# Allow only specific consumers on a route

**URL:** <https://discuss.konghq.com/t/allow-only-specific-consumers-on-a-route/6463>\
**Category:** Questions\
**Created:** [June 9, 2020, 2:14pm UTC](https://discuss.konghq.com/t/allow-only-specific-consumers-on-a-route/6463 "2020-06-09T14:14:07Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![alesanchez](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/alesanchez/32/2001_2.png) [@alesanchez](https://discuss.konghq.com/u/alesanchez)\
**Post date:** [June 9, 2020, 2:14pm UTC](https://discuss.konghq.com/t/allow-only-specific-consumers-on-a-route/6463/1 "2020-06-09T14:14:07Z")

</div>

Hello everyone!

Let me explain our scenario:

We have an endpoint called, for example, `/superSecure`.  
We want that endpoint to have basic authentication but ONLY for certain consumers.  
Every consumer not selected to go to the basic authentication step should be automatically blocked.

We tried to accomplish that with the basic-auth plugin but we weren’t able to do the last part of targeting only specific consumers. We always get the same error when we try to set something in the “comsumer” field:

“schema violation (consumer: value must be null)”

Just for the records, we are using Konga for managing kong but with cURL we are also receiving the same error. And our Kong is on kubernetes.

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![salazar](https://avatars.discourse-cdn.com/v4/letter/s/bbce88/32.png) [@salazar](https://discuss.konghq.com/u/salazar)\
**Post date:** [June 9, 2020, 7:48pm UTC](https://discuss.konghq.com/t/allow-only-specific-consumers-on-a-route/6463/2 "2020-06-09T19:48:29Z")

</div>

Hey @alesanchez, welcome to Kong Nation!

Authentication plugins cannot be applied on consumers - note they have a `no_consumer` attribute.

From what I understood about the use case, the following will accomplish it - applying the auth plugin on the route or the service (given you want all consumers without a credential to be blocked):

- Create a route/service:

```bash
curl localhost:8001/services --data name=s1 --data url=https://httpbin.org
curl localhost:8001/routes --data name=r1 --data service.id=95f9114f-e957-470f-96e3-2fde45a04941 --data paths=/

```

- Enable the basic-auth plugin on the route (or the service, if you want the plugin to be applied to all requests targeting that service):

```bash
curl localhost:8001/routes/r1/plugins --data name=basic-auth

```

- Create a Consumer:

```bash
curl localhost:8001/consumers --data username=c1

```

- Create a basic-auth credential for that consumer:

```bash
curl localhost:8001/consumers/c1/basic-auth --data username=u1 --data password=pass

```

Having done this, all requests without the credential will be blocked:

```bash
$ curl -I localhost:8000/status/200
HTTP/1.1 401 Unauthorized
Date: Tue, 09 Jun 2020 19:37:47 GMT
Content-Type: application/json; charset=utf-8
Connection: keep-alive
WWW-Authenticate: Basic realm="kong"
Content-Length: 30
X-Kong-Response-Latency: 4
Server: kong/2.0.4

```

Now, if you add the `Authorization` header, as expected, the request will be authorized:

```bash
$ curl -I localhost:8000/status/200 -H "Authorization: Basic dTE6cGFzcw=="
HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
Content-Length: 0
Connection: keep-alive
Date: Tue, 09 Jun 2020 19:39:19 GMT
Server: gunicorn/19.9.0
Access-Control-Allow-Origin: *
Access-Control-Allow-Credentials: true
X-Kong-Upstream-Latency: 601
X-Kong-Proxy-Latency: 33
Via: kong/2.0.4

```

Let me know if that helps!

---

<div class="post-metadata">

**Author:** ![alesanchez](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/alesanchez/32/2001_2.png) [@alesanchez](https://discuss.konghq.com/u/alesanchez)\
**Post date:** [June 11, 2020, 7:35am UTC](https://discuss.konghq.com/t/allow-only-specific-consumers-on-a-route/6463/3 "2020-06-11T07:35:58Z")

</div>

Thank you very much for your answer!! Ok, it makes sense. But one last question. That means that every user with basic auth credentials is going to be able to log in with those credentials to any route protected by the basic auth plugin, am I right?

---

<div class="post-metadata">

**Author:** ![salazar](https://avatars.discourse-cdn.com/v4/letter/s/bbce88/32.png) [@salazar](https://discuss.konghq.com/u/salazar)\
**Post date:** [June 13, 2020, 10:06pm UTC](https://discuss.konghq.com/t/allow-only-specific-consumers-on-a-route/6463/4 "2020-06-13T22:06:10Z")

</div>

That is correct, @alesanchez. This might also be useful to you: [https://docs.konghq.com/2.0.x/auth/#anonymous-access](https://docs.konghq.com/2.0.x/auth/#anonymous-access) - if you haven’t already read. Happy Konging! 🦍
