Skip to main content

Security

The Security tab sets cross-origin resource sharing, password requirements, and authentication behavior. Go to SettingsSecurity to access these settings.

CORS settings

Control which origins can access your API.

SettingDescription
Enable CORSWhen turned on, enables CORS for this project.
Allowed OriginsList of allowed CORS origins. Click + Add Origin to add more.

Rate limiting

Set rate limits to prevent abuse.

SettingDefaultDescription
Requests Per Minute60Maximum number of requests allowed per minute.
Burst Limit100Maximum number of concurrent requests allowed.

Other security settings

Set standard security headers.

SettingDefaultDescription
CSP Header Valuedefault-src 'self'Content Security Policy header value.
X-XSS-Protection1; mode=blockX-XSS-Protection header value.
X-Frame-OptionsSAMEORIGINX-Frame-Options header value.

Password policy

Define password requirements for user accounts.

SettingDefaultDescription
Minimum Length8Minimum number of characters required.
Maximum Age (days)90Days before password expiration.
History Count5Number of previous passwords to remember (prevents reuse).

Character requirements

Enable or disable specific character requirements:

RequirementDefaultDescription
Require UppercaseEnabledRequire at least one uppercase letter.
Require LowercaseEnabledRequire at least one lowercase letter.
Require NumbersEnabledRequire at least one number.
Require Special CharactersEnabledRequire at least one special character.

Authentication settings

Set how users authenticate with your application.

SettingDefaultDescription
Auth TypeJWTAuthentication mechanism.
JWT Secret(hidden)Secret key for JWT signing. Click the eye icon to reveal.
Token Expiration (seconds)3600How long access tokens remain valid.
Refresh Token Secret(hidden)Secret key for refresh token signing.
Refresh Token Expiration (seconds)604800How long refresh tokens remain valid (7 days default).
Password Salt Rounds10Number of bcrypt salt rounds for password hashing.
warning

Keep your JWT Secret and Refresh Token Secret secure. Never expose them in client-side code or public repositories.