ACP auth and tokens

ACP_SECRET

RIG_TOKEN

Rotate

See also

Two different secrets — do not mix them up.

Bearer token that unlocks the cloud ACP endpoint itself. Without it,{" "} /acp returns 401. Set on the Railway acp service; clients send{" "} Authorization: Bearer …. Local stdio mode does not need this.

A personal developer token from{" "} Account → Security → Developer tokens . It starts with rig_at_, is shown once at creation, and is stored hashed. Required for devices, Mesh, and tickets. Public status/health work without it. You can also send{" "} X-Rig-Token on cloud requests, or type{" "} set token <rig_at_…> in an ACP chat.

Rotate ACP_SECRET on Railway if a client key leaks. Revoke a developer token from Account → Security (same page you minted it) — that immediately stops ACP fleet calls using that token.

acp auth ACP_SECRET bearer RIG_TOKEN X-Rig-Token developer token account security devices mesh tickets

Related guides

This article is part of the Rig knowledge base at userig.app/docs. Rig is a local-first Mac app that runs, watches, and restarts development processes with unified logs, ports, and a scoped MCP hub for AI coding agents. Your source code stays on your Mac.

https://userig.app/docs/acp-auth