Skip to main content
Version: Next

User sign-in and identity

Enable authentication before onboarding users or deploying servers for shared use.

  1. Enable authentication using the bootstrap setup procedure, or use the preconfigured Local owner Docker setup.
  2. Configure one authentication provider, including allowed email domains and provider-specific group lookup requirements.
  3. Assign roles and resource policies for the users who sign in.
  4. Use agent authorization scopes for programmatic clients that need API keys.

Local authentication stores passwords as salted hashes and supports administrator-created accounts and required password changes. External providers authenticate through their configured OAuth/OIDC integration. Provider availability depends on edition.

Obot login and upstream MCP OAuth are separate authorizations. The authentication flow explains what the client receives and what Obot retains.

Before switching providers, read the provider-switch procedure. Identities are provider-scoped; a new provider login is not an automatic transfer of the user's existing resources.

After enabling authentication, open Identity & Access to manage users, roles, agent identities, and providers.

Users​

Open Identity & Access > Users. From this page you can:

  • See all registered users and their current roles
  • Update individual user roles
  • Monitor user activity

For details on updating roles, see User Roles.

User Roles​

Open Identity & Access > Roles to configure the default role assigned to new users. Choose from:

  • Standard User: Connect to approved MCP servers
  • Power User: Standard User features plus publish personal MCP servers
  • Power User Plus: Power User features plus share MCP servers through registries
  • Admin: Full platform management

For detailed role descriptions and permissions, see User Roles.

Agent Authorization Scopes​

Open Identity & Access > Agents to view and manage agent identities and their authorization scopes. Administrators can see which users have created agent authorization scopes and delete any if necessary. For details, see Agent Authorization Scopes.

Auth Providers​

Configure identity providers for user authentication. See Auth Providers for setup details.

Authentication setup​

Installation and provider configuration are covered in Configure authentication providers. The links below preserve existing setup bookmarks.

Step 1: Set Environment Variables​

Continue to Step 1: Set Environment Variables.

Step 2: Start Obot and Login​

Continue to Step 2: Start Obot and Login.

Step 3: Configure Authentication Provider​

Continue to Step 3: Configure Authentication Provider.

Post-Setup​

Continue to Post-Setup.

Troubleshooting​

Continue to Troubleshooting.

Bootstrap Token Not Working​

Continue to Bootstrap Token Not Working.

Authentication Provider Issues​

Continue to Authentication Provider Issues.

Next Steps​

Continue to Next Steps.