Skip to content
KoboldCpp
GitHub

Passwords and security

By default KoboldCpp has no password and accepts connections on all network interfaces. Any device that can reach your PC on port 5001 can use it.

Your situationDo this
Only you, on this PCSet Host: to 127.0.0.1 (--host 127.0.0.1).
Other devices on your network, or Remote TunnelSet a Password: (--password).
Admin mode is onAlways set an Admin Password: (--adminpassword).
Sharing with an image model loadedImage generation is not password-protected. Limit image size with --sdclamped, or don't load an image model.
  • Launcher: Network tab → Password:
  • Command line: --password <password>
  • Environment variable: KCPP_PASSWORD

In apps, enter the password where they ask for an API key. KoboldAI Lite asks for it in an API Key Required box when it opens.

Clients must send the header Authorization: Bearer <password>. This is the same way OpenAI apps send their API key.

Terminal
curl http://localhost:5001/v1/chat/completions \
-H "Authorization: Bearer mypassword" \
-H "Content-Type: application/json" \
-d '{"messages": [{"role": "user", "content": "Hello!"}]}'

On Windows, write it on one line with escaped quotes; see First requests.

  • No other header works. KoboldCpp does not accept x-api-key, which Anthropic clients use.
  • A missing or wrong password returns HTTP 401: {"detail": {"error": "Unauthorized", "msg": "Authentication key is missing or invalid.", "type": "unauthorized"}}

Protected:

  • Text generation on every API: KoboldAI, OpenAI, Responses, Anthropic, Ollama
  • Token counting, generation check, abort, logprobs
  • Speech-to-text, /api/extra/tts, /v1/audio/speech, embeddings, music
  • Web search, multiplayer, server-side saves, /mcp

Not protected:

  • Image generation: /sdapi/v1/txt2img, /sdapi/v1/img2img, /v1/images/*, ComfyUI /prompt and /upload/image

  • Upscaling: /sdapi/v1/upscale, /sdapi/v1/extra-single-image

  • Image captioning: /sdapi/v1/interrogate

  • XTTS text-to-speech: /tts_to_audio

  • Info pages (GET), such as /api/extra/version, /api/extra/perf, /v1/models and /props

  • /api/v1/model hides the model name without the password, but /v1/models and /props still show it.

  • The web interfaces (KoboldAI Lite, /sdui and the others) load without a password. Their requests to protected endpoints need it.

If you share an instance that has an image or TTS model loaded, anyone who can reach it can generate images and speech. Limit image size with Clamp Resolution (Hard): on the Image Gen tab (--sdclamped), or only load those models on instances you trust.

Admin mode (Enable Model Administration on the Admin tab, --admin) lets clients switch and unload models.

  • Launcher: Admin tab → Admin Password:
  • Command line: --adminpassword <password>
  • Environment variable: KCPP_ADMINPASSWORD

The admin password also works as the normal password. Give other users the normal password and keep the admin password for yourself. See Admin mode.

  • A saved config (.kcpps) contains your passwords in plain text. Don't share it.
  • Templates (.kcppt, Generate LaunchTemplate on the Extra tab) leave the passwords out. Share those instead, after checking them for local file paths and an embedded story.

Host: on the Network tab (--host) sets which network address KoboldCpp listens on.

HostWho can connect
Empty (default)Any device that can reach this PC
127.0.0.1Only this PC
One of this PC's IP addressesDevices that reach this PC through that network

For access from other devices, see Remote access.

Remote Tunnel also works with 127.0.0.1, because its cloudflared program runs on the same PC. If you only use KoboldCpp locally and through the tunnel, set Host: to 127.0.0.1 and leave Router Mode off, so that other devices on your network cannot connect directly.

KoboldCpp allows requests from web pages on any site. This is what lets browser apps, such as the hosted KoboldAI Lite at lite.koboldai.net, talk to your local server. There is no setting to restrict it.

It also means that any web page open in your browser can send requests to your KoboldCpp. The password keeps them out of the protected endpoints.

KoboldCpp serves plain HTTP by default. To serve HTTPS, give it a certificate and a key:

  • Launcher: Network tab → SSL Cert: and SSL Key:
  • Command line: --ssl cert.pem key.pem

The key must be unencrypted (no passphrase). If a file is missing, KoboldCpp prints Your SSL configuration is INVALID. SSL will not be used. and serves plain HTTP. If a file exists but is not a valid certificate or key, the server does not start.

To make a self-signed certificate for testing:

Terminal
openssl req -x509 -newkey rsa:4096 -keyout key.pem -out cert.pem -sha256 -days 365 -nodes

Browsers warn about self-signed certificates until you trust them. Remote Tunnel links are HTTPS already, without a certificate of your own.

LauncherFlagDefaultEffect
Multiuser Queue: (Network)--multiuser10How many requests it accepts at once, counting the one that runs (default: 1 runs, 9 wait); see Streaming and multiple users
Max Req. Size (MB): (Network)--maxrequestsize32Bigger requests get HTTP 500 Payload is too big.
IP Rate Limiter (s): (Network)--ratelimit0 (off)Each IP may start one generation per this many seconds; faster ones get HTTP 503. Behind Remote Tunnel, all users count as one IP.
Prompt Limit: (Context)--genlimit0 (off)Caps the reply length of every request
Clamp Resolution (Hard): (Image Gen)--sdclamped0 (off)Caps the longest image side; --sdclamped alone means 512
(Soft):, next to Clamp Resolution (Hard) (Image Gen)--sdclampedsoft0Caps the image area; 0 means 832×832 for SD 1.x/2.x and 1024×1024 for other models
  • NoCertify Mode (Insecure) (--nocertify) turns off certificate checks for KoboldCpp's own outgoing connections, such as web search, MCP servers and the Horde worker. Model downloads use aria2c, curl or wget, which still check certificates. It does not affect the server's HTTPS.
  • MCP servers from MCP JSON: (--mcpfile) that run as a local command have full access to your system. Remote MCP servers receive the data sent to them. Only add servers you trust. See Web search and MCP.
  • RPC (sharing a GPU with other PCs) must not be exposed to the internet. See RPC.
  • Don't combine SingleInstance Mode (--singleinstance) with Remote Tunnel.