# Secure different routes with different user

**URL:** <https://discourse.nodered.org/t/secure-different-routes-with-different-user/5883>\
**Category:** General\
**Created:** [17 December 2018 12:53 UTC](https://discourse.nodered.org/t/secure-different-routes-with-different-user/5883 "2018-12-17T12:53:00Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Georg25](https://avatars.discourse-cdn.com/v4/letter/g/ed8c4c/32.png) [@Georg25](https://discourse.nodered.org/u/Georg25)\
**Post date:** [17 December 2018 12:53 UTC](https://discourse.nodered.org/t/secure-different-routes-with-different-user/5883/1 "2018-12-17T12:53:00Z")

</div>

Hi,

is there a way to secure :1880/ui with another user and password as :1880/mui ?

Georg

---

<div class="post-metadata">

**Author:** ![ukmoose](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/ukmoose/32/13_2.png) [@ukmoose](https://discourse.nodered.org/u/ukmoose)\
**Post date:** [17 December 2018 13:09 UTC](https://discourse.nodered.org/t/secure-different-routes-with-different-user/5883/2 "2018-12-17T13:09:48Z")

</div>

I don't think you can run the dashboard and the node-red-contrib-mdashboard on the same instance anyway.

---

<div class="post-metadata">

**Author:** ![Georg25](https://avatars.discourse-cdn.com/v4/letter/g/ed8c4c/32.png) [@Georg25](https://discourse.nodered.org/u/Georg25)\
**Post date:** [17 December 2018 13:13 UTC](https://discourse.nodered.org/t/secure-different-routes-with-different-user/5883/3 "2018-12-17T13:13:05Z")

</div>

ok with mdashboard you can be right, but /ui and /test or something like this?

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [17 December 2018 13:16 UTC](https://discourse.nodered.org/t/secure-different-routes-with-different-user/5883/4 "2018-12-17T13:16:06Z")

</div>

Hi @Georg25 - it is not possible to secure different http routes with different credentials with the built-in authentication system.

You would have to embed node-red in your own node app and apply the authentication to the express routes outside of node-red
