# Securing custom rest endpoint

**URL:** <https://forum.keycloak.org/t/securing-custom-rest-endpoint/3652>\
**Category:** Getting advice\
**Created:** [July 6, 2020, 2:27pm UTC](https://forum.keycloak.org/t/securing-custom-rest-endpoint/3652 "2020-07-06T14:27:26Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![palani](https://avatars.discourse-cdn.com/v4/letter/p/ed655f/32.png) [@palani](https://forum.keycloak.org/u/palani)\
**Post date:** [July 6, 2020, 2:27pm UTC](https://forum.keycloak.org/t/securing-custom-rest-endpoint/3652/1 "2020-07-06T14:27:26Z")

</div>

I have added custom rest endpoint to keycloak by implementing provider,  
[https://www.keycloak.org/docs/latest/server\_development/#\_extensions\_rest](https://www.keycloak.org/docs/latest/server_development/#_extensions_rest)

now, the endpoint is open and not secured which anyone access.  
Whats the way the rest endpoint can be secured like with only admin credentials.

---

<div class="post-metadata">

**Author:** ![zonaut](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/zonaut/32/666_2.png) [@zonaut](https://forum.keycloak.org/u/zonaut)\
**Post date:** [July 6, 2020, 2:52pm UTC](https://forum.keycloak.org/t/securing-custom-rest-endpoint/3652/2 "2020-07-06T14:52:54Z")

</div>

Hi,

under the spi-resource example on my [https://github.com/zonaut/keycloak-extensions](https://github.com/zonaut/keycloak-extensions) repo you can find a couple of ways to do this. Hope this helps you further.
