Skip to content
Server & Web Software

Apache Software Foundation Apache APISIX API Gateway — Default Password

Default username and password for the Apache Software Foundation Apache APISIX API Gateway: (blank) / edd1c9f034335f136f87ad84b625c8f1. Learn how to log in and how to change the default credentials.

Versions prior to 3.10.0 shipped with a hardcoded default Admin API key edd1c9f034335f136f87ad84b625c8f1 in config.yaml. As of 3.10.0 (August 2024) the hardcoded key was removed and replaced with auto-generation. Actively exploited in the wild.

UsernamePasswordAccessVersion / firmwareNotes
(blank / none)
edd1c9f034335f136f87ad84b625c8f1
API< 3.10.0Admin API key sent as X-API-KEY header to port 9180 (or 9080 in some configs). Same key in all default installs pre-3.10.0.

Responsible use

This database lists publicly documented default credentials so administrators can find and change them. Only use these on systems you own or are authorized to test.

Related devices