---
title: "Deprecation: #110863 - Backend route access \"public\""
manual: "TYPO3 Core Changelog"
version: "main"
permalink: "https://docs.typo3.org/permalink/changelog:deprecation-110863-1790766913"
source: "Changelog/15.0/Deprecation-110863-BackendRouteAccessPublic.rst"
typo3-version: "15.0"
typo3-major: 15
type: "deprecation"
issue: 110863
forge: "https://forge.typo3.org/issues/110863"
tags: ["Backend", "PHP-API", "NotScanned", "ext:backend"]
rendered: "2026-10-07T19:18:07+00:00"
---

# Deprecation: #110863 - Backend route access "public" {#deprecation-110863-1790766913}

See [forge#110863](https://forge.typo3.org/issues/110863)

## Description {#description}

The value `public` of the backend route option `access` has been
deprecated. It only omitted the request token of a route, while the backend
user was still required for all routes not listed in the core. Therefore, the
name did not describe the behaviour.

The new values `anonymous` (no backend user, no request token) and
`authenticated-without-token` (backend user, but no request token) replace
it, see [Feature: #110863 - Improved configuration of public backend routes](https://docs.typo3.org/permalink/changelog:feature-110863-1790781220).

## Impact {#impact}

Routes declaring `'access' => 'public'` are still registered with the
unchanged behaviour of `authenticated-without-token`, and a PHP
deprecation is triggered when the route is registered.

## Affected installations {#affected-installations}

Installations with extensions that register backend routes in
[`Configuration/Backend/Routes.php`](https://docs.typo3.org/m/typo3/reference-coreapi/main/en-us/ExtensionArchitecture/FileStructure/Configuration/Backend/Index.html#file-extension-configuration-backend-routes-php) or
[`Configuration/Backend/AjaxRoutes.php`](https://docs.typo3.org/m/typo3/reference-coreapi/main/en-us/ExtensionArchitecture/FileStructure/Configuration/Backend/Index.html#file-extension-configuration-backend-ajaxroutes-php) with `'access' => 'public'`.

## Migration {#migration}

Replace `'access' => 'public'` with
`'access' => 'authenticated-without-token'` to keep the current behaviour,
which requires a backend user, but no request token.

Use `'access' => 'anonymous'` only if the route must be reachable without
a backend user, for example the callback of a single sign-on provider.
