[{"data":1,"prerenderedAt":1142},["ShallowReactive",2],{"docs:/docs/self-hosting/static-auth":3},{"id":4,"title":5,"body":6,"description":1134,"extension":1135,"meta":1136,"navigation":1137,"path":1138,"seo":1139,"stem":1140,"__hash__":1141},"docs/docs/self-hosting/static-auth.md","Static Auth File",{"type":7,"value":8,"toc":1120},"minimark",[9,13,22,103,108,320,330,335,524,535,539,545,661,665,668,703,733,737,752,756,765,870,899,903,906,935,953,1024,1028,1041,1047,1051,1082,1099,1103,1116],[10,11,5],"h1",{"id":12},"static-auth-file",[14,15,16,17,21],"p",{},"With its default auth backend, ",[18,19,20],"code",{},"static",", kraken reads tokens and their grants from a JSON file. There is no database and no other service: change the file, and kraken picks the change up without a restart.",[23,24,25,41],"table",{},[26,27,28],"thead",{},[29,30,31,35,38],"tr",{},[32,33,34],"th",{},"Setting",[32,36,37],{},"Default",[32,39,40],{},"Meaning",[42,43,44,59,82],"tbody",{},[29,45,46,52,56],{},[47,48,49],"td",{},[18,50,51],{},"AUTH_BACKEND",[47,53,54],{},[18,55,20],{},[47,57,58],{},"Selects this backend",[29,60,61,66,71],{},[47,62,63],{},[18,64,65],{},"AUTH_FILE",[47,67,68],{},[18,69,70],{},"/app/examples/auth.json",[47,72,73,74,77,78,81],{},"Path of the file inside the container. The repository's ",[18,75,76],{},"docker-compose.yml"," mounts ",[18,79,80],{},"./examples/auth.json"," there, read-only.",[29,83,84,89,94],{},[47,85,86],{},[18,87,88],{},"AUTH_ALLOW_ALL",[47,90,91],{},[18,92,93],{},"false",[47,95,96,97,102],{},"Accept any token with access to everything. Insecure; see ",[98,99,101],"a",{"href":100},"#allow-all-mode","allow-all mode",".",[104,105,107],"h2",{"id":106},"format","Format",[109,110,115],"pre",{"className":111,"code":112,"language":113,"meta":114,"style":114},"language-json shiki shiki-themes github-light github-dark","{\n  \"tokens\": {\n    \"dev-token-alice\": {\n      \"actorTokenId\": \"alice\",\n      \"projectId\": \"demo-project\",\n      \"organizationId\": \"demo-org\",\n      \"actorType\": \"user\",\n      \"allowedTopics\": [\n        {\n          \"pattern\": \"demo/general/#\",\n          \"permission\": \"pubSub\",\n          \"room_id\": \"room-general\",\n          \"room_slug\": \"general\",\n          \"app_id\": \"demo-app\",\n          \"app_name\": \"demo\"\n        }\n      ]\n    }\n  }\n}\n","json","",[18,116,117,126,136,144,160,173,186,199,208,214,227,240,253,266,279,290,296,302,308,314],{"__ignoreMap":114},[118,119,122],"span",{"class":120,"line":121},"line",1,[118,123,125],{"class":124},"sVt8B","{\n",[118,127,129,133],{"class":120,"line":128},2,[118,130,132],{"class":131},"sj4cs","  \"tokens\"",[118,134,135],{"class":124},": {\n",[118,137,139,142],{"class":120,"line":138},3,[118,140,141],{"class":131},"    \"dev-token-alice\"",[118,143,135],{"class":124},[118,145,147,150,153,157],{"class":120,"line":146},4,[118,148,149],{"class":131},"      \"actorTokenId\"",[118,151,152],{"class":124},": ",[118,154,156],{"class":155},"sZZnC","\"alice\"",[118,158,159],{"class":124},",\n",[118,161,163,166,168,171],{"class":120,"line":162},5,[118,164,165],{"class":131},"      \"projectId\"",[118,167,152],{"class":124},[118,169,170],{"class":155},"\"demo-project\"",[118,172,159],{"class":124},[118,174,176,179,181,184],{"class":120,"line":175},6,[118,177,178],{"class":131},"      \"organizationId\"",[118,180,152],{"class":124},[118,182,183],{"class":155},"\"demo-org\"",[118,185,159],{"class":124},[118,187,189,192,194,197],{"class":120,"line":188},7,[118,190,191],{"class":131},"      \"actorType\"",[118,193,152],{"class":124},[118,195,196],{"class":155},"\"user\"",[118,198,159],{"class":124},[118,200,202,205],{"class":120,"line":201},8,[118,203,204],{"class":131},"      \"allowedTopics\"",[118,206,207],{"class":124},": [\n",[118,209,211],{"class":120,"line":210},9,[118,212,213],{"class":124},"        {\n",[118,215,217,220,222,225],{"class":120,"line":216},10,[118,218,219],{"class":131},"          \"pattern\"",[118,221,152],{"class":124},[118,223,224],{"class":155},"\"demo/general/#\"",[118,226,159],{"class":124},[118,228,230,233,235,238],{"class":120,"line":229},11,[118,231,232],{"class":131},"          \"permission\"",[118,234,152],{"class":124},[118,236,237],{"class":155},"\"pubSub\"",[118,239,159],{"class":124},[118,241,243,246,248,251],{"class":120,"line":242},12,[118,244,245],{"class":131},"          \"room_id\"",[118,247,152],{"class":124},[118,249,250],{"class":155},"\"room-general\"",[118,252,159],{"class":124},[118,254,256,259,261,264],{"class":120,"line":255},13,[118,257,258],{"class":131},"          \"room_slug\"",[118,260,152],{"class":124},[118,262,263],{"class":155},"\"general\"",[118,265,159],{"class":124},[118,267,269,272,274,277],{"class":120,"line":268},14,[118,270,271],{"class":131},"          \"app_id\"",[118,273,152],{"class":124},[118,275,276],{"class":155},"\"demo-app\"",[118,278,159],{"class":124},[118,280,282,285,287],{"class":120,"line":281},15,[118,283,284],{"class":131},"          \"app_name\"",[118,286,152],{"class":124},[118,288,289],{"class":155},"\"demo\"\n",[118,291,293],{"class":120,"line":292},16,[118,294,295],{"class":124},"        }\n",[118,297,299],{"class":120,"line":298},17,[118,300,301],{"class":124},"      ]\n",[118,303,305],{"class":120,"line":304},18,[118,306,307],{"class":124},"    }\n",[118,309,311],{"class":120,"line":310},19,[118,312,313],{"class":124},"  }\n",[118,315,317],{"class":120,"line":316},20,[118,318,319],{"class":124},"}\n",[14,321,322,323,326,327,329],{},"Each key under ",[18,324,325],{},"tokens"," is a token a client may connect with. Use long random strings: anyone who has one can connect as that actor. Keys outside ",[18,328,325],{}," are ignored.",[331,332,334],"h3",{"id":333},"token-fields","Token fields",[23,336,337,349],{},[26,338,339],{},[29,340,341,344,347],{},[32,342,343],{},"Field",[32,345,346],{},"Required",[32,348,40],{},[42,350,351,371,383,398,413,433,453,469,484,508],{},[29,352,353,358,361],{},[47,354,355],{},[18,356,357],{},"actorTokenId",[47,359,360],{},"yes",[47,362,363,364,366,367,370],{},"The actor's id. The client sees it as ",[18,365,357],{}," in the ",[18,368,369],{},"auth"," reply and in presence; kraken uses it to revalidate and as the default load-balance group.",[29,372,373,378,380],{},[47,374,375],{},[18,376,377],{},"allowedTopics",[47,379],{},[47,381,382],{},"The grants. Without any, the token can connect but reach nothing.",[29,384,385,390,392],{},[47,386,387],{},[18,388,389],{},"projectId",[47,391],{},[47,393,394,395,397],{},"Reported back in the ",[18,396,369],{}," reply, and part of every load-balance group name.",[29,399,400,405,407],{},[47,401,402],{},[18,403,404],{},"organizationId",[47,406],{},[47,408,409,410,102],{},"The group kraken counts connections in for ",[18,411,412],{},"maxConnections",[29,414,415,420,422],{},[47,416,417],{},[18,418,419],{},"actorType",[47,421],{},[47,423,424,425,428,429,102],{},"A label, ",[18,426,427],{},"user"," by default. See ",[98,430,432],{"href":431},"/docs/authentication#actor-types","actor types",[29,434,435,439,441],{},[47,436,437],{},[18,438,412],{},[47,440],{},[47,442,443,444,446,447,449,450,102],{},"Connection limit for the token's ",[18,445,404],{},", counted across every token that shares it; it has no effect without an ",[18,448,404],{},". Absent means unlimited. A connect beyond the limit is refused with ",[18,451,452],{},"connection_limit_reached",[29,454,455,460,462],{},[47,456,457],{},[18,458,459],{},"activeSubscriptions",[47,461],{},[47,463,464,465,102],{},"Subscriptions kraken restores when this token reconnects. See ",[98,466,468],{"href":467},"#restoring-subscriptions","restoring subscriptions",[29,470,471,476,478],{},[47,472,473],{},[18,474,475],{},"allowedLobbies",[47,477],{},[47,479,480,481,102],{},"Lobbies the token may subscribe to, as ",[18,482,483],{},"[{ \"lobby_slug\": \"...