Tsunagu

Authentication

Two independent, optional gates sit in front of the API. Neither is required for local or loopback use; auth only matters once the server is reachable from outside your machine. CORS is wide open by default, so one of these two is worth setting before exposing a server publicly.

Static API token

Set api_token in tsunagu.toml. Clients send it as Authorization: Bearer or ?token=.

Password and sessions

Set a password via the setPassword mutation, or from a connected client’s settings. Login via POST /api/auth/login returns a 30-day HMAC-signed session token; GET /api/auth/status reports whether a password is required.

Either credential is accepted independently, and a static token keeps working even once a password is also set.