# \#auth

**URL:** https://discuss.dgraph.io/tag/auth/47.md

[Latest](https://discuss.dgraph.io/latest.md) · [Categories](https://discuss.dgraph.io/categories.md) · [Tags](https://discuss.dgraph.io/tags.md)

---

## [Standard Authentication and Authorization in Dgraph Self-Managed Deployment](https://discuss.dgraph.io/t/standard-authentication-and-authorization-in-dgraph-self-managed-deployment/19634)

<div class="topic-metadata">

**Author:** [@Jeff\_Leon](https://discuss.dgraph.io/u/Jeff_Leon)\
**Replies:** 0\
**Last updated:** [December 3, 2024, 11:13am UTC](https://discuss.dgraph.io/t/standard-authentication-and-authorization-in-dgraph-self-managed-deployment/19634 "2024-12-03T11:13:15Z")

</div>

Hello, I am a new Dgraph user and joined the community about a month ago. What I want to do I want to add free secure authentication and authorization for my self-managed dgraph database deployed on a single-server Kub…

---

## [Next-Auth Dgraph DQL/GraphQL Database Adapter](https://discuss.dgraph.io/t/next-auth-dgraph-dql-graphql-database-adapter/14760)

<div class="topic-metadata">

**Author:** [@amaster507](https://discuss.dgraph.io/u/amaster507)\
**Replies:** 5\
**Last updated:** [June 26, 2024, 8:09am UTC](https://discuss.dgraph.io/t/next-auth-dgraph-dql-graphql-database-adapter/14760 "2024-06-26T08:09:57Z")

</div>

Has anyone created a Dgraph DQL/GraphQL database adapter for next-auth? Thinking this probably varies as schema is different, just beginning to learn next-auth, so feel free to chime in with any advice in this area.

---

## [Is it possible to have an "array division" in an @auth rule?](https://discuss.dgraph.io/t/is-it-possible-to-have-an-array-division-in-an-auth-rule/18437)

<div class="topic-metadata">

**Author:** [@Poolshark](https://discuss.dgraph.io/u/Poolshark)\
**Replies:** 7\
**Last updated:** [March 30, 2023, 8:15pm UTC](https://discuss.dgraph.io/t/is-it-possible-to-have-an-array-division-in-an-auth-rule/18437 "2023-03-30T20:15:34Z")

</div>

Consider an array in the user claim { ... arr: \["one", "two", "three"\], ... } and a schema type Check { id: ID! test: \[String!\]! } where Check.test can only contain elements from arr but any number and any …

---

## [Thoughts about Using GraphQL Shield in a layer above Dgraph instead of @auth](https://discuss.dgraph.io/t/thoughts-about-using-graphql-shield-in-a-layer-above-dgraph-instead-of-auth/17721)

<div class="topic-metadata">

**Author:** [@amaster507](https://discuss.dgraph.io/u/amaster507)\
**Replies:** 2\
**Last updated:** [September 3, 2022, 3:34am UTC](https://discuss.dgraph.io/t/thoughts-about-using-graphql-shield-in-a-layer-above-dgraph-instead-of-auth/17721 "2022-09-03T03:34:15Z")

</div>

Copying most of this from Discord Conversation with @MichelDiz Has anyone in this community tried to use GraphQL Shield along with Dgraph’s GraphQL? I was interested if anyone used it along with Dgraph’s GraphQL and A…

---

## [How to set up Dgraph with Auth0 and secure endpoints properly](https://discuss.dgraph.io/t/how-to-set-up-dgraph-with-auth0-and-secure-endpoints-properly/17108)

<div class="topic-metadata">

**Author:** [@Poolshark](https://discuss.dgraph.io/u/Poolshark)\
**Replies:** 1\
**Last updated:** [April 16, 2022, 4:58pm UTC](https://discuss.dgraph.io/t/how-to-set-up-dgraph-with-auth0-and-secure-endpoints-properly/17108 "2022-04-16T16:58:55Z")

</div>

Hey there! I’ve just started a series of articles on Medium which will show you how you can secure your Dgraph Endpoint with Auth0, by building an example application. This project came together since Dgraph does not o…

---

## [Queries with ADMIN Key should ignore @auth rules](https://discuss.dgraph.io/t/queries-with-admin-key-should-ignore-auth-rules/15938)

