Skip to main content
Vigolium uses a file-based user system with Bearer token authentication. Each user has a unique access code that serves as their API token.

Users and Roles

Users are defined in a JSON file (default: ~/.vigolium/users.json). On first run, the file is auto-created from the embedded template with randomly generated access codes (prefixed vgl_). Three roles control API access: Default users created on bootstrap:

Login

Exchange a username and access code for user info and a Bearer token.

POST /api/auth/login

This endpoint is publicly accessible (no authentication required). Request body:
Success response (200):
Error responses:

Current User Info

Retrieve the authenticated user’s identity and role.

GET /api/user/info

Requires a valid Bearer token. Success response (200):
Error responses:

Using the Token

Include the token as a Bearer token in the Authorization header for all subsequent API requests:

Optional Per-Project Access Control

Projects can carry an allowlist of users that may access their data — allowed_emails (exact match) or allowed_domains (suffix match) on the project row. The server reads the X-User-Email request header to gate access; a missing header bypasses the check, a present-but-unauthorized email returns 403 Forbidden.
Setting VIGOLIUM_PROJECT_READONLY=true disables all mutating vigolium project CLI subcommands for the calling host.

Disabling Authentication

Set no_auth: true in vigolium-configs.yaml or pass the --no-auth flag to the server command to disable authentication entirely. This is not recommended for production use.