Iroh Managed Relays Now Authenticated by Default

Protect Your Relays

Iroh Managed Relays Now Authenticated by Default

Iroh has made its managed relays authenticated by default, requiring endpoints to present a token issued by the project's API key. This prevents unauthorized use of relay bandwidth and connection slots. The token is a signed capability token that proves the endpoint owns its key, is addressed to that specific endpoint, and expires. Leaked URLs are harmless without a valid token, and leaked tokens don't allow impersonation. Existing relays deployed before June 2026 remain open unless you enable authentication in settings. The iroh_services preset automatically handles token generation and attachment.

A leaked URL is harmless. Without a token issued by your API key, dialing it gets you nothing.
  1. Surac

    Lol i expected a text about protecting relays from mechanical or electric problems. You know those real mechanical relays we used to build computers of some years ago

  2. Retr0id

    > A leaked token enables connections, but not impersonations. The token is addressed to one specific endpoint's public key

    So now the problem is moved to "how do you decide who to issue tokens to?", which every project must solve individually. It might sound like I'm being dismissive here but I think that's exactly the right approach.

More from this day

2026-08-14