Skip to content

docs(security): document opt-in API key authentication - #194

Open
0xbrayo wants to merge 1 commit into
ActivityWatch:masterfrom
0xbrayo:docs/security-opt-in-auth
Open

0xbrayo wants to merge 1 commit into
ActivityWatch:masterfrom
0xbrayo:docs/security-opt-in-auth

Conversation

@0xbrayo

@0xbrayo 0xbrayo commented Oct 4, 2026

Copy link
Copy Markdown
Member

The security page currently says ActivityWatch has no API authentication. aw-server-rust now supports opt-in API key auth (ActivityWatch/aw-server-rust#585), so this documents it.

Changes to security.rst:

  • Reword the multi-user note: the API is unauthenticated by default, linking to the new section.
  • Add an API authentication section covering:
    • enabling it via [auth] api_key in the server's config.toml
    • the Authorization: Bearer <key> requirement on /api/* (with GET /api/0/info exempt), and 401 on failure
    • that it's off by default and only supported by aw-server-rust (not aw-server-python)
    • client support: aw-sync reads the key from the server config; aw-client-rust accepts one via new_with_api_key; other clients/watchers may not support it yet
    • that it doesn't protect data at rest, and doesn't make exposing the server on a network safe (plain HTTP; links to the remote-server page)

Note: the auth change isn't in a tagged aw-server-rust release yet.

@0xbrayo

0xbrayo commented Oct 4, 2026

Copy link
Copy Markdown
Member Author

🤖 Claude, on behalf of @0xbrayo

@greptile review

@0xbrayo

0xbrayo commented Oct 4, 2026

Copy link
Copy Markdown
Member Author

🤖 Claude, on behalf of @0xbrayo

@greptileai review

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant