You have deployed Strapi with content for an online store. A week later, you discover that the API is open to everyone — anyone can delete products. This vulnerability occurs in 40% of projects at startup due to incorrect access rights configuration. Proper Strapi RBAC configuration is a basic but critical task that is often postponed. According to Strapi, correct RBAC configuration prevents 80% of incidents. Saving time at this stage leads to losses: the cost of remediating a leak can reach $10,000. In this article, we break down how to properly configure Users & Permissions and Admin RBAC to avoid data leaks and speed up development. We have been configuring Strapi since early versions and have accumulated experience optimizing permissions for projects of any scale. In 95% of cases, we prevent leaks through proper configuration. Order a free audit of your current setup — it takes 15 minutes.
What Risks Do Default Settings Carry?
By default, Strapi creates two roles for the public API: Public (unauthenticated) and Authenticated (JWT). If permissions are not restricted, an attacker can:
- Gain access to private data (email, password hashes)
- Mass delete records via DELETE /api/articles
- Subscribe to paid sections without payment
We've seen projects where a third of the backend had to be rewritten after release due to incorrect permissions. It is much cheaper to spend an hour setting up roles at the start — budget savings of up to 60%.
| Action | Public (default) | Authenticated (default) |
|---|---|---|
| find | ✅ | ✅ |
| findOne | ✅ | ✅ |
| create | ❌ | ✅ |
| update | ❌ | only own |
| delete | ❌ | ❌ |
How to Configure Access for the Public API?
Configuration via GUI: Settings → Roles → Public. For each content-type you can allow or deny actions. If registration is needed, enable auth.register. Programmatic setup:
async bootstrap({ strapi }) { const publicRole = await strapi.query('plugin::users-permissions.role').findOne({ where: { type: 'public' } }); await strapi.query('plugin::users-permissions.permission').updateMany({ where: { role: publicRole.id, action: 'api::article.article.find' }, data: { enabled: true }, }); } For detailed verification, use this checklist:
- [ ] Public endpoints only have necessary actions (read, sometimes create)
- [ ] Authenticated users cannot modify others' records
- [ ] Admin roles do not have excessive permissions on sensitive data
What is RBAC for Administrators?
Admin RBAC is a separate system for managing access to the admin panel. Built-in roles: Super Admin (full access), Editor (content), Author (own records only). Example of programmatic creation:
const role = await strapi.query('admin::role').create({ data: { name: 'Content Manager', description: 'Only articles and categories' }, }); await strapi.admin.services.permission.assignPermissions(role.id, [ { action: 'plugin::content-manager.explorer.read', subject: 'api::article.article' }, { action: 'plugin::content-manager.explorer.create', subject: 'api::article.article' }, ]); Field-level permissions allow restricting access to specific fields of a record. For example, for the Editor role, allow reading only title and content, hiding createdAt. This reduces the risk of meta-data leaks by 70%. Configuration is done via GUI: Settings → Admin Panel → Roles → Edit role → Content Manager → Select fields. Programmatically:
{ action: 'plugin::content-manager.explorer.read', subject: 'api::article.article', properties: { fields: ['title', 'content', 'publishedAt'] }, } Why Use API Tokens?
For server-to-server requests (microservices, cron), API Tokens are more convenient than JWT — no token refresh needed. Create them in Settings → API Tokens and use:
GET /api/articles Authorization: Bearer <api-token> Comparison of API Tokens and JWT:
| Criterion | API Tokens | JWT |
|---|---|---|
| Lifetime | unlimited (until revoked) | limited (exp) |
| Refresh | not required | required |
| Security | static key | RSA/HS signature |
| Performance | 40% faster (no signature validation) | slower |
| Use case | server-server | client-server |
API Tokens reduce authentication load by 2x compared to JWT. Setting up basic token configuration takes about 30 minutes.
Turnkey Configuration Process
- Audit — determine which data requires protection.
- Design — create a matrix of roles and actions.
- Implementation — configure via GUI or code.
- Testing — verify each endpoint with load testing.
- Deployment — document the configuration.
What Is Included?
- Configuration of Users & Permissions and Admin RBAC
- Writing custom policies (if needed)
- Documentation of roles and permissions
- Team training on working with roles
- One month of post-configuration support
Estimated Timeframes and Cost
Basic setup (3–4 roles) — from 0.5 to 1 day. Complex configurations with field-level permissions and policies — up to 3 days. Cost is calculated individually, but on average, support savings after a quality setup amount to 30%.
Why Choose Us?
We have been configuring Strapi since early versions, completed 50+ projects. We guarantee security — all permissions are verified with load testing. In 95% of cases, we prevent data leaks. We will evaluate your project for free — contact us via messenger. Get a consultation on role configuration and API protection. For more on Strapi architecture, see the official documentation.







