# Use Admin API with adminAuth type strategy

**URL:** <https://discourse.nodered.org/t/use-admin-api-with-adminauth-type-strategy/21719>\
**Category:** Feature Requests\
**Created:** [14 February 2020 18:55 UTC](https://discourse.nodered.org/t/use-admin-api-with-adminauth-type-strategy/21719 "2020-02-14T18:55:08Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![gmerciel](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/gmerciel/32/25545_2.png) [@gmerciel](https://discourse.nodered.org/u/gmerciel)\
**Post date:** [14 February 2020 18:55 UTC](https://discourse.nodered.org/t/use-admin-api-with-adminauth-type-strategy/21719/1 "2020-02-14T18:55:08Z")

</div>

Hi, I would like to use strategy authorization for editor web ui, so I can use my OpenID Connect provider to define users and permissions, but at the same time, I need to be able to use the admin api, which only seems to support credentials type of authentication (or none). In particular, since I would use the admin api from a script with no user interaction, I would need to support the [Client Credentials Flow](https://auth0.com/docs/flows/concepts/client-credentials).

I'm willing to contribute with the necessary code changes, but first I would like to discuss what would be the best way to support this kind of escenario.

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [14 February 2020 19:16 UTC](https://discourse.nodered.org/t/use-admin-api-with-adminauth-type-strategy/21719/2 "2020-02-14T19:16:00Z")

</div>

There is some work happening at the moment to address this.

The current proposal is to all `adminAuth` to provide a custom `tokens` function that can be used to validate any Auth token that isn't recognised as one NR generated itself.

That would then allow you to create an admin-only Auth token that can be used independently of the main oauth login scheme.

I hope there will be a design note or PR that I can link in the near future.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [14 February 2020 20:14 UTC](https://discourse.nodered.org/t/use-admin-api-with-adminauth-type-strategy/21719/3 "2020-02-14T20:14:44Z")

</div>

I'd be happy to input into this if I can.

---

<div class="post-metadata">

**Author:** ![gmerciel](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/gmerciel/32/25545_2.png) [@gmerciel](https://discourse.nodered.org/u/gmerciel)\
**Post date:** [7 April 2020 13:00 UTC](https://discourse.nodered.org/t/use-admin-api-with-adminauth-type-strategy/21719/4 "2020-04-07T13:00:13Z")

</div>

Any news on this subject? Is there anything I can do to help? 🙂

---

<div class="post-metadata">

**Author:** ![knolleary](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/knolleary/32/3_2.png) [@knolleary](https://discourse.nodered.org/u/knolleary)\
**Post date:** [7 April 2020 13:05 UTC](https://discourse.nodered.org/t/use-admin-api-with-adminauth-type-strategy/21719/5 "2020-04-07T13:05:06Z")

</div>

Here is the design note - [https://github.com/node-red/designs/blob/master/designs/admin-api-authentication.md](https://github.com/node-red/designs/blob/master/designs/admin-api-authentication.md)

The code was merged into the `dev` branch a while ago. Will be in 1.1.0 whenever that arrives.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [6 June 2020 13:05 UTC](https://discourse.nodered.org/t/use-admin-api-with-adminauth-type-strategy/21719/6 "2020-06-06T13:05:07Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
