Credentials and Security¶
The data feed uses two credentials. Keeping them apart is what keeps your account safe.
| Credential | Starts with | What it can do | Where it may live |
|---|---|---|---|
| API key | sb_live_ |
Open and manage feeds for your account | On a computer or server you control only. Never in a browser, a mobile app or a public repository |
| Feed token | sbf_ |
Read and delete one feed, and nothing else | May reach a browser, but never in a URL |
The API Key¶
Your API key can open feeds on every machine its scope covers, so treat it like a password:
- Keep it in an environment variable, a secrets manager or a password manager. The
scorbit-feedagent reads it only from theSCORBIT_API_KEYenvironment variable, never from a command-line argument, and never logs or serves it. - Never put it in a web page, a URL, a screenshot or a shared OBS scene collection.
- Revoke keys you no longer use. The Developer page shows each key you hold.
The @scorbit/feed library refuses to use an API key where a browser window exists.
The Feed Token¶
When a feed is opened, Scorbit returns a feed token for that one feed, once. Whoever holds it can read that feed and delete it, so even though it is far less powerful than an API key, it is still a secret:
- Keep it out of URLs, query strings and OBS browser-source addresses. Those end up in logs, browser history, screenshots and shared scene collections.
- Hand it to a page in a response body (for example from an authenticated
fetch), never in the page address.
There are two safe ways to give a page what it needs:
- Run the agent. The agent holds the API key and feed token and serves your page only feed data
on
localhost. The page never sees a credential. This is the right choice for OBS. - Relay through your own server. Your server holds the feed and passes updates on to the page, so the page never sees a credential. This is the most reliable choice for a public website. See Building Your Own.
A page can also hold the feed token itself and attach in the browser. That suits your own kiosk or venue display. On a public page, a visitor who copies the token could end the live feed, which loses nothing but interrupts the display until your server opens a new one. See Browser Page.
Running the Agent Safely¶
- By default the agent listens on
127.0.0.1only. Binding it to another address with--hostexposes the feed to your network. - By default it accepts browser requests only from
http://localhostandhttp://127.0.0.1pages, plus any origin you add with--cors-origin.--allow-file-originwidens this to any page that sendsOrigin: null, which includes sandboxed iframes on any website, so avoid it where you can. - While listening on
127.0.0.1(the default), it refuses requests whoseHostis not a loopback name such aslocalhostor127.0.0.1, which blocks DNS-rebinding attacks from web pages. With--hostset to another address this check is off, so only do that on a network you trust. - With
--static, it serves only web file types from your folder: never a dotfile such as.env, and never anything outside the folder.
See The Agent for details.
If a Credential Is Exposed¶
- Revoke the API key on the Developer page in Scorbit Console. Every feed opened with it ends.
- Stop any live feed you don't recognize from the same page.
- Report it to security@scorbit.io, as the Developer Terms require.
- Generate a new key and update the computers or servers that use it.