mirror of
https://github.com/mudler/LocalAI.git
synced 2026-07-30 18:09:05 -04:00
* feat(ui): record finished gallery operations in a bounded history ring The operations panel drops an operation the moment it succeeds, so a user who steps away cannot tell whether an install finished, failed or was never started. OpCache now keeps the last 50 terminal operations, recorded from the point where an op leaves the cache. Assisted-by: Claude Code:claude-opus-5 [Read] [Edit] [Bash] Signed-off-by: Ettore Di Giacinto <mudler@localai.io> * test(ui): pin the history ring's dedupe, outcome order and start stamp Review of the history ring found four gaps. The dedupe guard and the bounded seen set were unreachable through the exported API and so had no coverage; an in-package spec file now drives opHistory directly. The outcome switch claimed an ordering was load bearing that nothing pinned, so an errored op that never reached Processed now has a spec. Two behaviour fixes come with it. StartedAt was the zero time for ops recovered from the store or replicated from a peer, since neither path stamps a start time, which would have rendered as a two-millennia duration; it now falls back to the finish time. Reusing a cache key with a fresh job ID orphaned the previous stamp, so Set and SetBackend now drop it. The comment on the outcome switch described a state the code cannot be in: CancelOperation sets Cancelled and Processed synchronously before the handler removes the entry, so status.Cancelled already covers the cancel endpoint. The !Processed clause stays for the dismiss endpoint firing on an in-flight op, and the comments now say so. Assisted-by: Claude Code:claude-opus-5 [Read] [Edit] [Bash] Signed-off-by: Ettore Di Giacinto <mudler@localai.io> * feat(ui): record operations that end on a peer replica The NATS end event is the only signal a replica gets for an install another replica ran. Record from applyEnd too, deduped by job ID so the originating replica does not record its own broadcast twice. Three start-stamp defects in the same path go with it. applyEnd now drops the stamp unconditionally, since recordTerminal only cleans up on the path where it found a cache key and an end event can overtake the local Set. applyStart drops the stamp of the job whose cache key it replaces, which a peer-driven retry previously stranded. And recordTerminal reads the stamp once instead of testing Exists and then reading, so a concurrent record for the same job can no longer delete the stamp between the two and let the zero time overwrite the finish-time fallback, which the Activity page would render as a two-millennia run. Assisted-by: Claude Code:claude-opus-5 [Read] [Edit] [Bash] Signed-off-by: Ettore Di Giacinto <mudler@localai.io> * fix(ui): do not guess the outcome of a peer operation with no local status A replica that restarts mid-operation hydrates its OpCache keys from PostgreSQL, but gallery statuses are in-memory only and come back empty. The end broadcast then landed on recordTerminal's nil-status branch, which reads a missing status as queued-and-removed and filed a successful install as cancelled. That reading is right locally and wrong on the peer path, where a missing status means the outcome was never held here. recordTerminal now takes the source of the terminal event and records nothing when the peer path finds no status, restoring what the replica did before the end event started recording. The local path is unchanged. Also move the ApplyEndForTest seam to the conventional export_test.go, and stop the dedupe spec from claiming to guard the ring's seen set: the local delete removes the status keys, so the broadcast that follows returns before reaching it. An in-package spec that calls recordTerminal twice does the pinning. Assisted-by: Claude Code:claude-opus-5 [Read] [Edit] [Bash] Signed-off-by: Ettore Di Giacinto <mudler@localai.io> * feat(api): add GET and DELETE /api/operations/history Admin gated like the rest of the operations API. The live /api/operations payload is unchanged so the one second poll stays small. Assisted-by: Claude Code:claude-opus-5 [Read] [Edit] [Bash] Signed-off-by: Ettore Di Giacinto <mudler@localai.io> * feat(ui): expose operation history through OperationsContext Fetched on demand and when the live list shrinks, never on the one second poll interval. Assisted-by: Claude Code:claude-opus-5 [Read] [Edit] [Bash] Signed-off-by: Ettore Di Giacinto <mudler@localai.io> * fix(ui): detect operation departure by identity and ignore committing ops in the ETA gate Refetching history on a shrinking live count missed a completion that coincided with a start, which is the common case during a batch install. Track the live job IDs instead, so any departure triggers the refetch regardless of how the count moved. An operation that has finished downloading stays live at currentBytes == totalBytes for the whole commit and install phase and can never produce an estimate, so counting it in the all-or-nothing gate blanked every other operation's time remaining for as long as it lasted. Only operations still moving bytes get a vote. Assisted-by: Claude Code:claude-opus-5 [Read] [Edit] [Bash] Signed-off-by: Ettore Di Giacinto <mudler@localai.io> * fix(ui): let only downloading operations gate the time remaining estimate Verifying pins an operation flat below its total for the whole sha256 pass: the AfterDownload hook reports completedBytes plus the finished file against a total summed over every file, then hashes synchronously without emitting progress. Files download sequentially, so a 15 shard model enters that window 14 times, and a byte comparison cannot see it because the counter is genuinely below the total throughout. Gating on phase closes resolving, verifying, committing and persisting in one predicate, so a quiet neighbour no longer blanks every other operation's estimate for minutes at a time. The byte clauses stay: a producer can report downloading with bytes already at the total. Assisted-by: Claude Code:claude-opus-5 [Read] [Edit] [Bash] Signed-off-by: Ettore Di Giacinto <mudler@localai.io> * feat(ui): collapse the operations bar to a single line Four concurrent installs used to take four rows above every page. The strip now shows one operation, failure first, with a counter linking to Activity. The close button hides the strip and no longer cancels an install. Assisted-by: Claude Code:claude-opus-5 [Read] [Edit] [Bash] Signed-off-by: Ettore Di Giacinto <mudler@localai.io> * fix(ui): keep the operations strip from widening the page and from muting a failure A long install error made the strip report a 1600px minimum width, which sized main-content to fit and gave every page under it a horizontal scrollbar. Inline-size containment plus shrinkable detail and bytes cells keep it inside the viewport. Hiding is no longer able to swallow the hidden job's own failure, a completed removal or staging says so instead of claiming an install, a cancelling operation renders as cancelling, and the live region no longer covers the per-second percentage. Assisted-by: Claude Code:claude-opus-5 [Read] [Edit] [Bash] Signed-off-by: Ettore Di Giacinto <mudler@localai.io> * fix(ui): shrink main-content instead of containing the strip, and expose progress min-width on .main-content is what actually lets a long install error shrink, and unlike inline-size containment it has no browser support floor and no latent collapse if the strip ever lands in