Security

Lock down an instance: the admin account, its secrets, HTTPS and what users and forms may do


For administrators preparing an instance for production, and for security reviews of an existing one.


In this section

Each topic has a page of its own:

Page What it covers
Hardening The admin account, the database, expressions, job data, optional features and role options
HTTPS Where TLS ends, serving HTTPS from the application, and replacing the sample certificate
Secrets and encryption ENCRYPTION_SECRET, ACCESS_TOKEN_SECRET, and token lifetimes

Related pages: Authentication for sign-in methods, Launch validation for server-side checks of every launch, and the Security variables.