Skip to content
Mimir

Dashboard Access

Dashboard Access is optional during setup, but required before the deployed dashboard API and redacted exchange objects can be used in a browser.

Terminal window
mimir access

One self-hosted Access application must protect exactly:

  • /dashboard/auth
  • /dashboard/api/*
  • /dashboard/log-objects/*

Do not protect the bare Worker host. /login must remain public for the branded handoff, and machine routes must remain outside Access because they use per-machine bearer tokens.

Automation uses CLOUDFLARE_API_TOKEN and normally MIMIR_ACCESS_EMAIL. The token needs Account Access Apps and Policies Edit, plus Account Access Organizations, Identity Providers, and Groups Read.

Mimir accepts only one exact Allow policy for the supplied email. It preserves permissive, bypass, additional, or conflicting policies and returns an action-required result instead of rewriting them.

After configuration, run:

Terminal window
mimir dashboard

The command opens the public /login handoff, completes Access authentication, and returns to the private session list.