Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Open WebUI’s Admin settings configure the instance; each user’s settings configure that person’s experience. Administrators connect model providers, manage authentication and signups, and set defaults, while individual users can change their own interface preferences. The exact controls and environment-variable behavior vary by release, so check the official documentation for the version you have installed.

Where do you configure Open WebUI as an admin?

Sign in with an administrator account and open the Admin area. Its sections group instance-wide controls such as provider connections, authentication, interface defaults, and models. Menu labels and available options may change between releases.

Open WebUI describes its admin role as root-equivalent on the deployment. Treat administrators as trusted operators with broad control; visibility toggles in the interface are not a security boundary against an administrator. See the official Authentication & Access documentation for the security model.

What’s the difference between Admin settings and my own settings?

Admin settings establish shared configuration and defaults for the instance. User settings belong to an individual account. For example, an administrator can set a default interface configuration, while a user can adjust that starting configuration for their own use.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Model settings follow a similar distinction: administrators can configure instance-wide model defaults or selections, while users make choices available to their own accounts. A default is a starting point, not necessarily a forced preference for every user.

For details on these distinctions, see Open WebUI’s Understanding Settings, Default Interface Settings, and Models documentation.

How do you connect Ollama or an OpenAI-compatible provider?

Open WebUI provides the interface, not the underlying models. Its Quick Start documentation puts it plainly: “Open WebUI has no models of its own.” To use models, connect a local or cloud provider in the Admin Connections area.

Provider type Where the endpoint runs What to check
Ollama Typically a local or otherwise reachable Ollama service Configure the service endpoint and confirm Open WebUI can reach it. Follow the Quick Start and connection documentation for the installed release.
OpenAI-compatible API May be a hosted cloud service or a compatible service you operate Supply the endpoint URL and credentials when required. Some providers do not expose a model list for automatic discovery, so you may need to enter model IDs manually. See the OpenAI-compatible provider guide.

Connection details depend on the provider: an endpoint URL, API credential, and model ID may be needed. Use the provider’s instructions alongside the Open WebUI connection guide rather than assuming that every compatible API behaves identically.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How do you control signups and authentication?

Plan first-admin creation before starting a fresh database

The environment-variable guide says automatic initial administrator creation requires both WEBUI_ADMIN_EMAIL and WEBUI_ADMIN_PASSWORD to be configured while the database has no users. This is a fresh-database condition, not a method for resetting an existing administrator. Use strong, unique credentials and keep passwords out of source control.

After the administrator account is created, signup is disabled automatically. Administrators can later enable new accounts in Admin Authentication; depending on configuration, new accounts may require approval. See the official Quick Start and Authentication & Access documentation.

Keep authentication controls distinct

WEBUI_AUTH defaults to enabled in the environment reference. Disabling authentication is described there as an option only for a fresh installation with no users. Do not treat this as a routine way to open an established instance.

The login form is a separate control. The reference says ENABLE_LOGIN_FORM can be changed through Admin Authentication and takes effect immediately. It also warns administrators to establish SSO or LDAP before disabling the form. The documented behavior distinguishes disabling the form and refusing local signup through the signup endpoint from password sign-in through the API, which has a separate control. Check the installed release’s documentation before changing either setting.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How do environment variables interact with settings in the UI?

Use the Admin UI for supported interactive configuration; use environment-based configuration when you need to set deployment behavior at startup or manage configuration through automation. They are not interchangeable in every case. The environment reference marks some values as ConfigVar: those are persisted internally, while other settings may be read from the process environment. Do not assume a universal precedence rule or that every environment variable is stored the same way.

Some model defaults and connection settings can be managed through the UI or environment configuration. The reference includes JSON-based defaults and warns that malformed JSON can result in empty defaults in the documented examples. Copy syntax only from the documentation for your installed version.

The official Reference describes itself as the canonical documentation for environment variables, API endpoints, network architecture, reverse proxies, and monitoring. Its Environment Variable Configuration page identifies itself as v0.11.1 and says it is a work in progress. Because configuration details can change, check both the reference and the release you run before applying a setting. For API-specific configuration, consult API Endpoints.

Which security settings deserve extra care?

  • Protect the secret key. The reference describes WEBUI_SECRET_KEY as a key used for JWT signing and encrypting sensitive data. Standard launch methods are described as generating and persisting a random key at first start; development launch methods may require the operator to set one. Confirm the behavior for your launch method and release.
  • Avoid non-expiring tokens in production. The environment reference warns against setting JWT_EXPIRES_IN to -1 in production because this disables token expiration.
  • Control deployment access. Since administrators have broad, root-equivalent authority by design, protect administrator accounts and the host or deployment access behind them.
  • Verify before changing login behavior. Plan SSO or LDAP and account access before disabling the login form, and distinguish that choice from local signup and API password authentication.

These behaviors and warnings come from the release-sensitive environment configuration reference and authentication documentation; verify the current guidance for your installed release.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.