Security
Teldrive
Configuration

Security

Configure authentication keys, allowed users, token lifetimes, and content encryption.

Authentication keys

security:
  signing-key: "..."
  data-key: "..."
  issuer: teldrive-v2
  allowed-users: []

signing-key

Signs Teldrive authentication tokens. Minimum 32 characters.

openssl rand -hex 32

Changing it invalidates existing signed sessions.

data-key

Encrypts sensitive PostgreSQL values such as Telegram credentials. It must be Base64 that decodes to exactly 32 bytes.

openssl rand -base64 32

Back it up. Data encrypted with an old key cannot be decrypted with a replacement.

Allowed users

Empty allows any Telegram user who completes login:

security:
  allowed-users: []

Restrict a private server:

security:
  allowed-users:
    - alice
    - bob

Environment form:

TELDRIVE_SECURITY_ALLOWED_USERS=alice,bob

Usernames are case-insensitive and may include or omit @.

Token lifetimes

SettingDefault
access-token-ttl15m
refresh-token-ttl720h
login-flow-ttl10m

File-content encryption

encryption.keys is separate from security.data-key:

encryption:
  active-key-version: 1
  keys:
    1: "YOUR_CONTENT_KEY"

See Content encryption and key rotation.

Secret handling

Protect at least:

  • PostgreSQL password;
  • signing/data keys;
  • content-encryption keys;
  • custom Telegram API hash, if configured;
  • proxy and bot credentials.

Do not commit secrets to Git. See Backup and restore for recovery requirements.