mirror of
https://github.com/langflow-ai/langflow.git
synced 2026-07-24 00:39:35 +08:00
* langflow-webhook-auth-enable
* add-not-contains-filter-operator
* does-not-contains-operator
* less-redundant-explanation
* docs: add jq and path selection to data operations (#10083)
add-jq-and-path-to-data-operations
* smart transform historical names
* change back to smart transform
* jq expression capitalization/package name
* small edit for clarity of not contains operator
* read/write file component name changes
* docs: add smart router component (#10097)
* init
* add-to-release-notes
* remove-dynamic-output-as-parameter
* Apply suggestion from @aimurphy
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
* Apply suggestion from @aimurphy
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
* Apply suggestion from @aimurphy
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
* Apply suggestion from @aimurphy
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
---------
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
* docs: screenshot audit (#10166)
* remove-unused
* agent-examples
* main-ui-screenshots
* components-screenshots
* combine-web-search-components
* simple-agent-flow-in-playground
* round-screenshots
* my-projects
* combine-data-components
* docs: component paths updates for lfx (#10130)
* contributing-bundles-path
* api-monitor-example
* concepts-components-page
* contribute-components-path
* Apply suggestion from @aimurphy
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
---------
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
* docs: auto-add projects as MCP servers (#10096)
* add-mcp-auto-auth-as-default-behavior
* Apply suggestion from @aimurphy
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
* Apply suggestion from @aimurphy
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
---------
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
Co-authored-by: Edwin Jose <edwin.jose@datastax.com>
* docs: amazon bedrock converse (#10289)
* use-bedrock-converse
* Apply suggestion from @aimurphy
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
* Update docs/docs/Components/bundles-amazon.mdx
---------
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
* docs 1.7 release: add mock data component (#10288)
* add-component-and-release-note
* Apply suggestion from @aimurphy
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
---------
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
* docs: update custom component docs (#10323)
* add-partial
* update-lfx-component-paths
* move-partial
* completed-quickstart
* clean up intro
* try-docker-with-custom-mount
* up-to-typed-annotations
* typed-annotations
* dynamic-fields
* end-of-file
* bundles-naming
* chore: update component index
---------
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
* docs: add cometapi back for 1.7 release (#10445)
* add-comet-bundle-back-for-1.7
* add-comet-to-release-notes
* docs: add back docling remote vlm for release 1.7 (#10489)
* add-back-docling-vlm-content
* add-release-note
* docs: ALTK component (#10511)
* broken-anchor
* sidebar-and-page
* add-release-note
* add-context-on-output
* docs: SSRF warning (#10573)
* add-ssrf-protection-env-var
* api-request-component
* Update docs/docs/Components/components-data.mdx
* Apply suggestions from code review
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
* move-note-to-table
* release-note
---------
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
* docs: dynamic create data component (#10517)
* add-dynamic-create-data-component-and-release-note
* Apply suggestions from code review
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
* clarify-message-types
---------
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
* docs: cuga component bundle (#10589)
* initlal-content
* cuga-specific-component-connections
* cleanup
* use-the-same-name
* add-lite-mode-remove-api-flag-and-mode
* Apply suggestions from code review
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
* public-or-private-internet
* agent-doesnt-check-urls
* peer-review
---------
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
* docs: remove docling vlm component from 1.7 release branch (#10630)
remove-vlm-component
* docs: rename component categories and make all components single pages (#10648)
* docs: OpenAPI spec version upgraded from 1.6.5 to 1.6.8 (#10627)
Co-authored-by: github-merge-queue <118344674+github-merge-queue@users.noreply.github.com>
Co-authored-by: Mendon Kissling <59585235+mendonk@users.noreply.github.com>
* up to models and agents
* sidebars
* fix-broken-links
* chore: Fix indentation on bundles-docling.mdx (#10640)
* sidebars
* redo-intros
* link-to-models
* data-components
* files-components-no-kb
* io-components
* helper-utility-components
* llm-ops-components
* logic-components
* processing-pages
* sidebars
* combine-legacy-components-into-one-page
* update-links
* remove-overview-pages-and-redirect
* make-mcp-tools-page
* Apply suggestions from code review
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
* no-cap
---------
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-merge-queue <118344674+github-merge-queue@users.noreply.github.com>
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
* docs: combined web search component (#10664)
* combine-pages
* remove-rss-and-news-search-and-update-links
* remove-vlm-link
* leave-old-release-note-but-remove-link
* docs: add altk reflection component (#10660)
* add-new-component
* differentiate-components
* docs: mcp streamable http client (#10621)
* release note
* mcp-client-changes
* update-astra-example
* icons-and-copy
* order-of-names
* docs: add cuga decomposition strategy as advanced parameter (#10672)
* update-component-link
* init
* add-decomp-as-advanced-param
* [autofix.ci] apply automated fixes
* [autofix.ci] apply automated fixes (attempt 2/3)
