# Websocket with a dynamic Autharization header

**URL:** <https://discourse.nodered.org/t/websocket-with-a-dynamic-autharization-header/97097>\
**Category:** Feature Requests\
**Created:** [16 May 2025 12:49 UTC](https://discourse.nodered.org/t/websocket-with-a-dynamic-autharization-header/97097 "2025-05-16T12:49:21Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![akd02](https://avatars.discourse-cdn.com/v4/letter/a/5e9695/32.png) [@akd02](https://discourse.nodered.org/u/akd02)\
**Post date:** [16 May 2025 12:49 UTC](https://discourse.nodered.org/t/websocket-with-a-dynamic-autharization-header/97097/1 "2025-05-16T12:49:21Z")

</div>

It seams a bit odd, but reading other requests on this i still find it hard to believe that there is absolutely no way to dynamically change an authorization token for a WebSocket, just want to make sure is this right?

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/8/c/8cb471d85e100474ca2628f8ca13fd0a728b055f.png)

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [16 May 2025 12:54 UTC](https://discourse.nodered.org/t/websocket-with-a-dynamic-autharization-header/97097/2 "2025-05-16T12:54:20Z")

</div>

Ah, interesting! Never noticed that before. Clearly nobody else has ever bothered either.

Of course, the header is only available on the initial handshake for ws connections so an authorization header is of very limited use.

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [16 May 2025 12:55 UTC](https://discourse.nodered.org/t/websocket-with-a-dynamic-autharization-header/97097/3 "2025-05-16T12:55:13Z")

</div>

That screenshot is not of the built in node.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [16 May 2025 12:55 UTC](https://discourse.nodered.org/t/websocket-with-a-dynamic-autharization-header/97097/4 "2025-05-16T12:55:54Z")

</div>

> [@Steve-Mcl](#):
>
> not of the built in node.

I think it is Steve:

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/4/b/4babb7f3b6aefec74c587bbd0fc9d8d876af1b13.png)

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [16 May 2025 12:58 UTC](https://discourse.nodered.org/t/websocket-with-a-dynamic-autharization-header/97097/5 "2025-05-16T12:58:17Z")

</div>

Doh! I was looking at the out node (where I expected this to be!)

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [16 May 2025 12:59 UTC](https://discourse.nodered.org/t/websocket-with-a-dynamic-autharization-header/97097/6 "2025-05-16T12:59:13Z")

</div>

No worries, took me several attempts to find it. I guess neither of us really use that node. 🤣

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [16 May 2025 13:00 UTC](https://discourse.nodered.org/t/websocket-with-a-dynamic-autharization-header/97097/7 "2025-05-16T13:00:57Z")

</div>

BTW, just seen my reply here:

> [@Setting Websocket Headers dynamically](https://discourse.nodered.org/t/setting-websocket-headers-dynamically/88162/4):
>
> So I think you will need to do something like watching for the connection error, using a catch node, using that to trigger a flow to regen the token which you capture to a flow context variable. Hmm, but then you would have to restart the websocket and not sure how to do that. Actual environment variables are only read when Node-RED starts. However, Node-RED has extended the idea of env variables and allows you to set them in its tabs, groups and sub-flows. I've not tried this but perhaps hav…

Might give you a work-around.

---

<div class="post-metadata">

**Author:** ![akd02](https://avatars.discourse-cdn.com/v4/letter/a/5e9695/32.png) [@akd02](https://discourse.nodered.org/u/akd02)\
**Post date:** [16 May 2025 13:00 UTC](https://discourse.nodered.org/t/websocket-with-a-dynamic-autharization-header/97097/8 "2025-05-16T13:00:58Z")

</div>

if this limitation, not being able to dynamically set an authorization header like a token which by definition expires, then i am not surprised why not many use it.... seems useless for those cases where you need to authenticate to start a WebSocket connection... or am i missing something?