\", \"lobby_id\": \"...\" }]",[29,485,486,495,497],{},[47,487,488,491,492],{},[18,489,490],{},"appId",", ",[18,493,494],{},"appName",[47,496],{},[47,498,499,500,503,504,102],{},"The app every grant of this token belongs to. Default: the ",[18,501,502],{},"app_id"," of the first grant. See ",[98,505,507],{"href":506},"#one-app-per-token","one app per token",[29,509,510,515,517],{},[47,511,512],{},[18,513,514],{},"scopeSlug",[47,516],{},[47,518,519,520,102],{},"An access scope slug. See ",[98,521,523],{"href":522},"/docs/scopes","Access Scopes",[14,525,526,527,530,531,534],{},"The repository's example file also carries ",[18,528,529],{},"rateLimit",". kraken ignores it: the limit is 50 publishes per second per connection for everyone. It ignores ",[18,532,533],{},"maxMessageSizeBytes"," too; the payload ceiling is a fixed 921,600 bytes. There is no way to configure webhooks in the static file.",[331,536,538],{"id":537},"grant-fields","Grant fields",[14,540,541,542,544],{},"Each entry in ",[18,543,377],{},":",[23,546,547,555],{},[26,548,549],{},[29,550,551,553],{},[32,552,343],{},[32,554,40],{},[42,556,557,599,619,628,638,651],{},[29,558,559,564],{},[47,560,561],{},[18,562,563],{},"pattern",[47,565,566,567,570,571,574,575,578,579,582,583,586,587,590,591,594,595,598],{},"Required. The addresses the grant covers, as ",[18,568,569],{},"app/room/topic",". ",[18,572,573],{},"+"," matches exactly one segment and ",[18,576,577],{},"#"," matches everything after it, so ",[18,580,581],{},"demo/general/#"," covers every topic in room ",[18,584,585],{},"general"," of app ",[18,588,589],{},"demo",", and ",[18,592,593],{},"demo/+/messages"," covers ",[18,596,597],{},"messages"," in every room.",[29,600,601,606],{},[47,602,603],{},[18,604,605],{},"permission",[47,607,608,609,491,612,615,616,102],{},"Required. ",[18,610,611],{},"subscribe",[18,613,614],{},"publish"," or ",[18,617,618],{},"pubSub",[29,620,621,625],{},[47,622,623],{},[18,624,502],{},[47,626,627],{},"The app the grant belongs to. kraken uses it to name its internal topics, so tokens that should reach each other must agree on it.",[29,629,630,635],{},[47,631,632],{},[18,633,634],{},"app_name",[47,636,637],{},"Descriptive",[29,639,640,648],{},[47,641,642,491,645],{},[18,643,644],{},"room_id",[18,646,647],{},"room_slug",[47,649,650],{},"Needed for presence and lobbies. A client sends presence for a room by its slug; kraken finds the room through these two fields. Presence for a slug no grant names is silently ignored.",[29,652,653,658],{},[47,654,655],{},[18,656,657],{},"topic",[47,659,660],{},"An internal topic name for an exact (wildcard-free) pattern. Leave it out unless you know you need it; see below.",[104,662,664],{"id":663},"how-grants-turn-into-topics","How grants turn into topics",[14,666,667],{},"kraken never uses your address as its internal topic directly. It resolves the address through the connection's grants, the same way for a subscribe and a publish:",[669,670,671,684,696],"ol",{},[672,673,674,675,677,678,680,681,683],"li",{},"If a grant's ",[18,676,563],{}," equals the address exactly and has a ",[18,679,657],{},", that ",[18,682,657],{}," is the internal topic.",[672,685,686,687,689,690,692,693,102],{},"Otherwise, if a grant matches