* [autofix.ci] apply automated fixes (attempt 3/3)
* Apply suggestions from code review
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
* update-component-index
* [autofix.ci] apply automated fixes
* [autofix.ci] apply automated fixes (attempt 2/3)
* [autofix.ci] apply automated fixes (attempt 3/3)
---------
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
* docs: datastax bundles page (#10686)
* init
* Apply suggestions from code review
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
---------
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
* docs: llm router changed to llm selector (#10663)
* update-component-name
* previous-name-and-release-note
* [autofix.ci] apply automated fixes
* [autofix.ci] apply automated fixes (attempt 2/3)
* [autofix.ci] apply automated fixes (attempt 3/3)
* docs: log alembic to stdout (#10711)
* docs-alembic-log-env-var
* cleanup
* remove-legacy-component-link
* docs: configure s3 for file storage backend (#10678)
* configure-file-storage-s3
* Apply suggestions from code review
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
* Apply suggestions from code review
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
* clarify-s3-credentials
* add-storage-tags-and-cleanup-creds-seciton
* role-link-name
* fix-parse-error
---------
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
* docs: allow rest tweaks to mcp tools component (#10833)
* typo
* tweak-mcp-tools-component
* Apply suggestions from code review
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
---------
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
* add-release-note
* docs: use mustache templates in prompts (#11262)
* mustache-templating
* syntax
* release-note
* peer-review
* docs: smart transform supports Message type (#11306)
* component-supports-message-type
* Apply suggestions from code review
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
* peer-review
---------
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
* docs: modular dependency imports for langflow-base (#11250)
* modular-base-dependencies
* syntax-and-clarification
* release-note
* Apply suggestions from code review
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
* [autofix.ci] apply automated fixes
* clarify-base-and-langflow
* component-index
* delete-component-index
* [autofix.ci] apply automated fixes
* set-agentic-experience
* potential-breaking-changes
* not-audio-package
* cleanup-and-syntax
* Apply suggestions from code review
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
---------
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
* docs: symmetric and asymmetric JWT (#11159)
* initial-content
* cleanup
* Apply suggestions from code review
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
* [autofix.ci] apply automated fixes
* docs-peer-review
* [autofix.ci] apply automated fixes
---------
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
* docs: add markdown output to url component (#11336)
* add-markdown-output-format
* raw-content
* Apply suggestions from code review
* docs: Add global variable support for MCP server headers (#11397)
* add-global-var-in-mcp-headers
* revert-curl-syntax-change
* remove-duplicate-tab
* Apply suggestions from code review
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
* remove-code-block
* add-release-note
---------
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
* Update docs/docs/Develop/install-custom-dependencies.mdx
* Update docs/docs/Develop/jwt-authentication.mdx
* docs: global model provider feature (#11231)
* initial-changes-to-model-providers
* add-icon-for-model-partial
* syntax
* adding-custom-language-model
* release-note
* Apply suggestions from code review
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
* peer-review
* use-anthropic-model-with-agent
* [autofix.ci] apply automated fixes
* design-changes
---------
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
* mustache-limitations
* release-note-for-jwt
* docs: playground refactor and screenshots (#11639)
* screenshots
* new-playground-and-icon
* release-note
* Apply suggestions from code review
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
---------
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
* docs: component inspection panel (#11675)
* docs-component-inspection-panel
* cleanup
* docs: add tool shortlisting and remove web_apps from CUGA component (#11669)
docs-add-shortlist-tools-and-remove-webapps-parameters
* fix-details-tab-error
* docs: workflow API draft build (#11323)
* delete-unused-yaml-file
* initial-content
* add-python-and-ts-to-example-requests
* separate-pages
* test-spec-presentation
* hide-async-and-make-workflows-plural
* fix-broken-link
* add-changes-to-async
* use-workflow-spec-from-sdk-build
* make-setup-partial
* add-fetch-script-for-openapi-spec
* update-workflows-spec
* remove-stream-for-now
* remove-reconnect-to-stream
* consolidate-pages
* remove-force-boolean
* [autofix.ci] apply automated fixes
* docs: add guardrails component (#11674)
* docs-add-guardrails-component
* cleanup
* example-and-heuristic-check
* Apply suggestions from code review
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
* [autofix.ci] apply automated fixes
* add-note-about-llm
* add-release-note
---------
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
* docs: pass env var to run command and endpoint as header (#11447)
* pass-env-var-to-lfx
* add-env-var-passing-to-run-endpoint
* add-python-and-js-commands
* docs: responses api token usage tracking (#11564)
* initlal-content
* add-release-note
* changes-for-accessing-advanced-parameters
* [autofix.ci] apply automated fixes
* [autofix.ci] apply automated fixes (attempt 2/3)
* small-playground-changes
* [autofix.ci] apply automated fixes
* Revert "docs: OpenAPI spec content updated without version change (#11787)"
This reverts commit a0d5618ac9.
