Choose how users authenticate, set the proxy mode, and save a persistent session secret key before continuing into the app.
Security
Pick who handles login. Use Basic when Sortarr should prompt for credentials directly. Use Basic + local bypass only for trusted direct local-network installs with Proxy mode set to Direct. Use External only when a trusted reverse proxy already handles login and sends the upstream auth header below.
Connection test buttons stay disabled until authentication is configured and security setup is complete. Saving settings still validates configured connections.
Choose the proxy chain in front of Sortarr. Basic + local bypass is only supported with Direct. External authentication requires Single, Double, or Custom. Use Custom only if you need per-header hop overrides.
Used for session and CSRF signing. Keep this stable, and use the same value on every replica. Leave it blank to let Sortarr generate and persist one when you save, or enter your own value now if you want to control it.
Sortarr generated a temporary session secret at startup. Saving this form will persist a stable secret automatically unless you enter or generate one here first.