English
Security Overview
Two authentication layers
| Layer | Purpose |
|---|---|
| IPA Harbor admin | Manage the web app (settings, users). JWT in authToken cookie. |
| Apple ID (ipatool) | App Store search and downloads. Stored in encrypted keychain data under /app/data. |
Apple ID login in the UI drives ipatool only — it is separate from admin Passkey/password.
Self-hosting expectations
- Run IPA Harbor on infrastructure you control.
- Do not share admin credentials or Apple ID with untrusted co-hosts.
- Use HTTPS and strict
ALLOWED_DOMAINSon the public internet. - Official image only:
uuphy/ipa-harbor.
Recovery
The ADMIN_INIT_PIN from deployment is used to verify recovery when reset is enabled (ADMIN_RECOVERY_ENABLED=true). For /recover, see Forgot admin password.
If a Passkey is unavailable, sign in with the admin username and password, then register a new one.