# Add proxy\_set\_header Authorization in Traefik

**URL:** <https://community.traefik.io/t/add-proxy-set-header-authorization-in-traefik/12201>\
**Category:** Traefik v2\
**Tags:** middleware\
**Created:** [October 21, 2021, 9:04pm UTC](https://community.traefik.io/t/add-proxy-set-header-authorization-in-traefik/12201 "2021-10-21T21:04:23Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![JamesAdams](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/jamesadams/32/2774_2.png) [@JamesAdams](https://community.traefik.io/u/JamesAdams)\
**Post date:** [October 21, 2021, 9:04pm UTC](https://community.traefik.io/t/add-proxy-set-header-authorization-in-traefik/12201/1 "2021-10-21T21:04:23Z")

</div>

Hi,

in Ningx i use `proxy_set_header Authorization "Basic hash...";`  
for automatically connect to a service and I would like to know how to do it with Traefik because I cannot find it and I find that the documentation is not very clear on this subject.

Thanks

---

<div class="post-metadata">

**Author:** ![cakiwi](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/cakiwi/32/3205_2.png) [@cakiwi](https://community.traefik.io/u/cakiwi)\
**Post date:** [October 21, 2021, 9:50pm UTC](https://community.traefik.io/t/add-proxy-set-header-authorization-in-traefik/12201/2 "2021-10-21T21:50:54Z")

</div>

Checkout the headers middlewares.

[https://doc.traefik.io/traefik/middlewares/http/headers/#adding-and-removing-headers](https://doc.traefik.io/traefik/middlewares/http/headers/#adding-and-removing-headers)

---

<div class="post-metadata">

**Author:** ![JamesAdams](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/jamesadams/32/2774_2.png) [@JamesAdams](https://community.traefik.io/u/JamesAdams)\
**Post date:** [October 22, 2021, 6:00pm UTC](https://community.traefik.io/t/add-proxy-set-header-authorization-in-traefik/12201/3 "2021-10-22T18:00:20Z")

</div>

I have already try with that : `traefik.http.middlewares.testHeader.headers.customrequestheaders.authorization=NhZGdsfDFSGSDF"`

but doesn't work ☹

---

<div class="post-metadata">

**Author:** ![kevdog](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/kevdog/32/2825_2.png) [@kevdog](https://community.traefik.io/u/kevdog)\
**Post date:** [October 22, 2021, 8:58pm UTC](https://community.traefik.io/t/add-proxy-set-header-authorization-in-traefik/12201/4 "2021-10-22T20:58:19Z")

</div>

Take a look at this plugin:[GitHub - adyanth/header-transform: Traefik plugin on header transformations](https://github.com/adyanth/header-transform)

It's kind of unclear how to use the plugin however if you take a look at these two sources it might help:

> <https://github.com/adyanth/header-transform/issues/3>
>
> It might help to add a non-dev configuration to the docs/README?
> 
> I know it's …still pretty experimental, but Traefik v2.5 supports local plugins now (it's really hard to find documentation on it though):
> 
> \* https://github.com/traefik/traefik/pull/8224
> \* https://traefik.io/blog/using-private-plugins-in-traefik-proxy-2-5/
> 
> You can then mount this into the Traefik container with \`docker-compose\` like so:
> 
> (static configuration)
> \`\`\`yaml
> command:
> # This will be search for in /plugins-local/src/github.com/adyanth/header-transform
> - "--experimental.localPlugins.header-transform.moduleName=github.com/adyanth/header-transform"
> - "--providers.file.filename=/htransform-rules.yaml" 
> \`\`\`
> 
> \\+
> 
> \`\`\`yaml
> http:
> middlewares:
> header-transform:
> plugin:
> # Plugin name here is the part after \`experimental.localPlugins\`
> header-transform:
> Rules:
> - Rule:
> Name: 'X-Client-Port Set'
> Header: 'X-Client-Port'
> Value: '^X-Forwarded-Port'
> HeaderPrefix: "^"
> Type: 'Set'
> - Rule:
> Name: 'X-SSL-Cert Set'
> Header: 'X-SSL-Cert'
> Value: '^X-Forwarded-Tls-Client-Cert'
> HeaderPrefix: "^"
> Type: 'Set'
> \`\`\`
> 
> and
> 
> \`\`\`yaml
> volumes:
> - "./traefik/htransform-rules.yaml:/htransform-rules.yaml"
> - "./traefik/header-transform:/plugins-local/src/github.com/adyanth/header-transform"
> \`\`\`
> 
> Then you can simply add it to the middleware list for any http router as \`header-transform@file\`

and here is an example from another project that uses this plugin to change some things:

