No way for a script or agent to use the API as a person #123
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The API takes a session cookie, a proxy's word, or the shared admin token. A script or an agent acting for one person (adding and removing their feeds, reading their items) has to either sign in with a password and carry the cookie, or be given the admin token, which is everyone's admin.
Each person should be able to make named API tokens on their own account, see when each was last used, and revoke one, and send one as Authorization: Bearer . A token acts as its owner and nothing more: an admin's is admin, anyone else's is not. Kept hashed, shown once when made.
Done in
00bd58a, deployed 2026-10-05. Settings makes named tokens (ipx_ and 256 random bits), sent as Authorization: Bearer; only their SHA-256 is kept, in the new api_tokens table, and an unknown or revoked one gets a 401. On the LAN (192.168.1.130:8099) a token works as it is; through the tunnel Cloudflare Access needs a service token beside it, which docs/sso.md describes.