# Celocli account unlock error

**URL:** <https://forum.celo.org/t/celocli-account-unlock-error/6827>\
**Category:** Testnets\
**Created:** [November 1, 2023, 2:52pm UTC](https://forum.celo.org/t/celocli-account-unlock-error/6827 "2023-11-01T14:52:44Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![saif-3230](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.celo.org/saif-3230/32/8467_2.png) [@saif-3230](https://forum.celo.org/u/saif-3230)\
**Post date:** [November 1, 2023, 2:52pm UTC](https://forum.celo.org/t/celocli-account-unlock-error/6827/1 "2023-11-01T14:52:44Z")

</div>

Hi team,  
I am trying to run a validator on the Baklava network. I have set up the technical infrastructure required, as per the documentation ([Run Baklava Testnet Validator](https://docs.celo.org/validator/run/baklava)). However, I am facing issues while registering the accounts using celocli.  
I am currently using celocli v3.0.2 and node v18.14.2.  
The command “celocli account: balance” is working correctly, displaying the celo testnet balance, But when using the command: “celocli account: unlock $CELO\_VALIDATOR\_GROUP\_ADDRESS”, I am receiving the following “error: account unlock with HTTP access is forbidden”.  
Can anyone please help me resolve this error?

---

<div class="post-metadata">

**Author:** ![arthurgousset](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.celo.org/arthurgousset/32/11117_2.png) [@arthurgousset](https://forum.celo.org/u/arthurgousset)\
**Post date:** [November 1, 2023, 6:15pm UTC](https://forum.celo.org/t/celocli-account-unlock-error/6827/2 "2023-11-01T18:15:09Z")

</div>

Hey @saif-3230, thanks for asking.

I’m using this this [StackOverflow](https://ethereum.stackexchange.com/q/69435) question and this section in the [docs](https://docs.celo.org/validator/run/baklava#unlocking):

> #### Unlocking[​](https://docs.celo.org/validator/run/baklava#unlocking)
> 
> Celo nodes store private keys encrypted on disk with a password, and need to be “unlocked” before use. Private keys can be unlocked in two ways:
> 
> 1. By running the `celocli account:unlock` command. Note that the node must have the “personal” RPC API enabled in order for this command to work.
> 2. By setting the `--unlock` flag when starting the node.
> 
> It is important to note that when a key is unlocked you need to be particularly careful about enabling access to the node’s RPC APIs.

Can you confirm that you are running your local node having the “personal” RPC API enabled?

From the [docs](https://docs.celo.org/validator/run/baklava#start-your-accounts-node), this is done by setting the `personal` flag in `--http.api eth,net,web3,debug,admin,personal` below:

> ### Start your Accounts node[​](https://docs.celo.org/validator/run/baklava#start-your-accounts-node)
> 
> Next, we’ll run a node on your local machine so that we can use these accounts to lock CELO and authorize the keys needed to run your validator.
> 
> To run the node:
> 
> ```auto
> # On your local machine
> mkdir celo-accounts-node
> cd celo-accounts-node
> docker run --name celo-accounts -it --restart always --stop-timeout 300 -p 127.0.0.1:8545:8545 -v $PWD:/root/.celo $CELO_IMAGE --verbosity 3 --syncmode full --http --http.addr 0.0.0.0 --http.api eth,net,web3,debug,admin,personal --baklava --light.serve 0 --datadir /root/.celo
> 
> ```

Small note, the [docs](https://docs.celo.org/validator/run/baklava#start-your-accounts-node) highlight that you should be particularly careful when running the command above.

> **Security** : The command line above includes the parameter `--http.addr 0.0.0.0` which makes the Celo Blockchain software listen for incoming RPC requests on all network adaptors. Exercise extreme caution in doing this when running outside Docker, as it means that any unlocked accounts and their funds may be accessed from other machines on the Internet. In the context of running a Docker container on your local machine, this together with the `docker -p 127.0.0.1:localport:containerport` flags allows you to make RPC calls from outside the container, i.e from your local host, but not from outside your machine. Read more about [Docker Networking](https://docs.docker.com/network/network-tutorial-standalone/#use-user-defined-bridge-networks) here.

Let me know if that helps!

---

<div class="post-metadata">

**Author:** ![tim](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.celo.org/tim/32/9_2.png) [@tim](https://forum.celo.org/u/tim)\
**Post date:** [November 1, 2023, 6:29pm UTC](https://forum.celo.org/t/celocli-account-unlock-error/6827/3 "2023-11-01T18:29:01Z")

</div>

It looks like the docs are a little out of date… you need to add the flag `--allow-insecure-unlock` to your node command line options, to allow the cli to unlock accounts whose keys are stored locally on the node.

As Arthur highlights, this is only safe to do on a testnet like Baklava or when you’re absolutely sure your node is not accessible to the outside world!

Let us know how you get on

---

<div class="post-metadata">

**Author:** ![saif-3230](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.celo.org/saif-3230/32/8467_2.png) [@saif-3230](https://forum.celo.org/u/saif-3230)\
**Post date:** [November 2, 2023, 6:38pm UTC](https://forum.celo.org/t/celocli-account-unlock-error/6827/4 "2023-11-02T18:38:15Z")

</div>

Hey @arthurgousset  
Thanks for your response.  
I have enabled the “personal” flag while starting my local node, as indicated in the official documentation. But I am still facing the same error.

---

<div class="post-metadata">

**Author:** ![saif-3230](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.celo.org/saif-3230/32/8467_2.png) [@saif-3230](https://forum.celo.org/u/saif-3230)\
**Post date:** [November 2, 2023, 6:47pm UTC](https://forum.celo.org/t/celocli-account-unlock-error/6827/5 "2023-11-02T18:47:26Z")

</div>

I agree the official docs are a bit outdated and need an update.  
Can I add the --allow-insecure-unlock flag to my existing local node running using docker, or should I run a new node altogether? It would be very helpful if you could guide me with this process ( As I am new to the docker ecosystem).  
The local node is currently running on dedicated hardware and is not accessible to the others.

---

<div class="post-metadata">

**Author:** ![saif-3230](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.celo.org/saif-3230/32/8467_2.png) [@saif-3230](https://forum.celo.org/u/saif-3230)\
**Post date:** [November 4, 2023, 10:45am UTC](https://forum.celo.org/t/celocli-account-unlock-error/6827/6 "2023-11-04T10:45:15Z")

</div>

Hey @tim ,  
Using the --allow-insecure-unlock worked for me. Although, I had to run a new docker container with the flag.  
Thank you very much for your guidance !! Have a nice weekend. 🙂

---

<div class="post-metadata">

**Author:** ![arthurgousset](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.celo.org/arthurgousset/32/11117_2.png) [@arthurgousset](https://forum.celo.org/u/arthurgousset)\
**Post date:** [November 6, 2023, 8:56pm UTC](https://forum.celo.org/t/celocli-account-unlock-error/6827/7 "2023-11-06T20:56:22Z")

</div>

Appreciate you following up here @saif-3230. Glad this worked for you 👍
