The auth would involve a shared key to prevent processes without access to ~/.roborev/config.toml from interacting with the daemon. For example, if the daemon is running on a machine under an isolated roborev account, then other accounts without access to /home/roborev/.roborev/config.toml would not be able to interact with the daemon process without the shared access key.