finds.dev← search

// the find

dineshgurjar/multi_user_esp32

C · updated Jun 2026

Multi user admin and user dashboard for esp32 client devices

ESP32-P4 firmware paired with a Flask backend that sets up two-way WebRTC audio calls between a physical device and a browser via LiveKit, with Flask acting as the only holder of LiveKit API secrets. Aimed at hobbyists building intercom/baby-monitor-style IoT audio devices who don't want to bake WebRTC credentials into firmware.

The token-broker pattern is actually correct: the LiveKit API secret never leaves the Flask server, and both ESP32 and browser get short-lived (1hr) JWTs scoped to a room derived from the device MAC, so one compromised device doesn't leak access to others. TLS is handled properly too — it uses esp_crt_bundle_attach against the full CA bundle instead of pinning or skipping verification, and explicitly syncs SNTP before anything cert-dependent runs, which is the exact thing people forget on ESP32 and then can't figure out why HTTPS silently fails. The device_<MAC> / user_<id>_<MAC> identity scheme gives per-device room isolation for free without extra access-control logic on the LiveKit side.

The device owner's password sits in plaintext in main/config.h and gets sent to the server on every boot, not once — the API key is RAM-only and wiped on reboot, so the 'one-time bootstrap' in the docs is really 'every power cycle,' a bigger exposure window than advertised. It ships with a hardcoded default admin account (admin@iot.com / admin123) auto-created on first startup, which is a real risk if someone deploys to Render without remembering to change it. The Flask backend uses SQLite for a system that wants multi-user accounts, device ownership, and an admin panel — workable for one instance but no story for concurrent writers or backups once there's more than a single user's devices. And the GitHub description ('Multi user admin and user dashboard for esp32 client devices') doesn't match the README at all, which is a LiveKit audio-calling project — reads like a repo mid-pivot, not something to build on yet, and the zero stars/forks confirm nobody else has tried.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →