# Tapir Generated documentation behind proxy which handles authorization

**URL:** <https://softwaremill.community/t/tapir-generated-documentation-behind-proxy-which-handles-authorization/136>\
**Category:** tapir\
**Created:** [February 22, 2023, 10:33pm UTC](https://softwaremill.community/t/tapir-generated-documentation-behind-proxy-which-handles-authorization/136 "2023-02-22T22:33:03Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![bclouser](https://dub1.discourse-cdn.com/flex005/user_avatar/softwaremill.community/bclouser/32/108_2.png) [@bclouser](https://softwaremill.community/u/bclouser)\
**Post date:** [February 22, 2023, 10:33pm UTC](https://softwaremill.community/t/tapir-generated-documentation-behind-proxy-which-handles-authorization/136/1 "2023-02-22T22:33:03Z")

</div>

Hello,

I am generating documentation for an API with Tapir and the service sits behind a gateway (kong), which already handles the authx and authz portions of every request used in the API.

It’s a bearer token flow - so the gateway validates/extracts the token, and puts the pertinent user information into headers before proxying the request to my scala application which hosts the API via tapir.  
I’m wondering if there is a good way to generate the authentication logic with the rest of the documentation of my endpoints without impacting the endpoints at all?

So I want the documentation to indicate that the user should send along the bearer token `Authorization: Bearer ${TOKEN}` but i don’t want the endpoint to actually handle a bearer token since that will be dealt with by the gateway before the request reaches the app… hoping that makes sense?

---

<div class="post-metadata">

**Author:** ![adamw](https://dub1.discourse-cdn.com/flex005/user_avatar/softwaremill.community/adamw/32/28_2.png) [@adamw](https://softwaremill.community/u/adamw)\
**Post date:** [February 23, 2023, 1:27pm UTC](https://softwaremill.community/t/tapir-generated-documentation-behind-proxy-which-handles-authorization/136/2 "2023-02-23T13:27:10Z")

</div>

I think it’s easiest to pass an amended list of endpoints to the documentation interpreter.

Sth like:

```plaintext
val myEndpoints: List[ServerEndpoint[Any, F]] = ...

val endpointsForDocs = myEndpoints.map(_.endpoint).map(_.in(auth.bearer[String]))
val swaggerEndpoints = SwaggerInterpreter().fromEndpoints[F](endpointsForDocs, "My App", "1.0")

```

---

<div class="post-metadata">

**Author:** ![bclouser](https://dub1.discourse-cdn.com/flex005/user_avatar/softwaremill.community/bclouser/32/108_2.png) [@bclouser](https://softwaremill.community/u/bclouser)\
**Post date:** [February 23, 2023, 7:52pm UTC](https://softwaremill.community/t/tapir-generated-documentation-behind-proxy-which-handles-authorization/136/3 "2023-02-23T19:52:11Z")

</div>

Yessss! i’ve been playing around with stuff like this and wasn’t sure if it was “right”.

This is exactly what i needed!

Thank you!
