如何在Hasura中配置无需认证的公开REST端点?
Got it, let's walk through how to make your Hasura REST endpoint for the restaurants table publicly accessible without authentication. You've already done the first part (creating a role with unrestricted select permissions), so let's cover the missing pieces:
Option 1: Specify the Role via Request Header
Even without an auth token, Hasura lets you explicitly set the role for a REST request using the X-Hasura-Role header. Here's how to use it with a tool like curl:
curl -H "X-Hasura-Role: public" http://localhost:8080/api/rest/restaurants/1
Replace public with the name of the role you created that has unrestricted select access to the restaurants table. This tells Hasura to apply the permissions tied to that role for the request—no authentication required.
Option 2: Set a Default Unauthenticated Role (No Header Needed)
If you want all unauthenticated REST requests to automatically use your public role (so you don't have to add the header every time), configure this in the Hasura Console:
- Go to Settings from the top navigation bar.
- Navigate to the Metadata tab, then select REST API from the left sidebar.
- Look for the Default Role for Unauthenticated Requests setting.
- Select the public role you created (e.g.,
public) from the dropdown and save the changes.
From now on, any unauthenticated request to your REST endpoint will automatically use this role, so you can call it directly without any headers:
curl http://localhost:8080/api/rest/restaurants/1
Important Notes
- Double-check your public role's permissions: Make sure the select permission for the
restaurantstable has no row/column restrictions (leave the condition blank, and check all necessary columns). If there are any filters, Hasura will enforce them even for unauthenticated requests. - For production environments: Be cautious with unrestricted public access. Only expose the columns you absolutely need, and avoid granting write permissions (insert/update/delete) to public roles unless you have specific safeguards in place.
内容的提问来源于stack exchange,提问作者Siraj Kakeh

