Protecting the Joomla WebCron Key
The Joomla WebCron key authenticates native WebCron requests and should be treated as a secret, even though it is managed inside Joomla’s System - Schedule Runner configuration.
Why the key matters
The QuantaCade worker appends the registered key as the WebCron hash parameter. Someone who obtains the key may be able to trigger Joomla WebCron outside your intended scheduler path, depending on site/network access.
Protection practices
- Do not publish the full WebCron URL/key in forum posts, screenshots, tickets, or documentation.
- Use HTTPS so the key is not exposed in plaintext transit.
- Restrict server/access logs and analytics systems that may record query strings.
- Rotate the key if exposure is suspected, then let QCTNH synchronize the new credential.
- Do not reuse the same key manually across unrelated Joomla sites.
QCTNH stores only what it needs locally
Local registration state uses a SHA-256 hash of the registered WebCron key to detect drift. The actual central wake-up credential is protected server-side and is not presented in the Dashboard.
Public service assumption
Protecting the Joomla WebCron Key assumes QuantaCade can safely reach the Joomla site from the public Internet. Private development environments can still use Joomla Scheduler through local/CLI/server-cron mechanisms, but they are intentionally outside the central Task Nudge wake-up model.
This is a product security constraint, not a licensing restriction; QCTNH remains free.
Protect and rotate the key safely
- Keep the Schedule Runner WebCron key out of public screenshots, forum posts, analytics, and tickets.
- Use HTTPS for the registered Joomla endpoint and restrict access to logs that record query strings.
- If exposure is suspected, regenerate the key in Joomla rather than continuing to trust it.
- Run Check WebCron/Test Connection as needed and verify QCTNH synchronizes the new key before expecting normal worker wake-ups.
Community Discussion
Want to compare scheduler workflows, share practical tips, or discuss how you use this QCTNH feature? Visit the QC Task Nudge & Health Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.