Sign-in and security

The dashboard lives on the public internet, so a password is never enough on its own.

Ways in

Brakes

Sessions

Sessions last 30 days of use (90 at most). Settings lists them with device and address; sign any out, or all others. Sensitive changes (passkeys, password, authenticator, recovery codes, API keys, alert channels, deleting monitors, exports) need a sign-in within the last 12 hours; otherwise Farsight asks you to confirm with a passkey tap or password and code, then carries on.

Data

Passwords are hashed with Argon2id. Sessions, API keys, links and recovery codes are stored only as SHA-256 hashes. Channel secrets, monitor credentials and the authenticator secret are encrypted (AES-256-GCM) with a key that lives only in the data folder (master.key). The data folder is readable by the service user alone.

Network

Farsight never probes cloud metadata addresses, and by default refuses private targets (loopback, private networks, CGNAT and Tailscale addresses) so an API key cannot reach services that were never meant to be public. A signed-in owner can allow private targets in Settings for a home network. The dashboard sends a strict Content Security Policy, HSTS and no-framing headers.