Introduction
While Open WebUI has revolutionized the way developers interact with local Large Language Models (LLMs), deploying it for a team often exposes a critical vulnerability: the lack of robust identity management. By default, many setups rely on simple password files or open access, which is insufficient for enterprise-grade collaboration. This guide details how to harden your Open WebUI instance using Keycloak as an Identity Provider (IdP) and LDAP for directory synchronization. This architecture ensures that every team member has a unique identity, granular access controls, and seamless Single Sign-On (SSO).
Prerequisites and Architecture
Before diving into configuration, ensure you have a running Keycloak server (version 21+) and an Open WebUI instance (Dockerized is recommended). The architecture relies on the OpenID Connect (OIDC) standard. Keycloak will handle user authentication, while Open WebUI acts as the relying party. You will need:
1. A Keycloak realm created for your organization.
2. A client application registered in Keycloak with Client Authentication enabled.
3. Network connectivity between the Open WebUI container and the Keycloak server.
Configuring Keycloak
First, navigate to your Keycloak admin console. Create a new client of type "OpenID Connect." Set the Root URL and Valid Redirect URIs to point to your Open WebUI installation (e.g., `http://your-domain/*`). Crucially, enable "Client Authentication" and "Standard Flow."
Next, configure the "Scope" settings. Ensure "User Info" scope is enabled, as Open WebUI requires the `email`, `preferred_username`, and `name` claims to map users correctly. If you are syncing with an LDAP directory, configure the user federation in Keycloak before proceeding, ensuring that LDAP usernames map cleanly to the IdP usernames.
Open WebUI Environment Variables
This is where the integration comes to life. You need to pass specific environment variables to your Open WebUI Docker container. These variables instruct the application where to find the identity provider and how to validate tokens.
```bash
WEBUI_AUTH=True
WEBUI_SECRET_KEY="change-me-to-a-random-secret"
AUTH_TYPE_CREDENTIALS=True
AUTH_TYPE_OAUTH_OIDC=True
# Keycloak Configuration
AUTH_OIDC_PROVIDER_URL=http://your-keycloak-domain/auth/realms/your-realm
AUTH_OIDC_CLIENT_ID=your-client-id
AUTH_OIDC_CLIENT_SECRET=your-client-secret
AUTH_OIDC_SERVER_NAME=http://your-open-webui-domain
AUTH_OIDC_SCOPES=openid email profile
AUTH_OIDC_JWKS_URI=http://your-keycloak-domain/auth/realms/your-realm/protocol/openid-connect/certs
AUTH_OIDC_TOKEN_ENDPOINT=http://your-keycloak-domain/auth/realms/your-realm/protocol/openid-connect/token
AUTH_OIDC_AUTH_ENDPOINT=http://your-keycloak-domain/auth/realms/your-realm/protocol/openid-connect/auth
AUTH_OIDC_USER_INFO_ENDPOINT=http://your-keycloak-domain/auth/realms/your-realm/protocol/openid-connect/userinfo
```
Ensure that `AUTH_TYPE_CREDENTIALS` is set to `True` if you want to allow fallback login for admin users, or set it to `False` to enforce strict OIDC only.
Mapping Users and Groups
Once the containers are restarted with these variables, navigate to your Open WebUI login page. You should see an "Sign in with OpenID Connect" button. Upon successful authentication, Keycloak returns the user's identity. Open WebUI automatically creates a local user profile if the email or username does not exist, provided the `ALLOW_USER_SIGN_UP` environment variable is not explicitly restricting it.
For advanced team collaboration, use Keycloak groups to manage access. You can configure Open WebUI to only allow users from specific Keycloak groups to log in by setting the `WEBUI_ADMIN_USER` and `WEBUI_USER_USER` flags appropriately, or by leveraging LDAP group membership sync in Keycloak itself.
Conclusion
By integrating Keycloak and LDAP with Open WebUI, you transform a personal tool into a secure, scalable platform for team collaboration. This setup not only enhances security through centralized identity management but also simplifies user lifecycle management. As local AI adoption grows, implementing proper authentication standards like OIDC is no longer optional—it is essential for maintaining data integrity and access control in any professional environment.