---

<div class="post-metadata">

**Author:** ![akd02](https://avatars.discourse-cdn.com/v4/letter/a/5e9695/32.png) [@akd02](https://discourse.nodered.org/u/akd02)\
**Post date:** [16 May 2025 13:04 UTC](https://discourse.nodered.org/t/websocket-with-a-dynamic-autharization-header/97097/9 "2025-05-16T13:04:30Z")

</div>

if the solution ends with "create your own node" 😃 😃

then.... i really question, why is it not a feature in the common / out of the box node.

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [16 May 2025 13:06 UTC](https://discourse.nodered.org/t/websocket-with-a-dynamic-autharization-header/97097/10 "2025-05-16T13:06:28Z")

</div>

You can always try a contrib node: [Library - Node-RED](https://flows.nodered.org/search?term=websocket&type=node)

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [16 May 2025 13:07 UTC](https://discourse.nodered.org/t/websocket-with-a-dynamic-autharization-header/97097/11 "2025-05-16T13:07:05Z")

</div>

No you aren't missing anything. Raw websockets are of limited use in terms of security. You can authorise the initial handshake using a header (don't forget that you also need to use WSS: not WS: - e.g. you need a TLS secured connection) but then you cannot have a timed session. Which means that once connected, you cannot timeout the connection without some other mechanism on the server end and that generally means that the client simply gets cut off and then has to go through a reconnection handshake and authorisation all over again.

But see my possible workaround using Node-RED's pseudo environment variables.

> [@akd02](#):
>
> if the solution ends with "create your own node" 😃 😃
> 
> then.... i really question, why is it not a feature in the common / out of the box node.

Well, not many people use raw websockets directly, most people use an intermediary such as MQTT. Which is still lightweight but is far more feature rich. Where people do use them, they tend to be local and therefore unsecured or ...

Even big vendors struggle with this issue BTW - Microsoft Teams has an undocumented websocket feature and has to have a fixed authorization header. 😃

---

<div class="post-metadata">

**Author:** ![marcus-j-davies](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/marcus-j-davies/32/103435_2.png) [@marcus-j-davies](https://discourse.nodered.org/u/marcus-j-davies)\
**Post date:** [17 May 2025 11:12 UTC](https://discourse.nodered.org/t/websocket-with-a-dynamic-autharization-header/97097/12 "2025-05-17T11:12:06Z")

</div>

I was the one that PR'd the ability to include Headers for the `UPGRADE` operation during socket connections - as some OEM's require a token header of sorts for a successful connect.

As headers are only used once in the handshake, changing it after the connection will make no difference.

And FWIW: it can be "dynamic" - but is only used, when a connection is being made, not for current connections - as that is not possible in a web socket connection.

The value can be taken from an `env variable`

 ![Screenshot 2025-05-17 at 12.11.01](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/3/a/3a13c4ed085eee13323a7ae35d51bea4a1694481.png)

Not sure if any of this helps - but just to explain its existence 😇

---

<div class="post-metadata">

**Author:** ![Steve-Mcl](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/steve-mcl/32/4826_2.png) [@Steve-Mcl](https://discourse.nodered.org/u/Steve-Mcl)\
**Post date:** [17 May 2025 11:26 UTC](https://discourse.nodered.org/t/websocket-with-a-dynamic-autharization-header/97097/13 "2025-05-17T11:26:21Z")

</div>

That's not runtime dynamic tho.

I think the op wants the ability to connect and present a token that is potentially generated (or renewed) while flows are running.

Of course that would require the connection to be restarted.

---

<div class="post-metadata">

**Author:** ![marcus-j-davies](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/marcus-j-davies/32/103435_2.png) [@marcus-j-davies](https://discourse.nodered.org/u/marcus-j-davies)\
**Post date:** [17 May 2025 11:32 UTC](https://discourse.nodered.org/t/websocket-with-a-dynamic-autharization-header/97097/14 "2025-05-17T11:32:10Z")

</div>

Got it!