* [autofix.ci] apply automated fixes
* docs: add LiteLLM proxy bundle (#11867)
* docs-add-litellm-proxy-component
* Update docs/docs/Components/bundles-lite-llm.mdx
* docs: 1.8 changes from QA (#11998)
* remove-rightside-playground
* tutorials
* image-size-update
* component-release-notes
* Apply suggestions from code review
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
---------
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
* docs: pass API keys to args and not env (#11997)
* remove-rightside-playground
* tutorials
* image-size-update
* docs-troubleshoot-mcp-proxy-header-keys
* Apply suggestions from code review
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
---------
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
* docs: knowledge bases (#11924)
* docs-add-back-kb-content
* update-with-release-candidate-branch
* fix-linking-error
* remove-advanced-flag
* Apply suggestions from code review
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
* add-release-note
---------
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
* docs: traces v0 (#12014)
* env-var-release-note-and-sidebars
* traces-and-database
* traces-ui-and-api-retrieval
* cleanup
* space
* move-section
* move-what-traces-capture-section
* docs: remove kb ingestion and rename kb retrieval (#12065)
remove-knowledge-ingestion-and-rename-knowledge-retrieval
* docs: add link to secret key rotation script (#12072)
* add-link-to-secret-key-rotation
* Apply suggestions from code review
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
---------
Co-authored-by: April I. Murphy <36110273+aimurphy@users.noreply.github.com>
* docs: openlayer follow-on (#12073)
* add-openlayer-to-sidebars-and-release-notes
* Update docs/docs/Support/release-notes.mdx
---------
Co-authored-by: April M <36110273+aimurphy@users.noreply.github.com>
Co-authored-by: Edwin Jose <edwin.jose@datastax.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: github-merge-queue <118344674+github-merge-queue@users.noreply.github.com>
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
331 lines
11 KiB
Plaintext
331 lines
11 KiB
Plaintext
---
|
|
title: JWT authentication
|
|
slug: /jwt-authentication
|
|
---
|
|
|
|
import Tabs from "@theme/Tabs";
|
|
import TabItem from "@theme/TabItem";
|
|
|
|
Langflow supports symmetric or asymmetric JSON Web Tokens (JWT) for user authentication and authorization.
|
|
|
|
JWT is an [open standard](https://tools.ietf.org/html/rfc7519) for securely transmitting information between parties as a JSON object.
|
|
Use JWT to create credentials that automatically expire, enable stateless authentication without database storage, and work across distributed systems.
|
|
|
|
JWT authentication with the HS256 algorithm is enabled by default, but can be configured further with the `LANGFLOW_ALGORITHM` environment variable.
|
|
|
|
<details closed>
|
|
<summary>About the JWT structure and contents</summary>
|
|
|
|
When a user logs in with their username and password at the `/api/v1/login` endpoint, Langflow validates the credentials and creates a JWT token containing the user's identity and expiration time. This token is then used for subsequent API requests instead of sending credentials with each request.
|
|
|
|
A JWT consists of three parts separated by dots (`.`):
|
|
|
|
```
|
|
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c
|
|
```
|
|
|
|
* The header contains the token type and signing algorithm.
|
|
* The payload contains _claims_, which are token data for user information and expiration time.
|
|
* The signature is a secret key that ensures the token hasn't been tampered with.
|
|
|
|
Each part of the JWT is Base64URL-encoded.