> <https://github.com/syncthing/docs/pull/684>
>
> Traefik's setup was convoluted, especially for rewriting headers to get \`X-Clien…t-Port\`. That's why I broke it up in the docs by header

and

> <https://github.com/syncthing/docs/pull/684/commits/1c455ae42b0d64c8c3850e81c445f6f27b9dcac1>
>
> Traefik's setup was convoluted, especially for rewriting headers to get \`X-Clien…t-Port\`. That's why I broke it up in the docs by header

Hopefully those links will get you started. You can write/set/change headers.

---

<div class="post-metadata">

**Author:** ![JamesAdams](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/jamesadams/32/2774_2.png) [@JamesAdams](https://community.traefik.io/u/JamesAdams)\
**Post date:** [October 23, 2021, 8:43am UTC](https://community.traefik.io/t/add-proxy-set-header-authorization-in-traefik/12201/5 "2021-10-23T08:43:11Z")

</div>

Thanks for the plugin but the documentation ... so impossible to make it work

---

<div class="post-metadata">

**Author:** ![kevinpollet](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/kevinpollet/32/1755_2.png) [@kevinpollet](https://community.traefik.io/u/kevinpollet)\
**Post date:** [October 29, 2021, 9:00am UTC](https://community.traefik.io/t/add-proxy-set-header-authorization-in-traefik/12201/6 "2021-10-29T09:00:55Z")

</div>

Hello @JamesAdams and thanks for your interest in Traefik!

@cakiwi is right using the [Headers middleware](https://doc.traefik.io/traefik/middlewares/http/headers/#adding-and-removing-headers) should work. Maybe this is not working because you missed adding the authorization scheme to the header (see [Authorization - HTTP | MDN](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Authorization#syntax)).

The middleware configuration should look like the following:

`"traefik.http.middlewares.testHeader.headers.customrequestheaders.authorization=Basic NhZGdsfDFSGSDF"`

Here is a working docker-compose example. Traefik adds the `Authorization` header to the request forwarded to the `whoami` backend (which only echo the received HTTP headers).

```yaml
version: "3.9"
services:
  traefik:
    image: traefik:v2.5
    command:
      - --api.insecure
      - --log.level=debug
      - --providers.docker.exposedByDefault=false

    volumes:
      - /var/run/docker.sock:/var/run/docker.sock:ro

    ports:
      - "8080:8080"
      - "80:80"

  whoami:
    image: traefik/whoami
    labels:
      - traefik.enable=true
      - traefik.http.routers.whoami.entrypoints=http
      - traefik.http.routers.whoami.rule=Host(`whoami.localhost`)
      - traefik.http.routers.whoami.middlewares=add-auth-header
      - "traefik.http.middlewares.add-auth-header.headers.customrequestheaders.authorization=Basic dXNlcjpwYXNzCg=="

```

Response of the backend after sending a curl request to `whoami.localhost`:

```bash
❯ curl whoami.localhost

Hostname: 6802990b3586
IP: 127.0.0.1
IP: 172.19.0.2
RemoteAddr: 172.19.0.3:56940
GET / HTTP/1.1
Host: whoami.localhost
User-Agent: curl/7.64.1
Accept: */*
Accept-Encoding: gzip
Authorization: Basic dXNlcjpwYXNzCg==
X-Forwarded-For: 172.19.0.1
X-Forwarded-Host: whoami.localhost
X-Forwarded-Port: 80
X-Forwarded-Proto: http
X-Forwarded-Server: 5e48141afff1
X-Real-Ip: 172.19.0.1

```

As expected the `whoami` backend has received the `Authorization` header added by Traefik.

Hope this helps!