Taking the MQTT `action:connect` control message as an example  
Adding the ability to have this supported in the WS Node I would think, would be a good addition.

And one that _should_ address this scenario (allowing headers to be included in the `connect``action`)

---

<div class="post-metadata">

**Author:** ![akd02](https://avatars.discourse-cdn.com/v4/letter/a/5e9695/32.png) [@akd02](https://discourse.nodered.org/u/akd02)\
**Post date:** [17 May 2025 13:24 UTC](https://discourse.nodered.org/t/websocket-with-a-dynamic-autharization-header/97097/15 "2025-05-17T13:24:25Z")

</div>

Exactly!

Thanks @Steve-Mcl for taking the words out of my mouth about $env variables not being the solution.

And thanks @marcus-j-davies for listening 🙂

While i have your ‘ears’ it would be great to have the ability to read flow / global variables as typically tokens are stored there as opposed to $env variables and/or alternatively being able to pass the Authorization header in the msg itself when a ‘connect’ is initiated.

Have a great weekend!!!

---

<div class="post-metadata">

**Author:** ![marcus-j-davies](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/marcus-j-davies/32/103435_2.png) [@marcus-j-davies](https://discourse.nodered.org/u/marcus-j-davies)\
**Post date:** [17 May 2025 13:42 UTC](https://discourse.nodered.org/t/websocket-with-a-dynamic-autharization-header/97097/16 "2025-05-17T13:42:28Z")

</div>

I think using flow variables at least, will see some non compatible approaches.  
A Configuration Node, doesn't have access to anything in the flow (I cant answer for globals).

As the web socket connection itself sits 'outside' the gears of the flow - it can't see anything inside of them - unless passed a message indirectly via a Node subscribed to that Config Node.

I would like to see something that MQTT has, but extending to the Web Socket Node.  
That allows to inject a new connection, but adding some toppings to support headers

This would address the need, and add some much needed control over the web socket node

```auto
/* msg */
{
  action: 'connect',
  webSocket: {
    url: 'ws://x.x.x.x',
    subProtocol: 'FooBar',
    mode: 'entire_message',
    headers: {
      token: 'xxxxxx',
      'user-agent':'BarFoo'
    }
  }
}

```

Just needs someone to PR it 😉

---

<div class="post-metadata">

**Author:** ![akd02](https://avatars.discourse-cdn.com/v4/letter/a/5e9695/32.png) [@akd02](https://discourse.nodered.org/u/akd02)\
**Post date:** [17 May 2025 13:51 UTC](https://discourse.nodered.org/t/websocket-with-a-dynamic-autharization-header/97097/17 "2025-05-17T13:51:51Z")

</div>

Not sure why you chose ‘token’ to be a static attribute for the header….

In the cases am working with, the attribute is ‘Authorization’ and the value of the attribute is ‘Bearer xxxxxxxxx’.

In summary much like how an http node works.

---

<div class="post-metadata">

**Author:** ![marcus-j-davies](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/marcus-j-davies/32/103435_2.png) [@marcus-j-davies](https://discourse.nodered.org/u/marcus-j-davies)\
**Post date:** [17 May 2025 13:55 UTC](https://discourse.nodered.org/t/websocket-with-a-dynamic-autharization-header/97097/18 "2025-05-17T13:55:12Z")

</div>

Sorry - was just using token as an example

the `token` in my example is the header name  
The headers in my example - are whatever is required at the other end.

```auto
headers: {
   Authorization: 'Bearer xxxxxxxxx’,
   'User-Agent': 'BarFoo',
   Accept: 'xxxxx',
   Anything: 'Really, that is required by your target server'
}

```

The headers names you put, don't need to follow any rule, whatever is required.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [16 July 2025 13:55 UTC](https://discourse.nodered.org/t/websocket-with-a-dynamic-autharization-header/97097/19 "2025-07-16T13:55:32Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
