Skip to content
rev0Docs

Security

The permission gate (The permission gate) decides what an agent may do. It does not decide who may drive the board. Whoever reaches the board’s API can create a ticket that asks for anything, approve every permission request, and turn the gate’s lists off in Settings. So the question that matters first is who can reach the port.

  • Loopback by default. rev0 serve binds to 127.0.0.1, so out of the box only this machine can reach it, and no token is needed.

  • Refuses an open bind. Binding to any other address with no REV0_AUTH_TOKEN set is refused at startup. REV0_ALLOW_INSECURE=1 overrides that and logs a loud warning on every start; do not use it on a network you do not fully control.

  • One token for everything. With REV0_AUTH_TOKEN set, a browser signs in once at /login and keeps a cookie; the CLI, the MCP server and the runner send the token as Authorization: Bearer. The one-line installer generates a token for you.

  • Human-only actions. Some actions only a signed in browser session may take, never a Bearer token, so an agent (which holds the token) cannot reach them:

    • answering a tool request (allowing or denying it);
    • minting, listing and revoking public share links, and stopping all public sharing at once;
    • changing which plugin sources load, which commit they are pinned to and which plugins you trust, and fetching a plugin source;
    • adding, editing, reordering and deleting apps in the App Space;
    • installing a browser extension on the ticket’s computer, and changing its session mode;
    • writing to the Knowledge Base directly (agents propose pages into a review queue instead);
    • testing an MCP server and reading the MCP and skills inventories.

    On a loopback board with no token set there is no browser session to check, so these are open to anything on this machine, like the rest of the board.

  • The agent’s environment can be narrowed. By default an agent’s processes inherit the board’s environment, token included. Allow-list the agent’s environment builds their environment from an allow-list instead; see What an approved command can read.

  1. Generate a token and set it: REV0_AUTH_TOKEN=... in ~/.rev0/.env, or --auth-token.
  2. Prefer a private network (a Tailscale tailnet) over a public one, and HTTPS over plain HTTP. Reach the board from your phone covers each option.
  3. On a public tunnel, add an identity layer in front of the token when you can.
  4. To show someone a result, share one artifact, ticket or board with a capability link rather than the token (Share a deliverable publicly).

Trusting a plugin’s hooks or tools lets its Python run inside the runner with the board’s full access. Read the code you trust; see Plugin trust.

Follow SECURITY.md rather than opening a public issue.