Question: why is ADMIN_TOKEN not mandatory #225

Closed
opened 2025-07-08 08:43:29 -04:00 by AtHeartEngineer · 0 comments

Originally created by @jflecool2 on 1/29/2025

Hello!
First, thanks for creating vaultwarden!!
I have a question,
Considering vaultwarden store passwords, (safety is primordial)
Considering a argon 'ADMIN_TOKEN' is necessary to be safe (according to https://github.com/dani-garcia/vaultwarden/releases/tag/1.33.0)
Why is ADMIN_TOKEN not forced?
If I wouldnt have checked the new release, I would have never known. Its maybe in the log (?), but I dont think every one looks at the logs. I know I dont.
Thanks

*Originally created by @jflecool2 on 1/29/2025* Hello! First, thanks for creating vaultwarden!! I have a question, Considering vaultwarden store passwords, (safety is primordial) Considering a argon 'ADMIN_TOKEN' is necessary to be safe (according to https://github.com/dani-garcia/vaultwarden/releases/tag/1.33.0) Why is ADMIN_TOKEN not forced? If I wouldnt have checked the new release, I would have never known. Its maybe in the log (?), but I dont think every one looks at the logs. I know I dont. Thanks
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github/vaultwarden#225