the address (exactly, or with ",[18,688,573],{}," and ",[18,691,577],{},"), the internal topic is ",[18,694,695],{},"\u003Capp_id>/\u003Caddress>",[672,697,698,699,702],{},"If no grant matches, the request fails with ",[18,700,701],{},"unknown_topic"," (42940).",[14,704,705,706,716,717,720,721,724,725,491,727,729,730,732],{},"So two tokens reach each other when they resolve the same address to the same internal topic. The simplest way to guarantee that is to ",[707,708,709,710,712,713,715],"strong",{},"leave ",[18,711,657],{}," out and use one ",[18,714,502],{}," per app across the whole file",". Then every token resolves ",[18,718,719],{},"demo/general/messages"," to ",[18,722,723],{},"demo-app/demo/general/messages",", whether its grant is ",[18,726,581],{},[18,728,593],{}," or the exact address. A token whose grant sets ",[18,731,657],{}," resolves that address somewhere else, and does not reach tokens whose grants do not.",[331,734,736],{"id":735},"one-app-per-token","One app per token",[14,738,739,740,742,743,745,746,748,749,751],{},"kraken puts all of a token's grants into one app, and gives every grant that app's id: the token's ",[18,741,490],{}," if it has one, otherwise the ",[18,744,502],{}," of its first grant. A token whose grants span two apps therefore resolves the second app's addresses under the first app's id, and does not reach tokens that hold only the second app. Give such a token its own ",[18,747,490],{}," shared with the tokens it talks to, or use one ",[18,750,502],{}," value for the whole file.",[104,753,755],{"id":754},"restoring-subscriptions","Restoring subscriptions",[14,757,758,759,762,763,544],{},"kraken does not remember what a client subscribed to. When a client reconnects (the SDKs send ",[18,760,761],{},"reconnect: true"," after an unexpected drop), kraken restores the subscriptions its auth backend lists for the actor, and for the static file that is ",[18,764,459],{},[109,766,768],{"className":111,"code":767,"language":113,"meta":114,"style":114},"\"dev-token-carol\": {\n  \"actorTokenId\": \"carol\",\n  \"allowedTopics\": [\n    { \"pattern\": \"demo/general/#\", \"permission\": \"pubSub\", \"app_id\": \"demo-app\", \"room_id\": \"room-general\", \"room_slug\": \"general\" }\n  ],\n  \"activeSubscriptions\": [\"demo/general/messages\"]\n}\n",[18,769,770,777,789,796,847,852,866],{"__ignoreMap":114},[118,771,772,775],{"class":120,"line":121},[118,773,774],{"class":155},"\"dev-token-carol\"",[118,776,135],{"class":124},[118,778,779,782,784,787],{"class":120,"line":128},[118,780,781],{"class":131},"  \"actorTokenId\"",[118,783,152],{"class":124},[118,785,786],{"class":155},"\"carol\"",[118,788,159],{"class":124},[118,790,791,794],{"class":120,"line":138},[118,792,793],{"class":131},"  \"allowedTopics\"",[118,795,207],{"class":124},[118,797,798,801,804,806,808,810,813,815,817,819,822,824,826,828,831,833,835,837,840,842,844],{"class":120,"line":146},[118,799,800],{"class":124},"    { ",[118,802,803],{"class":131},"\"pattern\"",[118,805,152],{"class":124},[118,807,224],{"class":155},[118,809,491],{"class":124},[118,811,812],{"class":131},"\"permission\"",[118,814,152],{"class":124},[118,816,237],{"class":155},[118,818,491],{"class":124},[118,820,821],{"class":131},"\"app_id\"",[118,823,152],{"class":124},[118,825,276],{"class":155},[118,827,491],{"class":124},[118,829,830],{"class":131},"\"room_id\"",[118,832,152],{"class":124},[118,834,250],{"class":155},[118,836,491],{"class":124},[118,838,839],{"class":131},"\"room_slug\"",[118,841,152],{"class":124},[118,843,263],{"class":155},[118,845,846],{"class":124}," }\n",[118,848,849],{"class":120,"line":162},[118,850,851],{"class":124},"  ],\n",[118,853,854,857,860,863],{"class":120,"line":175},[118,855,856],{"class":131},"  \"activeSubscriptions\"",[118,858,859],{"class":124},": [",[118,861,862],{"class":155},"\"demo/general/messages\"",[118,864,865],{"class":124},"]\n",[118,867,868],{"class":120,"line":188},[118,869,319],{"class":124},[14,871,872,873,875,876,878,879,491,881,491,884,689,887,890,891,894,895,102],{},"We tested this against kraken v0.9.0: after a restart, a client using this token received messages on ",[18,874,719],{}," again without subscribing a second time, while the demo tokens, which list no ",[18,877,459],{},", received nothing until they subscribed again. Entries are addresses, or objects with ",[18,880,563],{},[18,882,883],{},"loadBalance",[18,885,886],{},"loadBalanceGroup",[18,888,889],{},"filters",". The list is fixed per token, whatever the client subscribed to; for anything else, subscribe in the client's ",[18,892,893],{},"connect"," handler, as in the ",[98,896,898],{"href":897},"/docs/getting-started#reconnects-what-comes-back-and-what-does-not","Quick Start",[104,900,902],{"id":901},"reloading","Reloading",[14,904,905],{},"kraken checks the file's modification time whenever it looks a token up, and re-reads the file when it has changed. No restart is needed:",[907,908,909,915,921],"ul",{},[672,910,911,914],{},[707,912,913],{},"A new token"," works on its first connection.",[672,916,917,920],{},[707,918,919],{},"A changed grant"," reaches connections made with that token at their next revalidation, within about ten minutes. New connections get it at once, except that kraken may answer a connect from its 30 second cache.",[672,922,923,926,927,930,931,934],{},[707,924,925],{},"A removed token"," is refused for new connections once kraken's 30 second cache of that token expires. Connections already open with it are closed with code ",[18,928,929],{},"4001"," and reason ",[18,932,933],{},"token_revoked"," at their next revalidation, within about ten minutes.",[14,936,937,938,941,942,945,946,615,949,952],{},"If the file stops being valid JSON, kraken logs ",[18,939,940],{},"Failed to parse auth file"," and refuses ",[707,943,944],{},"every"," token until the file is fixed. Check it with ",[18,947,948],{},"python3 -m json.tool auth.json",[18,950,951],{},"jq . auth.json"," before you save it into place.",[954,955,957,972],"callout",{"type":956},"warning",[14,958,959,960,963,964,967,968,971],{},"On Docker Desktop we found that edits made on the host to a ",[707,961,962],{},"single-file"," bind mount (the repository's default, ",[18,965,966],{},"./examples/auth.json:/app/examples/auth.json:ro",") did not reach the container, so kraken kept serving the old tokens. Mounting the ",[707,969,970],{},"directory"," worked:",[109,973,977],{"className":974,"code":975,"language":976,"meta":114,"style":114},"language-yaml shiki shiki-themes github-light github-dark","services:\n  kraken:\n    environment:\n      - AUTH_FILE=/app/auth/auth.json\n    volumes:\n      - ./auth:/app/auth:ro\n","yaml",[18,978,979,988,995,1002,1010,1017],{"__ignoreMap":114},[118,980,981,985],{"class":120,"line":121},[118,982,984],{"class":983},"s9eBZ","services",[118,986,987],{"class":124},":\n",[118,989,990,993],{"class":120,"line":128},[118,991,992],{"class":983},"  kraken",[118,994,987],{"class":124},[118,996,997,1000],{"class":120,"line":138},[118,998,999],{"class":983},"    environment",[118,1001,987],{"class":124},[118,1003,1004,1007],{"class":120,"line":146},[118,1005,1006],{"class":124},"      - ",[118,1008,1009],{"class":155},"AUTH_FILE=/app/auth/auth.json\n",[118,1011,1012,1015],{"class":120,"line":162},[118,1013,1014],{"class":983},"    