# Authorization for DQL

**URL:** <https://discuss.dgraph.io/t/authorization-for-dql/10181>\
**Category:** Dgraph\
**Tags:** kind:question\
**Created:** [September 10, 2020, 11:36am UTC](https://discuss.dgraph.io/t/authorization-for-dql/10181 "2020-09-10T11:36:04Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![pcjun97](https://avatars.discourse-cdn.com/v4/letter/p/94ad74/32.png) [@pcjun97](https://discuss.dgraph.io/u/pcjun97)\
**Post date:** [September 10, 2020, 11:36am UTC](https://discuss.dgraph.io/t/authorization-for-dql/10181/1 "2020-09-10T11:36:04Z")

</div>

In GraphQL, the JWT authorization is available to authorize query and mutation. Is there a similar auth feature in DQL? If our endpoint is exposed to the public web without ACL, does anyone who comes across the domain can actually query or mutate the data with DQL?

---

<div class="post-metadata">

**Author:** ![gja](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/gja/32/2654_2.png) [@gja](https://discuss.dgraph.io/u/gja)\
**Post date:** [September 10, 2020, 12:47pm UTC](https://discuss.dgraph.io/t/authorization-for-dql/10181/2 "2020-09-10T12:47:15Z")

</div>

Hi @pcjun97,

Yes, dgraph endpoints are accessible by default without ACL. If you would like to lock these down to require an API key

1. You could put a proxy in front of your dgraph instance and set up a proxy that prevents access without some header
2. You can use Slash GraphQL, which allows you to spin up a secured, hosted instance of Dgraph, and set up API keys for access

Tejas

---

<div class="post-metadata">

**Author:** ![gotjoshua](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/gotjoshua/32/4150_2.png) [@gotjoshua](https://discuss.dgraph.io/u/gotjoshua)\
**Post date:** [September 20, 2020, 5:31pm UTC](https://discuss.dgraph.io/t/authorization-for-dql/10181/3 "2020-09-20T17:31:44Z")

</div>

In case you want to disable the DQL query interface all together (to rely only on GraphQL @auth rules),  
you can do this with a rather simple traefik config in docker-compose:

```auto
      traefik.disabled.frontend.rule: Host:your.dgraph.url;PathStrip:/query
      traefik.disabled.port: 666 # a port destined for failure
      traefik.dghttp.frontend.rule: Host:your.dgraph.url 
      traefik.dghttp.port: 8080 # the internal port to be exposed on https://your.dgraph.url

```
