> ## Documentation Index
> Fetch the complete documentation index at: https://docs.forge.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Configure Resources and routing

> Define a destination once, then enable direct access, automatic routing, or both.

A Resource identifies one protected destination. Its protocol determines the
client listener, available credentials, policy fields, and enforcement depth.
The same Resource definition is used for direct access and automatic routing.

## Resource settings

| Setting | Purpose |
| - | - |
| Name | Human-readable inventory and activity label |
| Protocol | `HTTP`, `PostgreSQL`, `MySQL`, or `Redis` |
| Destination host | Exact DNS hostname the Resource Gateway connects to |
| Destination port | Destination TCP port |
| Use HTTPS | Encrypt and verify the Gateway-to-destination connection for HTTP Resources |
| Private authority | Optional public CA certificate used to verify a privately issued destination certificate |
| Resource gateway | Customer deployment that can reach the destination |
| Automatic routing | Route matching traffic from managed devices without changing the client's destination |
| Enabled | Accept new Resource connections and operations |

PostgreSQL, MySQL, and Redis always require encrypted, verified destination
connections. HTTP can use plain HTTP or verified HTTPS. Forge does not provide
a skip-verification setting.

Publicly trusted destination certificates need no additional configuration.
For a private PKI, paste only the issuing public CA certificate into **Private
authority**. Never upload a private key or a destination server certificate's
private material.

## Select an access path

### Automatic routing

Enable **Automatic routing** when enrolled devices should continue using the
destination's original hostname and port. Forge publishes the Resource route
to eligible devices. The endpoint intercepts the matching connection,
authenticates the device and user, and sends it to the assigned Resource
Gateway.

The original destination must be expressed as a hostname. Forge does not infer
an HTTP Resource from an IP-only flow, and it does not apply a command policy to
a database connection that bypasses Forge.

### Direct access

Assign a Resource Gateway when a client should connect explicitly. The
Resource page generates the exact command and a short-lived credential for the
signed-in user. Services use an active Forge service account with the
`resources:connect` scope.

Direct and automatic access are independent choices over the same Resource:

| Configuration | Result |
| - | - |
| Gateway assigned, routing off | Direct access only |
| Gateway assigned, routing on | Direct access and automatic managed-device routing |
| No Gateway assigned | Inventory definition only; no Resource traffic can be served |

## How direct clients select a Resource

One Gateway listener can serve many Resources. Selection is protocol-specific
and the Console generates it for you.

| Protocol | Resource selector |
| - | - |
| HTTP/HTTPS | Resource-bound Forge token in `Proxy-Authorization` |
| PostgreSQL | Access name appended to the requested database as `database@access-name` |
| MySQL | Resource access name used as the client username |
| Redis | Resource access name used as the Redis ACL username |

The short-lived Forge credential authenticates the caller and selects the
Resource. It is not forwarded to the destination. The Gateway separately
chooses the destination credential assigned to that caller.

## Test before enabling access

Use **Test connection** after assigning a Gateway and credential. The test runs
from the Gateway, so it verifies private-network reachability, DNS, destination
TLS, and supported authentication from the same environment that will serve
traffic. Identity token exchange needs a real caller token, so its test covers
reachability and TLS; verify authentication with a real request.

A successful test does not bypass policy. Run an actual client operation to
verify policy and activity behavior, then open **Live → Resources** to see
the result.

## Disable or remove a Resource

Disabling a Resource prevents new traffic while preserving its definition,
credentials, policies, and activity. Before deleting a Gateway, reassign or
remove all Resources that use it. Forge rejects deletion while assignments
remain.

See [Deploy a Resource gateway](/resources/deploy-resource-gateway) for
installation and client trust, and [Resource Policies](/secure/resource-policies)
for enforcement.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.