Skip to content
Server & Web Software

Kong Inc. Kong Gateway Community Edition (Admin API) — Default Password

Default username and password for the Kong Inc. Kong Gateway Community Edition (Admin API): (blank) / (blank). Learn how to log in and how to change the default credentials.

Kong's Admin API runs unauthenticated on localhost:8001 by default. Any local process can make unrestricted calls. RBAC must be explicitly enabled; when enabled with KONG_PASSWORD, a super admin 'kong_admin' is created. Applies to Kong Gateway prior to enforced RBAC in 3.x. Vendor docs warn: 'The Admin API allows full control of Kong Gateway.'

UsernamePasswordAccessNotes
(blank / none)
(blank / none)
APIAdmin API on port 8001 is unauthenticated by default. No credentials required.

Responsible use

This database lists publicly documented default credentials so administrators can find and change them. Only use these on systems you own or are authorized to test.

Related devices