Skip to content
BotServBotServ
Open WebUIAdministrationUser ManagementLocal AIChat

Open WebUI Administration

Administer Open WebUI: manage users, groups, models, providers, and security settings.

S

schutzgeist

3 min read
Open WebUI Administration

Open WebUI Administration

What This Article Covers

  • How to administer Open WebUI.
  • Users, groups, and permissions.
  • Configuring models, providers, and API keys.
  • Security and system settings.
  • Backing up and maintaining your installation.

Introduction: Open WebUI Administration

Open WebUI is much more than a chat frontend. The admin interface lets you manage user accounts, provision models, configure API providers, and adjust global settings. If you run Open WebUI for a team or across multiple projects, understanding these features is essential for maintaining security and stability.

This article walks through the main administrative areas of Open WebUI and how to configure them properly for local deployment.

Key Concepts

  • Admin Panel: Open WebUI’s management interface.
  • Workspace: A personal or shared area for chats.
  • Model: A selectable language model.
  • Connection: A link to an external or local provider.
  • API Key: Authentication credential for hosted models.
  • Pipeline: Advanced processing chain for requests.
  • Role: User role with specific permissions.
  • Group: A collection of multiple users.

Initial Admin Access

When you first install Open WebUI and sign in, you become the default administrator. Access the admin panel through the gear icon. For security, choose a strong admin username and a robust password.

User Management

Under Admin Panel and Users, you can:

  • Create new user accounts.
  • Assign roles: Admin, User, Pending.
  • Disable or delete accounts.
  • Reset passwords.
  • Configure user-specific settings.

In a team environment, avoid giving every user admin rights.

Groups and Permissions

Groups simplify permission management:

  • An AI Developers group can access coding models.
  • A Support group uses only certain chat models.
  • A Guests group has restricted token usage.

Through groups, you can selectively enable models, prompts, and features for specific user categories.

Model and Provider Management

In the Connections or Settings area, you can:

  • Configure Ollama as your default provider.
  • Add OpenAI, Anthropic, OpenRouter, or other providers.
  • Store API keys.
  • Set default models.
  • Restrict model visibility by user or group.

Global Settings

Important system configurations include:

  • Web Search: Search engine integration.
  • RAG: Vector database and embedding model.
  • Image Generation: Connection to a local image model.
  • Speech-to-Text: Whisper integration.
  • Title Generation: Automatic chat titles.
  • Default Model: The model preselected for new users.

API Keys and Security

API keys for external providers should never be shared in plaintext. Open WebUI stores them server-side, but you as an admin have access. Best practices include:

  • Using separate keys for different environments.
  • Rotating keys regularly.
  • Keeping keys out of prompts and logs.
  • Using group limits to control costs.

Pipelines and Workflows

Pipelines extend Open WebUI with filtering, logging, or request modifications. They’re especially useful in teams for:

  • Screening prompts for sensitive data.
  • Recording requests.
  • Caching responses.
  • Building multi-step agent workflows.

Backup and Maintenance

Open WebUI stores settings, chats, and databases in a local directory. For Docker deployments, mount this directory:

-v /path/to/open-webui:/app/backend/data

Regular backups of this directory protect:

  • User accounts and chat history.
  • Settings and prompts.
  • RAG documents, if stored locally.

Common Pitfalls

  • The first user is automatically admin: Use a non-trivial username.
  • API keys visible to all: Use group and role controls.
  • Ollama unreachable: Verify the OLLAMA_BASE_URL setting.
  • Wrong default model: Users choose from what’s available.
  • No backups: Data is lost if the container is recreated.
  • Registration too open: Disable open registration in the admin panel if needed.

Further Reading

FAQ: Open WebUI Administration

How do I access the admin panel? Click the gear icon in the top right of the Open WebUI interface.

Can I create users without admin rights? Yes. The User role limits access to personal chats and permitted models.

Where are API keys stored? Server-side in the Open WebUI database, either within the container or in your mounted data directory.

How do I restrict models to specific groups? Use the model or group settings in the admin panel.

Should I disable public registration? Yes, for private or team-internal setups, let only the admin create user accounts.

Sources and Further Reading

Summary: Open WebUI Administration

Open WebUI offers comprehensive administration for users, groups, models, and providers. By using the admin panel effectively, you can control access, cap costs, strengthen security, and support team workflows. Key priorities are regular backups, careful API key management, and a clear role structure. With these in place, Open WebUI transforms from a simple chat tool into a full-featured platform for local AI.

Back to Blog
Share:

Related Posts