|
|
You can paste this example JWT to decode the actual JSON data at [jwt.io](https://jwt.io/).
|
|
|
|
</details>
|
|
|
|
## Configure JWT environment variables
|
|
|
|
Configure JWT authentication in Langflow using the following environment variables:
|
|
|
|
| Variable | Description | Default |
|
|
|----------|-------------|---------|
|
|
| `LANGFLOW_ALGORITHM` | JWT signing algorithm (`HS256`, `RS256`, or `RS512`) | `HS256` |
|
|
| `LANGFLOW_SECRET_KEY` | Secret key for HS256 signing | Auto-generated |
|
|
| `LANGFLOW_PRIVATE_KEY` | RSA private key for RS256/RS512 signing | Auto-generated |
|
|
| `LANGFLOW_PUBLIC_KEY` | RSA public key for RS256/RS512 verification | Derived from private key |
|
|
| `LANGFLOW_ACCESS_TOKEN_EXPIRE_SECONDS` | Access token expiration time | `3600` (1 hour) |
|
|
| `LANGFLOW_REFRESH_TOKEN_EXPIRE_SECONDS` | Refresh token expiration time | `604800` (7 days) |
|
|
|
|
## Configure signing algorithms
|
|
|
|
Langflow supports multiple signing algorithms and both symmetric (HS256) and asymmetric (RS256, RS512) JWTs.
|
|
|
|
Which method you choose depends upon your deployment's requirements.
|
|
|
|
### HS256 (Default)
|
|
|
|
HS256 is the default JWT algorithm, with a good security level for single-server deployments.
|
|
Langflow automatically generates and persists a secret key.
|
|
No configuration is necessary, but if you want to explicitly set it in the Langflow `.env`, the default value is `LANGFLOW_ALGORITHM=HS256`.
|
|
|
|
To generate a custom secure key instead of using the Langflow-generated secret key, do the following:
|
|
|
|
1. Generate a secure secret key with the Python secrets module or OpenSSL.
|
|
The key must be at least 32 characters long.
|
|
|
|
**Using Python:**
|
|
|
|
```bash
|
|
python -c "import secrets; print(secrets.token_urlsafe(32))"
|
|
```
|
|
|
|
**Using OpenSSL:**
|
|
|
|
```bash
|
|
openssl rand -base64 32
|
|
```
|
|
|
|
2. Set the value for `LANGFLOW_SECRET_KEY` in your `.env` file.
|
|
```bash
|
|
LANGFLOW_ALGORITHM="HS256"
|
|
LANGFLOW_SECRET_KEY="your-custom-secret-key"
|
|
```
|
|
|
|
### RS256
|
|
|
|
The RS256 signing algorithm provides better security for production deployments by using a pair of private and public keys.
|
|
The private key signs tokens, and the public verifies them.
|
|
The private key must be kept secret, while the public key can be safely shared.
|
|
|
|
To automatically generate a private and public key pair and store it in the Langflow [`LANGFLOW_CONFIG_DIR`](/logging), set `LANGFLOW_ALGORITHM="RS256"` in your Langflow `.env`.
|
|
When Langflow starts, it will:
|
|
1. Check if RSA keys exist in the configuration directory.
|
|
2. If not, generate a new 2048-bit RSA key pair.
|
|
3. Save the keys to `private_key.pem` and `public_key.pem`.
|
|
4. Reuse the same keys on subsequent startups.
|
|
|
|
To use a custom private key instead of the auto-generated keys, set the following in your `.env` file.
|
|
The `LANGFLOW_PUBLIC_KEY` will be automatically derived from the private key.
|
|
|
|
```bash
|
|
LANGFLOW_ALGORITHM=RS256
|
|
LANGFLOW_PRIVATE_KEY="-----BEGIN PRIVATE KEY-----
|
|
MIIEvgIBADANBgkqhkiG9w0BAQEF...
|
|
-----END PRIVATE KEY-----"
|
|
```
|
|
|
|
To use a custom key pair, set both keys in your Langflow `.env` file.
|
|
|
|
```bash
|
|
LANGFLOW_ALGORITHM=RS256
|
|
LANGFLOW_PRIVATE_KEY="-----BEGIN PRIVATE KEY-----
|
|
MIIEvgIBADANBgkqhkiG9w0BAQEF...
