# What is needed just to require a login to access the dashboard/ui?

**URL:** <https://discourse.nodered.org/t/what-is-needed-just-to-require-a-login-to-access-the-dashboard-ui/87284>\
**Category:** General\
**Created:** [16 April 2024 20:40 UTC](https://discourse.nodered.org/t/what-is-needed-just-to-require-a-login-to-access-the-dashboard-ui/87284 "2024-04-16T20:40:11Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![rmystique](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/rmystique/32/84365_2.png) [@rmystique](https://discourse.nodered.org/u/rmystique)\
**Post date:** [16 April 2024 20:40 UTC](https://discourse.nodered.org/t/what-is-needed-just-to-require-a-login-to-access-the-dashboard-ui/87284/1 "2024-04-16T20:40:11Z")

</div>

Looking at the user guide its not too clear on what steps I need to take so when I access the ip I get asked for a login to be able to get into the interface? looks like editing the admin/auth in the settings file?

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [17 April 2024 13:36 UTC](https://discourse.nodered.org/t/what-is-needed-just-to-require-a-login-to-access-the-dashboard-ui/87284/2 "2024-04-17T13:36:22Z")

</div>

Does this help?  
[https://nodered.org/docs/user-guide/runtime/securing-node-red](https://nodered.org/docs/user-guide/runtime/securing-node-red)

---

<div class="post-metadata">

**Author:** ![rmystique](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/rmystique/32/84365_2.png) [@rmystique](https://discourse.nodered.org/u/rmystique)\
**Post date:** [17 April 2024 23:18 UTC](https://discourse.nodered.org/t/what-is-needed-just-to-require-a-login-to-access-the-dashboard-ui/87284/3 "2024-04-17T23:18:55Z")

</div>

That is what I was referring too, but not sure what parts I need and don't need to make it work for just a login?

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [18 April 2024 05:58 UTC](https://discourse.nodered.org/t/what-is-needed-just-to-require-a-login-to-access-the-dashboard-ui/87284/4 "2024-04-18T05:58:05Z")

</div>

Are you going to be logging in across the Internet or just in an internal network?

Is the login to stop those without authorization from accessing the system, or just for auditing?

---

<div class="post-metadata">

**Author:** ![kitori](https://avatars.discourse-cdn.com/v4/letter/k/f08c70/32.png) [@kitori](https://discourse.nodered.org/u/kitori)\
**Post date:** [18 April 2024 06:00 UTC](https://discourse.nodered.org/t/what-is-needed-just-to-require-a-login-to-access-the-dashboard-ui/87284/5 "2024-04-18T06:00:17Z")

</div>

You can set the http-node-security  
[https://nodered.org/docs/user-guide/runtime/securing-node-red#http-node-security](https://nodered.org/docs/user-guide/runtime/securing-node-red#http-node-security)

this line in the config:

```auto
httpNodeAuth: {user:"user",pass:"$2a$08$zZWtXTja0fB1pzD4sHCMyOCMYz2Z6dNbM6tl8sJogENOMcxWV9DN."},

```

create a hash with this command

```auto
node-red admin hash-pw

```

A more fancy auth you can achieve with a reverse proxy and [GitHub - authelia/authelia: The Single Sign-On Multi-Factor portal for web apps](https://github.com/authelia/authelia)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [17 July 2024 06:00 UTC](https://discourse.nodered.org/t/what-is-needed-just-to-require-a-login-to-access-the-dashboard-ui/87284/6 "2024-07-17T06:00:25Z")

</div>

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.
