# Validate my custom api key in http node middleware in settings.js

**URL:** <https://discourse.nodered.org/t/validate-my-custom-api-key-in-http-node-middleware-in-settings-js/79732>\
**Category:** General\
**Tags:** http-request, http-in\
**Created:** [11 July 2023 13:02 UTC](https://discourse.nodered.org/t/validate-my-custom-api-key-in-http-node-middleware-in-settings-js/79732 "2023-07-11T13:02:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Josh](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/josh/32/62208_2.png) [@Josh](https://discourse.nodered.org/u/Josh)\
**Post date:** [11 July 2023 13:02 UTC](https://discourse.nodered.org/t/validate-my-custom-api-key-in-http-node-middleware-in-settings-js/79732/1 "2023-07-11T13:02:37Z")

</div>

Hi Forum,  
New bie here. I want to create a custom API with a API key which I generate in Nodered and want to validate the same API key in httpNodeMiddleware property in settings.js. Whats the best approach to do this?

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [11 July 2023 20:17 UTC](https://discourse.nodered.org/t/validate-my-custom-api-key-in-http-node-middleware-in-settings-js/79732/2 "2023-07-11T20:17:04Z")

</div>

Why not just use http in -\> http response nodes?

What's the reason for involving httpNodeMiddleware?

---

<div class="post-metadata">

**Author:** ![Josh](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/josh/32/62208_2.png) [@Josh](https://discourse.nodered.org/u/Josh)\
**Post date:** [12 July 2023 06:46 UTC](https://discourse.nodered.org/t/validate-my-custom-api-key-in-http-node-middleware-in-settings-js/79732/3 "2023-07-12T06:46:54Z")

</div>

> What's the reason for involving httpNodeMiddleware?

@Steve-Mcl I want to validate the API key in the middleware before the request reaches the flow context.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [10 September 2023 06:47 UTC](https://discourse.nodered.org/t/validate-my-custom-api-key-in-http-node-middleware-in-settings-js/79732/4 "2023-09-10T06:47:01Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