a shrink-to-fit context. It matches what .app-layout-chat .main-content already does, and it clears pre-existing horizontal overflow on narrow viewports as a side effect. The progress track is now a labelled progressbar, so assistive tech can read the value on demand rather than losing it to the aria-hidden that stopped the live region re-announcing every poll. Assisted-by: Claude Code:claude-opus-5 [Read] [Edit] [Bash] Signed-off-by: Ettore Di Giacinto <mudler@localai.io> * feat(ui): add the live operation card for the Activity page Carries the detail the one-line strip has to drop: phase, bytes, the per-node breakdown for cluster installs, and a labelled Cancel button. Cancelling is destructive, so it gets a labelled button rather than a glyph. A cancelling operation drops its progress bar and its time estimate, the same call the strip makes: a percentage still climbing under "Cancelling" reads as the cancel not having taken. Assisted-by: Claude Code:claude-opus-5 [Read] [Edit] [Bash] Signed-off-by: Ettore Di Giacinto <mudler@localai.io> * fix(ui): give the operation card a verb, live node disclosure and its per-node detail The card carried no verb, so an install, a removal and a staging op rendered as spinner plus name plus kind tag and were indistinguishable. It now runs the same verb and icon chain as the one-line strip, which is what stops the page that is meant to carry more detail from carrying less. The auto-expand default was evaluated once at mount. An operation is listed as soon as it is admitted but its nodes are filled in only when the fan-out starts reporting, so a card mounted at creation latched on the empty list and stayed collapsed. The default is a live expression now, and state holds only an explicit choice. Also: an optional onRetry gates a Retry button, so the page can own the install reconstruction without the card ever showing a control with nothing behind it; the disclosure moved above the region it controls and gained aria-controls; the toggle is gated at more than one node so the count is never "1 nodes"; an unmapped node status is passed through instead of being relabelled "Queued"; error text is clamped with the full string in the title; and file_name plus the per-node progress bar are rendered again, reviving three CSS rules that had gone dead along with the detail they styled. Assisted-by: Claude Code:claude-opus-5 [Read] [Edit] [Bash] Signed-off-by: Ettore Di Giacinto <mudler@localai.io> * feat(ui): add the Activity page Live operations, unacknowledged failures and the record of what finished, at /app/activity in the Operate console. Cancelling an install now lives here behind a labelled button rather than on the strip, and a failed install can be retried: the retry dismisses the failure first so it still reaches the record, then reissues the model, backend or node-scoped backend install. The sidebar Operate entry carries the operation count. The console rail is only rendered on an Operate route and can be collapsed, so a badge there could vanish while operations were still running. Two follow-ups from review fold in here: a failed removal or staging job no longer reports a failed install on either the card or the strip, and the card's error text can shrink so one unbroken token cannot widen the card. Assisted-by: Claude Code:claude-opus-5 [Read] [Edit] [Bash] Signed-off-by: Ettore Di Giacinto <mudler@localai.io> * fix(ui): dismiss operations by job, and stop the Activity page contradicting itself Dismissing resolved the job by display id, but /api/operations strips the "node:<nodeID>:" prefix before emitting, so a local install and a node-scoped install of one backend arrive as two jobs sharing one id. Dismissing by id retired whichever came first. That defeated the guarantee retry was built around: with the wrong job dismissed, the reinstall overwrote the acted-on failure's opcache entry in place, bypassing recordTerminal, while an unrelated failure vanished from Needs attention. dismissFailedOp, the card's dismiss control and the strip now all pass the jobID, which is what the endpoint takes. A filter matching nothing rendered the "nothing has ever run" empty state while the header counted the records the filter had hidden. The empty state is now gated on the All chip and a narrowed view gets its own message plus a way back; the header counts the instance rather than the chip, so selecting Backends no longer reports "Nothing running" over running model installs. Also: the summary drops a zero clause instead of rendering "0 needs attention" on the happy path and pluralises both counts; a record duration is floored at "< 1s" and rejected above a day, so a zero-value start stamp cannot render a span of millennia and a zero span cannot render "installed in" with nothing after it; a deletion cancelled mid-flight reports the cancellation rather than claiming it was removed; and the retry variant comment names the fix instead of calling the gap closed. Assisted-by: Claude Code:claude-opus-5 [Read] [Edit] [Bash] Signed-off-by: Ettore Di Giacinto <mudler@localai.io> * docs: document the Activity page and the operations history endpoints Adds an Activity page under Operations covering the one-line operations strip, the /app/activity sections and filters, per-operation cancel, retry and dismiss, the in-memory 50-entry record, and the sidebar count. Documents GET and DELETE /api/operations/history, and fills the gap in the admin-only endpoint list, which also omitted the pre-existing POST /api/operations/:jobID/dismiss. Corrects the distributed-mode install-watching section: the per-node breakdown now lives on the Activity page rather than on the strip, which rolls a fan-out up into a single phrase. Assisted-by: Claude Code:claude-opus-5 [Read] [Edit] [Bash] Signed-off-by: Ettore Di Giacinto <mudler@localai.io> * docs: correct nine details in the Activity page documentation The operations strip never renders a file name: its detail line is the error, the node roll-up, the target node, the phase or the queued note. Drops the stale clause in the distributed-mode section, where the per-node bullet is now the only place a file name is described. Scopes the phase vocabulary to artifact-backed gallery models, since a plain GGUF install emits no phase. Corrects the per-node list: the toggle exists for any fan-out of two or more workers and the four-node threshold only governs whether it starts open, while the N nodes tag needs more than one node. Notes that a cancelled operation can sit in the live section reading Cancelling, that cluster staging never reaches the record, and that Clear history appears only when the record has something in it. Names the operations response envelope, with a JSON example, so callers do not index a bare array, and stops describing the icon-only dismiss control as a labelled button. Assisted-by: Claude Code:claude-opus-5 [Read] [Edit] [Bash] Signed-off-by: Ettore Di Giacinto <mudler@localai.io> * docs: drop the unreachable Cancelling state and scope the byte claims An operation can only report isCancelled while it is unprocessed, but every writer of Cancelled sets Processed in the same breath, on the peer path as much as the local one, and the cache evicts cancelled entries before the handler sees them. The state cannot reach the page, so the live section is described again as running or queued operations. Byte counts come from the artifact bridge alone, the same producer as the phase, so