# Rasa REST API security concerns

**URL:** <https://forum.rasa.com/t/rasa-rest-api-security-concerns/33255>\
**Category:** Rasa Open Source\
**Created:** [September 1, 2020, 2:09pm UTC](https://forum.rasa.com/t/rasa-rest-api-security-concerns/33255 "2020-09-01T14:09:53Z")\
**Posts on this page:** 1\
**Showing post:** 1

<div class="post-metadata">

**Author:** ![lotcz](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.rasa.com/lotcz/32/10758_2.png) [@lotcz](https://forum.rasa.com/u/lotcz)\
**Post date:** [September 1, 2020, 2:09pm UTC](https://forum.rasa.com/t/rasa-rest-api-security-concerns/33255/1 "2020-09-01T14:09:53Z")

</div>

Hello,

I’d like to use Rasa with my own chat widget. I used REST API and it works fine. Now I am concerned about security - since REST API needs to be exposed to outside world to enable exchanging messages between my widget and Rasa, it is now open to anyone who might use API to manipulate my chatbot.

Maybe I missed something in docs, but I couldn’t find a way to only expose part of the API needed to chat, not other stuff used for administration etc.

If you are also using REST API, how to you protect yourselves?

Thank you.

Karel

---

_[View the full topic](https://forum.rasa.com/t/rasa-rest-api-security-concerns/33255)._
