Skip to content

Authentication & Security Configuration Reference ​

The auth block in config.yaml manages API access control, cryptographic signature keys, token lifetimes, and password hashing cost factors.


1. Authentication Configuration Block ​

yaml
auth:
  # Enable JWT authentication for REST API and stream access
  enabled: true
  
  # Cryptographically secure random secret (minimum 32 characters)
  jwt_secret: "replace_with_a_very_long_secure_random_string_here_32chars"
  
  # Access token validity duration
  token_expiry: "24h"
  
  # Refresh token lifetime
  refresh_token_expiry: "720h" # 30 days
  
  # Bcrypt hashing cost factor (4 to 31; recommended: 12)
  bcrypt_cost: 12
  
  # Rate limiting on /api/v1/auth/login (attempts per minute per IP)
  rate_limit_login: 5

2. Authentication Parameters Reference ​

ParameterTypeDefaultDescription
auth.enabledbooleantrueWhen false, API endpoints do not require tokens (dev mode only)
auth.jwt_secretstring""256-bit secret used to sign HMAC-SHA256 JWT tokens
auth.token_expiryduration"24h"Access token expiration duration
auth.bcrypt_costinteger12Computational work factor for hashing user passwords

3. Initial Administrator Account ​

Upon the very first boot, if no administrator account exists in BadgerDB:

  1. RUSEON Core generates a random 32-character password for user admin.
  2. It hashes the password using bcrypt_cost and writes the record to the database.
  3. The plain-text password is printed once to the startup logs.

Released under the MIT License.