# Nodered API authentication using keycloak auth

**URL:** <https://discourse.nodered.org/t/nodered-api-authentication-using-keycloak-auth/70616>\
**Category:** General\
**Tags:** security\
**Created:** [15 November 2022 04:12 UTC](https://discourse.nodered.org/t/nodered-api-authentication-using-keycloak-auth/70616 "2022-11-15T04:12:01Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Chinmai](https://avatars.discourse-cdn.com/v4/letter/c/c5a1d2/32.png) [@Chinmai](https://discourse.nodered.org/u/Chinmai)\
**Post date:** [15 November 2022 04:12 UTC](https://discourse.nodered.org/t/nodered-api-authentication-using-keycloak-auth/70616/1 "2022-11-15T04:12:01Z")

</div>

Hi,

I am trying to achieve a GET operation on [http://localhost/nodered/admin/flows](http://localhost/nodered/admin/flows) and getting 401 error.

Curl Command for GET /flows operation  
curl --request GET '[http://localhost/nodered/admin/flows](http://localhost/nodered/admin/flows)' --header 'Authorization: Bearer '

Curl command to generate the keycloak token  
curl [http://localhost/auth/realms/smp/protocol/openid-connect/token](http://localhost/auth/realms/smp/protocol/openid-connect/token) --data 'client\_id=nodered&grant\_type=password&username=nodered&password=nodered1'

settings.js file used

```auto
.
.
.
var auth = require("node-red-auth-client");
auth.init({
    "authenticateFlows" : true,
    "authServerUrl": "http://localhost/auth",
    "realm" : "smp",
    "role": "flows.execute"
});

module.exports = {
.
.
.

    // nodered User name and password
    noderedUser : {
        userName : 'nodered',
        password : 'nodered1',
        noderedIp: '127.0.0.1'
    },

    // By default, the Node-RED UI is available at http://localhost:1880/
    // The following property can be used to specifiy a different root path.
    // If set to false, this is disabled.
    httpAdminRoot: '/nodered/admin',

    // Some nodes, such as HTTP In, can be used to listen for incoming http requests.
    // By default, these are served relative to '/'. The following property
    // can be used to specifiy a different root path. If set to false, this is
    // disabled.
    httpNodeRoot: '/nodered/flows',

    adminAuth: require("node-red-auth-keycloak")({
        sessionExpiryTime: 3600,
        realm: 'smp',
        authServerUrl: 'http://localhost/auth',
        callbackURL : 'http://localhost/nodered/admin'
    }),
        requireHttps: false,

    // The following property can be used to add a custom middleware function
    // in front of all http in nodes. This allows custom authentication to be
    // applied to all http in nodes, or any other sort of common request processing.
    httpNodeMiddleware: function(req,res,next) {
        if(auth.shouldAuthenticate()) {
            var promises = [];
            new Promise((resolve, reject) => {
                promises.push(auth.isAuthorized(req));
                Promise.all(promises).then(function(promiseResults) {
                    if(Array.isArray(promiseResults) && promiseResults.length == 1 && promiseResults[0] == true) {
                        next();
                    } else {
                        const error = new Error('Unauthorized access');
                        error.httpStatusCode = 401;
                        next(error);
                    }
                }).catch(function(err) {
                    const error = new Error('Unauthorized access');
                    error.httpStatusCode = 401;
                    next(error);
                });
            });
        } else {
            //Authorization is not needed because shouldAuthenticate is false
            next();
        }
    }
	.
	.
	.

```

We are trying to get flow details from /flows nodered API using keycloak auth token (bearer token).  
Nodered API throws 401 error when keycloak access token is used.

Requesting your support here.

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [15 November 2022 07:31 UTC](https://discourse.nodered.org/t/nodered-api-authentication-using-keycloak-auth/70616/2 "2022-11-15T07:31:33Z")

</div>

Where does `node-red-auth-keycloak` come from? I do not see it on the npm registry. Given you are using that to configure `adminAuth`, without any details then we don't know what configuration it's providing.

---

<div class="post-metadata">

**Author:** ![Chinmai](https://avatars.discourse-cdn.com/v4/letter/c/c5a1d2/32.png) [@Chinmai](https://discourse.nodered.org/u/Chinmai)\
**Post date:** [15 November 2022 11:20 UTC](https://discourse.nodered.org/t/nodered-api-authentication-using-keycloak-auth/70616/3 "2022-11-15T11:20:09Z")

</div>

Please refer the attached file for node-red-auth-keycloak implementation.  
[node-red-auth-keycloak.txt](https://discourse.nodered.org/uploads/short-url/n63PR3jR5uedXu5bsp7726Pvz1U.txt) (3.9 KB)

---

<div class="post-metadata">

**Author:** ![dceejay](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dceejay/32/38_2.png) [@dceejay](https://discourse.nodered.org/u/dceejay)\
**Post date:** [15 November 2022 12:14 UTC](https://discourse.nodered.org/t/nodered-api-authentication-using-keycloak-auth/70616/4 "2022-11-15T12:14:12Z")

</div>

That doesn't answer where you got it from... who is the author ? you may need to contact them to get help as it's not part of the core project.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [14 January 2023 12:14 UTC](https://discourse.nodered.org/t/nodered-api-authentication-using-keycloak-auth/70616/5 "2023-01-14T12:14:43Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
