Customization

Server auth & app lock

Two separate lock layers exist, configured from Settings → Auth, and they don’t interact with each other.

Server password

Requiring a password protects the Tsunagu server itself once it’s reachable from outside localhost. Setting one issues a token stored locally through the OS credential store; disabling it clears that token. A static API token, if the server operator has set one, keeps working alongside a password rather than replacing it. See Tsunagu → Authentication for how the server enforces this.

App lock

A numeric PIN (up to 8 digits) can be required at Moku startup; leaving it empty disables the lock. On Windows, Windows Hello can stand in for typing the PIN, but only once a PIN has already been set.