# Put Ghost behind a login

**URL:** <https://forum.ghost.org/t/put-ghost-behind-a-login/1433>\
**Category:** Installation\
**Created:** [May 29, 2018, 4:05pm UTC](https://forum.ghost.org/t/put-ghost-behind-a-login/1433 "2018-05-29T16:05:40Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![i8ramin](https://sea1.discourse-cdn.com/flex015/user_avatar/forum.ghost.org/i8ramin/32/703_2.png) [@i8ramin](https://forum.ghost.org/u/i8ramin)\
**Post date:** [May 30, 2018, 5:24pm UTC](https://forum.ghost.org/t/put-ghost-behind-a-login/1433/3 "2018-05-30T17:24:50Z")

</div>

Thanks for the info. Going to look into nginx subrequest authentication, but wondering if its possible to use passport w/o having to hack the core. I noticed that the ghostServer takes in an express instance, as seen in the main Ghost repo ([https://github.com/TryGhost/Ghost/blob/master/index.js](https://github.com/TryGhost/Ghost/blob/master/index.js)).

I am currently using the Ghost-on-Heroku repo ([GitHub - cobyism/ghost-on-heroku: One-button Heroku deploy for the Ghost blogging platform.](https://github.com/cobyism/ghost-on-heroku)), which has its own server.js to launch Ghost on Heroku. I am wondering if its possible to utilize this to introduce passport to support authentication.

> <https://gist.github.com/i8ramin/2a8e96ef03eb4d88db1bdd6711d07135>

---

_[View the full topic](https://forum.ghost.org/t/put-ghost-behind-a-login/1433)._
