Users and Roles
Users are defined in a JSON file (default:~/.vigolium/users.json). On first run, the file is auto-created from the embedded template with randomly generated access codes (prefixed vgl_).
Three roles control API access:
Default users created on bootstrap:
Login
Exchange a username and access code for user info and a Bearer token.POST /api/auth/login
This endpoint is publicly accessible (no authentication required).
Request body:
Current User Info
Retrieve the authenticated user’s identity and role.GET /api/user/info
Requires a valid Bearer token.
Success response (200):
Using the Token
Include the token as a Bearer token in theAuthorization header for all subsequent API requests:
Optional Per-Project Access Control
Projects can carry an allowlist of users that may access their data —allowed_emails (exact match) or allowed_domains (suffix match) on the project row. The server reads the X-User-Email request header to gate access; a missing header bypasses the check, a present-but-unauthorized email returns 403 Forbidden.
VIGOLIUM_PROJECT_READONLY=true disables all mutating vigolium project CLI subcommands for the calling host.
Disabling Authentication
Setno_auth: true in vigolium-configs.yaml or pass the --no-auth flag to the server command to disable authentication entirely. This is not recommended for production use.