* chore: open the 0.11.4 changelog Starts the section for the commits landed on dev after the 0.11.3 entry was merged. Fixed records the direct connection listener left behind on every request that ended badly, the metadata attached to an uploaded file that never reached the retrieved sources, the slash command menu showing white text on white in the light theme, and image editing refusing an image the instance already held. Added carries the general improvements placeholder and the Traditional Chinese, Korean and Finnish catalogues. The tailwind reflow and the raw string escapes are omitted, the first being whitespace and the second changing nothing that is visible today, though it keeps the knowledge filesystem tools importable on a later Python. * chore: extend the metadata and translation entries in 0.11.4 The metadata entry gains the follow-up that trims what travels with each piece of a file, keeping the oversized and internal fields out of every chunk and picking up metadata nested a level down, and is recorded there rather than as a second entry because it continues the same story. The translation entry gains the Russian and Ukrainian catalogues. The settings group headings and the keys added for them are omitted: the new keys carry no translation in any catalogue yet, so every heading still reads as it did, and the change only makes them translatable later. * chore: add the security advisory notice to 0.11.4 Adds the standard notice as the first item in the Fixed section. The release touches the guard that keeps image editing from reaching private addresses, and carries a listener leak a caller could drive without limit, so it meets the trigger the format sets for the notice. The notice is the fixed wording and takes no reference links of its own; the individual entries keep theirs. * chore: record the file metadata entry as an addition in 0.11.4 Metadata attached to an upload reaching the retrieved sources is a capability that was not there before rather than a correction, so the entry moves to Added and leads that section, ahead of the general improvements placeholder and the translation entry in their reserved places. The wording drops the framing that described it as something no longer going missing; its pull request, issue and follow-up commit travel with it unchanged. * chore: give the file metadata entry a noun phrase label The label read as an outcome, which suits a correction rather than an addition and left the entry sounding like something that had stopped going wrong. It is now the plain noun phrase the format asks of a label, with the sentence beneath carrying what the metadata now does. * chore: add the settings group heading entry to 0.11.4 The groundwork that made these headings translatable was held back last time, the keys having landed empty in every catalogue so nothing read differently. Russian and Ukrainian now carry the wording, so the change shows and the entry joins Fixed at the foot of the section, below the corrections that reach further. The two commits that made the headings translatable are referenced; the catalogues that filled them sit in the translation entry, which names both languages and carries no links. * chore: add the code formatter entry and widen the translation coverage entry in 0.11.4 Fixed leads with the built-in code formatter, which pulled in the formatter but none of the packages it depends on, so saving any tool or function ended in a missing module error however plain the code was. It sits directly below the advisory, being the correction that stops the most people getting their work saved. The settings heading entry widens into one covering every string that was fixed in English, the headings among them, now that labels and messages across the admin pages, the workspace and notifications have been opened up the same way and Spanish, Russian and Ukrainian have filled them in. Its five commits travel together. German and Spanish join the translation entry. * chore: add the notes shortcut and web citation entries to 0.11.4 Added records the shortcut that turns a note's menu button into a delete button while Shift is held, ahead of the placeholder and translation entries in their reserved places. Fixed records the pages a web search only listed no longer being offered as things to cite, which had produced citations pointing at the wrong result under a title that read as correct. It sits directly below the code formatter, a citation that is wrong being worse to a reader than one that is missing. * chore: add the version check, ligature and search entries to 0.11.4 Fixed gains the version check that reported whatever it was running as the newest release whenever it could not reach the listing, and logged nothing about it, which is placed high because an administrator reads it as an answer rather than a failure. It also gains the arrow sequences drawn as glyphs, which had text look altered although every character was stored and sent as typed; that one sits with the other reading corrections. Added gains the text search moved off the path the server answers on, so a long search no longer keeps other requests waiting. The metadata entry gains the four vector stores that never applied the shared size cap, coercion and sanitising, bringing them in line with the other eleven rather than standing as an entry of its own. * chore: extend the quick delete entry to automations in 0.11.4 The shortcut that turns a note's trailing controls into a delete button now does the same for a row on the automations page, so the entry names both places and carries both pull requests with the issues they close, rather than repeating itself for the second surface. The pass blanking redundant English values in the en-US catalogue is omitted: the key stands in for the value there, so nothing reads differently. * chore: add the note from search entry to 0.11.4 Fixed records the three ways starting a note from the search box went wrong, as one entry because they are one action: the browser back button making a further note on every press, the action doing nothing at all when the notes page was already open, and the typed text losing everything from the first ampersand or hash onwards. It sits below the listener leak, unwanted notes being a nuisance rather than something that grows on the server. * chore: add the arena, relevance and dialog entries to 0.11.4 Fixed gains the arena model that failed on something unrelated whenever its provider answered with an error, so the reason never reached the chat and titles and tags broke alongside it; it is placed high, a message that fails outright costing more than one that reads oddly. It also gains the relevance figure that a reply drawing on a single source never showed, appearing only once a second source joined it, and the grey band the attach webpage dialog carried between its address box and its button. * chore: add the per-language model wording entries to 0.11.4 Added leads with a model carrying its name, description and starter prompts in each language, written in the workspace editor or the admin defaults and chosen by the language the interface is set to, falling back to the plain wording where that