Authentication: Securing Your AI Services
What This Article Covers
- Why authentication is essential for your AI services
- What API keys, Basic Auth, OAuth, and 2FA mean
- How to set up authentication in front of a reverse proxy
- How to restrict access to Ollama and Open WebUI
- Common mistakes that create security vulnerabilities
Introduction
When you expose an AI service like Ollama, Open WebUI, or your own API to your network or the internet, encryption is only part of the story. Authentication is equally critical. Without it, anyone who knows the address can use your models, send prompts, or query sensitive data.
Authentication ensures that only authorized users and applications can access a service. This article covers the main approaches using standard terminology: API keys, Basic Auth, OAuth, and 2FA. You’ll learn how to implement them in typical AI setups and which pitfalls to avoid.
If you’re new to network security, start with Secure Operations and Network Security Fundamentals.
Why Authentication Matters for AI Services
AI services can be powerful within your network. An agent might access files, execute commands, or interact with other services through tools. If anyone can access without verification, that’s a serious risk.
Authentication prevents:
- Unauthorized use of compute resources and API quotas
- Exposure or modification of private data
- External attacks that use your AI as a foothold
- Configuration mistakes that accidentally expose everything publicly
Authentication alone isn’t enough. Always pair it with TLS and a firewall. Only the combination of encryption, access control, and network isolation creates a solid setup.
Authentication Explained
Authentication answers: Who are you? Don’t confuse it with authorization, which answers: What are you allowed to do? Both terms often appear together.
For an AI service, a typical flow looks like this:
- The client sends a request to an API endpoint.
- The server demands an authentication credential, such as an API key or token.
- The client provides the credential in a header or cookie.
- The server validates the credential and grants or denies access.
The main approaches are API keys, Basic Auth, OAuth, and 2FA. Each has strengths and weaknesses. API keys are simple but vulnerable if stored carelessly. Basic Auth is straightforward and suits internal tools. OAuth works well for user logins via external providers. 2FA increases security by requiring a second verification step.
Who Should Read This Article
This article is for beginners who want to secure their own AI services. You should be comfortable using a terminal and understand how HTTP requests work. Experience with Bash or Python helps but isn’t required.
This is for you if you:
- Want to expose Ollama or Open WebUI on your network
- Need to pick the right authentication method
- Use or plan to set up a reverse proxy
- Want to prevent unauthorized access to your AI
Key Terms
| Term | Explanation |
|---|---|
| API Key | A secret string the client includes with every request. |
| Basic Auth | A simple method that sends username and password Base64-encoded in a header. |
| OAuth | A protocol allowing users to sign in via an external provider. |
| 2FA | Two-Factor Authentication. Two different factors are required, such as a password and a code. |
| Token | A time-limited credential issued after authentication. |
| Header | A field in an HTTP request containing metadata like authentication. |
| Endpoint | A URL through which a service is accessible, such as an API. |
| Reverse Proxy | A server that accepts requests and forwards them to internal services. |
| Replay Attack | An attack where an intercepted request is replayed. |
| Secret | A confidential value such as a password or private key. |
API Keys
API keys are the simplest form of authentication. The client includes a secret string in every request. The server checks whether it recognizes the key.
A typical request looks like this:
curl -H "Authorization: Bearer mein-api-key-12345" \
https://ki.dein-domain.de/api/generate
The advantage: API keys are easy to generate and distribute. The disadvantage: they function like passwords. Anyone holding a key can impersonate an authorized client. Never commit keys to public repositories or documentation.
Better practice is to issue multiple keys for different purposes and rotate them regularly. Monitor which IP addresses use a key and at what times. This helps you spot abuse early.
Basic Auth
Basic Auth is a simple standard that transmits username and password in an HTTP header. The credentials are Base64-encoded but not encrypted. For this reason, Basic Auth only works over HTTPS.
An example for Nginx looks like this:
sudo htpasswd -c /etc/nginx/.htpasswd admin
In your Nginx configuration, add these lines:
auth_basic "KI-Service";
auth_basic_user_file /etc/nginx/.htpasswd;
When a client accesses the endpoint, a browser popup appears. Basic Auth works well for internal services with few users. It’s not very convenient and doesn’t support 2FA.
For AI services, Basic Auth is a practical starting point as long as you enforce HTTPS. Learn more about TLS in the article on TLS certificates.
OAuth and 2FA
OAuth is a protocol that authenticates users through an external provider. Common providers include Google, GitHub, or your own identity server. The advantage: your AI service doesn’t store passwords. Instead, it receives a token from the provider.
