Open WebUI is an extensible, feature-rich, and user-friendly self-hosted WebUI for various LLM runners, supported LLM runners include Ollama and OpenAI-compatible APIs.
Open WebUI uses native OIDC for Authentik’s users group. It redirects to
Authentik by default while retaining password authentication for recovery; use
?form=1 on the login page to access the local form.
Setup
Create config/docker/<host>/open-webui/authentik-client-secret with mode
0600. Set OPEN_WEBUI_AUTHENTIK_CLIENT_ID,
OPEN_WEBUI_AUTHENTIK_CLIENT_SECRET in ignored
config/docker/<host>/.env.open-webui, and set
OPEN_WEBUI_AUTHENTIK_SIGNING_KEY in the ignored host .env. The signing key
is an asymmetric Authentik certificate/key UUID used for ID-token validation.
scripts/authentik-apps.py --application open-webui --apply
scripts/labctl.py service recreate ai/open-webui
Keep the callback URI exact:
https://open-webui.<domain>/oauth/oidc/callback. Account merging by email
requires Authentik to provide verified, unique email addresses.
Verify
Confirm an authorized user can sign in, a user outside users is denied, an
existing account links as intended, and local-password recovery still works.
name: open-webuiservices:
open-webui:
image: ghcr.io/open-webui/open-webui:v0.11.4container_name: open-webuirestart: unless-stoppedvolumes:
- ${DOCKER_VOLUMES}/open-webui:/app/backend/datanetworks:
- proxy# Environment Variable Configuration# https://docs.openwebui.com/getting-started/advanced-topics/env-configuration/environment:
WEBUI_SECRET_KEY: ${OPEN_WEBUI_SECRET_KEY}WEBUI_URL: "https://open-webui.${MYDOMAIN}"# Auth# Use Authentik by default; append ?form=1 to the login URL for local password recovery.ENABLE_LOGIN_FORM: "false"ENABLE_PASSWORD_AUTH: "true"ENABLE_OAUTH: "true"ENABLE_OAUTH_SIGNUP: "true"OAUTH_AUTO_REDIRECT: "true"OAUTH_MERGE_ACCOUNTS_BY_EMAIL: "true"OAUTH_CLIENT_ID: ${OPEN_WEBUI_AUTHENTIK_CLIENT_ID:?Configure Open WebUI Authentik client ID}OAUTH_CLIENT_SECRET: ${OPEN_WEBUI_AUTHENTIK_CLIENT_SECRET:?Configure Open WebUI Authentik client secret}OPENID_PROVIDER_URL: "https://sso.${MYDOMAIN}/application/o/open-webui/.well-known/openid-configuration"OPENID_REDIRECT_URI: "https://open-webui.${MYDOMAIN}/oauth/oidc/callback"OAUTH_SCOPES: "openid email profile"OLLAMA_API_BASE_URL: "https://ollama.${MYDOMAIN}/api"# Web search using SearXNG# Details: https://github.com/open-webui/docs/blob/main/docs/tutorials/integrations/web_search.mdENABLE_RAG_WEB_SEARCH: trueRAG_WEB_SEARCH_ENGINE: "searxng"RAG_WEB_SEARCH_RESULT_COUNT: 5RAG_WEB_SEARCH_CONCURRENT_REQUESTS: 10SEARXNG_QUERY_URL: "https://searxng.${MYDOMAIN}/search?q=<query>&format=json"# Image models# https://github.com/open-webui/docs/blob/main/docs/reference/env-configuration.mdx#image_url_response_models_regex_patternIMAGE_URL_RESPONSE_MODELS_REGEX_PATTERN: "^gpt-image|.*gpt-.*-image"# Fixes "Got more than 131072 bytes when reading" for image generation models# that stream base64-encoded images as large SSE lines (e.g. gpt-5.4-image-2 via OpenRouter).# Switches from aiohttp line-based iteration to iter_chunks(), bypassing the 128KB limit.# See: https://github.com/open-webui/open-webui/issues/17626CHAT_STREAM_RESPONSE_CHUNK_MAX_BUFFER_SIZE: 20971520extra_hosts:
- host.docker.internal:host-gatewaylabels:
traefik.enable: truetraefik.http.routers.open-webui.middlewares: localaccess@filetraefik.http.services.open-webui.loadbalancer.server.port: 8080homepage.group: AIhomepage.name: "Open WebUI"homepage.icon: open-webui.pnghomepage.href: https://open-webui.${MYDOMAIN}/homepage.description: "[SSO] User-friendly WebUI for LLMs"networks:
proxy:
external: true