|
|
-----END PRIVATE KEY-----"
|
|
LANGFLOW_PUBLIC_KEY="-----BEGIN PUBLIC KEY-----
|
|
MIIBIjANBgkqhkiG9w0BAQEFAAOC...
|
|
-----END PUBLIC KEY-----"
|
|
```
|
|
|
|
To generate an RSA key pair manually, do the following:
|
|
|
|
1. Generate a 2048-bit private key:
|
|
```bash
|
|
openssl genrsa -out private_key.pem 2048
|
|
```
|
|
|
|
2. Extract the public key from the private key:
|
|
```bash
|
|
openssl rsa -in private_key.pem -pubout -out public_key.pem
|
|
```
|
|
|
|
3. Verify the keys were created:
|
|
```bash
|
|
cat private_key.pem
|
|
cat public_key.pem
|
|
```
|
|
|
|
### RS512
|
|
|
|
RS512 uses the same RSA format of private and public keys as RS256, but uses the SHA-512 hashing algorithm for greater security.
|
|
The private key signs tokens, and the public verifies them.
|
|
The private key must be kept secret, while the public key can be safely shared.
|
|
|
|
To automatically generate a private and public key pair and store it in the Langflow [`LANGFLOW_CONFIG_DIR`](/logging), set `LANGFLOW_ALGORITHM="RS512"` in your Langflow `.env`.
|
|
When Langflow starts, it does the following:
|
|
1. Check if RSA keys exist in the configuration directory.
|
|
2. If not, generate a new 2048-bit RSA key pair.
|
|
3. Save the keys to `private_key.pem` and `public_key.pem`.
|
|
4. Reuse the same keys on subsequent startups.
|
|
|
|
To use a custom private key instead of the auto-generated keys, set the following in your `.env` file.
|
|
The `LANGFLOW_PUBLIC_KEY` will be automatically derived from the private key.
|
|
|
|
```bash
|
|
LANGFLOW_ALGORITHM=RS512
|
|
LANGFLOW_PRIVATE_KEY="-----BEGIN PRIVATE KEY-----
|
|
MIIEvgIBADANBgkqhkiG9w0BAQEF...
|
|
-----END PRIVATE KEY-----"
|
|
```
|
|
|
|
To use a custom key pair, set both keys in your Langflow `.env` file.
|
|
|
|
```bash
|
|
LANGFLOW_ALGORITHM=RS512
|
|
LANGFLOW_PRIVATE_KEY="-----BEGIN PRIVATE KEY-----
|
|
MIIEvgIBADANBgkqhkiG9w0BAQEF...
|
|
-----END PRIVATE KEY-----"
|
|
LANGFLOW_PUBLIC_KEY="-----BEGIN PUBLIC KEY-----
|
|
MIIBIjANBgkqhkiG9w0BAQEFAAOC...
|
|
-----END PUBLIC KEY-----"
|
|
```
|
|
|
|
To generate an RSA key pair manually, do the following:
|
|
|
|
1. Generate a 2048-bit private key:
|
|
```bash
|
|
openssl genrsa -out private_key.pem 2048
|
|
```
|
|
|
|
2. Extract the public key from the private key:
|
|
```bash
|
|
openssl rsa -in private_key.pem -pubout -out public_key.pem
|
|
```
|
|
|
|
3. Verify the keys were created:
|
|
```bash
|
|
cat private_key.pem
|
|
cat public_key.pem
|
|
```
|
|
|
|
## Configure Docker and Kubernetes deployments
|
|
|
|
Use Docker with HS256 (symmetric) for single-server deployments or development environments where simplicity is preferred.
|
|
|
|
Use Docker or Kubernetes with RS256 (asymmetric) for production deployments requiring enhanced security with private/public key pairs.
|
|
|
|
### Docker with HS256
|
|
|
|
1. Add the value for your JWT secret key to the Langflow `.env` file.
|
|
```bash
|
|
JWT_SECRET_KEY=your-secret-key
|
|
```
|
|
|
|
2. Set the signing algorithm and include a variable for the secret key in the Docker Compose file.
|
|
```yaml
|
|
version: "3.8"
|
|
services:
|
|
langflow:
|
|
image: langflowai/langflow:latest
|
|
environment:
|
|
- LANGFLOW_ALGORITHM=HS256
|
|
- LANGFLOW_SECRET_KEY=${JWT_SECRET_KEY} # Set in .env file
|
|
volumes:
|
|
- langflow_data:/app/langflow
|
|
|
|
volumes:
|
|
langflow_data:
|
|
```
|
|
|
|
### Docker with RS256
|
|
|
|
To use Langflow's automatically generated key pair, set the `RS256` signing algorithm in the Docker Compose file.
