Individual Node API Keys — Per-Device Security for High-Security Environments

Individual Node API Keys — Per-Device Security for High-Security Environments

In the default configuration, all nodes in a group share a single API key. This is simple to manage and works well for most deployments. But some environments demand stricter isolation.

ProxyPass supports individual API keys per node. When enabled on a group, each node gets its own unique key. Knowing one node's key does not grant access to any other node in the fleet.

Required Individual Keys

You can take this further by requiring individual keys. With this setting, new nodes automatically receive a generated API key on registration. Existing nodes that do not have one yet receive a key on their next reconnect. No node operates without its own credential.

Scenario: Multi-Tenant Deployment

You deploy ProxyPass nodes at 30 different customer sites. Each site runs independently — different companies, different security requirements. If all 30 nodes share one API key and that key leaks — from a decommissioned device, a compromised backup, an overshared config file — every node in the group is exposed.

With individual keys, a compromised key affects exactly one node. You block that node, regenerate its key, and the rest of your fleet is unaffected. The customer at Site #14 had a security incident, but Sites #1 through #13 and #15 through #30 continue operating without interruption.

Granular Access Control

Individual node keys also enable finer access control in your own systems. If you integrate ProxyPass with your internal tooling via the Management API, you can grant access to specific nodes without exposing the group-wide key. Your field team accesses only the nodes they manage. Your monitoring system authenticates per-device.

Visibility and Management

The dashboard shows which nodes have individual keys, and you can generate, regenerate, or revoke keys at any time. Key changes trigger a webhook event (Node Settings Changed) if you have webhooks configured, so your systems stay in sync automatically.

Per-device security is not default because not everyone needs it. But when you do, it is one toggle away.

Request Access →

An unhandled error has occurred. Reload 🗙

Connection lost

Attempting to reconnect...

Connection failed

The server is not reachable.