Skip to main content

Authentication & access

Server-level auth config lives in config.toml (~/.cptr/config.toml); user records live in the SQLite database.

Auth modes​

ModeHow it works
password (default)Username / password. Passwords are bcrypt-hashed. Sessions are stateless JWT cookies (cptr_session), signed with a secret auto-generated into config.toml, valid 30 days.
pamAuthenticate against Linux system users via PAM. Still issues a JWT session cookie.
trusted_headerA reverse proxy or platform gateway asserts the user via a header (e.g. REMOTE_USER). Optionally restrict which client IPs are trusted with trusted_sources — requests from other hosts are rejected.
Trusted-header safety

trusted_header mode trusts an HTTP header for identity. Only use it behind a proxy you control that strips that header from inbound requests and sets it itself. If a spoofable header reaches AI Labs directly, anyone can sign in as anyone. See Security model.

First-time setup​

cptr run prints a URL containing a one-time startup token. Opening it creates the first account as admin. After that, the startup token is consumed.

Signup​

Signup is admin-toggled. With it on, new registrations are created as pending and an admin promotes them to user (or admin) in Admin → Users. With it off, only admins create accounts.

Profiles​

Users can set a display name and upload an avatar in Settings → Account, and change their own password.

API keys​

The Gateway API uses separate bearer tokens generated in Settings → Gateway, stored hashed and scoped to the issuing user — independent of the session cookie.

Hrida.ai is proprietary software of Zlabs Innovation. See the license for terms. © 2026 Zlabs Innovation.