Dashboard Access
Dashboard Access is optional during setup, but required before the deployed dashboard API and redacted exchange objects can be used in a browser.
mimir accessOne self-hosted Access application must protect exactly:
/dashboard/auth/dashboard/api/*/dashboard/log-objects/*
Do not protect the bare Worker host. /login must remain public for the branded
handoff, and machine routes must remain outside Access because they use
per-machine bearer tokens.
Automation uses CLOUDFLARE_API_TOKEN and normally MIMIR_ACCESS_EMAIL. The
token needs Account Access Apps and Policies Edit, plus Account Access
Organizations, Identity Providers, and Groups Read.
Mimir accepts only one exact Allow policy for the supplied email. It preserves permissive, bypass, additional, or conflicting policies and returns an action-required result instead of rewriting them.
After configuration, run:
mimir dashboardThe command opens the public /login handoff, completes Access authentication,
and returns to the private session list.