<div class="topic-metadata">

**Author:** [@Poolshark](https://discuss.dgraph.io/u/Poolshark)\
**Replies:** 1\
**Last updated:** [March 16, 2022, 7:53pm UTC](https://discuss.dgraph.io/t/queries-with-admin-key-should-ignore-auth-rules/15938 "2022-03-16T19:53:52Z")

</div>

Hi! I was recently experimenting with all sorts of @auth rules and came across a use-case, I am obviously not alone with - see here. Scenario In some occasions it might be useful to run queries (eg. from an external b…

---

## [Trying to set a simple authorization rule but \`filter\` can't handle it](https://discuss.dgraph.io/t/trying-to-set-a-simple-authorization-rule-but-filter-cant-handle-it/16797)

<div class="topic-metadata">

**Author:** [@corysimmons](https://discuss.dgraph.io/u/corysimmons)\
**Replies:** 2\
**Last updated:** [February 7, 2022, 8:36pm UTC](https://discuss.dgraph.io/t/trying-to-set-a-simple-authorization-rule-but-filter-cant-handle-it/16797 "2022-02-07T20:36:03Z")

</div>

I’m following the Instaclone tutorial here and got to this part: Modeling an Instagram Clone: Authentication - Dgraph Blog I’ve swapped out a couple names with Todo instead of Comment or something, and I’m just trying t…

---

## [Bug: Cannot limit number of results using auth directive to prevent malicious queries](https://discuss.dgraph.io/t/bug-cannot-limit-number-of-results-using-auth-directive-to-prevent-malicious-queries/14828)

<div class="topic-metadata">

**Author:** [@pshaddel](https://discuss.dgraph.io/u/pshaddel)\
**Replies:** 4\
**Last updated:** [January 25, 2022, 11:10pm UTC](https://discuss.dgraph.io/t/bug-cannot-limit-number-of-results-using-auth-directive-to-prevent-malicious-queries/14828 "2022-01-25T23:10:02Z")

</div>

We are trying to prevent users from requesting too many documents by setting a big number in first argument. What edition and version of Dgraph are you using? v21.03.1 Have you tried reproducing the issue with the late…

---

## [Auth Rule checks if value exists in array](https://discuss.dgraph.io/t/auth-rule-checks-if-value-exists-in-array/11356)

<div class="topic-metadata">

**Author:** [@tommo](https://discuss.dgraph.io/u/tommo)\
**Replies:** 4\
**Last updated:** [January 21, 2022, 10:06am UTC](https://discuss.dgraph.io/t/auth-rule-checks-if-value-exists-in-array/11356 "2022-01-21T10:06:30Z")

</div>

I’m trying to write something like this: type User @auth( delete: { rule: "{$ROLE: { eq: \\"ADMIN\\" } }"} ) { username: String! @id todos: \[Todo\] } Although I’m returning “roles” from Auth0 and my roles va…

---

## [HTTP response code](https://discuss.dgraph.io/t/http-response-code/16278)

<div class="topic-metadata">

**Author:** [@cueloop](https://discuss.dgraph.io/u/cueloop)\
**Replies:** 4\
**Last updated:** [December 10, 2021, 8:47am UTC](https://discuss.dgraph.io/t/http-response-code/16278 "2021-12-10T08:47:14Z")

</div>

Hi, I am trying to setup Apollo Client in a React web app with Cognito JWT Tokens using Amplify. So, I noticed I was getting 200 as response code on a GraphQL request with an expired token. Is that correct? This imple…

---

## [Is custom access control only possible in enterprise?](https://discuss.dgraph.io/t/is-custom-access-control-only-possible-in-enterprise/16243)

<div class="topic-metadata">

**Author:** [@gerarts](https://discuss.dgraph.io/u/gerarts)\
**Replies:** 3\
**Last updated:** [December 6, 2021, 9:54pm UTC](https://discuss.dgraph.io/t/is-custom-access-control-only-possible-in-enterprise/16243 "2021-12-06T21:54:06Z")

</div>

I’m trying to figure out what access control features are supported in the open-source version but a lot of the articles and support documents start by going through the Cloud / Slash setup procedure. Can anyone tell me…

---

## [Using @auth on individual fields?](https://discuss.dgraph.io/t/using-auth-on-individual-fields/7208)

<div class="topic-metadata">

**Author:** [@amaster507](https://discuss.dgraph.io/u/amaster507)\
**Replies:** 19\
**Last updated:** [December 2, 2021, 12:33pm UTC](https://discuss.dgraph.io/t/using-auth-on-individual-fields/7208 "2021-12-02T12:33:46Z")

