Commons:Bots/Secure login

Bot operators are encouraged to use secure login methods such as OAuth or BotPassword, especially when running the bots on shared environment such as Toolforge.

Secure login methods

BotPassword

Bot passwords allow access to a bot account via the API, but not via the Weblogin, without using the account's main login credentials. The user rights available when logged in with a bot password may be restricted. OAuth is more secure than bot passwords and should be preferred whenever the bot supports it.

Bot passwords are shared, you need to create the password only on your local Wiki, but if you want to use them in a different Wiki, log in with the Weblogin and visit any page in that Wiki.

OAuth

OAuth allow access to a bot account via the API, but not via the Weblogin, without using the account's main login credentials. The user rights available when logged in with a OAuth may be restricted.

Bot with special privileges

It is highly suggested for adminbots and bots with other special privileges (license reviewer) to use one of the aforementioned login methods and restrict permission/access only to needed permissions.

Bots
Bot Login method Permission
AnankeBotUnknownlicense review
CommonsDelinkerBotPasswordsysop
KrinkleBotBotPasswordsysop
FlickreviewR 2BotPasswordlicense review
FaebotOAuthlicense review
Hazard-BotUnknownlicense review
INaturalistReviewBotUnknownlicense review
JarektBotUnknownlicense review
JoRobotUnknownlicense review
LicenseReviewerBotUnknownlicense review
MDanielsBotUnknownlicense review
Open Access Media Importer BotUnknownlicense review
Wiki-BotUnknownlicense review
タチコマ robotUnknownlicense review
Category:Commons bots#%20 Category:Commons help
Category:Commons bots Category:Commons help