Security and trust
Keep Hugin's CA-bearing proxy off the open internet with token auth and strict role checks, and verify the binary you run is a genuine signed release.
Hugin sits in the middle of your HTTPS traffic and runs with enough privilege to read and rewrite it. Two questions follow: who can reach the instance you run, and whether the binary you launched is the real one. This page covers both.
Run it safely
To decrypt HTTPS, the Proxy holds a certificate authority (CA) private key.
Anyone who can reach that key, or the control API sitting behind it, can read and
modify HTTPS traffic for every browser that trusts your CA. Treat the control
port like a credential: don't expose it to the internet, and run hugin ca untrust when you finish a session.
hugin start listens on 127.0.0.1 only. hugin serve is the shared-team mode:
it binds 0.0.0.0, turns token auth on, and mints a token if you have none.
--no-auth removes that gate — use it only on a network you fully control.
On any instance another machine can reach, set HUGIN_REST_RBAC_STRICT=1.
Without it, an authenticated request that carries no X-Hugin-Role header is
treated as a full admin. Strict mode drops an unidentified caller to read-only,
so writing, scanning, and admin actions need an explicit role. The desktop app
talks to itself in-process and is unaffected.
Two endpoints answer without auth by default: /openapi.json (the route list)
and /api/health (proxy up or down). Neither returns flow, scope, or project
data. If the bind is anything but loopback and you want them closed, set
HUGIN_OPENAPI_REQUIRES_AUTH=1 and HUGIN_HEALTH_REQUIRES_AUTH=1. As always,
only point Hugin at targets you are authorised to test — see
installation.
Verify what you run
Every release binary is signed with an Ed25519 key whose public half ships inside
the app (a61ff9262c4509a7879ddaa5a8d86345ef805f6ddced28b097bf58dae270618b).
That key can't be fetched or swapped at runtime, so a forged build can't bring
its own.
hugin verify <file> checks a release against its .sig and prints the trusted
key that signed it. A tampered or unsigned file fails. See the
command line.
hugin update installs a release only when its SHA-256 matches the published
checksum and its Ed25519 signature verifies. An unsigned binary is rejected.
hugin doctor re-hashes the running binary against the hash built into it, then
checks database file permissions, DNS consistency (system versus
DNS-over-HTTPS), suspicious always-on services, and unexpected VPN tunnels.
What leaves your machine
The Pro trial binds to your machine so one device can't reset it forever. Hugin
derives a hardware fingerprint, hashes it with SHA-256, and sends only that hash
to the licence server at license.hugin.nu — the raw hardware identifiers never
leave your machine.