Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
25 changes: 24 additions & 1 deletion src/security.rst
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,30 @@ ActivityWatch is only as secure as your system

Some things we can't protect against. Examples are malware running on the same host and anything that can access the database file.

As an example, ActivityWatch is not secure on systems with multiple users (due to there being no API authentication).
As an example, ActivityWatch is not secure on systems with multiple users, since the API is unauthenticated by default (see `API authentication`_ below).


API authentication
------------------

By default, the ActivityWatch API requires no authentication: any process that can reach the server (normally only processes on the same machine, since it listens on ``localhost``) can read, write, and delete all data.

``aw-server-rust`` supports **opt-in** API key authentication. To enable it, set an API key under the ``[auth]`` section of the server's ``config.toml`` (see `directories <config-directory>` for its location) and restart the server:

.. code-block:: toml

[auth]
api_key = "your-secret-key-here"

When an API key is set, every request to ``/api/*`` (except ``GET /api/0/info``) must include the header ``Authorization: Bearer <api_key>``, otherwise the server responds with ``401 Unauthorized``. An empty ``api_key`` leaves authentication disabled.

Things to keep in mind:

- Authentication is disabled by default on desktop, so existing setups keep working unchanged.
- It is only supported by ``aw-server-rust``. ``aw-server`` (Python) does not support it.
- Every client must send the key. ``aw-sync`` reads it from the server config automatically, and ``aw-client-rust`` accepts one via ``AwClient::new_with_api_key``, but other clients and watchers may not support it yet and will fail with ``401`` once it's enabled.
- The key protects the API, not the data at rest: anything that can read the config file or the database file can still access your data.
- Authentication does not make it safe to expose the server on a network. The API is served over plain HTTP, so see `remote-server` before doing so.


Deleting sensitive data
Expand Down
Loading