Skip to content

Authentication API Reference & Token Lifecycle ​

RUSEON Core secures management and streaming APIs using standard JSON Web Tokens (JWT, RFC 7519) signed via HMAC-SHA256.


1. Authentication Endpoints ​

1.1 User Login (POST /api/login) ​

Authenticates username and password against BadgerDB and returns a 1-hour access token:

bash
curl -X POST http://localhost:8080/api/login \
  -H "Content-Type: application/json" \
  -d '{
    "username": "admin",
    "password": "your_secure_password"
  }'

Response (200 OK):

json
{
  "token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..."
}

Initial Admin Password: ​

On the very first launch, if no admin exists, RUSEON Core generates a random 16-character password and outputs it to standard console log:

text
==================================================
INITIAL ADMIN CREDENTIALS:
Username: admin
Password: <16_RANDOM_CHARS>
Please change this password after first login!
==================================================

2. Protected Request Headers ​

Include the JWT in the standard Authorization header:

http
GET /api/cameras HTTP/1.1
Host: localhost:8080
Authorization: Bearer <JWT_TOKEN>

3. Short-Lived Stream Tokens (GET /api/cameras/:id/stream-token) ​

For HTML5 <video> elements, WebCodecs WebSockets, or third-party players that cannot pass custom authorization headers:

  1. Request a 60-second token from the API:
    bash
    curl -H "Authorization: Bearer <JWT_TOKEN>" http://localhost:8080/api/cameras/cam-01/stream-token
  2. Pass the token in the URL query string:
    text
    http://localhost:8080/stream/hls/cam-01/index.m3u8?token=eyJhbGci...
    ws://localhost:8080/stream/ws/cam-01?token=eyJhbGci...

Released under the MIT License.