a plain GGUF install, a removal and a backend install report none. Scopes both to artifact-backed gallery models and leaves the verb, the name and the percentage as what every operation shows. A worker backend install reports its bytes through fields the operations payload does not carry, so the distributed section now describes the percentage and the node roll-up, with per-file counts pointed at the per-node detail. Also: staging jobs carry no error, so they never reach Needs attention and Retry never had a staging case to exclude; an install that involves workers is no longer called node-scoped, which this page uses for node-targeted installs; and the record timestamps carry nanoseconds. Assisted-by: Claude Code:claude-opus-5 [Read] [Edit] [Bash] Signed-off-by: Ettore Di Giacinto <mudler@localai.io> * docs: state only the verb and the name as unconditional on the strip The percentage is as conditional as the bytes were: it renders only for a running operation that has reported progress, so a queued operation, a failed one and a removal never carry it. A removal in particular sits at progress zero for its whole visible life, since the delete path reports none and its completion is filtered out. Both the strip and the card paragraphs now lead with what always shows and list the rest as conditions. The Cluster chip matches on a node list that finished operations do not carry, so a fan-out install leaves the chip once it reaches the record. Scoped that claim to the live sections. Two more of the same shape, found by re-reading each clause alone: the strip also appears for a failure, which is not running, and the four-second hold only applies when nothing replaces the operation that just finished. Assisted-by: Claude Code:claude-opus-5 [Read] [Edit] [Bash] Signed-off-by: Ettore Di Giacinto <mudler@localai.io> * fix(ui): stop reporting a cancelled install as installed, and make queued real Three defects that all trace to one root cause: `isCancelled: true` is unreachable from /api/operations. Every writer of Cancelled=true also sets Processed=true, the handler skips Processed && Cancelled, and OpCache.GetStatus evicts a cancelled op before the handler iterates it. Cancelling the last running operation put a green "Installed model X" on the strip for four seconds: the completion hold was guarded by `!previous.isCancelled`, which is dead. A cancellation deletes the operation server side, so the strip sees exactly what it sees on a completion, and nothing in the payload separates the two. The signal now comes from the side that issued the cancel: the operations context remembers the job IDs it cancelled (pruned after a minute) and the strip asks before it holds anything. A cancelled operation goes as soon as it stops; the record already reports it as cancelled. isQueued was set only when the gallery status was missing, but markQueued publishes a "queued" status at admission, so a queued op has a status for its whole queued life and the state was unreachable outside a microsecond window. Every operation waiting behind a running install rendered as "Installing model X" with a spinner. The queued phase is now the signal, via an exported PhaseQueued and a nil-safe OpStatus.IsQueued() next to the writer. With those two fixed, the Cancelling state has no way to be entered: cancelling is instantaneous from the API's point of view. Its branches, CSS, locale key and the isCancelled field itself are removed rather than left for a future reader to assume they work. Assisted-by: Claude Code:claude-opus-5 [Read] [Edit] [Bash] Signed-off-by: Ettore Di Giacinto <mudler@localai.io> * fix(ui): keep a removal a removal, and say what an install is doing OpStatus.Deletion was set once, at admission, and lost on the next status write: UpdateStatus replaces the whole status and only carried Nodes forward. Every later writer (the worker's first write, the progress ticks, the failure path) leaves the field at its zero value, so the flag survived only the queued window, and both surfaces test isQueued first. The reachable consequence is that a failed removal reported itself as a failed install, which is exactly the shape the Activity page offers Retry for, and Retry installs: pressing it on a removal that failed re-downloaded the model. A running delete also rendered as "Installing model X" with a spinner, and a successful one as "Installed model X". Carry Deletion forward the way Nodes already is. A job is a delete or an install for its whole life; an unset flag means "no new information", not "this is an install". Pinned by Go specs on both the service and /api/operations: the existing Playwright specs were green only because they stubbed a payload the server could not emit. Also restore the operation's own status message on the Activity card. Phases and byte counters exist only on the managed-artifact path, so a legacy files: gallery model and every backend install rendered a sub-row with nothing in it but the verb. The strip stays terse on purpose. And give the strip's name a min-width floor: overflow: hidden zeroes its automatic minimum, so a long error squeezed the name down to "mod…" and the identity of the thing that broke was the first thing lost. primaryOperation is made module-private: its comment claimed the Activity page selected the same operation, but that page shows all of them, partitioned into failed and running, and never imported it. Assisted-by: Claude Code:Opus 5 [Read] [Edit] [Bash] Signed-off-by: Ettore Di Giacinto <mudler@localai.io> * feat(activity): read the operations record from PostgreSQL The Activity page's record of finished installs and removals was a 50-entry in-memory ring per frontend replica. In distributed mode that is the wrong place for it: each replica keeps its own copy, a replica added by a scale-out or a rolling deploy starts empty and never backfills, and "Clear history" clears only the replica that served the request, so the record reappears on the next poll routed elsewhere. The data is already in gallery_operations. Read it from there. GalleryStore gains ListTerminal and ClearTerminal, sharing a lifted terminalStatuses set with CleanOld so there is one definition of "finished". ListTerminal orders by updated_at, when the operation reached its terminal status, because the record reports what finished and when. OpCache.History and ClearHistory dispatch on whether a store is wired, so the HTTP handlers and the OpRecord JSON shape are unchanged and the page needed no change. A failed store read falls back to the local ring rather than blanking the page, and ClearHistory empties the ring as well so a database blip cannot resurrect a record the admin just cleared. The name derivation in recordTerminal is lifted into operationDisplayName and used by both paths, so the ring and the store cannot name the same operation differently. Also fixes a pre-existing bug the store path made visible: the backend channel hardcoded op_type "backend_install" even for a removal, while the model channel derives model_install/model_delete from op.Delete. Both channels carry the same ManagementOp, whose Delete field the backend handler already branches on, so the backend channel now derives backend_delete the same way. Assisted-by: Claude Code:claude-opus-5 [Read] [Edit] [Bash] Signed-off-by: Ettore Di Giacinto <mudler@localai.io> * fix(activity): keep a cancelled operation cancelled, and report a failed clear Review follow-up on the store-backed