Skip to main content

Reference

Use these pages when you know which setting or interface you need. For a complete working example, start with Protect your first app.

Caddyfile configuration​

AuthCrunch's named stores, portals, and policies belong inside the global security block. The authenticate and authorize handlers connect them to routes in a site block.

AreaReference
Portal configurationFirst portal configuration
Local identitiesIdentity store and static users
OAuth / OIDC identity providersProvider settings and endpoint configuration
User mappingTransforms
Login requirementsAuthentication challenges
Policy syntaxAuthorization syntax
Access rulesRoles and claims and paths
Request identityHeaders and placeholders

For Caddy itself, use the official Caddyfile concepts and route reference. Handler order determines whether an access check runs before the application.

Tokens and cookies​

APIs​

Begin with the API overview, then select the interface that matches your caller:

API permissions and authentication requirements are endpoint-specific. A portal login alone does not establish administrative API access.

Executable and versions​

The bundled executable is named authcrunch; a custom Caddy build may be named caddy. Use the actual executable path when running these commands:

./bin/authcrunch version
./bin/authcrunch security version
./bin/authcrunch list-modules
./bin/authcrunch security --help

version reports Caddy's version; security version reports the AuthCrunch library version. The installation guide identifies the bundle used in the learning path. Check the release notes before using configuration from a different version.