# Password for crate user

**URL:** <https://community.cratedb.com/t/password-for-crate-user/194>\
**Category:** CrateDB\
**Created:** [April 30, 2019, 8:00am UTC](https://community.cratedb.com/t/password-for-crate-user/194 "2019-04-30T08:00:04Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![ritwick](https://avatars.discourse-cdn.com/v4/letter/r/74df32/32.png) [@ritwick](https://community.cratedb.com/u/ritwick)\
**Post date:** [April 30, 2019, 8:00am UTC](https://community.cratedb.com/t/password-for-crate-user/194/1 "2019-04-30T08:00:04Z")

</div>

Hi Team,

The page [here](https://crate.io/docs/crate/reference/en/latest/admin/user-management.html#create-user) mentions that the built-in superuser `crate` has no password and it is not possible to set a new password for this user.

This essentially means that anyone can access any resource bypassing the privileges set for different groups by simply using crate user without any password. I even tried to DENY all privileges on a schema to crate user but it was not allowed to change the privileges of a superuser.

Please could you share the recommended practice on securing the data.

Thanks,  
Ritwick

---

<div class="post-metadata">

**Author:** ![roman](https://sea2.discourse-cdn.com/flex020/user_avatar/community.cratedb.com/roman/32/36_2.png) [@roman](https://community.cratedb.com/u/roman)\
**Post date:** [May 3, 2019, 12:20pm UTC](https://community.cratedb.com/t/password-for-crate-user/194/2 "2019-05-03T12:20:55Z")

</div>

Hi @ritwick!

Did you check this article on authentification: [https://crate.io/docs/crate/reference/en/latest/admin/auth/hba.html](https://crate.io/docs/crate/reference/en/latest/admin/auth/hba.html)

Best  
Roman
