# Bitcoin RPC security: why a node API needs restricted access

Bitcoin Core’s RPC interface lets authorized software inspect and control the node and, where available, wallet operations. That can include spending funds, reading private data or changing important behavior. Core’s documentation says not to expose RPC directly to the public internet: authentication is not encrypted transport, and the interface is not hardened for arbitrary internet traffic. Restrict access to trusted software and protected connections.

Evidence: [JSON-RPC interface](https://raw.githubusercontent.com/bitcoin/bitcoin/v29.0/doc/JSON-RPC-interface.md)

Canonical: https://degreesofsatoshi.com/encyclopedia/bitcoin-node-rpc-security/
Published: 2026-10-02
Substantively modified: 2026-10-02
Independently verified by an automated reviewer: 2026-10-02T19:29:20.637Z
Data current through: 2026-10-02

AI-assisted research and drafting with a separate automated source-verification pass; no external expert or named human review is implied.

## Key facts

- **Authority:** RPC is a control interface, not just public data ([JSON-RPC interface](https://raw.githubusercontent.com/bitcoin/bitcoin/v29.0/doc/JSON-RPC-interface.md))
- **Default scope:** Local authenticated access ([JSON-RPC interface](https://raw.githubusercontent.com/bitcoin/bitcoin/v29.0/doc/JSON-RPC-interface.md))
- **Transport:** Authentication alone does not encrypt RPC traffic ([JSON-RPC interface](https://raw.githubusercontent.com/bitcoin/bitcoin/v29.0/doc/JSON-RPC-interface.md))

## Know what an API credential can reach

The cited security guidance includes wallet spending, privacy-sensitive reads and changes that can affect verification. An encrypted wallet can add an unlocking condition for particular actions, but that does not make broad RPC access harmless.

With multiple wallets loaded, wallet-specific endpoints matter. A program should target the intended wallet and receive only the access its deployment is designed to provide.

Evidence: [JSON-RPC interface](https://raw.githubusercontent.com/bitcoin/bitcoin/v29.0/doc/JSON-RPC-interface.md)

## A network fix can accidentally expose control

Consider a local dashboard that cannot reach Core inside a container. Publishing the RPC port on every network interface may make the dashboard work while also exposing the control API beyond the host. Core’s documentation calls out this container-port hazard explicitly.

The correct question is which trusted client needs access and over which protected path. It is not whether any remote machine can now connect.

Evidence: [JSON-RPC interface](https://raw.githubusercontent.com/bitcoin/bitcoin/v29.0/doc/JSON-RPC-interface.md)

## Local access still assumes a trustworthy host

Core normally supports a per-startup authentication cookie readable by the user running it, and documents rpcauth for suitable static credentials. Protect those files and the host account. Another program with sufficient local access can obtain credentials or imitate an RPC service.

Avoid placing credentials in public code, shared screenshots or untrusted diagnostic requests. A remote administration requirement calls for a deliberately secured private connection, not merely a difficult-to-guess password on an exposed endpoint.

Evidence: [JSON-RPC interface](https://raw.githubusercontent.com/bitcoin/bitcoin/v29.0/doc/JSON-RPC-interface.md)

## Questions

### Is RPC the same as Bitcoin’s peer-to-peer port?

No. Peer connections exchange Bitcoin network data. RPC lets authorized clients control a particular node and possibly its wallets. The security requirements differ, even though both are network interfaces.

Evidence: [JSON-RPC interface](https://raw.githubusercontent.com/bitcoin/bitcoin/v29.0/doc/JSON-RPC-interface.md); [P2P Network](https://developer.bitcoin.org/devguide/p2p_network.html)

### Does a strong RPC password make direct public exposure safe?

No. Core warns that RPC transport is unencrypted and the interface is not hardened for arbitrary internet traffic. Strong credentials do not remove those design limits or the risk of a compromised host.

Evidence: [JSON-RPC interface](https://raw.githubusercontent.com/bitcoin/bitcoin/v29.0/doc/JSON-RPC-interface.md)

## Claims and scope

### bitcoin-node-rpc-security-quick-answer

Bitcoin Core’s RPC interface lets authorized software inspect and control the node and, where available, wallet operations. That can include spending funds, reading private data or changing important behavior. Core’s documentation says not to expose RPC directly to the public internet: authentication is not encrypted transport, and the interface is not hardened for arbitrary internet traffic. Restrict access to trusted software and protected connections.

Educational explanation. Product-specific behavior is scoped to the cited documentation, checked 2026-10-02.

Scope: {"collection":"bitcoin","dataAsOf":"2026-10-02","blockHeight":null}

### bitcoin-node-rpc-security-fact-authority

Authority: RPC is a control interface, not just public data

Scope: {"collection":"bitcoin","dataAsOf":"2026-10-02","blockHeight":null}

### bitcoin-node-rpc-security-fact-default-scope

Default scope: Local authenticated access

Scope: {"collection":"bitcoin","dataAsOf":"2026-10-02","blockHeight":null}

### bitcoin-node-rpc-security-fact-transport

Transport: Authentication alone does not encrypt RPC traffic

Scope: {"collection":"bitcoin","dataAsOf":"2026-10-02","blockHeight":null}

## Sources

- [JSON-RPC interface](https://raw.githubusercontent.com/bitcoin/bitcoin/v29.0/doc/JSON-RPC-interface.md) — Bitcoin Core. Privileged RPC scope, authentication, local access and unencrypted transport limitations. Locator: Introduction; Endpoints; Versioning; Security; RPC consistency guarantees. Retrieved: 2026-10-02T18:53:55.910Z.
- [P2P Network](https://developer.bitcoin.org/devguide/p2p_network.html) — Bitcoin developer documentation. Peer connections, initial download and block/transaction relay. Locator: Peer Discovery; Connecting To Peers; Initial Block Download; Block Broadcasting; Transaction Broadcasting. Retrieved: 2026-10-02T18:53:53.860Z.

## Revision history

- 2026-10-02: First publication after primary-source research and separate automated verification.

## Cite this entry

Degrees of Satoshi editorial project. “Bitcoin RPC security: why a node API needs restricted access.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/bitcoin-node-rpc-security/
