Skip to content

Users & Roles

CBOM uses JWT-based authentication with two roles: Admin and Viewer.


On first deployment, no users exist. Create the initial admin account:

  • Navigate to the platform URL — you’ll be prompted to create an admin account
  • Or use the API: POST /api/v1/auth/register-admin

This endpoint only works once. After the first admin is created, all subsequent users must be created from the admin panel.


RolePermissions
AdminFull access — create/edit/delete sensors, scanners, users, settings, trigger scans, import data, manage compliance standards
ViewerRead-only access — browse inventory, view dashboard, view compliance results, export data

Navigate to Users in the sidebar (admin only).

  1. Click Create User
  2. Enter username, password (minimum 4 characters), display name
  3. Select role: Admin or Viewer
  4. Click Create

Click the role badge on any user to toggle between Admin and Viewer.

Click Delete on the user row. You cannot delete your own account.


Users authenticate with username and password. The API returns a JWT token valid for 24 hours.

Tokens expire after 24 hours. The UI handles re-authentication automatically when a token expires.

  • Tokens are signed with the CBOM_JWT_SECRET environment variable
  • Tokens contain the username and role — no database lookup on each request
  • Sign out invalidates the token on the client side

Sensors use a separate authentication mechanism — API keys issued during registration. Sensor API keys do not expire and are not tied to user accounts.