Open WebUI Administration
What This Article Covers
- How to administer Open WebUI.
- Users, groups, and permissions.
- Configuring models, providers, and API keys.
- Security and system settings.
- Backing up and maintaining your installation.
Introduction: Open WebUI Administration
Open WebUI is much more than a chat frontend. The admin interface lets you manage user accounts, provision models, configure API providers, and adjust global settings. If you run Open WebUI for a team or across multiple projects, understanding these features is essential for maintaining security and stability.
This article walks through the main administrative areas of Open WebUI and how to configure them properly for local deployment.
Key Concepts
- Admin Panel: Open WebUI’s management interface.
- Workspace: A personal or shared area for chats.
- Model: A selectable language model.
- Connection: A link to an external or local provider.
- API Key: Authentication credential for hosted models.
- Pipeline: Advanced processing chain for requests.
- Role: User role with specific permissions.
- Group: A collection of multiple users.
Initial Admin Access
When you first install Open WebUI and sign in, you become the default administrator. Access the admin panel through the gear icon. For security, choose a strong admin username and a robust password.
User Management
Under Admin Panel and Users, you can:
- Create new user accounts.
- Assign roles: Admin, User, Pending.
- Disable or delete accounts.
- Reset passwords.
- Configure user-specific settings.
In a team environment, avoid giving every user admin rights.
Groups and Permissions
Groups simplify permission management:
- An
AI Developersgroup can access coding models. - A
Supportgroup uses only certain chat models. - A
Guestsgroup has restricted token usage.
Through groups, you can selectively enable models, prompts, and features for specific user categories.
Model and Provider Management
In the Connections or Settings area, you can:
- Configure Ollama as your default provider.
- Add OpenAI, Anthropic, OpenRouter, or other providers.
- Store API keys.
- Set default models.
- Restrict model visibility by user or group.
Global Settings
Important system configurations include:
- Web Search: Search engine integration.
- RAG: Vector database and embedding model.
- Image Generation: Connection to a local image model.
- Speech-to-Text: Whisper integration.
- Title Generation: Automatic chat titles.
- Default Model: The model preselected for new users.
API Keys and Security
API keys for external providers should never be shared in plaintext. Open WebUI stores them server-side, but you as an admin have access. Best practices include:
- Using separate keys for different environments.
- Rotating keys regularly.
- Keeping keys out of prompts and logs.
- Using group limits to control costs.
Pipelines and Workflows
Pipelines extend Open WebUI with filtering, logging, or request modifications. They’re especially useful in teams for:
- Screening prompts for sensitive data.
- Recording requests.
- Caching responses.
- Building multi-step agent workflows.
Backup and Maintenance
Open WebUI stores settings, chats, and databases in a local directory. For Docker deployments, mount this directory:
-v /path/to/open-webui:/app/backend/data
Regular backups of this directory protect:
- User accounts and chat history.
- Settings and prompts.
- RAG documents, if stored locally.
Common Pitfalls
- The first user is automatically admin: Use a non-trivial username.
- API keys visible to all: Use group and role controls.
- Ollama unreachable: Verify the
OLLAMA_BASE_URLsetting. - Wrong default model: Users choose from what’s available.
- No backups: Data is lost if the container is recreated.
- Registration too open: Disable open registration in the admin panel if needed.
Further Reading
- BotServ.de Open WebUI Features
- BotServ.de Open WebUI Multi-User Setup
- BotServ.de Setting Up RAG in Open WebUI
- BotServ.de Open WebUI Tools
- BotServ.de Managing Ollama in Open WebUI
FAQ: Open WebUI Administration
How do I access the admin panel? Click the gear icon in the top right of the Open WebUI interface.
Can I create users without admin rights?
Yes. The User role limits access to personal chats and permitted models.
Where are API keys stored? Server-side in the Open WebUI database, either within the container or in your mounted data directory.
How do I restrict models to specific groups? Use the model or group settings in the admin panel.
Should I disable public registration? Yes, for private or team-internal setups, let only the admin create user accounts.
Sources and Further Reading
- Open WebUI Docs: https://docs.openwebui.com/
- Open WebUI GitHub: https://github.com/open-webui/open-webui
- Open WebUI Features: https://docs.openwebui.com/features/
Summary: Open WebUI Administration
Open WebUI offers comprehensive administration for users, groups, models, and providers. By using the admin panel effectively, you can control access, cap costs, strengthen security, and support team workflows. Key priorities are regular backups, careful API key management, and a clear role structure. With these in place, Open WebUI transforms from a simple chat tool into a full-featured platform for local AI.


