# LM Studio: choose authentication, execution location and model lifecycle

The application’s API address does not fully describe who can call the server or where model execution occurs. Model switching can also introduce cold-load latency and memory pressure.

## Which deployment does this concern?

Authentication is optional by default. Enabling network serving makes the API reachable beyond localhost. With LM Link, a localhost API request can be served by a model on a linked remote machine.

**Applies to:** Configuration-dependent behaviour. Native API-token authentication is documented for LM Studio 0.4.0 or newer; this case does not identify a vulnerable version range.

## Vendor controls and evaluation

The vendor provides native API tokens and permissions, recommends authentication for network binds, documents LM Link routing, and exposes idle TTL and Auto-Evict controls.

**Configuration to validate:** Enable required authentication and scoped token permissions for shared access; approve bind addresses and remote devices; configure model residency intentionally.

## What clients can learn

Verify effective server settings, token permissions and execution location. Measure first-load and repeated-request behaviour under the model lifecycle settings your application actually uses.

Keep an endpoint inventory, the effective configuration and the running artifact together. A configuration or model change should trigger a review of the boundary it changes. Assign an owner to the evidence and to any required action.

## Questions for your provider

- Do requests without a valid token fail on the deployed API?
- Which inference, model-management and tool permissions does each token have?
- Does LM Link resolve the model to an approved device?
- How do JIT loading, explicit loads, idle TTL and Auto-Evict affect latency and memory?

Use the [inference guide](/resources/llm-inference-security-and-operations) and [evaluation worksheet](/assets/downloads/ai-gateway-evaluation-worksheet.pdf) to record the answer in your deployment context.

### Technical detail: source scope and identifiers

This is documented configuration behaviour, not a security advisory, CVE or an observed compromise. The offline documentation describes local operation; enabled remote links and integrations require their own data-flow review.

- No CVE is assigned by this case. Evidence type: documented behaviour.
- The vendor distinguishes JIT-loaded models from explicitly loaded models. Auto-Evict does not apply indiscriminately to every model in memory.

## Primary and supporting records

- [Native authentication and token permissions](https://lmstudio.ai/docs/developer/core/authentication)
- [Serving on a network](https://lmstudio.ai/docs/developer/core/server/serve-on-network)
- [LM Link execution location](https://lmstudio.ai/docs/developer/core/lmlink)
- [Idle TTL and Auto-Evict](https://lmstudio.ai/docs/developer/core/ttl-and-auto-evict)
- [Offline operations and runtime updates](https://lmstudio.ai/docs/app/offline)

---
Published: 2026-10-07. Modified: 2026-10-07. Sources reviewed: 2026-10-07.

Author: OneQuill Research. Affiliation: OneQuill develops OneVir. Documentary review; selected case totals are not vendor security rankings.
