Reverse proxy header authentication
CloudBeaver offers a feature for authorization and authentication using reverse proxy headers. This method allows to authenticate users via specific HTTP header fields.
Configuration Steps¶
Enabling Reverse proxy authentication¶
-
As an administrator, navigate to the Settings -> Server configuration.
-
Locate the Reverse proxy option and activate this setting to allow reverse proxy authentication.

-
Save changes.
Reverse proxy identity provider configuration in Community Edition¶
To configure reverse proxy authentication, follow these steps:
- Open your
.cloudbeaver.runtime.confconfiguration file. - Locate the
appsection within the file. - Add a new entry to the
authConfigurationsarray with the following structure:
"app": {
...
"authConfigurations": [
{
"id": "your_proxy_id",
"provider": "reverseProxy",
"displayName": "your_proxy_username",
"disabled": true,
"iconURL": "",
"description": "",
"parameters": {
"logout-url": "https://link_if_needed",
"user-header": "",
"team-header": "",
"team-delimiter": "",
"first-name-header": "",
"last-name-header": ""
}
}
]
}
Important
Ensure you include the mandatory fields id, provider, and displayName. The provider name
must be set to reverseProxy.
Reverse proxy identity provider configuration¶
To configure reverse proxy authentication in the CloudBeaver using the graphical user interface (GUI), follow these steps:
- Log in as an administrator.
- Navigate to Settings -> Server configuration in the CloudBeaver interface.
- Click on the + Add button to create a new authentication provider.
- In the Provider dropdown menu, select Reverse Proxy.
- Enter a unique identifier in the ID field and a name for the configuration in the Configuration name field.
- Click on Save to apply the changes.

Configuring default HTTP header fields¶
Configure the standard HTTP header fields as follows:
| Header | Description |
|---|---|
X-User |
user login |
X-Team |
user teams |
X-First-name |
user profile firstname |
X-Last-name |
user profile lastname |
X-Full-name |
user profile fullname |
X-Role |
user roles, only for DBeaver Team edition |
Header example¶
Consider a user named newuser, belonging to both user and admin teams. To access an application with reverse proxy
header authentication enabled, the following HTTP headers should be set in the request to the CloudBeaver application:
Tip
CloudBeaver categorizes users into two default teams: user and admin. Default delimiter used to separate
teams in the header is | (could be customized in team-delimiter parameter, all characters are allowed).