Nodes/Orel's Nodes/Hugging Face Token
ComfyUI Node

Hugging Face Token

The node with no wires, and that's deliberate

By DarkOrel·Created 21 days ago·Updated 13 days ago· 1
Hugging Face Token

      A node with no inputs and no outputs looks broken the first time you drop it on the canvas. There's no socket to plug anything into, so what is it even doing? Here's the thing: it's not passing a value along a wire. It's setting state for the whole ComfyUI server.

      Why you'd need it at all

      Because Hugging Face doesn't hand everything over anonymously. BFL's FLUX repos - the FLUX.1 [dev] and Kontext line, the FLUX.2 weights - sit behind gates where you click through terms while logged in, and the file endpoints then want a read token. Same story for private repos or anything a creator has locked down. Without a credential, Model's Download comes back with an access-denied message and nothing else happens.

      The token is global to the server, which is why there's no cable. Every model download node on that machine picks it up - you set it once, not per node.

      How it actually works

      Precedence, and this is the part to internalise: HF_TOKEN in the environment of the running ComfyUI process always wins. If it's set, the dialog refuses to save anything and tells you to change it in the environment and restart. Past that, the token comes from a session value (gone when ComfyUI restarts) or, if you tick Remember on this server, from a file at ComfyUI/user/orels-nodes/hf_token written into a 0700 directory with an atomic replace. Ungoverned by encryption - it's a plaintext file with private permissions, so treat it like one.

      Nothing about the token is ever serialised into the workflow or returned to the browser. The status endpoint only ever reports where the credential came from: environment, session, saved on server, or not configured. Save checks the shape of what you typed (hf_ prefix, 10–512 characters, no whitespace) and does not verify that it can access anything - you discover that at download time.

      Two buttons do the work: Set / change Hugging Face token, a dialog with a link to HF's token settings, a password field, a Remember checkbox and a full-width Remove saved/session token; and Check token / connections to re-read status. The node also snaps itself back to 460×240 on reload, which explains the suspiciously immovable size - that's the author stopping a Node-2.0-era resize from leaving an empty slab on your canvas.

      The trap nobody warns you about

      A token does not grant you license access. If you never opened the repo page and clicked accept on the gated agreement, you get a gated-repo error and a 403 no matter how valid your token is. The node can't do it for you, and neither can anyone else - it's a click on the site, in the same account that owns the token. Do that first, then paste the token here.

      The other one is quiet: this is server-wide state, so anyone who can reach your ComfyUI and open that dialog can swap the token every download uses. If you're exposing ComfyUI beyond localhost, put it behind TLS and auth.

      Install and use

      cd ComfyUI/custom_nodes
      git clone https://github.com/DarkOrel/Orels-Nodes orels-nodes
      python -m pip install -r orels-nodes/requirements.txt
      

      Restart, hard-refresh, and the four nodes appear together under Orel's Nodes / Models. Create a read-only token at huggingface.co/settings/tokens, paste it, click Save. Session mode is the right default on a shared or cloud box; Remember is convenient locally, but on RunPod the saved file lands in the ComfyUI user directory - if that's inside the container and not on a mounted volume, it evaporates with the pod.

      Honestly, on a rented box, set HF_TOKEN as an environment variable and never touch this node. It's the option that survives restarts, keeps the secret out of the UI, and takes priority anyway. The node exists for the other case: a local install where you'd rather not edit shell profiles for one gated download.

      CategoryOrel's Nodes/Models

      Inputs (0)

      No inputs

      Outputs (0)

      No outputs