</div>

Breaking this into it’s own topic, so here is the context: From reading over the docs on @auth directive I understand that these directives can restrict access to the nodes themselves by using JWT properties to chec…

---

## [Auth rules seem to fail when using multiple queries in and / or construct](https://discuss.dgraph.io/t/auth-rules-seem-to-fail-when-using-multiple-queries-in-and-or-construct/15787)

<div class="topic-metadata">

**Author:** [@Poolshark](https://discuss.dgraph.io/u/Poolshark)\
**Replies:** 1\
**Last updated:** [November 10, 2021, 8:55am UTC](https://discuss.dgraph.io/t/auth-rules-seem-to-fail-when-using-multiple-queries-in-and-or-construct/15787 "2021-11-10T08:55:55Z")

</div>

Hi! I have recently encountered a problem when playing around with Auth Rules for queries. I was strongly following Dgraph’s own tutorial but I could not reproduce their expected results. Consider the following schema: …

---

## [Cognito Authentication](https://discuss.dgraph.io/t/cognito-authentication/15867)

<div class="topic-metadata">

**Author:** [@zmajew](https://discuss.dgraph.io/u/zmajew)\
**Replies:** 3\
**Last updated:** [October 23, 2021, 10:37pm UTC](https://discuss.dgraph.io/t/cognito-authentication/15867 "2021-10-23T22:37:37Z")

</div>

Hi, I am trying to integrate AWS Cognito authentication in GraphQl schema. I have added this line to the bottom of my graphql schema # Dgraph.Authorization {"VerificationKey":"","Header":"Bearer", "jwkurl":"https://co…

---

## [Authentication for admin endpoints](https://discuss.dgraph.io/t/authentication-for-admin-endpoints/6786)

<div class="topic-metadata">

**Author:** [@abhimanyusinghgaur](https://discuss.dgraph.io/u/abhimanyusinghgaur)\
**Replies:** 10\
**Last updated:** [October 11, 2021, 4:40pm UTC](https://discuss.dgraph.io/t/authentication-for-admin-endpoints/6786 "2021-10-11T16:40:09Z")

</div>

Starting with this PR, all the admin endpoints now require three kinds of auth: IP White-listing, if --whitelist flag is passed to alpha. Poor-man’s auth, if --auth\_token flag is passed to alpha (means you will need t…

---

## [Auth rules for @lamdba queries/mutations](https://discuss.dgraph.io/t/auth-rules-for-lamdba-queries-mutations/15365)

<div class="topic-metadata">

**Author:** [@rcbevans](https://discuss.dgraph.io/u/rcbevans)\
**Replies:** 1\
**Last updated:** [September 29, 2021, 11:01am UTC](https://discuss.dgraph.io/t/auth-rules-for-lamdba-queries-mutations/15365 "2021-09-29T11:01:55Z")

</div>

Is it possible to define auth rules for a lambda query/mutation in the GraphQL schema being sent to Dgraph? Something like Query { myAdminOnlyQuery(...): \[MyResultType\] @auth(...) @lamdba } If it’s not possible to…

---

## [Allowing to choose AND or OR (or XOR) rule for @auth directives implemented from interface](https://discuss.dgraph.io/t/allowing-to-choose-and-or-or-or-xor-rule-for-auth-directives-implemented-from-interface/15673)

<div class="topic-metadata">

**Author:** [@kolmez](https://discuss.dgraph.io/u/kolmez)\
**Replies:** 0\
**Last updated:** [September 27, 2021, 8:07pm UTC](https://discuss.dgraph.io/t/allowing-to-choose-and-or-or-or-xor-rule-for-auth-directives-implemented-from-interface/15673 "2021-09-27T20:07:50Z")

</div>

Problem I have an interface IProtect which adds an array of Permission to implementing types. This way I’m able to write auth rules based on the permissions someone possesses or not. What I would have liked to do was s…

---

## [Authorization and lookup against a tree structure](https://discuss.dgraph.io/t/authorization-and-lookup-against-a-tree-structure/15292)

<div class="topic-metadata">

**Author:** [@dhartweg](https://discuss.dgraph.io/u/dhartweg)\
**Replies:** 9\
**Last updated:** [September 11, 2021, 2:26pm UTC](https://discuss.dgraph.io/t/authorization-and-lookup-against-a-tree-structure/15292 "2021-09-11T14:26:05Z")

