Encyclopedia How the network works · Entry 202
Bitcoin RPC security: why a node API needs restricted access
In this article
At a glance
Key facts
Know what an API credential can reach
The cited security guidance includes wallet spending, privacy-sensitive reads and changes that can affect verification. An encrypted wallet can add an unlocking condition for particular actions, but that does not make broad RPC access harmless.
With multiple wallets loaded, wallet-specific endpoints matter. A program should target the intended wallet and receive only the access its deployment is designed to provide.
A network fix can accidentally expose control
Consider a local dashboard that cannot reach Core inside a container. Publishing the RPC port on every network interface may make the dashboard work while also exposing the control API beyond the host. Core’s documentation calls out this container-port hazard explicitly.
The correct question is which trusted client needs access and over which protected path. It is not whether any remote machine can now connect.
Local access still assumes a trustworthy host
Core normally supports a per-startup authentication cookie readable by the user running it, and documents rpcauth for suitable static credentials. Protect those files and the host account. Another program with sufficient local access can obtain credentials or imitate an RPC service.
Avoid placing credentials in public code, shared screenshots or untrusted diagnostic requests. A remote administration requirement calls for a deliberately secured private connection, not merely a difficult-to-guess password on an exposed endpoint.
Direct answers
Questions people ask
Is RPC the same as Bitcoin’s peer-to-peer port?
No. Peer connections exchange Bitcoin network data. RPC lets authorized clients control a particular node and possibly its wallets. The security requirements differ, even though both are network interfaces.
Does a strong RPC password make direct public exposure safe?
No. Core warns that RPC transport is unencrypted and the interface is not hardened for arbitrary internet traffic. Strong credentials do not remove those design limits or the risk of a compromised host.
Inspect the evidence
The answer and key facts have stable claim links. These records retain the scope and qualification when reused.
Bitcoin Core’s RPC interface lets authorized software inspect and control the node and, where available, wallet operations. That can include spending funds, reading private data or changing important behavior. Core’s documentation says not to expose RPC directly to the public internet: authentication is not encrypted transport, and the interface is not hardened for arbitrary internet traffic. Restrict access to trusted software and protected connections.
Educational explanation. Product-specific behavior is scoped to the cited documentation, checked 2026-10-02.
Scope: Bitcoin · data through 2026-10-02. Verification: verified · 2026-10-02T19:29:20.637Z.
Link to this claimDefault scope: Local authenticated access
Scope: Bitcoin · data through 2026-10-02. Verification: verified · 2026-10-02T19:29:20.637Z.
Link to this claimTransport: Authentication alone does not encrypt RPC traffic
Scope: Bitcoin · data through 2026-10-02. Verification: verified · 2026-10-02T19:29:20.637Z.
Link to this claimRevision history
- — First publication after primary-source research and separate automated verification.
Source register
Sources and references
Retrieval dates and locators are recorded individually.- JSON-RPC interfaceBitcoin Core
Privileged RPC scope, authentication, local access and unencrypted transport limitations.
Locator: Introduction; Endpoints; Versioning; Security; RPC consistency guarantees · Version / scope: Bitcoin Core v29.0 · Retrieved: 2026-10-02T18:53:55.910ZOpen source - P2P NetworkBitcoin developer documentation
Peer connections, initial download and block/transaction relay.
Locator: Peer Discovery; Connecting To Peers; Initial Block Download; Block Broadcasting; Transaction Broadcasting · Version / scope: Developer guide; historical implementation details require qualification · Retrieved: 2026-10-02T18:53:53.860ZOpen source
Research and drafting use AI assistance. A separate automated review checks claims against primary sources; no external expert or named human review is implied. Publication, substantive editing, source retrieval and verification are recorded separately. This version was independently checked by an automated reviewer on 2 October 2026.
Editorial method and correctionsDegrees of Satoshi editorial project. “Bitcoin RPC security: why a node API needs restricted access.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/bitcoin-node-rpc-security/