Skip to main content
(*TheAuth).Doctor(ctx) inspects the live Config and storage and returns a Report: a summary count per severity and a list of findings, most serious first. Findings carry counts and setting names only, never secrets, tokens or user identifiers. Checks that need an optional storage capability are skipped when it is missing.

Use it

HTTP: GET /auth/admin/doctor (needs Config.APITokens) returns the report as JSON to a caller holding the root ability, by session or bearer token. See examples/doctor-admin for an admin page next to /healthz. CLI, for CI:
Exit codes: 0 ok, 1 findings at or above --fail-on or a request failure, 2 usage. Colors are off unless stdout is a TTY (also --no-color, NO_COLOR). Optional storage capabilities: UserCountStorage, DoctorAdminLister, DoctorSessionCounter, APITokenStorage, TOTPStorage.

Findings

<a id=“signup-open_no_allowlist”></a> <a id=“bootstrap-gate_off_no_users”></a> <a id=“network-trusted_proxies_empty”></a> <a id=“cookie-insecure_http”></a> <a id=“csrf-disabled”></a> <a id=“throttle-disabled”></a> <a id=“throttle-lax”></a> <a id=“password-min_length_low”></a> <a id=“password-no_breach_checker”></a> <a id=“mfa-admin_without_totp”></a> <a id=“mfa-none_enabled”></a> <a id=“session-ttl_long”></a> <a id=“session-no_idle_timeout”></a> <a id=“token-no_expiry”></a> <a id=“token-expiry_beyond_year”></a> <a id=“token-root_ability”></a> <a id=“token-agent_beyond_24h”></a> <a id=“token-expired_unpruned”></a> <a id=“session-expired_unpruned”></a> <a id=“crypto-encryption_key_missing”></a> <a id=“audit-no_sink”></a> <a id=“webauthn-rpid_mismatch”></a> <a id=“redirect-allowlist_empty”></a>
Last modified on October 7, 2026