Skip to content

Security Overview ​

Two authentication layers ​

LayerPurpose
IPA Harbor adminManage the web app (settings, users). JWT in authToken cookie.
Apple ID (ipatool)App Store search and downloads. Stored in encrypted keychain data under /app/data.

Apple ID login in the UI drives ipatool only — it is separate from admin Passkey/password.

Self-hosting expectations ​

  • Run IPA Harbor on infrastructure you control.
  • Do not share admin credentials or Apple ID with untrusted co-hosts.
  • Use HTTPS and strict ALLOWED_DOMAINS on the public internet.
  • Official image only: uuphy/ipa-harbor.

Recovery ​

The ADMIN_INIT_PIN from deployment is used to verify recovery when reset is enabled (ADMIN_RECOVERY_ENABLED=true). For /recover, see Forgot admin password.

If a Passkey is unavailable, sign in with the admin username and password, then register a new one.