Activity record. A cancelled install was recorded as a failure. The cancel handler persists "cancelled" synchronously, then the handler goroutine unwinds with the context error and Start hands that to updateError unconditionally, which overwrote the row with "failed: context canceled". The page rendered a cancelled install as a red failure card offering Retry, with a raw context error as the reason. Fixed in GalleryStore rather than in Start, because an operation finishes once and the paths that retire one are not mutually exclusive: UpdateStatus now refuses to rewrite a row that already reached a terminal status. That also pins updated_at to when the operation really finished, which is the key the record is ordered by, and Create's upsert now freezes the same columns so a worker dequeuing an operation the admin cancelled while it was queued cannot reopen it as pending. ClearHistory returned nothing, so a failed delete logged a warning while the handler still answered 200. The admin watched the record clear and come back on the next fetch with nothing said about why. It now returns the error, the DELETE handler answers 500, and the store is cleared before the local ring so a failure leaves the fallback record intact rather than faking an empty one. Hydrate is the only reader that decides from op_type whether an operation is a removal, and it tested for "model_delete" exactly, so the backend_delete added in the previous commit hydrated as an install: a replica restarting during a backend removal rendered "Installing backend X". Both discriminations now go through IsDeleteOpType/IsBackendOpType so a fifth op_type cannot silently read as an install in whichever consumer was missed. Also: the backend channel now persists Cancellable as !op.Delete, matching the model channel; IsBackend falls back to the op_type prefix, since is_backend_op is only written by UpsertCacheKey and the rows needing the name fallback were reporting backend operations as models; and an unrecognized terminal status is logged rather than quietly filed as a success, which is what the comment already claimed. Assisted-by: Claude Code:claude-opus-5 [Read] [Edit] [Bash] Signed-off-by: Ettore Di Giacinto <mudler@localai.io> * fix(activity): keep a reaped operation correctable by its real outcome The terminal-status freeze added in the previous commit was too wide. It froze "failed" alongside "completed" and "cancelled", and the stale reaper writes "failed" onto operations that are still going to run. The gallery worker is a single goroutine consuming both channels serially, so an operation queued behind a large download sits in "pending" with nothing bumping updated_at, and ReapStaleOperations gives up on it after 30 minutes. That used to be self-healing: the worker dequeued it, Create reset the row to "pending", and the operation reported its real outcome. With the freeze the row stayed "failed" forever while the install ran and succeeded underneath it: a red failure card offering Retry for a model that is installed, omitted from ListActive so no replica hydrates it, and no longer deduped cluster-wide by FindDuplicate. Freeze on ("completed", "cancelled") instead. That is all the cancelled-install fix ever needed, and it leaves a failure correctable by what actually happened. The set is separate from terminalStatuses, which ListTerminal, ClearTerminal and CleanOld all still want in full, because the two mean different things: a failure can be superseded by a real outcome, a completion or a cancellation is the real outcome. UpdateStatus now writes the error column unconditionally, so a corrected outcome drops the previous attempt's reason rather than being recorded as completed while still carrying "stale operation reaped" as its error. Also adds the route-level spec for the 500 branch of DELETE /api/operations/history, and trims a comment that credited the persisted cancellable column with more than it survives long enough to do. Assisted-by: Claude Code:claude-opus-5 [Read] [Edit] [Bash] Signed-off-by: Ettore Di Giacinto <mudler@localai.io> * fix(activity): offer Cancel in the phase that can honour it The cancellable flag was set at both ends of an operation's life and was wrong at both, in opposite directions. A queued operation is cancellable whatever it is. EnqueueModelOp and EnqueueBackendOp select on the operation context, so cancelling one that is still waiting releases the delivery goroutine and abandonQueued retires it: the worker never sees it, nothing is downloaded, nothing is deleted. markQueued nevertheless wrote Cancellable: !deletion, so a queued removal reported cancellable: false and the UI hid the Cancel button in the one window where pressing it both works and leaves no trace. A removal queued behind a large install was stuck there until the install finished. A running removal is not cancellable at all. DeleteModel and DeleteBackend take no context, and modelHandler only checks the operation context after the call returns, so a "cancelled" verdict would land after the model was already gone. Both handlers nevertheless wrote Cancellable: true unconditionally at entry, ahead of the op.Delete branch, offering a Cancel button the server cannot honour. So the queued phase is more cancellable than the running phase, which is the reverse of the usual shape. markQueued now reports true unconditionally, and the handler-entry writes report !op.Delete. Both sites carry a comment saying why, because reading either one alone suggests the other is a bug. GalleryStore.Create keeps !op.Delete: it runs at dequeue, so its value already describes the running phase. Its comment now says so. Specs cover queued removal, queued install, running removal and running install through the handlers, plus the queued-removal case through /api/operations where the flag is consumed, plus the behaviour the whole asymmetry rests on: a removal cancelled while queued never reaches the worker and deletes nothing. No existing spec asserted the old values. Assisted-by: Claude Code:claude-opus-5 [Read] [Edit] [Write] [Bash] Signed-off-by: Ettore Di Giacinto <mudler@localai.io> * fix(activity): clamp the installer message, and add a real-binary e2e spec Running the page against a real local-ai showed the legacy installer message wrapping to three lines and dominating the card: it embeds an absolute file path, so it is both long and a single unbreakable token. One line, ellipsised, full text in the title, matching what the error string already does. The spec that found it runs with no route stubbing at all. Every other spec here stubs /api/operations, which is how a payload the server cannot emit (isDeletion true on a live operation) stayed green through a full review while the UI rendered a removal as an install. It is skipped unless LOCALAI_REAL_BINARY is set, so CI is unaffected. Assisted-by: Claude Code:claude-opus-5 [Read] [Edit] [Bash] Signed-off-by: Ettore Di Giacinto <mudler@localai.io> --------- Signed-off-by: Ettore Di Giacinto <mudler@localai.io> Co-authored-by: Ettore Di Giacinto <mudler@localai.io>
430 lines
18 KiB
Markdown
430 lines
18 KiB
Markdown
+++
|
|
disableToc = false
|
|
title = "Authentication & Authorization"
|
|
weight = 85
|
|
url = '/features/authentication'
|
|
+++
|
|
|
|
LocalAI supports two authentication modes: **legacy API key authentication** (simple shared keys) and a full **user authentication system** with roles, sessions, OAuth, and per-user usage tracking.
