FerryDocs
ArchitectureSecurity model

What a token can do

An API token has full access to the server, but not to the account.

Edit on GitHub
API tokenServices, datafull accessAccount/api/v1/auth/…

A token reads each variable and each datastore password through the API.

1 / 4

Treat a token like a root password

Each has the same access. A person who has one token can read all your secrets and delete all your services.

What a token cannot do

A token cannot use the (/api/v1/auth/…). They control:

  • the password
  • the sessions
  • the tokens
  • the approval of a ferry login

These endpoints accept only the session of the dashboard. Thus a stolen token cannot change the password or make more tokens.

Each request needs a proof

Each /api/v1 request needs an API token or the session cookie. This includes routes that do not exist. The exceptions are in Endpoints with no authentication.

On this page