How the Joomla WebCron Key Is Created and Used
The Joomla WebCron key is the secret hash value required by native Schedule Runner requests; QCTNH creates one only when Joomla does not already have one.
Key lifecycle
QCTNH reads com_scheduler parameters. If webcron.key is empty, it uses Joomla’s random-password helper to generate a 20-character value and saves it. Existing keys are preserved rather than rotated on every check.
How QCTNH uses the key
The local component includes the key during secure service registration. QuantaCade stores the service secret and WebCron key together in encrypted form. The worker later calls the exact registered WebCron endpoint and appends hash=<key>.
Drift detection
The local registration stores a SHA-256 hash of the current WebCron key. If Joomla’s key changes, registered() becomes false until QCTNH synchronizes the new WebCron credential. Saving Joomla Scheduler configuration also triggers an automatic synchronization attempt.
Security rule
Treat the WebCron key as a secret. Do not publish a full WebCron URL containing hash=... in screenshots, forum posts, logs, or documentation.
Timing consequence
The scheduler rule described in How the Joomla WebCron Key Is Created and Used also affects when QuantaCade should wake the site. QCTNH reports aggregate next_due, whether that value is known, and a due count. When an exact future time is known, the central service can sleep toward that point instead of generating fixed high-frequency traffic.
If timing is unknown, QCTNH falls back to the configured Maximum Scheduler Delay and safety rechecks. Therefore a timing problem should be diagnosed from the scheduler snapshot first, not by assuming the service is simply a cron request every N minutes.
Community Discussion
Want to compare scheduler workflows, share practical tips, or discuss how you use this QCTNH feature? Visit the QC Task Nudge & Health Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.