You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 45f5c65
Browse filesBrowse the repository at this point in the historyBrowse files
Copy file name to clipboardExpand all lines: docs/en/development/dashboard.md
+5-4Lines changed: 5 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,6 +1,6 @@
1
1
# Dashboard design principles
2
2
3
-
The Dashboard is a content viewer for personal use and demonstrations, authenticated by a static token and disabled by default. This document helps developers and reviewers decide what a page should show, how to organize reading, and whether a change preserves the behavior users need. The API contract in `openapi/powercontext.yaml` and the service implementation define the available capabilities.
3
+
The Dashboard is a content viewer for personal use and demonstrations, disabled by default. It shares the Server access mode: local access can be anonymous, while enforced access requires a static token. This document helps developers and reviewers decide what a page should show, how to organize reading, and whether a change preserves the behavior users need. The API contract in `openapi/powercontext.yaml` and the service implementation define the available capabilities.
4
4
5
5
## What the Dashboard helps users do
6
6
@@ -96,9 +96,10 @@ Chinese, English, light and dark settings apply across the Dashboard, including
96
96
97
97
Pages show actual readable data, and actions correspond to existing capabilities. If one section fails, other independently readable content remains visible. Read errors, insufficient permissions and missing generation configuration have different meanings and must not collapse into an empty state.
98
98
99
-
The Dashboard supports the built-in static Bearer identity, with the same permissions for every token holder. Enabling it
100
-
requires `POWERCONTEXT_SERVER_DASHBOARD_ENABLED=true`, `ACCESS_MODE=enforced`, and `AUTH_TOKEN`. Team deployments that
101
-
inject authentication or authorization Providers must disable it. Pages reuse the existing API and its access checks;
99
+
Enable Dashboard with `POWERCONTEXT_SERVER_DASHBOARD_ENABLED=true`. Local `ACCESS_MODE=disabled` opens directly without
100
+
a token. With `ACCESS_MODE=enforced`, it requires `AUTH_TOKEN` and uses the built-in static Bearer identity, with the
101
+
same permissions for every token holder. Team deployments that inject authentication or authorization Providers must
102
+
disable it. Pages reuse the existing API and follow the Server access mode;
102
103
they add no data endpoints or member and role management. See [Install and run](../docs/get-started/install-and-run.md)
Copy file name to clipboardExpand all lines: docs/en/docs/get-started/quickstart.md
+10-8Lines changed: 10 additions & 8 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -29,7 +29,7 @@ For a first local installation:
29
29
1.**Storage**: SQLite works without another database dependency. To try embedded seekdb, select it and approve the background dependency installation.
30
30
2.**Usage scenario**: choose “Only on this machine” when your Agent, browser, and Server share a machine. For a remote Server, first read [Connect to a remote Server](../operate/connect-remote-server.md).
31
31
3.**Memory capabilities**: select full memory and enter Generation and Embedding API details. See [Configure models](configure-models.md) for protocols and dimensions.
32
-
4.**Dashboard**: enable it to inspect Sources and memories. The wizard creates or reuses a Server token.
32
+
4.**Dashboard**: enable it to inspect Sources and memories. Local authentication defaults to off; enable it if you want to require a token. See [optional authentication](configure-server-environment.md#local-dashboard-and-optional-authentication).
33
33
5.**Background processing**: start with the recommended schedule for each Artifact. An inspection interval is not a completion deadline; model processing takes additional time.
34
34
6.**Agent**: select Codex and plan a new isolated Scope. Select Claude Code next if needed, then choose “Finish Agent configuration”.
35
35
7. Review and save.
@@ -38,11 +38,12 @@ The wizard writes:
38
38
39
39
| File | Purpose |
40
40
| --- | --- |
41
-
|`.env`| Server, client, Agent, database, and model settings, including credentials and the Server token|
41
+
|`.env`| Server, client, Agent, database, and model settings, including any configured credentials|
42
42
|`.env.next-steps.md`| Startup, Scope creation, plugin connection, and checks for your choices |
43
43
44
-
The final screen shows the Dashboard URL, a newly generated token, and the SSH command when selected. Later, look up
45
-
`POWERCONTEXT_SERVER_AUTH_TOKEN` in `.env`. These files contain credentials; do not commit them.
