Security
Why the port is the boundary
Section titled “Why the port is the boundary”The permission gate (The permission gate) decides what an agent may do. It does not decide who may drive the board. Whoever reaches the board’s API can create a ticket that asks for anything, approve every permission request, and turn the gate’s lists off in Settings. So the question that matters first is who can reach the port.
What rev0 does about it
Section titled “What rev0 does about it”-
Loopback by default.
rev0 servebinds to127.0.0.1, so out of the box only this machine can reach it, and no token is needed. -
Refuses an open bind. Binding to any other address with no
REV0_AUTH_TOKENset is refused at startup.REV0_ALLOW_INSECURE=1overrides that and logs a loud warning on every start; do not use it on a network you do not fully control. -
One token for everything. With
REV0_AUTH_TOKENset, a browser signs in once at/loginand keeps a cookie; the CLI, the MCP server and the runner send the token asAuthorization: Bearer. The one-line installer generates a token for you. -
Human-only actions. Some actions only a signed in browser session may take, never a Bearer token, so an agent (which holds the token) cannot reach them:
- answering a tool request (allowing or denying it);
- minting, listing and revoking public share links, and stopping all public sharing at once;
- changing which plugin sources load, which commit they are pinned to and which plugins you trust, and fetching a plugin source;
- adding, editing, reordering and deleting apps in the App Space;
- installing a browser extension on the ticket’s computer, and changing its session mode;
- writing to the Knowledge Base directly (agents propose pages into a review queue instead);
- testing an MCP server and reading the MCP and skills inventories.
On a loopback board with no token set there is no browser session to check, so these are open to anything on this machine, like the rest of the board.
-
The agent’s environment can be narrowed. By default an agent’s processes inherit the board’s environment, token included. Allow-list the agent’s environment builds their environment from an allow-list instead; see What an approved command can read.
Exposing the board safely
Section titled “Exposing the board safely”- Generate a token and set it:
REV0_AUTH_TOKEN=...in~/.rev0/.env, or--auth-token. - Prefer a private network (a Tailscale tailnet) over a public one, and HTTPS over plain HTTP. Reach the board from your phone covers each option.
- On a public tunnel, add an identity layer in front of the token when you can.
- To show someone a result, share one artifact, ticket or board with a capability link rather than the token (Share a deliverable publicly).
Plugins that run code
Section titled “Plugins that run code”Trusting a plugin’s hooks or tools lets its Python run inside the runner with the board’s full access. Read the code you trust; see Plugin trust.
Reporting a vulnerability
Section titled “Reporting a vulnerability”Follow SECURITY.md rather than opening a public issue.