Skip to main content
Drupal is a registered trademark of Dries Buytaert
Release: OpenID Connect / OAuth client 3.0.0-alpha9 New alpha version released for module openid_connect (3.0.0-alpha9). Usage Milestone: Google Analytics Module google_analytics crossed 1,000 active installs. Release: Timelinr 1.0.1 Minor update available for module timelinr (1.0.1). Release: GraphQL Compose Codegen 1.1.2 Minor update available for module graphql_compose_codegen (1.1.2). Release: Mapy.com 1.1.3 Minor update available for module mapycom (1.1.3). Release: Ckeditor5 entity browser 3.0.3 Minor update available for module ckeditor5_entity_browser (3.0.3). Release: Ckeditor5 entity browser 3.0.1 Minor update available for module ckeditor5_entity_browser (3.0.1). Release: Ckeditor5 entity browser 3.0.2 Minor update available for module ckeditor5_entity_browser (3.0.2). Release: Teamleader Integration 4.0.2 Minor update available for module teamleader (4.0.2). Module Revived: Entityqueue Buttons 1.1.2 Module entityqueue_buttons updated after 8 months of inactivity (1.1.2).

Null auth

No security coverage
View on drupal.org

This module allows anonymous users to access Drupal REST resources through an auto-login method. It provides a "null" authentication provider that can be configured via the REST UI module to grant access to specific resources. Use with caution in controlled environments.

Drupal Null Authentication Provider module

This module is a null authentication provider. Enabling anonymous user access to Drupal 8 REST Resources, using an auto-login method.

WARNING: This module does not control any flood and give auto-login for all requests. Use only in environments with controlled access.

Configuration and usage instructions

There is no specific configuration for this module, it enables automatically a null authentication method. You need to add a _null_auth query parameter to all your requests.

Using the contrib module REST UI, you can enable REST Resources using the Authentication Provider null, remember to enable the specific permissions for the REST Resource to anonymous user.

Steps:

  1. Get the X-CSRF-Token: GET /rest/session/token
    HEADERS:
           - Content-Type: application/json
  2. Create a new user: POST /entity/user?_format=json&_null_auth=1
    HEADERS:
           - Content-Type: application/json
           - X-CSRF-Token: ---
         BODY:
         {
           "name":{
             "value":"userName"
           },
           "mail":{
             "value":"userMail"
           }
         }

Get in touch with us for customizations and consultancy.

Depends on

Dependencies of the latest stable release

No dependencies recorded for this project.

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
1
Tracked since
Nov 2025
Latest release
9 months ago
Releases (12 mo)
1 ▲ from 0
Maintenance
Slowing

Releases

Version Type Core Release date
2.x-dev Dev 8–11 Nov 25, 2025