Skip to content

Why can unsecured API calls be made? #1881

Answered by aeneasr
focus38 asked this question in Q&A
Discussion options

You must be logged in to vote

Ory Kratos does not tell you how to protect the Admin API endpoint. You can do that any way you like - using proxies such as Ory Oathkeeper, Nginx, Kong, ...

It's up to you how you want to secure the Admin API. You can of course also chose not to expose the Admin API to the public internet, in which case, it might be easier to secure depending on your security context.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by focus38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants