for API: authn, you can replace composite:quantumapi_v2_0 in api-paste.ini [composite:quantumapi_v2_0] use = call:quantum.auth:pipeline_factory noauth = extensions quantumapiapp_v2_0 keystone = authtoken keystonecontext extensions quantumapiapp_v2_0 authz: if your authn can return roles right, it will pass the policy check.

for CLI, u can provide --os-auth-strategy <auth-strategy> Authentication strategy (Env: OS_AUTH_STRATEGY, default keystone). For now, any other value will disable the authentication --os-auth-url <auth-url> Authentication URL (Env: OS_AUTH_URL) as long as it can provide service catalog right.