> For the complete documentation index, see [llms.txt](https://audomsak.gitbook.io/red-hat-service-registry/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://audomsak.gitbook.io/red-hat-service-registry/security/configuring-service-registry/enable-basic-auth.md).

# Enable HTTP Basic Authentication

By default, Service Registry supports authentication using OpenID Connect. Users (or API clients) must obtain an access token to make authenticated calls to the Service Registry REST API. However, because some tools do not support OpenID Connect, you can also configure Service Registry to support HTTP basic authentication.

Apicurio Registry supports both OAuth and BASIC auth at the same time. a custom authentication handler has been implemented to use OAuth **Client Credentials** flow to support BASIC auth. In other words, the client can provide BASIC auth credentials, and the server-side custom handler will extract the username/password and then use OAuth **Client Credentials** flow against the Keycloak server to obtain an access token. Once that is done, everything else works the same as if the client had provided an OAuth bearer token to begin with.

To enable HTTP basic authentication, login to Service Registry web console with administrator privilege i.e. `registry-admin` account you've created in [this section](/red-hat-service-registry/security/rhsso-deployment/create-registry-realm.md). Go to **Settings** tab, then enable the **HTTP basic authentication** option.

![Enable HTTP basic authentication](https://2900952542-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F5K4aVwhFRyCBBx4mXirV%2Fuploads%2Fgit-blob-16bc803786f9d5f5e10c8fcb1c174d6fd9ee752c%2Fservice-registry-authn-authz-16.png?alt=media)
