Defaults

Security

qLLM is built for limited, intentional exposure: read-only queries, required limits, secrets in env vars, and loopback bind until you opt into a wider surface.

Read-only and bounded

Bearer auth

Set serve.authTokenEnv (or --auth-token-env) to an env var that holds the shared Bearer token for HTTP /v1 and MCP HTTP. If the env name is set, the variable must be non-empty or serve refuses to start. Stdio MCP is unaffected.

export QLLM_AUTH_TOKEN=dev-secret
curl -s -H "Authorization: Bearer $QLLM_AUTH_TOKEN" http://127.0.0.1:8088/v1/catalog

GET /v1/health stays unauthenticated. For per-app table scopes, use qllm.access.yaml instead of a single token — see Configure.

Bind loopback

Defaults: 127.0.0.1:8088 and 127.0.0.1:8089. Binding a non-loopback address without auth requires --insecure-bind or serve.insecureBind: true — an explicit opt-in, not a silent default.

CORS — MCP browser clients only

CORS is off when origins is empty. Wildcard * is rejected. Enable an allowlist only if a browser client needs Streamable HTTP / SSE against MCP HTTP — typical server-side agents do not need CORS.

serve:
  cors:
    origins: []   # empty = CORS off

Write denylist

Deep reference for multi-user scoped credentials: docs/en/multi-user-safety.md.