Web And Auth Configuration
This page covers the config that controls the web dashboard and shared authentication.
Web Config
The web block maps to types.WebConfig.
web:
enabled: true
listen: localhost:9615
auth:
enabled: false
| Field | Type | Notes |
|---|---|---|
enabled | bool | Enables web startup from config-aware daemon flows |
listen | string | Defaults to localhost:9615 |
auth | object | Legacy compatibility block |
Legacy web.auth
web.auth is still present in the config structs:
web:
auth:
enabled: true
username: admin
password: dev-password
Fields:
| Field | Type |
|---|---|
enabled | bool |
username | string |
password | string |
Current code prefers security.auth for actual authentication behavior. Treat web.auth as compatibility-only unless you are working with older integrations.
Shared Security Auth
security.auth is the current auth source for the web server, daemon IPC, and MCP HTTP transport.
security:
auth:
enabled: true
mode: basic
username: admin
password_hash: "$2a$10$replace-me"
local_only: false
Supported modes:
| Mode | Behavior |
|---|---|
disabled | No authentication |
basic | HTTP basic auth for APIs, session login for the web UI |
token | Bearer token or X-API-Token header |
Web Login Behavior
When security.auth.mode is basic:
GET /loginserves the embedded login pagePOST /api/auth/loginvalidates credentials and sets a session cookiePOST /api/auth/logoutclears the sessionGET /api/auth/statusreturns auth mode and current session state
When mode is token:
- API and WebSocket requests still require token auth
- browser form login is disabled by design
Example Secure Setup
web:
enabled: true
listen: 127.0.0.1:9615
mcp:
enabled: true
transport: http
listen: 127.0.0.1:8090
security:
auth:
enabled: true
mode: token
token: "replace-with-a-long-random-token"
local_only: false
Notes
runix web --listen ...overrides the configured web listen address for that start request- the web dashboard frontend is embedded into the binary with
//go:embed - browser sessions are only created for basic auth mode