|
|
|
|
## Legacy API Key Authentication
|
|
|
|
The simplest way to protect your LocalAI instance is with API keys. Set one or more keys via environment variable or CLI flag:
|
|
|
|
```bash
|
|
# Single key
|
|
LOCALAI_API_KEY=sk-my-secret-key localai run
|
|
|
|
# Multiple keys (comma-separated)
|
|
LOCALAI_API_KEY=key1,key2,key3 localai run
|
|
```
|
|
|
|
Clients provide the key via any of these methods:
|
|
|
|
- `Authorization: Bearer <key>` header
|
|
- `x-api-key: <key>` header
|
|
- `xi-api-key: <key>` header
|
|
- `token` cookie
|
|
|
|
Legacy API keys grant **full admin access** - there is no role separation. For multi-user deployments with role-based access, use the user authentication system instead.
|
|
|
|
API keys can also be managed at runtime through the [Runtime Settings]({{%relref "features/runtime-settings" %}}) interface.
|
|
|
|
## User Authentication System
|
|
|
|
The user authentication system provides:
|
|
|
|
- **User accounts** with email, name, and avatar
|
|
- **Role-based access control** (admin vs. user)
|
|
- **Session-based authentication** with secure cookies
|
|
- **OAuth login** (GitHub) and **OIDC single sign-on** (Keycloak, Google, Okta, Authentik, etc.)
|
|
- **Per-user API keys** for programmatic access
|
|
- **Admin route gating** - management endpoints are restricted to admins
|
|
- **Per-user usage tracking** with token consumption metrics
|
|
|
|
### Enabling Authentication
|
|
|
|
Set `LOCALAI_AUTH=true` or provide a GitHub OAuth Client ID or OIDC Client ID (which auto-enables auth):
|
|
|
|
```bash
|
|
# Enable with SQLite (default, stored at {DataPath}/database.db)
|
|
LOCALAI_AUTH=true localai run
|
|
|
|
# Enable with GitHub OAuth
|
|
GITHUB_CLIENT_ID=your-client-id \
|
|
GITHUB_CLIENT_SECRET=your-client-secret \
|
|
LOCALAI_BASE_URL=http://localhost:8080 \
|
|
localai run
|
|
|
|
# Enable with OIDC provider (e.g. Keycloak)
|
|
LOCALAI_OIDC_ISSUER=https://keycloak.example.com/realms/myrealm \
|
|
LOCALAI_OIDC_CLIENT_ID=your-client-id \
|
|
LOCALAI_OIDC_CLIENT_SECRET=your-client-secret \
|
|
LOCALAI_BASE_URL=http://localhost:8080 \
|
|
localai run
|
|
|
|
# Enable with PostgreSQL
|
|
LOCALAI_AUTH=true \
|
|
LOCALAI_AUTH_DATABASE_URL=postgres://user:pass@host/dbname \
|
|
localai run
|
|
```
|
|
|
|
### Configuration Reference
|
|
|
|
| Environment Variable | Default | Description |
|
|
|---|---|---|
|
|
| `LOCALAI_AUTH` | `false` | Enable user authentication and authorization |
|
|
| `LOCALAI_AUTH_DATABASE_URL` | `{DataPath}/database.db` | Database URL - `postgres://...` for PostgreSQL, or a file path for SQLite |
|
|
| `GITHUB_CLIENT_ID` | | GitHub OAuth App Client ID (auto-enables auth when set) |
|
|
| `GITHUB_CLIENT_SECRET` | | GitHub OAuth App Client Secret |
|
|
| `LOCALAI_OIDC_ISSUER` | | OIDC issuer URL for auto-discovery (e.g. `https://accounts.google.com`) |
|
|
| `LOCALAI_OIDC_CLIENT_ID` | | OIDC Client ID (auto-enables auth when set) |
|
|
| `LOCALAI_OIDC_CLIENT_SECRET` | | OIDC Client Secret |
|
|
| `LOCALAI_BASE_URL` | | Base URL for OAuth callbacks (e.g. `http://localhost:8080`) |
|
|
| `LOCALAI_ADMIN_EMAIL` | | Email address to auto-promote to admin role on login |
|
|
| `LOCALAI_REGISTRATION_MODE` | `approval` | Registration mode: `open`, `approval`, or `invite` |
|
|
| `LOCALAI_DISABLE_LOCAL_AUTH` | `false` | Disable local email/password registration and login (for OAuth/OIDC-only deployments) |
|
|
|
|
> **Note: network-backed storage.** File-based SQLite relies on POSIX file locking, which is unreliable over network filesystems (SMB/CIFS/NFS, e.g. Azure Files / Azure Container Apps shared volumes). On such storage the auth DB can fail to migrate with `database is locked`. Use PostgreSQL (`LOCALAI_AUTH_DATABASE_URL=postgres://...`) when the data directory lives on shared or network storage, or place `database.db` on a local volume.
