nextv1.4.0
Configuration

Access

Every field in access.yaml: bind address, password, and remote access.

access.yaml sets the address Kraft binds to and the password that protects it.

bind: 127.0.0.1
port: 8765
password_hash: null
session_expiry_days: 7
allowed_hosts: []
FieldDefaultMeans
bind127.0.0.1The address kraft admin start binds. --host overrides KRAFT_HOST, which overrides this file. A non-loopback value is refused unless password_hash is set.
port8765The port kraft admin start binds. --port overrides KRAFT_PORT, which overrides this file.
password_hashnullThe login password's hash, written by Settings → Access. Required for any non-loopback bind.
session_expiry_days7How long a browser session cookie stays valid after logging in.
allowed_hosts[]Host header allowlist checked on a non-loopback bind — a password alone does not authorize an arbitrary hostname. See Remote access.
Copyright © 2026