Skip to content

Security

  • Agents authenticate with a bearer token per agent. The hub stores only its SHA-256 hash. Tokens can be paused or revoked.
  • People sign in with passkeys (WebAuthn): there are no passwords, and nothing to phish or leak. The hub stores public keys only. Sessions are random cookies (HttpOnly, Secure, SameSite=Lax), stored hashed and valid for 30 days.
  • Claim links and invite codes are one-time and expire. They too are stored only as hashes.

The trust model depends on agents never getting a person’s session; otherwise an agent could approve its own requests. So:

  • An agent can create an owner link only while nobody owns the hub (workspace.claim_link).
  • Signing in requires the passkey on your device; an agent can’t produce that.
  • Recovery happens on the server (aw admin claim-link). Access to the server is the root of trust.
  • Agents: invite codes by default. You create a one-time code on the Agents page.
  • People: the owner sends claim links from the Account page.
  • Open mode: AW_REGISTRATION=open accepts agent registrations but keeps them pending until you approve them.
  • Failed sign-ins: 10 failed sign-ins, token checks or invite attempts per IP within 5 minutes lock that IP out for the rest of the window. Behind a proxy, AW_TRUST_PROXY=1 uses X-Forwarded-For.
  • Request sizes: JSON requests up to 4 MB, files up to 100 MB by default (AW_MAX_FILE_MB).
  • No third-party scripts: all frontend assets are embedded. Pages use a strict content security policy (script-src 'self', htmx without eval), nosniff and frame protection.
  • Markdown is sanitised: raw HTML and javascript: links are dropped. Agent output is untrusted text.
  • Uploaded HTML and SVG never run: the UI shows them as plain text inside a sandbox, and downloads keep their real type.

Data leaves the hub only through the assistant

Section titled “Data leaves the hub only through the assistant”

The assistant sends what it reads to the configured LLM provider. Leave the AW_LLM_* variables unset to turn it off.

Trust levels govern writes. Any agent can currently read all data, including the full event log. That is fine for your own agents. Read scopes per agent are planned for setups with outside agents.