User sign-in and identity
Enable authentication before onboarding users or deploying servers for shared use.
- Enable authentication using the bootstrap setup procedure, or use the preconfigured Local owner Docker setup.
- Configure one authentication provider, including allowed email domains and provider-specific group lookup requirements.
- Assign roles and resource policies for the users who sign in.
- Use agent authorization scopes for programmatic clients that need API keys.
Local authentication stores passwords as salted hashes and supports administrator-created accounts and required password changes. External providers authenticate through their configured OAuth/OIDC integration. Provider availability depends on edition.
Obot login and upstream MCP OAuth are separate authorizations. The authentication flow explains what the client receives and what Obot retains.
Before switching providers, read the provider-switch procedure. Identities are provider-scoped; a new provider login is not an automatic transfer of the user's existing resources.
After enabling authentication, open Identity & Access to manage users, roles, agent identities, and providers.
Users
Open Identity & Access > Users. From this page you can:
- See all registered users and their current roles
- Update individual user roles
- Monitor user activity
For details on updating roles, see User Roles.
User Roles
Open Identity & Access > Roles to configure the default role assigned to new users. Choose from:
- Standard User: Connect to approved MCP servers
- Power User: Standard User features plus publish personal MCP servers
- Power User Plus: Power User features plus share MCP servers through registries
- Admin: Full platform management
For detailed role descriptions and permissions, see User Roles.
Agent Authorization Scopes
Open Identity & Access > Agents to view and manage agent identities and their authorization scopes. Administrators can see which users have created agent authorization scopes and delete any if necessary. For details, see Agent Authorization Scopes.
Auth Providers
Configure identity providers for user authentication. See Auth Providers for setup details.
Authentication setup
Installation and provider configuration are covered in Configure authentication providers. The links below preserve existing setup bookmarks.
Step 1: Set Environment Variables
Continue to Step 1: Set Environment Variables.
Step 2: Start Obot and Login
Continue to Step 2: Start Obot and Login.
Step 3: Configure Authentication Provider
Continue to Step 3: Configure Authentication Provider.
Post-Setup
Continue to Post-Setup.
Troubleshooting
Continue to Troubleshooting.
Bootstrap Token Not Working
Continue to Bootstrap Token Not Working.
Authentication Provider Issues
Continue to Authentication Provider Issues.
Next Steps
Continue to Next Steps.