Security
GRiMbot holds Twitch tokens, a Client Secret, GRiMbOS credentials, optional plugin tokens, chat history, and community records. Protect the host the same way you would protect a password manager.
Secrets
| Secret | Where it lives | Rule |
|---|---|---|
| Twitch Client Secret | SETUP BOT and .env |
Shown once in the Twitch Console. Never paste into chat or screenshots. |
| Twitch OAuth tokens | .env / database |
Re-authorize from GRiMbOS. Do not paste tokens. |
| GRiMbOS username and password | .env and SETUP BOT |
Unique. Unrelated to Twitch. |
STREAMERBOT_AGENT_TOKEN |
.env and the PC Agent |
Shared secret between bot and streaming PC. |
| Discord bot token | Discord Bot Settings | Same handling as Twitch secrets. |
| Spotify Client Secret | Spotify Settings | Same handling. |
| AI Provider keys | AI Settings | Same handling. |
| SQLite database | data/grimbot.db |
Contains operational and authorization data. |
SECURITY
Never commit
.env, tokens, ordata/grimbot.dbto git. Never attach an unsanitized diagnostic bundle to a public issue.
Access control
GRiMbOS at /admin is gated by the GRiMbOS username and password. Button Box is not password protected. Its LAN URL is the only gate. Disable the pad when it is not in use.
Do not reuse the Twitch account password as the GRiMbOS password.
Screenshots and logs
Before sharing:
- [ ] Crop out tokens, secrets, and
.envvalues. - [ ] Remove private IP addresses and host names.
- [ ] Remove local user names from paths.
- [ ] Remove Chat Messages that are not required.
- [ ] Keep the feature name, time, and exact error.
Network exposure
Packaged installs bind to localhost. Do not port-forward GRiMbOS. Read Network and Ports before changing firewall or tunnel settings.