</div>

Looking for some suggestions on how to handle authorization (and lookup) against branches of a tree. Let’s use this schema as an example: type Organization { id: ID! hasItems: \[Item!\] } type Item { id: ID! isPu…

---

## [Only allow calling generated mutations from lamdba](https://discuss.dgraph.io/t/only-allow-calling-generated-mutations-from-lamdba/15364)

<div class="topic-metadata">

**Author:** [@rcbevans](https://discuss.dgraph.io/u/rcbevans)\
**Replies:** 0\
**Last updated:** [August 24, 2021, 6:02am UTC](https://discuss.dgraph.io/t/only-allow-calling-generated-mutations-from-lamdba/15364 "2021-08-24T06:02:16Z")

</div>

Since Dgraph doesn’t currently support system generated fields such as @createdTime, @updatedTime for mutations, and due to the update-after-auth issue, I’m likely to need to implement all mutations as lambdas and preven…

---

## [Auth rules for arrays](https://discuss.dgraph.io/t/auth-rules-for-arrays/15242)

<div class="topic-metadata">

**Author:** [@Poolshark](https://discuss.dgraph.io/u/Poolshark)\
**Replies:** 4\
**Last updated:** [August 15, 2021, 12:19pm UTC](https://discuss.dgraph.io/t/auth-rules-for-arrays/15242 "2021-08-15T12:19:42Z")

</div>

Hello, I have another question regarding auth rules in Dgraph. I have understood the concept of role based authentication via JWT claims. So a typical rule for a variable role in the JWT would be: type User auth( que…

---

## [GraphQL auth claim with punctuation](https://discuss.dgraph.io/t/graphql-auth-claim-with-punctuation/15295)

<div class="topic-metadata">

**Author:** [@rcbevans](https://discuss.dgraph.io/u/rcbevans)\
**Replies:** 0\
**Last updated:** [August 14, 2021, 10:57pm UTC](https://discuss.dgraph.io/t/graphql-auth-claim-with-punctuation/15295 "2021-08-14T22:57:20Z")

</div>

Is it possible to use a JWT claim containing punctuation (specifically a colon :) in an auth rule, for example, claims from Cognito such as "cognito:groups", "cognito:roles", and "cognito:username"? In the documentation…

---

## [Auth variables access on custom resolver](https://discuss.dgraph.io/t/auth-variables-access-on-custom-resolver/13893)

<div class="topic-metadata">

**Author:** [@Thammada](https://discuss.dgraph.io/u/Thammada)\
**Replies:** 2\
**Last updated:** [July 31, 2021, 6:23am UTC](https://discuss.dgraph.io/t/auth-variables-access-on-custom-resolver/13893 "2021-07-31T06:23:51Z")

</div>

I would a custom field to have access to auth variables, such that we don’t need to check for authorization at the front-end layer. For the following schema type User { id: ID! displayName: String! post: \[Post\] @…

---

## [@auth directives don't apply to nested objects when using interfaces?](https://discuss.dgraph.io/t/auth-directives-dont-apply-to-nested-objects-when-using-interfaces/14157)

<div class="topic-metadata">

**Author:** [@elhil](https://discuss.dgraph.io/u/elhil)\
**Replies:** 10\
**Last updated:** [June 8, 2021, 5:28pm UTC](https://discuss.dgraph.io/t/auth-directives-dont-apply-to-nested-objects-when-using-interfaces/14157 "2021-06-08T17:28:07Z")

</div>

Say I have a schema something like this: type Approval { id: ID! approvedAt: DateTime! } type Author @auth( query: { rule: """ query { queryAuthor(filter: { has: approval }) { id } …

---

## [Optional JWT Authorisation](https://discuss.dgraph.io/t/optional-jwt-authorisation/14248)

<div class="topic-metadata">

**Author:** [@bendechrai](https://discuss.dgraph.io/u/bendechrai)\
**Replies:** 2\
**Last updated:** [May 20, 2021, 6:49pm UTC](https://discuss.dgraph.io/t/optional-jwt-authorisation/14248 "2021-05-20T18:49:06Z")

</div>

Hey folks! I have schema that includes Users and Groups. The relevant parts are: type User { id: ID! sub: String! @id displayName: String! } type Group @auth( query: { or: \[ { rule:…

---

## [Securing Dgraph Cloud with GCP API Gateway](https://discuss.dgraph.io/t/securing-dgraph-cloud-with-gcp-api-gateway/13547)

