What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To protect a Spring Boot web app with Apache Shiro, add the Shiro Spring Boot web starter, provide a Realm that connects Shiro to your identity and permission store, and define URL rules with a ShiroFilterChainDefinition. You can also use @RequiresRoles and @RequiresPermissions for method-level checks, but annotation-based checks do not eliminate the need for a filter-chain definition.

The Apache Shiro Spring Boot page lists version 3.0.1 and says Shiro v2 was superseded by v3 on June 29, 2026. Check the official Spring Boot integration guide when choosing a version, since releases can change.

Add the Shiro dependency

For a Spring Boot web application, add the web starter to your Maven project. Use shiro-spring-boot-starter instead for a standalone application that does not need web integration.

<dependency>
  <groupId>org.apache.shiro</groupId>
  <artifactId>shiro-spring-boot-web-starter</artifactId>
  <version>3.0.1</version>
</dependency>

Apache Shiro describes its Spring web support as first-class. The starter integrates Shiro with the application, but you still need to tell it how your app identifies users and what those users can do.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Provide a Realm

A Realm connects Shiro to the application’s identity and authorization data. It is responsible for supplying the authentication and authorization information Shiro needs; implement it against your own user, credential, role, and permission store.

@Bean
public Realm realm() {
    // Connect Shiro to the application's identity and permission store.
    return ...;
}

The code above is a bean outline, not a complete Realm implementation: the appropriate implementation depends on how your application stores and verifies credentials and permissions.

Protect URLs with a filter chain

Declare a ShiroFilterChainDefinition bean to map URL patterns to Shiro filters. For example:

@Bean
public ShiroFilterChainDefinition shiroFilterChainDefinition() {
    DefaultShiroFilterChainDefinition chain =
        new DefaultShiroFilterChainDefinition();
    chain.addPathDefinition("/admin/**", "authc, roles[admin]");
    chain.addPathDefinition("/docs/**", "authc, perms[document:read]");
    chain.addPathDefinition("/**", "authc");
    return chain;
}
  • authc requires authentication.
  • roles[admin] requires the authenticated subject to have the admin role.
  • perms[document:read] requires the document:read permission.
  • anon allows access without authentication.

Put specific routes before broader patterns so a general rule such as /** does not take precedence over the policy intended for a more specific path. Make the chain explicit for sensitive routes rather than relying on an unstated assumption about access.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use annotations for method-level authorization

The Spring Boot starters enable Shiro annotations. Use @RequiresPermissions to guard an operation that requires a permission:

@RequiresPermissions("document:read")
public void readDocument() {
    // Protected operation.
}

A controller or service method can also use @RequiresRoles("admin") when it requires a role. Annotations let you express checks close to the protected operation, while the filter chain governs URL access. Even if annotations make the authorization decisions, Shiro’s Spring Boot guide still requires a filter-chain definition. Its examples map /** to anon or to permissive basic authentication so the annotation layer can decide access.

Review settings before deployment

Authentication and authorization rules are only part of the security configuration. Check these settings against your app’s deployment and access policy:

  • Login and denial destinations: review shiro.loginUrl and shiro.unauthorizedUrl so unauthenticated and unauthorized requests are handled as intended.
  • Sessions and cookies: review shiro.sessionManager.cookie.secure, the session-cookie name, URL rewriting, and remember-me settings.
  • Path matching and defaults: the official Shiro 3.x property table lists shiro.caseInsensitive as true and shiro.allowAccessByDefault as false. Check the version-specific behavior and ensure it matches the policy you intend.
  • Realm behavior: verify how the Realm finds and validates credentials and resolves roles and permissions.
  • Coverage: confirm each sensitive URL has an explicit filter-chain rule, including routes that should remain public.
  • Authorization caching: if repeated permission checks need caching, add a CacheManager bean. The guide documents MemoryConstrainedCacheManager as an example.

Shiro’s broader reference covers authentication, authorization, realms, sessions, cryptography, web URL security, caching, and Spring integration. Its authorization model has a Subject delegate checks to the SecurityManager, including role, permission, and authentication checks; Shiro sessions retain the subject’s identity and authentication state.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Consider whether Shiro fits your application

Shiro is one option for application security in a Spring Boot project. Spring Boot’s reference also documents auto-configuration for Spring Security web applications and authentication. The available documentation does not establish a complete migration or feature comparison between Shiro and Spring Security, so choose based on your existing architecture and requirements rather than assuming a direct, one-to-one replacement.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.