Skip to content

Credentials and Security

The data feed uses two credentials. Keeping them apart is what keeps your account safe.

Credential Starts with What it can do Where it may live
API key sb_live_ Open and manage feeds for your account On a computer or server you control only. Never in a browser, a mobile app or a public repository
Feed token sbf_ Read and delete one feed, and nothing else May reach a browser, but never in a URL

The API Key

Your API key can open feeds on every machine its scope covers, so treat it like a password:

  • Keep it in an environment variable, a secrets manager or a password manager. The scorbit-feed agent reads it only from the SCORBIT_API_KEY environment variable, never from a command-line argument, and never logs or serves it.
  • Never put it in a web page, a URL, a screenshot or a shared OBS scene collection.
  • Revoke keys you no longer use. The Developer page shows each key you hold.

The @scorbit/feed library refuses to use an API key where a browser window exists.

The Feed Token

When a feed is opened, Scorbit returns a feed token for that one feed, once. Whoever holds it can read that feed and delete it, so even though it is far less powerful than an API key, it is still a secret:

  • Keep it out of URLs, query strings and OBS browser-source addresses. Those end up in logs, browser history, screenshots and shared scene collections.
  • Hand it to a page in a response body (for example from an authenticated fetch), never in the page address.

There are two safe ways to give a page what it needs:

  1. Run the agent. The agent holds the API key and feed token and serves your page only feed data on localhost. The page never sees a credential. This is the right choice for OBS.
  2. Relay through your own server. Your server holds the feed and passes updates on to the page, so the page never sees a credential. This is the most reliable choice for a public website. See Building Your Own.

A page can also hold the feed token itself and attach in the browser. That suits your own kiosk or venue display. On a public page, a visitor who copies the token could end the live feed, which loses nothing but interrupts the display until your server opens a new one. See Browser Page.

Running the Agent Safely

  • By default the agent listens on 127.0.0.1 only. Binding it to another address with --host exposes the feed to your network.
  • By default it accepts browser requests only from http://localhost and http://127.0.0.1 pages, plus any origin you add with --cors-origin. --allow-file-origin widens this to any page that sends Origin: null, which includes sandboxed iframes on any website, so avoid it where you can.
  • While listening on 127.0.0.1 (the default), it refuses requests whose Host is not a loopback name such as localhost or 127.0.0.1, which blocks DNS-rebinding attacks from web pages. With --host set to another address this check is off, so only do that on a network you trust.
  • With --static, it serves only web file types from your folder: never a dotfile such as .env, and never anything outside the folder.

See The Agent for details.

If a Credential Is Exposed

  1. Revoke the API key on the Developer page in Scorbit Console. Every feed opened with it ends.
  2. Stop any live feed you don't recognize from the same page.
  3. Report it to security@scorbit.io, as the Developer Terms require.
  4. Generate a new key and update the computers or servers that use it.