Docs

Parameters

See plugin common configurations (opens in Apache APISIX docs) for configuration options available to all plugins.

Credentials

The following are plugin attributes available for configurations on credentials (opens in Apache APISIX docs).

  • username

    string

    required


    Unique basic auth username for a consumer.

  • password

    string

    required


    Basic auth password for the consumer.

    In API7 Enterprise 3.9.20 and 3.10.7, and in APISIX 3.19.0, configuration validation rejects empty passwords, and passwords containing colons are accepted. Following RFC 7617, everything after the first colon of the decoded credentials is taken as the password. Whitespace is still stripped from both halves of the decoded credentials before they are compared, so a password containing spaces cannot be used.

    The password is encrypted with AES before being stored in etcd. You can also store it in an environment variable and reference it using the $env:// prefix, or in a secret manager such as HashiCorp Vault's KV secrets engine, and reference it using the $secret:// prefix. For more information, see secrets (opens in Apache APISIX docs).

    A $env:// or $secret:// reference that resolves to an empty value still passes configuration validation, because references are resolved at request time. In API7 Enterprise 3.9.20 and 3.10.7, and in APISIX 3.19.0, Basic Auth cannot authenticate that consumer. The request returns HTTP 401 unless an anonymous consumer or another method configured through multi-auth allows it.

Routes or Services

The following are plugin attributes available for configurations on routes (opens in Apache APISIX docs) or services (opens in Apache APISIX docs).

  • hide_credentials

    boolean

    default: false


    If true, do not pass the authorization request header to upstream services.

  • anonymous_consumer

    string


    Anonymous consumer name. If configured, allow anonymous users to bypass the authentication. See Rate Limit with Anonymous Consumer for more details.

  • realm

    string

    default: basic


    Realm in the WWW-Authenticate response header returned with a 401 Unauthorized response due to authentication failure. For example:

    • If realm is set to basic-auth, the 401 response will include the following header:

      WWW-Authenticate: Basic realm="basic-auth"
    • If realm is not configured, the 401 response will include the following header:

      WWW-Authenticate: Basic realm="basic"

    This parameter is available in API7 Enterprise version 3.9.2 and later, and in Apache APISIX version 3.15.0 and later.