Your bookmarks are a map of what you care about, and that map should live on your own disk. nextDash has no user accounts and is built for a trusted network. Do not expose it directly to the public internet. Run it behind a private overlay network such as Tailscale, behind a reverse proxy with authentication, or bound to localhost.
Two tokens do two jobs: one protects every destructive endpoint, the other opens capture and nothing else. The API answers this dashboard by default, not every site open in your browser.
nextDash can also push out. Outgoing webhooks are signed with the Standard Webhooks scheme and cover five events: a bookmark added, changed or removed, and a monitored bookmark going down or coming back. The assistant endpoint is off until you switch it on.
Try it
- Set a write token in your compose file.
- Open Config, then Data and backups, then Webhooks, and add an endpoint.
- Check what you have switched on under Config.
