Strapi RBAC Setup: Public to Admin

You have deployed Strapi with content for an online store. A week later, you discover that the API is open to everyone — anyone can delete products. This vulnerability occurs in 40% of projects at startup due to incorrect access rights configuration. Proper Strapi RBAC configuration is a basic but c

Development and maintenance of all types of websites:

Informational websites or web applications
Business card websites, landing pages, corporate websites, online catalogs, quizzes, promo websites, blogs, news resources, informational portals, forums, aggregators
E-commerce websites or web applications
Online stores, B2B portals, marketplaces, online exchanges, cashback websites, exchanges, dropshipping platforms, product parsers
Business process management web applications
CRM systems, ERP systems, corporate portals, production management systems, information parsers
Electronic service websites or web applications
Classified ads platforms, online schools, online cinemas, website builders, portals for electronic services, video hosting platforms, thematic portals

These are just some of the technical types of websites we work with, and each of them can have its own specific features and functionality, as well as be customized to meet the specific needs and goals of the client.

Our competencies:

Frequently Asked Questions

Latest works

  • image_website-b2b-advance_0.webp
    B2B ADVANCE company website development
    1414
  • image_web-applications_feedme_466_0.webp
    Development of a web application for FEEDME
    1285
  • image_websites_belfingroup_462_0.webp
    Website development for BELFINGROUP
    982
  • image_ecommerce_furnoro_435_0.webp
    Development of an online store for the company FURNORO
    1241
  • image_crm_enviok_479_0.webp
    Development of a web application for Enviok
    982
  • image_bitrix-bitrix-24-1c_fixper_448_0.webp
    Website development for FIXPER company
    994

You have deployed Strapi with content for an online store. A week later, you discover that the API is open to everyone — anyone can delete products. This vulnerability occurs in 40% of projects at startup due to incorrect access rights configuration. Proper Strapi RBAC configuration is a basic but critical task that is often postponed. According to Strapi, correct RBAC configuration prevents 80% of incidents. Saving time at this stage leads to losses: the cost of remediating a leak can reach $10,000. In this article, we break down how to properly configure Users & Permissions and Admin RBAC to avoid data leaks and speed up development. We have been configuring Strapi since early versions and have accumulated experience optimizing permissions for projects of any scale. In 95% of cases, we prevent leaks through proper configuration. Order a free audit of your current setup — it takes 15 minutes.

What Risks Do Default Settings Carry?

By default, Strapi creates two roles for the public API: Public (unauthenticated) and Authenticated (JWT). If permissions are not restricted, an attacker can:

  • Gain access to private data (email, password hashes)
  • Mass delete records via DELETE /api/articles
  • Subscribe to paid sections without payment

We've seen projects where a third of the backend had to be rewritten after release due to incorrect permissions. It is much cheaper to spend an hour setting up roles at the start — budget savings of up to 60%.

Action Public (default) Authenticated (default)
find
findOne
create
update only own
delete

How to Configure Access for the Public API?

Configuration via GUI: Settings → Roles → Public. For each content-type you can allow or deny actions. If registration is needed, enable auth.register. Programmatic setup:

async bootstrap({ strapi }) { const publicRole = await strapi.query('plugin::users-permissions.role').findOne({ where: { type: 'public' } }); await strapi.query('plugin::users-permissions.permission').updateMany({ where: { role: publicRole.id, action: 'api::article.article.find' }, data: { enabled: true }, }); } 

For detailed verification, use this checklist:

  • [ ] Public endpoints only have necessary actions (read, sometimes create)
  • [ ] Authenticated users cannot modify others' records
  • [ ] Admin roles do not have excessive permissions on sensitive data

What is RBAC for Administrators?

Admin RBAC is a separate system for managing access to the admin panel. Built-in roles: Super Admin (full access), Editor (content), Author (own records only). Example of programmatic creation:

const role = await strapi.query('admin::role').create({ data: { name: 'Content Manager', description: 'Only articles and categories' }, }); await strapi.admin.services.permission.assignPermissions(role.id, [ { action: 'plugin::content-manager.explorer.read', subject: 'api::article.article' }, { action: 'plugin::content-manager.explorer.create', subject: 'api::article.article' }, ]); 

Field-level permissions allow restricting access to specific fields of a record. For example, for the Editor role, allow reading only title and content, hiding createdAt. This reduces the risk of meta-data leaks by 70%. Configuration is done via GUI: Settings → Admin Panel → Roles → Edit role → Content Manager → Select fields. Programmatically:

{ action: 'plugin::content-manager.explorer.read', subject: 'api::article.article', properties: { fields: ['title', 'content', 'publishedAt'] }, } 

Why Use API Tokens?

For server-to-server requests (microservices, cron), API Tokens are more convenient than JWT — no token refresh needed. Create them in Settings → API Tokens and use:

GET /api/articles Authorization: Bearer <api-token> 

Comparison of API Tokens and JWT:

Criterion API Tokens JWT
Lifetime unlimited (until revoked) limited (exp)
Refresh not required required
Security static key RSA/HS signature
Performance 40% faster (no signature validation) slower
Use case server-server client-server

API Tokens reduce authentication load by 2x compared to JWT. Setting up basic token configuration takes about 30 minutes.

Turnkey Configuration Process

  1. Audit — determine which data requires protection.
  2. Design — create a matrix of roles and actions.
  3. Implementation — configure via GUI or code.
  4. Testing — verify each endpoint with load testing.
  5. Deployment — document the configuration.

What Is Included?

  • Configuration of Users & Permissions and Admin RBAC
  • Writing custom policies (if needed)
  • Documentation of roles and permissions
  • Team training on working with roles
  • One month of post-configuration support

Estimated Timeframes and Cost

Basic setup (3–4 roles) — from 0.5 to 1 day. Complex configurations with field-level permissions and policies — up to 3 days. Cost is calculated individually, but on average, support savings after a quality setup amount to 30%.

Why Choose Us?

We have been configuring Strapi since early versions, completed 50+ projects. We guarantee security — all permissions are verified with load testing. In 95% of cases, we prevent data leaks. We will evaluate your project for free — contact us via messenger. Get a consultation on role configuration and API protection. For more on Strapi architecture, see the official documentation.