|
|
|
|
### Disabling Local Authentication
|
|
|
|
If you want to enforce OAuth/OIDC-only login and prevent users from registering or logging in with email/password, set `LOCALAI_DISABLE_LOCAL_AUTH=true` (or pass `--disable-local-auth`):
|
|
|
|
```bash
|
|
# OAuth-only setup (no email/password)
|
|
LOCALAI_DISABLE_LOCAL_AUTH=true \
|
|
GITHUB_CLIENT_ID=your-client-id \
|
|
GITHUB_CLIENT_SECRET=your-client-secret \
|
|
LOCALAI_BASE_URL=http://localhost:8080 \
|
|
localai run
|
|
```
|
|
|
|
When disabled:
|
|
- The login page will not show email/password forms (the UI checks the `providers` list from `/api/auth/status`)
|
|
- `POST /api/auth/register` returns `403 Forbidden`
|
|
- `POST /api/auth/login` returns `403 Forbidden`
|
|
- OAuth/OIDC login continues to work normally
|
|
|
|
### Roles
|
|
|
|
There are two roles:
|
|
|
|
- **Admin**: Full access to all endpoints, including model management, backend configuration, system settings, traces, agents, and user management.
|
|
- **User**: Access to inference endpoints only - chat completions, embeddings, image/video/audio generation, TTS, MCP chat, and their own usage statistics.
|
|
|
|
The **first user** to sign in is automatically assigned the admin role. Additional users can be promoted to admin via the admin user management API or by setting `LOCALAI_ADMIN_EMAIL` to their email address.
|
|
|
|
### Registration Modes
|
|
|
|
| Mode | Description |
|
|
|---|---|
|
|
| `open` | Anyone can register and is immediately active |
|
|
| `approval` | New users land in "pending" status until an admin approves them. If a valid invite code is provided during registration, the user is activated immediately (skipping the approval wait). **(default)** |
|
|
| `invite` | Registration requires a valid invite link generated by an admin. Without one, registration is rejected. |
|
|
|
|
### Invite Links
|
|
|
|
Admins can generate single-use, time-limited invite links from the **Users → Invites** tab in the web UI, or via the API:
|
|
|
|
```bash
|
|
# Create an invite link (default: expires in 7 days)
|
|
curl -X POST http://localhost:8080/api/auth/admin/invites \
|
|
-H "Authorization: Bearer <admin-key>" \
|
|
-H "Content-Type: application/json" \
|
|
-d '{"expiresInHours": 168}'
|
|
|
|
# List all invites
|
|
curl http://localhost:8080/api/auth/admin/invites \
|
|
-H "Authorization: Bearer <admin-key>"
|
|
|
|
# Revoke an unused invite
|
|
curl -X DELETE http://localhost:8080/api/auth/admin/invites/<invite-id> \
|
|
-H "Authorization: Bearer <admin-key>"
|
|
|
|
# Check if an invite code is valid (public, no auth required)
|
|
curl http://localhost:8080/api/auth/invite/<code>/check
|
|
```
|
|
|
|
Share the invite URL (`/invite/<code>`) with the user. When they open it, the registration form is pre-filled with the invite code. Invite codes are single-use - once consumed, they cannot be reused. Expired or used invites are rejected.
|
|
|
|
For GitHub OAuth, the invite code is passed as a query parameter to the login URL (`/api/auth/github/login?invite_code=<code>`) and stored in a cookie during the OAuth flow.
|
|
|
|
### Admin-Only Endpoints
|
|
|
|
When authentication is enabled, the following endpoints require admin role:
|
|
|
|
**Model & Backend Management:**
|
|
- `GET /api/models`, `POST /api/models/install/*`, `POST /api/models/delete/*`
|
|
- `GET /api/backends`, `POST /api/backends/install/*`, `POST /api/backends/delete/*`
|
|
- `GET /api/operations`, `POST /api/operations/*/cancel`, `POST /api/operations/*/dismiss`
|
|
- `GET /api/operations/history`, `DELETE /api/operations/history`
|
|
- `GET /models/available`, `GET /models/galleries`, `GET /models/jobs/*`
|
|
- `GET /backends`, `GET /backends/available`, `GET /backends/galleries`
|
|
|
|
**System & Monitoring:**
|
|
- `GET /api/traces`, `GET /api/traces/{id}`, `POST /api/traces/clear`
|
|
- `GET /api/backend-traces`, `GET /api/backend-traces/{id}`, `POST /api/backend-traces/clear`
|
|
- `GET /api/backend-logs/*`, `POST /api/backend-logs/*/clear`
|
|
- `GET /api/resources`, `GET /api/settings`, `POST /api/settings`
|
|
- `GET /system`, `GET /backend/monitor`, `POST /backend/shutdown`, `POST /backend/load`
|
|
|
|
**P2P:**
|
|
- `GET /api/p2p/*`
|
|
|
|
**Agents & Jobs:**
|
|
- All `/api/agents/*` endpoints
|
|
- All `/api/agent/tasks/*` and `/api/agent/jobs/*` endpoints
|
|
|
|
**User-Accessible Endpoints (all authenticated users):**
|
|
- `POST /v1/chat/completions`, `POST /v1/embeddings`, `POST /v1/completions`
|
|
- `POST /v1/images/generations`, `POST /v1/audio/*`, `POST /tts`, `POST /vad`, `POST /video`
|
|
- `GET /v1/models`, `POST /v1/tokenize`, `POST /v1/detection`
|
|
- `POST /v1/mcp/chat/completions`, `POST /v1/messages`, `POST /v1/responses`
|
|
- `POST /stores/*`, `GET /api/cors-proxy`
|
|
- `GET /version`, `GET /api/features`, `GET /swagger/*`, `GET /metrics`
|
|
- `GET /api/auth/usage` (own usage data)
|
|
|
|
### Web UI Access Control
|
|
|
|
When auth is enabled, the React UI sidebar dynamically shows/hides sections based on the user's role:
|
|
|
|
- **All users see**: Home, Chat, Images, Video, TTS, Sound, Talk, Usage, API docs link
|
|
- **Admins also see**: Install Models, Agents section (Agents, Skills, Memory, MCP CI Jobs), System section (Backends, Traces, Swarm, System, Settings)
|
|
|
|
Admin-only pages are also protected at the router level - navigating directly to an admin URL redirects non-admin users to the home page.
