Super Admin Registration

Using the superadmin-registration.conf file you can provide a list of super admin registration tokens mapped to an email and password. The super admin can be activated as explained here and login as shown here.

superadmin-registration.conf
tokens = {
    "token-according-super-admin-conf": {
        expiration = "2029-01-01T00:00:00Z",  # Token has to be used by this expiration date
        devModeOnly = false                   # Required in production, see below
        account = {
            type = "email"
            identifier = { email = "superadmin@walt.id" }
            data = { password = "pw-according-super-admin-conf" }
        }
    }
}

devModeOnly

Boolean, optional — defaults to true. A token is only usable while dev-mode is disabled if this is explicitly set to false.

Production runs with dev-mode disabled, so a production token must set devModeOnly = false. Leave it unset on demo and example tokens so they can never be used in production.

Bootstrapping and recovery

Each token creates exactly one account and cannot be reused. To recover a lost super admin, add a second token to this file, activate it, then delete the old account.

Activation is rate limited to 5 requests per minute per source IP, configurable via rate-limit.conf.

Last updated on September 3, 2026