Repository navigation
Feature Guide Access Lists
HTTP basic authentication for protecting services behind proxy hosts.
- What Access Lists Do
- Create an Access List
- Manage Credentials
- Apply an Access List to a Proxy Host
- Pagination
- Security Notes
- Troubleshooting
Access lists add browser-native HTTP basic auth in front of your upstream.
Typical use cases:
- Protect admin dashboards
- Gate internal/staging apps
- Add simple auth to apps without login support
How requests flow:
- Client requests a protected host
- Browser prompts for username/password
- Credentials are validated against the selected access list
- If valid, request is proxied upstream
- Open Access Lists from the sidebar.
- Scroll to Create access list.
- Fill in:
- Name (required)
- Description (optional)
-
Seed members (optional): one
username:passwordpair per line
- Click Create Access List.
Example seed members:
alice:StrongPass#1
bob:AnotherStrongPass#2
The application stores hashed passwords (bcrypt), not plaintext.
Each access list supports multiple accounts.
Inside each list card you can:
- Edit list name/description
- Add new accounts with Username + Password
- Remove existing accounts
- Delete the entire list
After list changes are saved, Caddy config is reapplied automatically.
- Open Proxy Hosts.
- Create or edit a host.
- Set Access List to the list you want.
- Save.
Set Access List = None to remove HTTP basic auth from that host.
Access Lists now use server-side pagination.
- Default page size:
25lists per page - Use the pager at the bottom to move between pages
- URL state is preserved with
?page=Nfor shareable links
Note: the Create access list form remains available below the paginated list.
HTTP basic auth is simple and widely supported, but has limits:
- Credentials are sent on every request (always use HTTPS)
- Browsers cache credentials; logout UX is limited
- No built-in MFA
Recommended practices:
- Use long, unique passwords per account
- Rotate credentials regularly
- Prefer OAuth/OIDC for user SSO or stronger identity controls
- Combine with geo blocking where appropriate
Possible causes:
- Wrong username/password
- Access list not attached to the host
- Browser cached stale credentials
Checks:
- Confirm the account exists in the selected list
- Re-enter credentials manually (case-sensitive)
- Verify the proxy host has the expected access list selected
- Review the Audit Log for list/host updates
Possible causes:
- Host has no access list assigned
- Host changes not saved
Checks:
- Edit proxy host and verify Access List is not
None - Save host again
- Confirm host is enabled
Need help? Open an issue with your access list and host setup (do not include real passwords).