44
+
The final screen shows the Dashboard URL and the SSH command when selected. If authentication is enabled, it also
45
+
shows a newly generated Server token once; later, look up `POWERCONTEXT_SERVER_AUTH_TOKEN` in `.env`.
46
+
These files can contain credentials; do not commit them.
46
47
If seekdb is still installing, the wizard waits with an activity indicator. Complete any reported dependency recovery
47
48
before starting the Server. Saving files or installing dependencies does not start the Server.
48
49
@@ -56,7 +57,8 @@ powercontext server run --env-file .env
56
57
```
57
58
58
59
Keep the terminal running. Open the Dashboard URL printed by the wizard, using the port saved as
59
-
`POWERCONTEXT_SERVER_HTTP_PORT` in `.env`. Sign in with the **Server token**, not a model API key.
60
+
`POWERCONTEXT_SERVER_HTTP_PORT` in `.env`. With authentication disabled, the page opens directly. Otherwise, sign in
61
+
with the **Server token**, not a model API key.
60
62
An empty Dashboard is expected before you capture data. For operation after closing the terminal, stop the foreground
61
63
Server and install a [persistent personal service](../operate/deploy-server.md#run-a-persistent-personal-server)
62
64
with `powercontext service install --env-file .env` to reuse the same configuration.
@@ -101,11 +103,11 @@ codex
101
103
102
104
Confirm that the PowerContext Hook and MCP have both loaded in Codex. For a non-default address, follow the Codex
103
105
connection instructions in `.env.next-steps.md`: the installed plugin's `.mcp.json` must use the same Server as the Hook,
104
-
and read Authorization from `POWERCONTEXT_CODEX_AUTHORIZATION`. Installing the plugin does not start the Server.
106
+
with credentials configured when authentication is enabled. Installing the plugin does not start the Server.
105
107
106
108
These commands use Codex CLI. A desktop app may not inherit terminal environment variables. Before testing in the
107
-
desktop app, verify that both its Hook and MCP receive the same URL, token, and Scope. See
108
-
[Codex](../integrations/codex.md) and [Claude Code](../integrations/claude-code.md) for host-specific behavior.
109
+
desktop app, verify that both its Hook and MCP receive the same URL and Scope, and credentials when authentication
110
+
is enabled. See [Codex](../integrations/codex.md) and [Claude Code](../integrations/claude-code.md) for host-specific behavior.
109
111
110
112
Full memory also needs a generation policy for this real Scope to use Profile. Follow the
111
113
[Profile policy steps](configure-models.md#enable-a-profile-policy-for-the-scope) to read its current version and update it;
|`POWERCONTEXT_SERVER_DASHBOARD_ENABLED`|`false`| Personal and demonstration Dashboard; requires static Bearer authentication and does not support injected authentication or authorization Providers |
52
+
|`POWERCONTEXT_SERVER_DASHBOARD_ENABLED`|`false`| Personal and demonstration Dashboard; local `ACCESS_MODE=disabled` needs no token, while `enforced` requires a static Bearer token; injected authentication or authorization Providers are unsupported|
53
53
|`POWERCONTEXT_SERVER_AUTH_ENABLED`|`false`| Legacy static bearer switch; `true` maps to `ACCESS_MODE=enforced` and requires `AUTH_TOKEN`|
54
54
|`POWERCONTEXT_SERVER_AUTH_TOKEN`| unset | Legacy static bearer token; used as compatibility authentication and mapped to the built-in administrator when no Authentication Provider is injected |
55
55
|`POWERCONTEXT_SERVER_ACCESS_MODE`|`disabled`| The only supported Access switch: `disabled` or `enforced`|
0 commit comments