624_2.png) [@FStefanni](https://discourse.nodered.org/u/FStefanni)\
**Post date:** [6 October 2020 08:39 UTC](https://discourse.nodered.org/t/multiple-instances-authentication/33819/3 "2020-10-06T08:39:57Z")

</div>

Hi,

thank you for the quick reply.  
So I'll wait for the issue closing.

Regards

---

<div class="post-metadata">

**Author:** ![kuema](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/kuema/32/6542_2.png) [@kuema](https://discourse.nodered.org/u/kuema)\
**Post date:** [6 October 2020 08:42 UTC](https://discourse.nodered.org/t/multiple-instances-authentication/33819/4 "2020-10-06T08:42:14Z")

</div>

You could open the other instance in a private/incognito browser tab. That way the local storages won't interfere.

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [6 October 2020 08:57 UTC](https://discourse.nodered.org/t/multiple-instances-authentication/33819/5 "2020-10-06T08:57:52Z")

</div>

Or open the second one in a different browser.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [8 October 2020 09:48 UTC](https://discourse.nodered.org/t/multiple-instances-authentication/33819/6 "2020-10-08T09:48:18Z")

</div>

Does it work with a different sub-domain? If so, that should be easy to do.

Otherwise, like others, I'd recommend different browser profiles. I have to do this for work as I have accounts on the same service across multiple tenants, Office 365 in particular. The new Microsoft Edge (Chromium based) is excellent for this. But plenty of other browsers also support it. It is better than using an in-private session as that doesn't remember your settings.

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [8 October 2020 09:51 UTC](https://discourse.nodered.org/t/multiple-instances-authentication/33819/7 "2020-10-08T09:51:31Z")

</div>

Different sub-domains is fine and is how all of the existing multi-tenant node-red systems have approached it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [7 December 2020 09:51 UTC](https://discourse.nodered.org/t/multiple-instances-authentication/33819/8 "2020-12-07T09:51:36Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
