Skip to content

Operator Login ​

The console requires a username and password before it shows any project data. This page covers first login, changing your password, what to do when you are locked out or have forgotten the password or username, and the host-only AUTH=off switch.

First login and the setup code ​

The first time the console starts with no admin account yet, it shows Create the admin account instead of the sign-in form. You need a setup code, printed on the host console (the terminal of the machine running the stack):

bash
nikto-launcher admin setup-code

The launcher's up and update commands also print the setup code automatically when no admin account exists yet.

The code is shown as XXXX-XXXX-XXXX-XXXX, is valid for 24 hours, and can be used once. On the setup screen, enter the code, choose a username (default admin) and a password that meets the password rules, then click Create admin account. You are signed in immediately.

If someone else creates the admin account while you have the setup screen open, the console tells you an admin already exists and switches to the sign-in form.

Signing in and out ​

Enter your username and password on the sign-in screen and click Sign in. A session lasts 7 days from sign-in, shown on Settings → Security as the time it expires. There is no sliding renewal — signing in again resets the clock.

The session cookie is always HttpOnly and SameSite=Strict. It is also marked Secure when the console is served over HTTPS; on plain HTTP (the default http://localhost console, or an SSH tunnel to it) it is not, because some browsers, Safari among them, refuse Secure cookies on plain HTTP and the flag adds no protection when the traffic is unencrypted anyway. If a browser still does not keep the cookie, the sign-in screen says so; open the console at http://localhost or through an SSH tunnel to it (see Remote Access).

To sign out, use Sign out in the top bar. This ends the session on the server as well as in your browser, so the same session cannot be reused from another tab or device.

If your session expires while the console is open, the next action shows the sign-in screen again. Nothing you were doing is lost beyond needing to sign in again.

Changing your password ​

Open Settings → Security. Under Change password, enter your current password, a new password meeting the password rules below, and confirm it, then click Change password.

Changing your password always requires the current one — there is no way to set a new password from inside the console without it. Once the change succeeds, every other session for your account is signed out; the browser you just changed the password from stays signed in.

Password rules ​

A password must be:

  • At least 12 characters
  • At least one uppercase letter
  • At least one lowercase letter
  • At least one digit
  • At least one special character (anything that is not a letter or a digit)
  • Different from the username

The setup and change-password forms show a checklist next to the password field that updates as you type, so you can see exactly which rule still needs to be met.

Locked out? ​

Ten wrong passwords in a row lock an account for 5 minutes. A username that is not an account locks the same way, so a lock never confirms which names exist. While locked, even the right password is refused, and the sign-in screen shows when the lock ends.

Who can lock you out: anyone who can reach the sign-in page. On a loopback-only console that means another user or process on the same machine, or anyone sharing the SSH tunnel you use to reach it (see Remote Access). They do not need your password, only ten wrong guesses, and they can repeat it every 5 minutes. There is no per-address limit: behind the console's web server every browser appears to come from the same address, so a limit per address would lock everyone out at once.

The fix: sign in from the host. On the machine running the stack, run:

bash
nikto-launcher admin login-link

It prints a sign-in link such as http://localhost:3001/#login=... (the port is UI_PORT from .env). Open it in a browser on that machine, or through your SSH tunnel to it. The link:

  • signs you in even while the account is locked, and clears the lock;
  • is valid for 10 minutes and works once. After that, or if it was already used, the sign-in screen says so; run the command again for a new one;
  • does not change your password.

The console removes the link from the address bar as soon as it opens. The link stops working once it has signed you in, or after 10 minutes, whichever comes first (your browser's own history may still list the address). Until then, treat it like a password, and do not paste it into chat or tickets.

If signing in with a link fails with a server error rather than the "invalid, expired or already used" message, the link may already be used up: run the command again for a new one.

If more than one admin account exists, add --user NAME.

Forgotten password ​

If you have forgotten the password, as opposed to being locked out, run the host-side reset:

bash
nikto-launcher admin reset-password

This prints a new, randomly generated password, signs out every existing session for the account, and clears any lock. Use the printed password to sign in, then change it to one you will remember from Settings → Security.

If more than one admin account exists, add --user NAME to reset a specific one.

Forgotten username ​

Run the host-side status command:

bash
nikto-launcher admin status

This lists every admin account that exists, without needing to sign in.

All the nikto-launcher admin subcommands, with flags and exit codes: Host Commands.

Turning login off (AUTH=off) ​

Login can be disabled entirely by setting AUTH=off in .env and restarting the stack. With login off, the console opens straight to your projects — there is no sign-in screen and no session. Settings → Security and the /nikto-diag status page both show that login is disabled, and the API logs a warning at every startup while it is off.

AUTH=off is a host-only setting. It cannot be turned off from inside the console — there is no UI toggle for it, on purpose. Anyone who can reach the console with login off has full control of the platform: every project, every scan result, and every setting.

Only use AUTH=off on a single-user machine where no one else can reach the console. If you are using Remote Access or sharing the host with anyone else, leave login on.

  • Settings — the Security tab and other settings
  • Remote Access — using the console from another computer, and why login does not change the exposure rules
  • Docker Deployment — the AUTH environment variable

Proprietary software. Licensed for use under the End User License Agreement.