OAuth is especially useful when multiple people use your AI service. Each person signs in with their existing account. You manage permissions per user.
2FA, also called Multi-Factor Authentication, requires two independent proofs of identity. A classic example is a password plus a code from an authenticator app. WebAuthn with hardware keys is also possible.
For sensitive AI setups in corporate environments, OAuth and 2FA are often essential. Open WebUI, for example, supports OAuth integration with external providers. See more at Open WebUI.
Authentication for Ollama and Open WebUI
Ollama itself doesn’t include built-in authentication. If you expose Ollama to your network, place a Reverse Proxy in front of it with Basic Auth or API Key protection. Alternatively, run Ollama in a container that’s only reachable on your internal network.
Open WebUI, by contrast, comes with a user account system. You can create local accounts, set passwords, and optionally enable external authentication. Still, access should go through HTTPS so passwords aren’t sent in plaintext.
Picture this setup: Open WebUI runs on port 8080. An Nginx proxy listens on HTTPS and requires Basic Auth before forwarding the request to Open WebUI. This gives you two layers of protection: TLS encrypts the traffic, and authentication controls who gets in. For details on networking Ollama, see the article on Ollama network access.
Common Pitfalls
- API keys in code or Git repositories: Anyone with access to the repo can use the key. Store keys in environment variables or a secret manager instead.
- Authentication without HTTPS: Sending Basic Auth or API keys over unencrypted connections is dangerous. Always require TLS.
- Weak passwords: Short passwords are insufficient for Basic Auth. Use long, random passwords.
- Forgetting 2FA: A password alone isn’t enough for sensitive data. Enable 2FA as soon as your tool supports it.
- Not rotating tokens: API keys and tokens should be renewed regularly. Otherwise, a leaked key can be exploited for a long time undetected.
- No access logs: Track who accessed what and when. Without logs, you won’t spot attacks early enough.
- Admin interfaces publicly accessible: Never expose an admin panel to the internet without protection. Restrict it to internal IPs or a VPN.
Hardware, Costs, and Security
Authentication typically costs nothing. You generate API keys yourself. Basic Auth requires only a password file. OAuth can run free with open-source identity providers like Keycloak or Authentik.
Computing power for authentication is negligible. Even a small home server like a Raspberry Pi can handle OAuth checks or password hashing. What matters more is backing up your user data and keys. If you lose the password file or secret keys, you might lock yourself out.
For maximum security, use a Reverse Proxy that terminates authentication. This keeps your AI services simple behind it. Also pay attention to a good Firewall so no unnecessary ports are exposed.
Further Reading
- Secure operation overview
- Network security
- Reverse Proxy
- Firewall
- TLS certificates
- Ollama network access
- Open WebUI
FAQ
What is an API key?
An API key is a secret string the client sends with each request. The server validates whether the key is legitimate.
What’s the difference between authentication and authorization?
Authentication verifies identity, such as through a password. Authorization determines what actions that identity is allowed to perform.
Is Basic Auth secure?
Basic Auth is only secure over HTTPS. Without it, credentials are easily intercepted.
Can I secure Ollama directly?
Ollama doesn’t have built-in authentication. Use a Reverse Proxy with Basic Auth or an API Gateway.
What is OAuth?
OAuth is a protocol that lets users sign in via an external provider without your service storing their password.
What is 2FA?
2FA stands for Two-Factor Authentication. It requires two independent proofs, such as a password and an authenticator code.
Where should I store API keys securely?
Use environment variables, secret managers, or vaults. Never put them in Git repositories or public documentation.
Should I use Basic Auth or OAuth?
Basic Auth works for a small number of technical users. OAuth is better for teams and users signing in with existing accounts.
What is a token?
A token is a time-limited proof issued after successful authentication.
Why is HTTPS important for authentication?
Without HTTPS, passwords and keys travel in plaintext. Anyone on the network can intercept them.
How often should I rotate API keys?
Rotate keys at least every few months, or immediately if you suspect a leak.
Can I enable 2FA for Open WebUI?
Open WebUI supports external authentication depending on the version. Check the current settings in the documentation.
Sources
- OWASP Authentication Cheat Sheet - https://cheatsheetseries.owasp.org/cheatsheets/Authentication_Cheat_Sheet.html
- RFC 7617 HTTP Basic Authentication - https://datatracker.ietf.org/doc/html/rfc7617
- Ollama Documentation - https://github.com/ollama/ollama/tree/main/docs
- Open WebUI Documentation - https://docs.openwebui.com/