<div class="topic-metadata">

**Author:** [@Jon\_Flynn](https://discuss.dgraph.io/u/Jon_Flynn)\
**Replies:** 2\
**Last updated:** [May 2, 2021, 7:10pm UTC](https://discuss.dgraph.io/t/securing-dgraph-cloud-with-gcp-api-gateway/13547 "2021-05-02T19:10:29Z")

</div>

I’m using Slash Dgraph cloud, with all my other services running on Cloud Functions or App Engine. I have GCP API Gateway securing all these services by generating the JWT using their code here: Using JWT to authenticate…

---

## [@auth directive on $ROLE array for Auth0 compatibility](https://discuss.dgraph.io/t/auth-directive-on-role-array-for-auth0-compatibility/14071)

<div class="topic-metadata">

**Author:** [@ctjlewis](https://discuss.dgraph.io/u/ctjlewis)\
**Replies:** 18\
**Last updated:** [May 9, 2021, 4:23am UTC](https://discuss.dgraph.io/t/auth-directive-on-role-array-for-auth0-compatibility/14071 "2021-05-09T04:23:35Z")

</div>

\[v21.03\] Consider Auth0 JWT structure where ROLE claim is an array: { "https://dgraph.io/jwt/claims": { "USER": "ctjlewis", "ROLE": \[ "Admin", ... \] }, ... } I have tried the following for…

---

## [How to write @auth incase of user role claim in JWT has a array format](https://discuss.dgraph.io/t/how-to-write-auth-incase-of-user-role-claim-in-jwt-has-a-array-format/10104)

<div class="topic-metadata">

**Author:** [@sarankrishna](https://discuss.dgraph.io/u/sarankrishna)\
**Replies:** 12\
**Last updated:** [May 9, 2021, 2:56am UTC](https://discuss.dgraph.io/t/how-to-write-auth-incase-of-user-role-claim-in-jwt-has-a-array-format/10104 "2021-05-09T02:56:18Z")

</div>

Hi there, I have the following schema in dgraph type Todo { id: ID! text: String! @search(by: \[term\]) owner: String! } I wanted to implement Role-Based Access control (RBAC) using the JWT token. My sample…

---

## [Role based access control rules are not working in DGraph Cloud](https://discuss.dgraph.io/t/role-based-access-control-rules-are-not-working-in-dgraph-cloud/14025)

<div class="topic-metadata">

**Author:** [@The\_In](https://discuss.dgraph.io/u/The_In)\
**Replies:** 5\
**Last updated:** [May 5, 2021, 5:46pm UTC](https://discuss.dgraph.io/t/role-based-access-control-rules-are-not-working-in-dgraph-cloud/14025 "2021-05-05T17:46:08Z")

</div>

Hello, I’ve been setting up security for my database this week with the @auth directive and I’m noticing some rules are not being evaluated correctly in DGraph Cloud. Namely, the ones in the last section of auth docs. A…

---

## [Using Auth rules in Dgraph Cloud / Slash GraphQL when running the Firebase Emulator](https://discuss.dgraph.io/t/using-auth-rules-in-dgraph-cloud-slash-graphql-when-running-the-firebase-emulator/13970)

<div class="topic-metadata">

**Author:** [@charklewis](https://discuss.dgraph.io/u/charklewis)\
**Replies:** 1\
**Last updated:** [May 2, 2021, 3:00am UTC](https://discuss.dgraph.io/t/using-auth-rules-in-dgraph-cloud-slash-graphql-when-running-the-firebase-emulator/13970 "2021-05-02T03:00:15Z")

</div>

I am currently using parts of the Firebase emulator including its Authentication feature. I have Firebase + Dgraph Cloud authentication working, however it fails when I switch to using the local emulator. To get around t…

---

## [Moving GraphQL Authorization to admin API](https://discuss.dgraph.io/t/moving-graphql-authorization-to-admin-api/13304)

<div class="topic-metadata">

**Author:** [@verneleem](https://discuss.dgraph.io/u/verneleem)\
**Replies:** 4\
**Last updated:** [April 30, 2021, 3:34am UTC](https://discuss.dgraph.io/t/moving-graphql-authorization-to-admin-api/13304 "2021-04-30T03:34:12Z")

</div>

Experience Report for Feature Request Note: Feature requests are judged based on user experience and modeled on Go Experience Reports. These reports should focus on the problems: they should not focus on and need not pro…

[Next page](https://discuss.dgraph.io/tag/auth/47.md?match_all_tags=true&page=1&tags%5B%5D=auth)
