# Request to authentication server (not a plugin) before send to upstream

**URL:** <https://discuss.konghq.com/t/request-to-authentication-server-not-a-plugin-before-send-to-upstream/953>\
**Category:** General\
**Tags:** kong-gateway\
**Created:** [May 9, 2018, 1:29am UTC](https://discuss.konghq.com/t/request-to-authentication-server-not-a-plugin-before-send-to-upstream/953 "2018-05-09T01:29:25Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![keepinco](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/keepinco/32/323_2.png) [@keepinco](https://discuss.konghq.com/u/keepinco)\
**Post date:** [May 9, 2018, 1:29am UTC](https://discuss.konghq.com/t/request-to-authentication-server-not-a-plugin-before-send-to-upstream/953/1 "2018-05-09T01:29:25Z")

</div>

I want to use my own authentication server. Not a kong plugin.  
Can I send request for checking authentication to authentication server, before kong send request to upstream uri?

I found [GitHub - pantsel/kong-middleman-plugin: A Kong plugin that enables you to make an extra HTTP POST request before calling an API.](https://github.com/pantsel/kong-middleman-plugin), but it seems to have a performance issue.  
[Do not use LuaSocket · Issue #7 · pantsel/kong-middleman-plugin · GitHub](https://github.com/pantsel/kong-middleman-plugin/issues/7)

---

<div class="post-metadata">

**Author:** ![jeremyjpj0916](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/jeremyjpj0916/32/1388_2.png) [@jeremyjpj0916](https://discuss.konghq.com/u/jeremyjpj0916)\
**Post date:** [May 10, 2018, 5:30am UTC](https://discuss.konghq.com/t/request-to-authentication-server-not-a-plugin-before-send-to-upstream/953/2 "2018-05-10T05:30:37Z")

</div>

OpenID Connect/External Oauth2 token issuers?:

```auto
https://github.com/nokia/kong-oidc
https://github.com/mogui/kong-external-oauth

```

If you are an enterprise subscriber they have an official ballin plugin too -  
[https://getkong.org/plugins/ee-oauth2-introspection/](https://getkong.org/plugins/ee-oauth2-introspection/)

I will also be releasing one too so stay tuned 🙂 .

---

<div class="post-metadata">

**Author:** ![keepinco](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/keepinco/32/323_2.png) [@keepinco](https://discuss.konghq.com/u/keepinco)\
**Post date:** [May 11, 2018, 5:20pm UTC](https://discuss.konghq.com/t/request-to-authentication-server-not-a-plugin-before-send-to-upstream/953/3 "2018-05-11T17:20:49Z")

</div>

Thanks 🙂

---

<div class="post-metadata">

**Author:** ![rajdevdurg](https://avatars.discourse-cdn.com/v4/letter/r/67e7ee/32.png) [@rajdevdurg](https://discuss.konghq.com/u/rajdevdurg)\
**Post date:** [May 14, 2018, 8:52am UTC](https://discuss.konghq.com/t/request-to-authentication-server-not-a-plugin-before-send-to-upstream/953/4 "2018-05-14T08:52:57Z")

</div>

Hi,

We also had the same requirement, we have handled this using the Custom Plug-in. we have invoked the Authorization server using Lua language. Once the token is validated then only the call will reach to Upstream url.Let me know if you need more details

Thanks  
Raj

---

<div class="post-metadata">

**Author:** ![alya](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/alya/32/967_2.png) [@alya](https://discuss.konghq.com/u/alya)\
**Post date:** [April 29, 2019, 7:01pm UTC](https://discuss.konghq.com/t/request-to-authentication-server-not-a-plugin-before-send-to-upstream/953/5 "2019-04-29T19:01:53Z")

</div>

@rajdevdurg Can you please help with the below implementation in Kong

I am trying to implement Kong API Gateway with client\_credentails flow. I have a custom auth service that takes care of authentication of clients.

When the client tries to authenticate by presenting the client Id and secret(Basic Auth) in the auth request, I want to route the request to custom authentication service. We have the client information saved in our database and is segregated to different realms(user groups). Implemented an auth-service that validates the client credentials based on the realm and generates a JWT response. JWT has sensitive information so cannot be shared with the client. This auth-service has multiple versions, so we need to route the request to different auth-service endpoints based on the realm(sent in the query parameter) and a custom header.

Once the auth-service returns a JWT response, Kong should be able to generate an oauth token and save the associated JWT in cache. This OAuth token will be shared with the client. When client presents this token in the Authorization header, API Gateway should be able to validate the token and get the JWT that was saved before and inject into to the backend request.

Does Kong support any plugin for this set up? Can you please share the related github links for custom plugins.

---

<div class="post-metadata">

**Author:** ![Ragunath\_Sudalaimuth](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/ragunath_sudalaimuth/32/2667_2.png) [@Ragunath\_Sudalaimuth](https://discuss.konghq.com/u/Ragunath_Sudalaimuth)\
**Post date:** [May 3, 2021, 5:44pm UTC](https://discuss.konghq.com/t/request-to-authentication-server-not-a-plugin-before-send-to-upstream/953/6 "2021-05-03T17:44:33Z")

</div>

Can you please help us with the same requirement.

We need to call backend OAUth endpoint. Get the token cache it and then call the Actual backend API endpoint in Kong.

We use Kong for Kubernetes setup with DB mode.
