> Markdown version of [Security](https://vaadin.com/docs/next/building-apps/security). Section index: [llms.txt](https://vaadin.com/docs/next/building-apps/llms.txt)

# Security

These guides show how to secure a Vaadin application with Spring Security: how users log in and out, and how to restrict what each user can see and do.

Read them in order. [Add Login](https://vaadin.com/docs/next/building-apps/security/add-login.md) and [Add Logout](https://vaadin.com/docs/next/building-apps/security/add-logout.md) set up authentication. [Protect Views](https://vaadin.com/docs/next/building-apps/security/protect-views.md) controls which views each user can open, and what they can do in them. [Protect Services](https://vaadin.com/docs/next/building-apps/security/protect-services.md) enforces the same rules in the application services. Protect both: the views decide what users can reach through the user interface, and the services are the actual security boundary.

Add Login uses an in-memory user store, which you should only use for development and testing. To let users log in with an existing account at an identity provider, see [OAuth2 Authentication](https://vaadin.com/docs/next/flow/integrations/spring/oauth2.md).

To verify the security rules with automated tests, see [Test View Access Control](https://vaadin.com/docs/next/building-apps/testing/browserless/test-view-access.md) and [Testing Method Security](https://vaadin.com/docs/next/building-apps/security/protect-services.md#testing-method-security).

## <a id="topics"></a>Topics

- [Add Login](https://vaadin.com/docs/next/building-apps/security/add-login.md): Learn how to add user login to a Vaadin application using Spring Security.
- [Add Logout](https://vaadin.com/docs/next/building-apps/security/add-logout.md): Learn how to securely logout users from a Vaadin application using Spring Security.
- [Protect Views](https://vaadin.com/docs/next/building-apps/security/protect-views.md): Learn how to protect views in a Vaadin application based on user roles.
- [Protect Services](https://vaadin.com/docs/next/building-apps/security/protect-services.md): Learn how to protect services in a Vaadin application based on user roles.
