Authentication API Reference & Token Lifecycle
RUSEON Core secures management and streaming APIs using standard JSON Web Tokens (JWT, RFC 7519) signed via HMAC-SHA256.
1. Authentication Endpoints
1.1 User Login (POST /api/login)
Authenticates username and password against BadgerDB and returns a 1-hour access token:
bash
curl -X POST http://localhost:8080/api/login \
-H "Content-Type: application/json" \
-d '{
"username": "admin",
"password": "your_secure_password"
}'Response (200 OK):
json
{
"token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..."
}Initial Admin Password:
On the very first launch, if no admin exists, RUSEON Core generates a random 16-character password and outputs it to standard console log:
text
==================================================
INITIAL ADMIN CREDENTIALS:
Username: admin
Password: <16_RANDOM_CHARS>
Please change this password after first login!
==================================================2. Protected Request Headers
Include the JWT in the standard Authorization header:
http
GET /api/cameras HTTP/1.1
Host: localhost:8080
Authorization: Bearer <JWT_TOKEN>3. Short-Lived Stream Tokens (GET /api/cameras/:id/stream-token)
For HTML5 <video> elements, WebCodecs WebSockets, or third-party players that cannot pass custom authorization headers:
- Request a 60-second token from the API:bash
curl -H "Authorization: Bearer <JWT_TOKEN>" http://localhost:8080/api/cameras/cam-01/stream-token - Pass the token in the URL query string:text
http://localhost:8080/stream/hls/cam-01/index.m3u8?token=eyJhbGci... ws://localhost:8080/stream/ws/cam-01?token=eyJhbGci...