How to secure a Node-Red based API/microservice using Keycloak

Viewed 278

I'm creating a small IoT oriented REST API based on Node-Red, and i'm wondering how to protect this API, from unauthorized/unauthenticated access.

Browsing around the internet I came across Keycloak, that seemed to me to be a very complete and easy to use solution. so my question is How to secure a Node-Red based API/microservice using Keycloak and tokens, and is it feasible at all.

1 Answers

You can get tokens directly from Keycloak via OAuth2 flow.

Then when you call to node-red you must pass the token to Header for API call From the Node-Red flow, you add a function to verify the token: If correct then pass the other func (to call real API) from your backend side.

If failure: response 401

Related