docs

Security and trust

Keep Hugin's CA-bearing proxy off the open internet with token auth and strict role checks, and verify the binary you run is a genuine signed release.

Hugin sits in the middle of your HTTPS traffic and runs with enough privilege to read and rewrite it. Two questions follow: who can reach the instance you run, and whether the binary you launched is the real one. This page covers both.

Run it safely

To decrypt HTTPS, the Proxy holds a certificate authority (CA) private key. Anyone who can reach that key, or the control API sitting behind it, can read and modify HTTPS traffic for every browser that trusts your CA. Treat the control port like a credential: don't expose it to the internet, and run hugin ca untrust when you finish a session.

hugin start listens on 127.0.0.1 only. hugin serve is the shared-team mode: it binds 0.0.0.0, turns token auth on, and mints a token if you have none. --no-auth removes that gate — use it only on a network you fully control.

On any instance another machine can reach, set HUGIN_REST_RBAC_STRICT=1. Without it, an authenticated request that carries no X-Hugin-Role header is treated as a full admin. Strict mode drops an unidentified caller to read-only, so writing, scanning, and admin actions need an explicit role. The desktop app talks to itself in-process and is unaffected.

Two endpoints answer without auth by default: /openapi.json (the route list) and /api/health (proxy up or down). Neither returns flow, scope, or project data. If the bind is anything but loopback and you want them closed, set HUGIN_OPENAPI_REQUIRES_AUTH=1 and HUGIN_HEALTH_REQUIRES_AUTH=1. As always, only point Hugin at targets you are authorised to test — see installation.

Verify what you run

Every release binary is signed with an Ed25519 key whose public half ships inside the app (a61ff9262c4509a7879ddaa5a8d86345ef805f6ddced28b097bf58dae270618b). That key can't be fetched or swapped at runtime, so a forged build can't bring its own.

Check a download

hugin verify <file> checks a release against its .sig and prints the trusted key that signed it. A tampered or unsigned file fails. See the command line.

Updates verify themselves

hugin update installs a release only when its SHA-256 matches the published checksum and its Ed25519 signature verifies. An unsigned binary is rejected.

Local tamper checks

hugin doctor re-hashes the running binary against the hash built into it, then checks database file permissions, DNS consistency (system versus DNS-over-HTTPS), suspicious always-on services, and unexpected VPN tunnels.

What leaves your machine

The Pro trial binds to your machine so one device can't reset it forever. Hugin derives a hardware fingerprint, hashes it with SHA-256, and sends only that hash to the licence server at license.hugin.nu — the raw hardware identifiers never leave your machine.

Last updated 2026-06-17.