Authentication & Security Configuration Reference
The auth block in config.yaml manages API access control, cryptographic signature keys, token lifetimes, and password hashing cost factors.
1. Authentication Configuration Block
yaml
auth:
# Enable JWT authentication for REST API and stream access
enabled: true
# Cryptographically secure random secret (minimum 32 characters)
jwt_secret: "replace_with_a_very_long_secure_random_string_here_32chars"
# Access token validity duration
token_expiry: "24h"
# Refresh token lifetime
refresh_token_expiry: "720h" # 30 days
# Bcrypt hashing cost factor (4 to 31; recommended: 12)
bcrypt_cost: 12
# Rate limiting on /api/v1/auth/login (attempts per minute per IP)
rate_limit_login: 52. Authentication Parameters Reference
| Parameter | Type | Default | Description |
|---|---|---|---|
auth.enabled | boolean | true | When false, API endpoints do not require tokens (dev mode only) |
auth.jwt_secret | string | "" | 256-bit secret used to sign HMAC-SHA256 JWT tokens |
auth.token_expiry | duration | "24h" | Access token expiration duration |
auth.bcrypt_cost | integer | 12 | Computational work factor for hashing user passwords |
3. Initial Administrator Account
Upon the very first boot, if no administrator account exists in BadgerDB:
- RUSEON Core generates a random 32-character password for user
admin. - It hashes the password using
bcrypt_costand writes the record to the database. - The plain-text password is printed once to the startup logs.