Skip to main content

Web And Auth Configuration

This page covers the config that controls the web dashboard and shared authentication.

Web Config​

The web block maps to types.WebConfig.

web:
enabled: true
listen: localhost:9615
auth:
enabled: false
FieldTypeNotes
enabledboolEnables web startup from config-aware daemon flows
listenstringDefaults to localhost:9615
authobjectLegacy compatibility block

Legacy web.auth​

web.auth is still present in the config structs:

web:
auth:
enabled: true
username: admin
password: dev-password

Fields:

FieldType
enabledbool
usernamestring
passwordstring

Current code prefers security.auth for actual authentication behavior. Treat web.auth as compatibility-only unless you are working with older integrations.

Shared Security Auth​

security.auth is the current auth source for the web server, daemon IPC, and MCP HTTP transport.

security:
auth:
enabled: true
mode: basic
username: admin
password_hash: "$2a$10$replace-me"
local_only: false

Supported modes:

ModeBehavior
disabledNo authentication
basicHTTP basic auth for APIs, session login for the web UI
tokenBearer token or X-API-Token header

Web Login Behavior​

When security.auth.mode is basic:

  • GET /login serves the embedded login page
  • POST /api/auth/login validates credentials and sets a session cookie
  • POST /api/auth/logout clears the session
  • GET /api/auth/status returns auth mode and current session state

When mode is token:

  • API and WebSocket requests still require token auth
  • browser form login is disabled by design

Example Secure Setup​

web:
enabled: true
listen: 127.0.0.1:9615

mcp:
enabled: true
transport: http
listen: 127.0.0.1:8090

security:
auth:
enabled: true
mode: token
token: "replace-with-a-long-random-token"
local_only: false

Notes​

  • runix web --listen ... overrides the configured web listen address for that start request
  • the web dashboard frontend is embedded into the binary with //go:embed
  • browser sessions are only created for basic auth mode