# Support for REMOTE\_USER authentication

**URL:** https://discuss.tryton.org/t/support-for-remote-user-authentication/5734
**Category:** System Administrator
**Created:** [November 30, 2022, 2:42am UTC](https://discuss.tryton.org/t/support-for-remote-user-authentication/5734 "2022-11-30T02:42:08Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![cyruspy](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/cyruspy/32/2059_2.png) [@cyruspy](https://discuss.tryton.org/u/cyruspy)
#### Post date: [November 30, 2022, 2:42am UTC](https://discuss.tryton.org/t/support-for-remote-user-authentication/5734/1 "2022-11-30T02:42:08Z")

</div>

Hello!,

I’m new to Tryton, I’m currently deploying my first test environment, I understand that there are native & web clients.

I’m wondering if it’s possible to have a web server infront of the trytond process, configured as reverse proxy that solves authentication and defines a variable (usually REMOTE\_USER) I could use for Tryton user authentication. The aim would be to reuse credentials and the users don’t need to remember yet another password.

My specific usecase would be using GMail accounts for example (browser handling OIDC), but it can work for anything that the web server with external modules can handle (Kerberos, SAML2, OIDC, etc)

Regards.

---

<div class="post-metadata">

### Author: ![ced](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/ced/32/1237_2.png) [@ced](https://discuss.tryton.org/u/ced)
#### Post date: [November 30, 2022, 8:19am UTC](https://discuss.tryton.org/t/support-for-remote-user-authentication/5734/2 "2022-11-30T08:19:00Z")

</div>

Tryton was not really designed for such usage. It is based on `Authorization` header which could be be `user/password` or a session. But also the user id depends on the database used (as Tryton is multi-database).  
So if you can manage to have the proxy retrieved the right user id and create a session in the database table `ir_session` than you can fill the `Authorization` header.

But indeed it is probably simpler to use the [`authentication_saml` module](https://docs.tryton.org/projects/modules-authentication-saml/en/latest/) or to write that support your preferred protocol (as long it is web based, it should not be difficult).

---

<div class="post-metadata">

### Author: ![cyruspy](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/cyruspy/32/2059_2.png) [@cyruspy](https://discuss.tryton.org/u/cyruspy)
#### Post date: [November 30, 2022, 5:13pm UTC](https://discuss.tryton.org/t/support-for-remote-user-authentication/5734/3 "2022-11-30T17:13:08Z")

</div>

I think that GApps can also provide SAML2. Will look into it, thanks!.
