# Securing Node-red endpoints

**URL:** <https://discourse.nodered.org/t/securing-node-red-endpoints/56392>\
**Category:** General\
**Tags:** http-request, security\
**Created:** [10 January 2022 11:46 UTC](https://discourse.nodered.org/t/securing-node-red-endpoints/56392 "2022-01-10T11:46:10Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![SangamBgk](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/sangambgk/32/51549_2.png) [@SangamBgk](https://discourse.nodered.org/u/SangamBgk)\
**Post date:** [10 January 2022 11:46 UTC](https://discourse.nodered.org/t/securing-node-red-endpoints/56392/1 "2022-01-10T11:46:10Z")

</div>

Hi There,  
I created bunch of end points which can be accessed by anyone. can anyone please suggest how I can protect node-red api end points (Token based or any alt ways)

Thanks in Advance,  
Regards,  
Sangamesh

---

<div class="post-metadata">

**Author:** ![marcus-j-davies](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/marcus-j-davies/32/103435_2.png) [@marcus-j-davies](https://discourse.nodered.org/u/marcus-j-davies)\
**Post date:** [10 January 2022 13:06 UTC](https://discourse.nodered.org/t/securing-node-red-endpoints/56392/2 "2022-01-10T13:06:40Z")

</div>

Hi @SangamBgk,

Are you referring to HTTP-IN nodes or http admin endpoints?

If the former, there are various ways, from the easiest, to the more involved.

Easiest:  
Include in your URI a parameter placeholder.  
**/SomeURI/:Token/APIMethod**

You can then check the value at this path: **msg.req.params.Token** and react accordingly i.e. send a 401 if its not the expected value.

The problem here - its a plant text value - but you can develop a means to generate a token prior to this call. i.e create an endpoint to generate a token with a predefined shelf life, providing the POSTED value contains some valid credentials.

You could also just require some header information, that must be valid, for the call to be honored.

The more involved:  
Add middlware to **settings.js** ( **httpNodeMiddleware** )  
This will however apply to every HTTP-IN NODE.

Example - I do this to correct a mimetype from one of our servers.  
but you can apply the same tactic, to authorize the incoming request, and if it isn't to be authorized.  
return a 401 (and don't call **next** ())

```javascript
httpNodeMiddleware: function (req, res, next) {
        var ContentType = req.headers['content-type'];
        if (ContentType === 'xml' || ContentType === 'json') {
            req.headers['content-type'] = 'application/' + ContentType;
        }
        next();
},

```

There are also nodes that add security to the http in flow - But I have not had much exp with them.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [11 January 2022 00:47 UTC](https://discourse.nodered.org/t/securing-node-red-endpoints/56392/3 "2022-01-11T00:47:05Z")

</div>

There are various posts on the forum about securing Node-RED applications.

Probably the easiest way is to use a reverse proxy and do the security there. Then you don't have to mess with Node-RED.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [12 March 2022 00:47 UTC](https://discourse.nodered.org/t/securing-node-red-endpoints/56392/4 "2022-03-12T00:47:42Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
