GRiMbot documentation

Security

This is the hosted copy of the GRiMbot technical manual. Use the table of contents to open any page in the manual.

Security

GRiMbot holds Twitch tokens, a Client Secret, GRiMbOS credentials, optional plugin tokens, chat history, and community records. Protect the host the same way you would protect a password manager.

Secrets

Secret Where it lives Rule
Twitch Client Secret SETUP BOT and .env Shown once in the Twitch Console. Never paste into chat or screenshots.
Twitch OAuth tokens .env / database Re-authorize from GRiMbOS. Do not paste tokens.
GRiMbOS username and password .env and SETUP BOT Unique. Unrelated to Twitch.
STREAMERBOT_AGENT_TOKEN .env and the PC Agent Shared secret between bot and streaming PC.
Discord bot token Discord Bot Settings Same handling as Twitch secrets.
Spotify Client Secret Spotify Settings Same handling.
AI Provider keys AI Settings Same handling.
SQLite database data/grimbot.db Contains operational and authorization data.

SECURITY

Never commit .env, tokens, or data/grimbot.db to git. Never attach an unsanitized diagnostic bundle to a public issue.

Access control

GRiMbOS at /admin is gated by the GRiMbOS username and password. Button Box is not password protected. Its LAN URL is the only gate. Disable the pad when it is not in use.

Do not reuse the Twitch account password as the GRiMbOS password.

Screenshots and logs

Before sharing:

  • [ ] Crop out tokens, secrets, and .env values.
  • [ ] Remove private IP addresses and host names.
  • [ ] Remove local user names from paths.
  • [ ] Remove Chat Messages that are not required.
  • [ ] Keep the feature name, time, and exact error.

Network exposure

Packaged installs bind to localhost. Do not port-forward GRiMbOS. Read Network and Ports before changing firewall or tunnel settings.

Related pages