|
|
|
|
```yaml
|
|
# docker-compose.yml
|
|
version: "3.8"
|
|
services:
|
|
langflow:
|
|
image: langflowai/langflow:latest
|
|
environment:
|
|
- LANGFLOW_ALGORITHM=RS256
|
|
volumes:
|
|
- langflow_data:/app/langflow # Keys stored here
|
|
|
|
volumes:
|
|
langflow_data:
|
|
```
|
|
|
|
To mount an existing key pair, set the `RS256` signing algorithm and mount the private and public keys as volumes.
|
|
|
|
```yaml
|
|
# docker-compose.yml
|
|
version: "3.8"
|
|
services:
|
|
langflow:
|
|
image: langflowai/langflow:latest
|
|
environment:
|
|
- LANGFLOW_ALGORITHM=RS256
|
|
volumes:
|
|
- ./keys/private_key.pem:/app/langflow/private_key.pem:ro
|
|
- ./keys/public_key.pem:/app/langflow/public_key.pem:ro
|
|
- langflow_data:/app/langflow
|
|
|
|
volumes:
|
|
langflow_data:
|
|
```
|
|
|
|
### Kubernetes with RS256
|
|
|
|
Store JWT keys as Kubernetes Secrets and reference them in your Langflow deployment configuration.
|
|
|
|
```yaml
|
|
# jwt-secret.yaml
|
|
apiVersion: v1
|
|
kind: Secret
|
|
metadata:
|
|
name: langflow-jwt-keys
|
|
type: Opaque
|
|
stringData:
|
|
algorithm: "RS256"
|
|
private-key: |
|
|
-----BEGIN PRIVATE KEY-----
|
|
MIIEvgIBADANBgkqhkiG9w0BAQEF...
|
|
-----END PRIVATE KEY-----
|
|
public-key: |
|
|
-----BEGIN PUBLIC KEY-----
|
|
MIIBIjANBgkqhkiG9w0BAQEFAAOC...
|
|
-----END PUBLIC KEY-----
|
|
---
|
|
# langflow-deployment.yaml
|
|
apiVersion: apps/v1
|
|
kind: Deployment
|
|
metadata:
|
|
name: langflow
|
|
spec:
|
|
template:
|
|
spec:
|
|
containers:
|
|
- name: langflow
|
|
image: langflowai/langflow:latest
|
|
env:
|
|
- name: LANGFLOW_ALGORITHM
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: langflow-jwt-keys
|
|
key: algorithm
|
|
- name: LANGFLOW_PRIVATE_KEY
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: langflow-jwt-keys
|
|
key: private-key
|
|
- name: LANGFLOW_PUBLIC_KEY
|
|
valueFrom:
|
|
secretKeyRef:
|
|
name: langflow-jwt-keys
|
|
key: public-key
|
|
```
|
|
|
|
## Configure token expiration
|
|
|
|
To configure access and refresh token expiration times, set the values in the Langflow `.env`.
|
|
|
|
```bash
|
|
LANGFLOW_ACCESS_TOKEN_EXPIRE_SECONDS=3600 # 1 hour
|
|
LANGFLOW_REFRESH_TOKEN_EXPIRE_SECONDS=604800 # 7 days
|
|
```
|
|
|
|
Access tokens authenticate API requests and typically expire within 15 minutes to 1 hour to limit security risks.
|
|
|
|
Refresh tokens obtain new access tokens without requiring the user to log in again.
|
|
Refresh tokens typically expire within 7 to 30 days.
|
|
|
|
When an access token expires, the client can use the refresh token to get a new access token from the `/api/v1/refresh` endpoint.
|
|
This maintains the user's session without prompting for credentials again.
|
|
|
|
## See also
|
|
|
|
- [Langflow API keys and authentication](/api-keys-and-authentication)
|
|
- [JWT.io](https://jwt.io/)
|
|
- [RFC 7519 specification](https://tools.ietf.org/html/rfc7519)
|
|
- [OWASP JWT Security Cheat Sheet](https://cheatsheetseries.owasp.org/cheatsheets/JSON_Web_Token_for_Java_Cheat_Sheet.html)
|
|
- [Langflow Security Best Practices](/security) |