FRP Tunnel uses token-based authentication. Tokens are generated with ft token using secrets.token_hex(16).
- Change the default dashboard password (
admin/admin) infrps.yaml - Restrict firewall rules to specific IP ranges when possible
- Use SSH key authentication instead of passwords
- Keep FRP binaries updated
Please report security issues via GitHub Issues with the "security" label.