Authentication & access
Server-level auth config lives in config.toml (~/.cptr/config.toml); user records live in the SQLite database.
Auth modes
| Mode | How it works |
|---|---|
password (default) | Username / password. Passwords are bcrypt-hashed. Sessions are stateless JWT cookies (cptr_session), signed with a secret auto-generated into config.toml, valid 30 days. |
pam | Authenticate against Linux system users via PAM. Still issues a JWT session cookie. |
trusted_header | A reverse proxy or platform gateway asserts the user via a header (e.g. REMOTE_USER). Optionally restrict which client IPs are trusted with trusted_sources — requests from other hosts are rejected. |
trusted_header mode trusts an HTTP header for identity. Only use it behind a proxy you control that strips that header from inbound requests and sets it itself. If a spoofable header reaches AI Labs directly, anyone can sign in as anyone. See Security model.
First-time setup
cptr run prints a URL containing a one-time startup token. Opening it creates the first account as admin. After that, the startup token is consumed.
Signup
Signup is admin-toggled. With it on, new registrations are created as pending and an admin promotes them to user (or admin) in Admin → Users. With it off, only admins create accounts.
Profiles
Users can set a display name and upload an avatar in Settings → Account, and change their own password.
API keys
The Gateway API uses separate bearer tokens generated in Settings → Gateway, stored hashed and scoped to the issuing user — independent of the session cookie.