# Admin Panel Still Accessible After Disabling ADMIN\_TOKEN

**URL:** <https://vaultwarden.discourse.group/t/admin-panel-still-accessible-after-disabling-admin-token/4967>\
**Category:** Help\
**Created:** [March 27, 2026, 9:52pm UTC](https://vaultwarden.discourse.group/t/admin-panel-still-accessible-after-disabling-admin-token/4967 "2026-03-27T21:52:35Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![daave](https://avatars.discourse-cdn.com/v4/letter/d/7cd45c/32.png) [@daave](https://vaultwarden.discourse.group/u/daave)\
**Post date:** [March 27, 2026, 9:52pm UTC](https://vaultwarden.discourse.group/t/admin-panel-still-accessible-after-disabling-admin-token/4967/1 "2026-03-27T21:52:35Z")

</div>

I’m running `vaultwarden/server:1.35.4` via docker and I enabled the admin panel ADMIN\_TOKEN to configure SMTP. After I was done, I commented out the ADMIN\_TOKEN line in `docker_compose.yaml,`ran `docker compose down` and `docker compose up -d` and after that I was still able to hard refresh the admin panel and access it without re-entering the token. After clicking log out, I was still able to re-enter the token and log back in. Is this a security bug? How can I ensure the admin panel is disabled during production? Thanks!

---

<div class="post-metadata">

**Author:** ![stefan0xC](https://yyz2.discourse-cdn.com/free1/user_avatar/vaultwarden.discourse.group/stefan0xc/32/1765_2.png) [@stefan0xC](https://vaultwarden.discourse.group/u/stefan0xC)\
**Post date:** [March 28, 2026, 4:28am UTC](https://vaultwarden.discourse.group/t/admin-panel-still-accessible-after-disabling-admin-token/4967/2 "2026-03-28T04:28:26Z")

</div>

If you have configured SMTP via the `/admin` panel you probably have created a `data/config.json` that sets the `ADMIN_TOKEN`. So it’s not a bug but how the configuration system currently works.

> **[Configuration overview](https://github.com/dani-garcia/vaultwarden/wiki/Configuration-overview)**
>
> Unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden\_rs - dani-garcia/vaultwarden

> [@daave](#):
>
> How can I ensure the admin panel is disabled during production?

Make sure an `ADMIN_TOKEN` is not configured (and also `DISABLE_ADMIN_TOKEN` is not set). Cf. [Enabling admin page · dani-garcia/vaultwarden Wiki · GitHub](https://github.com/dani-garcia/vaultwarden/wiki/Enabling-admin-page#disabling-the-admin-page)

You can also add additional safeguards via a reverse proxy to e.g. deny all access to `/admin`.

---

<div class="post-metadata">

**Author:** ![daave](https://avatars.discourse-cdn.com/v4/letter/d/7cd45c/32.png) [@daave](https://vaultwarden.discourse.group/u/daave)\
**Post date:** [April 11, 2026, 12:06am UTC](https://vaultwarden.discourse.group/t/admin-panel-still-accessible-after-disabling-admin-token/4967/3 "2026-04-11T00:06:09Z")

</div>

But the admin panel remained accessible after the admin token had been removed. Seems bad.

---

<div class="post-metadata">

**Author:** ![stefan0xC](https://yyz2.discourse-cdn.com/free1/user_avatar/vaultwarden.discourse.group/stefan0xc/32/1765_2.png) [@stefan0xC](https://vaultwarden.discourse.group/u/stefan0xC)\
**Post date:** [April 11, 2026, 12:54am UTC](https://vaultwarden.discourse.group/t/admin-panel-still-accessible-after-disabling-admin-token/4967/4 "2026-04-11T00:54:15Z")

</div>

> [@daave](#):
>
> after the admin token had been removed

Like I said you probably did not actually remove it because you had configured it twice by saving the config via the `/admin` panel. If I remove the admin token I get the message “The admin panel is disabled, please configure the ‘ADMIN\_TOKEN’ variable to enable it” for `/admin` and all other routes are 404 not found.

---

<div class="post-metadata">

**Author:** ![daave](https://avatars.discourse-cdn.com/v4/letter/d/7cd45c/32.png) [@daave](https://vaultwarden.discourse.group/u/daave)\
**Post date:** [April 11, 2026, 3:09am UTC](https://vaultwarden.discourse.group/t/admin-panel-still-accessible-after-disabling-admin-token/4967/5 "2026-04-11T03:09:01Z")

</div>

Ah, yes, now I understand! Thanks for clarifying that! Saving the config created a `config.json`file that _included_ the `ADMIN_TOKEN` value. Makes sense!
