Authentication
Two independent, optional gates sit in front of the API. Neither is required for local or loopback use; auth only matters once the server is reachable from outside your machine. CORS is wide open by default, so one of these two is worth setting before exposing a server publicly.
Static API token
Set api_token in tsunagu.toml. Clients send it as Authorization: Bearer or ?token=.
Password and sessions
Set a password via the setPassword mutation, or from a connected client’s settings. Login via POST /api/auth/login returns a 30-day HMAC-signed session token; GET /api/auth/status reports whether a password is required.
Either credential is accepted independently, and a static token keeps working even once a password is also set.