volumes",[118,1016,987],{"class":124},[118,1018,1019,1021],{"class":120,"line":175},[118,1020,1006],{"class":124},[118,1022,1023],{"class":155},"./auth:/app/auth:ro\n",[104,1025,1027],{"id":1026},"rotating-a-token","Rotating a token",[669,1029,1030,1035,1038],{},[672,1031,1032,1033,102],{},"Add the new token as a second entry with the same ",[18,1034,357],{},[672,1036,1037],{},"Move the client over to the new token.",[672,1039,1040],{},"Delete the old entry.",[14,1042,1043,1044,1046],{},"While two entries share an ",[18,1045,357],{},", revalidation finds the actor through either of them, so connections made with the old token stay up until both entries are gone.",[104,1048,1050],{"id":1049},"allow-all-mode","Allow-all mode",[109,1052,1056],{"className":1053,"code":1054,"language":1055,"meta":114,"style":114},"language-bash shiki shiki-themes github-light github-dark","AUTH_ALLOW_ALL=true docker compose up -d\n","bash",[18,1057,1058],{"__ignoreMap":114},[118,1059,1060,1062,1066,1069,1073,1076,1079],{"class":120,"line":121},[118,1061,88],{"class":124},[118,1063,1065],{"class":1064},"szBVR","=",[118,1067,1068],{"class":155},"true",[118,1070,1072],{"class":1071},"sScJk"," docker",[118,1074,1075],{"class":155}," compose",[118,1077,1078],{"class":155}," up",[118,1080,1081],{"class":131}," -d\n",[14,1083,1084,1085,1088,1089,1092,1093,1095,1096,1098],{},"With ",[18,1086,1087],{},"AUTH_ALLOW_ALL=true",", kraken accepts ",[707,1090,1091],{},"any"," token. The token string itself becomes the actor id, every actor gets ",[18,1094,618],{}," on every topic (",[18,1097,577],{},"), and the file is not read. kraken logs a line saying so for each token it accepts. It exists to try things out on your own machine and must never be set anywhere else: a broker started this way lets anyone who can reach it read and write everything.",[104,1100,1102],{"id":1101},"when-to-move-on","When to move on",[14,1104,1105,1106,1110,1111,1115],{},"The static file suits a fixed set of services and devices. Move to an ",[98,1107,1109],{"href":1108},"/docs/self-hosting/http-auth","HTTP auth service"," or the ",[98,1112,1114],{"href":1113},"/docs/self-hosting/full-stack","full stack"," when you need tokens per user, short-lived browser tokens, changes without editing a file, or webhooks.",[1117,1118,1119],"style",{},"html pre.shiki code .sVt8B, html code.shiki .sVt8B{--shiki-default:#24292E;--shiki-dark:#E1E4E8}html pre.shiki code .sj4cs, html code.shiki .sj4cs{--shiki-default:#005CC5;--shiki-dark:#79B8FF}html pre.shiki code .sZZnC, html code.shiki .sZZnC{--shiki-default:#032F62;--shiki-dark:#9ECBFF}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .s9eBZ, html code.shiki .s9eBZ{--shiki-default:#22863A;--shiki-dark:#85E89D}html pre.shiki code .szBVR, html code.shiki .szBVR{--shiki-default:#D73A49;--shiki-dark:#F97583}html pre.shiki code .sScJk, html code.shiki .sScJk{--shiki-default:#6F42C1;--shiki-dark:#B392F0}",{"title":114,"searchDepth":128,"depth":128,"links":1121},[1122,1126,1129,1130,1131,1132,1133],{"id":106,"depth":128,"text":107,"children":1123},[1124,1125],{"id":333,"depth":138,"text":334},{"id":537,"depth":138,"text":538},{"id":663,"depth":128,"text":664,"children":1127},[1128],{"id":735,"depth":138,"text":736},{"id":754,"depth":128,"text":755},{"id":901,"depth":128,"text":902},{"id":1026,"depth":128,"text":1027},{"id":1049,"depth":128,"text":1050},{"id":1101,"depth":128,"text":1102},"kraken's default auth backend: tokens and their grants in a JSON file that kraken re-reads when it changes. The format, how grants resolve, reloading and revocation, and the insecure AUTH_ALLOW_ALL switch.","md",{},true,"/docs/self-hosting/static-auth",{"title":5,"description":1134},"docs/self-hosting/static-auth","nvgpJFqGGXDLzeGRzacxw1quCGMJ1Mt7uj9iYOx1SuI",1791536075239]