|
|
|
|
### GitHub OAuth Setup
|
|
|
|
1. Create a GitHub OAuth App at **Settings → Developer settings → OAuth Apps → New OAuth App**
|
|
2. Set the **Authorization callback URL** to `{LOCALAI_BASE_URL}/api/auth/github/callback`
|
|
3. Set `GITHUB_CLIENT_ID` and `GITHUB_CLIENT_SECRET` environment variables
|
|
4. Set `LOCALAI_BASE_URL` to your publicly-accessible URL
|
|
|
|
### OIDC Setup
|
|
|
|
Any OIDC-compliant identity provider can be used for single sign-on. This includes Keycloak, Google, Okta, Authentik, Azure AD, and many others.
|
|
|
|
**Steps:**
|
|
|
|
1. Create a client/application in your OIDC provider
|
|
2. Set the redirect URL to `{LOCALAI_BASE_URL}/api/auth/oidc/callback`
|
|
3. Set the three environment variables: `LOCALAI_OIDC_ISSUER`, `LOCALAI_OIDC_CLIENT_ID`, `LOCALAI_OIDC_CLIENT_SECRET`
|
|
|
|
LocalAI uses OIDC auto-discovery (the `/.well-known/openid-configuration` endpoint) and requests the standard scopes: `openid`, `profile`, `email`.
|
|
|
|
**Provider examples:**
|
|
|
|
```bash
|
|
# Keycloak
|
|
LOCALAI_OIDC_ISSUER=https://keycloak.example.com/realms/myrealm
|
|
|
|
# Google
|
|
LOCALAI_OIDC_ISSUER=https://accounts.google.com
|
|
|
|
# Authentik
|
|
LOCALAI_OIDC_ISSUER=https://authentik.example.com/application/o/localai/
|
|
|
|
# Okta
|
|
LOCALAI_OIDC_ISSUER=https://your-org.okta.com
|
|
```
|
|
|
|
For OIDC, invite codes work the same way as GitHub OAuth - the invite code is passed as a query parameter to the login URL (`/api/auth/oidc/login?invite_code=<code>`) and stored in a cookie during the OAuth flow.
|
|
|
|
### User API Keys
|
|
|
|
Authenticated users can create personal API keys for programmatic access:
|
|
|
|
```bash
|
|
# Create an API key (requires session auth)
|
|
curl -X POST http://localhost:8080/api/auth/api-keys \
|
|
-H "Cookie: session=<session-id>" \
|
|
-H "Content-Type: application/json" \
|
|
-d '{"name": "My Script Key"}'
|
|
```
|
|
|
|
User API keys inherit the creating user's role. Admin keys grant admin access; user keys grant user-level access.
|
|
|
|
### Auth API Endpoints
|
|
|
|
| Method | Endpoint | Description | Auth Required |
|
|
|---|---|---|---|
|
|
| `GET` | `/api/auth/status` | Auth state, current user, providers | No |
|
|
| `POST` | `/api/auth/logout` | End session | Yes |
|
|
| `GET` | `/api/auth/me` | Current user info | Yes |
|
|
| `POST` | `/api/auth/api-keys` | Create API key | Yes |
|
|
| `GET` | `/api/auth/api-keys` | List user's API keys | Yes |
|
|
| `DELETE` | `/api/auth/api-keys/:id` | Revoke API key | Yes |
|
|
| `GET` | `/api/auth/usage` | User's own usage stats | Yes |
|
|
| `GET` | `/api/auth/usage/sources` | User's own per-API-key / per-source breakdown | Yes |
|
|
| `GET` | `/api/auth/admin/users` | List all users | Admin |
|
|
| `PUT` | `/api/auth/admin/users/:id/role` | Change user role | Admin |
|
|
| `DELETE` | `/api/auth/admin/users/:id` | Delete user | Admin |
|
|
| `GET` | `/api/auth/admin/usage` | All users' usage stats | Admin |
|
|
| `GET` | `/api/auth/admin/usage/sources` | All users' per-API-key / per-source breakdown | Admin |
|
|
| `POST` | `/api/auth/admin/invites` | Create invite link | Admin |
|
|
| `GET` | `/api/auth/admin/invites` | List all invites | Admin |
|
|
| `DELETE` | `/api/auth/admin/invites/:id` | Revoke unused invite | Admin |
|
|
| `GET` | `/api/auth/invite/:code/check` | Check if invite code is valid | No |
|
|
| `GET` | `/api/auth/github/login` | Start GitHub OAuth | No |
|
|
| `GET` | `/api/auth/github/callback` | GitHub OAuth callback (internal) | No |
|
|
| `GET` | `/api/auth/oidc/login` | Start OIDC login | No |
|
|
| `GET` | `/api/auth/oidc/callback` | OIDC callback (internal) | No |
|
|
|
|
## Usage Tracking
|
|
|
|
When authentication is enabled, LocalAI automatically tracks per-user token usage for inference endpoints. Usage data includes:
|
|
|
|
- **Prompt tokens**, **completion tokens**, and **total tokens** per request
|
|
- **Model** used and **endpoint** called
|
|
- **Request duration**
|
|
- **Timestamp** for time-series aggregation
|
|
|
|
### Viewing Usage
|
|
|
|
Usage is accessible through the **Usage** page in the web UI (visible to all authenticated users) or via the API:
|
|
|
|
```bash
|
|
# Get your own usage (default: last 30 days)
|
|
curl http://localhost:8080/api/auth/usage?period=month \
|
|
-H "Authorization: Bearer <key>"
|
|
|
|
# Admin: get all users' usage
|
|
curl http://localhost:8080/api/auth/admin/usage?period=week \
|
|
-H "Authorization: Bearer <admin-key>"
|
|
|
|
# Admin: filter by specific user
|
|
curl "http://localhost:8080/api/auth/admin/usage?period=month&user_id=<user-id>" \
|
|
-H "Authorization: Bearer <admin-key>"
|
|
```
|
|
|
|
**Period values:**
|
|
- `day` - last 24 hours, bucketed by hour
|
|
- `week` - last 7 days, bucketed by day
|
|
- `month` - last 30 days, bucketed by day (default)
|
|
- `all` - all time, bucketed by month
|
|
|
|
**Response format:**
|
|
|
|
```json
|
|
{
|
|
"usage": [
|
|
{
|
|
"bucket": "2026-03-18",
|
|
"model": "gpt-4",
|
|
"user_id": "abc-123",
|
|
"user_name": "Alice",
|
|
"prompt_tokens": 1500,
|
|
"completion_tokens": 800,
|
|
"total_tokens": 2300,
|
|
"request_count": 12
|
|
}
|
|
],
|
|
"totals": {
|
|
"prompt_tokens": 1500,
|
|
"completion_tokens": 800,
|
|
"total_tokens": 2300,
|
|
"request_count": 12
|
|
}
|
|
}
|
|
```
|
|
|
|
### Usage Dashboard
|
|
|
|
The web UI Usage page provides:
|
|
- **Period selector** - switch between day, week, month, and all-time views
|
|
- **Summary cards** - total requests, prompt tokens, completion tokens, total tokens
|
|
- **By Model table** - per-model breakdown with visual usage bars
|
|
- **By User table** (admin only) - per-user breakdown across all models
|
|
- **Sources tab** - per-API-key and per-source breakdown (described below)
|
|
|
|
### Per-API-key Breakdown
|
|
|
|
The **Sources** tab on the Usage page surfaces a third dimension of the same data: traffic broken down by API key and by request source. Three source classes are tracked:
|
|
|
|
- **API key** - request authenticated with a named user API key (`Authorization: Bearer lai-...`, `x-api-key`, or `token` cookie). Each key shows up with its label (snapshotted at write time, so revoked keys still display the original name).
