# Set all queries to private with @auth

**URL:** <https://discuss.dgraph.io/t/set-all-queries-to-private-with-auth/10358>\
**Category:** GraphQL\
**Tags:** kind:question, status:accepted, ticket:created\
**Created:** [September 14, 2020, 10:21pm UTC](https://discuss.dgraph.io/t/set-all-queries-to-private-with-auth/10358 "2020-09-14T22:21:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![MrHephaestus](https://avatars.discourse-cdn.com/v4/letter/m/b9e5f3/32.png) [@MrHephaestus](https://discuss.dgraph.io/u/MrHephaestus)\
**Post date:** [September 14, 2020, 10:21pm UTC](https://discuss.dgraph.io/t/set-all-queries-to-private-with-auth/10358/1 "2020-09-14T22:21:02Z")

</div>

How would I go about preventing my API from being query-able unless provided a valid token.

---

<div class="post-metadata">

**Author:** ![amaster507](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/amaster507/32/4123_2.png) [@amaster507](https://discuss.dgraph.io/u/amaster507)\
**Post date:** [September 14, 2020, 10:42pm UTC](https://discuss.dgraph.io/t/set-all-queries-to-private-with-auth/10358/2 "2020-09-14T22:42:28Z")

</div>

It is a pending feature request:

> [@Root @auth directives](http://discuss.hypermode.com/t/root-auth-directives/7532/2):
>
> Yeah, this is a really nice idea. There’s a couple of other ‘global’ things that we have thought about throwing in - e.g. having a switch for ‘all queries/mutations are public unless I state otherwise in the rules’ vs ‘all queries/mutations require an authenticated JWT unless I explicitly open one up in a rule’.
> 
> @arijit can you make sure this discussion gets noted on the list of community features to pick up.

@arijit any update on these discussions?

---

<div class="post-metadata">

**Author:** ![michaelcompton](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/michaelcompton/32/1774_2.png) [@michaelcompton](https://discuss.dgraph.io/u/michaelcompton)\
**Post date:** [September 16, 2020, 4:23am UTC](https://discuss.dgraph.io/t/set-all-queries-to-private-with-auth/10358/3 "2020-09-16T04:23:12Z")

</div>

@pawan do we have enough eng resources to add some global auth switches in before 20.11.0 ? We could add a switch into the Dgraph.Authorization key that changes the behaviour of un-decorated types to be requires a JWT.

It’s possible to get the same behaviour by adding a rule like `{ rule: "{$isAuthenticated: {eq: \"True\"}}" }` and arranging all JWTs to have that claim. But that then needs to be added for every type.

Feels like there is two valid approaches here - open by default, and closed by default.

---

<div class="post-metadata">

**Author:** ![pawan](https://yyz1.discourse-cdn.com/flex007/user_avatar/discuss.dgraph.io/pawan/32/1946_2.png) [@pawan](https://discuss.dgraph.io/u/pawan)\
**Post date:** [September 29, 2020, 8:07am UTC](https://discuss.dgraph.io/t/set-all-queries-to-private-with-auth/10358/4 "2020-09-29T08:07:23Z")

</div>

> [@michaelcompton](#):
>
> We could add a switch into the Dgraph.Authorization key that changes the behaviour of un-decorated types to require a JWT.

Yeah, that sounds like a valid one. So we could check that the JWT is valid and only then allow you to perform actions. If there were auth rules then they would be applied on top of this. Marking it as accepted and will tackle it in the upcoming sprints.