|
|
- **Web UI** - request authenticated with a browser session cookie.
|
|
- **Legacy** - request authenticated with an env-configured `LOCALAI_API_KEY`. Visible to admins only.
|
|
|
|
The Sources tab is visible to every authenticated user. Non-admins see only their own keys plus their own Web UI traffic (legacy is filtered server-side). Admins see every key from every user.
|
|
|
|
The tab is laid out as:
|
|
|
|
- A **source mix ribbon** showing the percentage split across the three classes.
|
|
- A **top-N + Other stacked time chart** (top 7 sources by total tokens; the rest roll up).
|
|
- A **searchable, sortable table** of every key plus the Web UI and Legacy pseudo-rows. Click a row to filter the chart to that source.
|
|
|
|
#### Endpoints
|
|
|
|
| Method | Path | Auth | Description |
|
|
|--------|------|------|-------------|
|
|
| `GET` | `/api/auth/usage/sources` | Self | Caller's per-source breakdown. Excludes legacy. |
|
|
| `GET` | `/api/auth/admin/usage/sources` | Admin | All users' per-source breakdown. Accepts `user_id` and `api_key_id` filters. Includes legacy. |
|
|
|
|
Both endpoints accept the same `period` parameter (`day`, `week`, `month`, `all`) as `/api/auth/usage`.
|
|
|
|
```bash
|
|
# Your own per-source usage for the last week
|
|
curl "http://localhost:8080/api/auth/usage/sources?period=week" \
|
|
-H "Authorization: Bearer <key>"
|
|
|
|
# Admin: filter to a single API key across all users
|
|
curl "http://localhost:8080/api/auth/admin/usage/sources?period=month&api_key_id=<key-id>" \
|
|
-H "Authorization: Bearer <admin-key>"
|
|
```
|
|
|
|
**Response shape:**
|
|
|
|
```json
|
|
{
|
|
"buckets": [
|
|
{ "bucket": "2026-05-19", "source": "apikey",
|
|
"api_key_id": "uuid", "api_key_name": "ci-runner",
|
|
"total_tokens": 20000, "request_count": 142, "...": "..." },
|
|
{ "bucket": "2026-05-19", "source": "web",
|
|
"total_tokens": 300, "request_count": 11, "...": "..." }
|
|
],
|
|
"totals": {
|
|
"by_source": {
|
|
"apikey": { "tokens": 1234567, "requests": 8420 },
|
|
"web": { "tokens": 92000, "requests": 211 }
|
|
},
|
|
"by_key": [
|
|
{ "api_key_id": "uuid", "api_key_name": "ci-runner",
|
|
"tokens": 2100000, "requests": 8420,
|
|
"last_used": "2026-05-20T12:34:56Z" }
|
|
],
|
|
"grand_total": { "tokens": 1334777, "requests": 8645 }
|
|
},
|
|
"truncated": false
|
|
}
|
|
```
|
|
|
|
The `by_key` list is server-sorted by tokens descending and capped at 200 entries. When more keys would qualify, the response sets `"truncated": true` so the UI can show a notice.
|
|
|
|
#### Migration of pre-feature data
|
|
|
|
Usage rows recorded before this feature have no `source` column. On startup, `InitDB` backfills them as `legacy` when the synthetic `legacy-api-key` user_id was used, and `web` for everything else. The migration is idempotent; existing aggregations remain correct after the upgrade.
|
|
|
|
## Combining Auth Modes
|
|
|
|
Legacy API keys and user authentication can be used simultaneously. When both are configured:
|
|
|
|
1. User sessions and user API keys are checked first
|
|
2. Legacy API keys are checked as fallback - they grant **admin-level access**
|
|
3. This allows a gradual migration from shared API keys to per-user accounts
|
|
|
|
## Build Requirements
|
|
|
|
The user authentication system requires CGO for SQLite support. It is enabled with the `auth` build tag, which is included by default in Docker builds.
|
|
|
|
```bash
|
|
# Building from source with auth support
|
|
GO_TAGS=auth make build
|
|
|
|
# Or directly with go build
|
|
go build -tags auth ./...
|
|
```
|
|
|
|
The default Dockerfile includes `GO_TAGS="auth"`, so all Docker images ship with auth support. When building from source without the `auth` tag, setting `LOCALAI_AUTH=true` has no effect - the system operates without authentication.
|