language has none. Every part of it arrived together, so it is one entry. Changed opens the section for the saving call that now answers with the suggestions and their per-language wording together where it returned the bare list, which anything reading that response directly has to account for. No schema change travels with it, so the section carries no migration warning. * chore: widen the per-language wording entry in 0.11.4 The mechanism that gave a model its name, description and starter prompts in each language now covers tools, skills, functions, banners and arena entries too, each written in the editor that owns it, so the entry names them rather than standing as a second one beside it. Both commits travel with it. The response shape entry is unchanged: it is the saving call for the admin defaults, which this second commit does not touch. * chore: carry the valve labels and translation table into the wording entry The entry named only what a resource is called and says about itself, leaving out the labels on its valves, which are translatable down to the options in a dropdown, and the table each editor now offers in place of the code when a language is picked, with the JSON file it reads and writes. An import that drops a placeholder the original fills in is refused, which is worth the words it takes to say. It stays one entry: every part of this arrived together and none of it existed in another form before. * chore: add the interface wording and sketch upload entries to 0.11.4 Added records an administrator being able to replace the interface's own wording language by language, which is a separate thing from a model or a tool carrying wording of its own and so stands beside that entry rather than joining it. A replacement that drops a placeholder the original fills in is refused, as it is for the resources. Fixed records the Arduino sketch that failed to upload to a knowledge base because its extension was missing from the list of files read as plain text, so it went to a document extraction server that answered with something the loader could not read. * chore: carry the wording editor follow-ups into the 0.11.4 entry Two follow-ups tidy the editor the per-language wording is written in, dropping the line that said whether a field was translated or using the default and holding back the controls beside a skill or tool name. Neither changes what the entry describes, so they join its links rather than standing on their own. The terminal work is left out: the dock it adds is not rendered anywhere yet, and the rest of that commit rewrites the existing terminal in place and sends two identifying headers upstream, none of which shows to anyone using it. * chore: add the document escape sequence entry to 0.11.4 Fixed records the escape sequences in an uploaded file being rewritten before the text was stored, so what was indexed and what the model read differed from the file as written, and inconsistently at that, since the rewriting stopped at the first line holding an angle bracket. It sits beside the sketch upload, both being corrections to what a file turns into on its way into knowledge. * chore: add the Apple Silicon and WebKit entries to 0.11.4 Fixed gains the question against a knowledge base that killed the server outright on a Mac when a reranking model ran locally, placed high, an answer lost with the connection costing more than one that reads oddly. It also gains the two separate things the WebKit pull request corrects, kept apart because a reader meets them as different problems: an assistant reply coming up blank on Apple devices whose browser never says Safari, and the sidebar hover preview laid out at the width of a full conversation there since 0.11.0. * chore: add the terminal dock entry to 0.11.4 Added leads with the terminal pane carrying a tab for every command a model is running beside the shell, which is the most visible thing in the release for anyone who watches an agent work. It was held back earlier on the reading that the dock was built but never rendered. That reading came from searching a checkout that predated the commit; the commit swaps the single terminal for the dock in the files pane, so it has been in front of people since it landed. * chore: add the note date entry to 0.11.4 Fixed records the date beneath a note title, which was wrapped in a button left over from an earlier styling pass, so it took a pointing hand and announced itself as something to press while doing nothing at all. It sits at the foot of the section beside the dialog banding, both being small corrections to how something looks rather than what it does. * chore: add the token logging, model picture and image size entries to 0.11.4 Fixed leads, below the advisory, with the credentials an identity provider handed over being written into the application log when a sign-in failed part way through, and with the model picture that any signed-in person could fetch whatever their access, which also told them whether a model id existed at all. Both sit above the rest of the section, a credential in a log file and a way to enumerate what a server holds costing more than anything below them. Changed records the consequence a viewer will notice: a model picture falling back to the standard logo wherever no grant is held, which is a change to what people see rather than a correction, so it is kept apart from the entry above. Added records the container image losing the second Python it never used. * chore: gather the image size work and add the docx preview entries to 0.11.4 The image size entry now carries the fonts nothing loaded and the packages nothing imports alongside the second Python it already named, with all four pull requests, and states the running total rather than the one measurement it started from. They are one entry because a reader meets them as one thing: less to pull. Changed records what that costs anyone whose tool or function imported a package it never declared, which worked only while the package happened to be in the image. Fixed records the Word document preview no longer rendering an HTML sub-document embedded in the file, and refusing a link that points anywhere but a web address, a mail address or a telephone number. * chore: write the image size figure in digits The file gives every measurement in digits and spells out only counts of things, so the size the image loses is written the same way as the ones recorded before it. * chore: add the slim image entry to 0.11.4 Changed records the slim image giving up the local models and converters it carried, so an instance built that way now needs a service configured for embeddings, vector storage, document extraction past plain text, and speech, and refuses to build alongside the graphics card or Ollama options. The admin pages mark what is unavailable and the server answers with what to configure, both part of the same change. It is kept out of the image size entry above, which gathers what was carried and never used; this one removes things that were used and asks for them from somewhere else. * chore: correct the slim entry and add the citation link entry to 0.11.4 The slim entry read as though a service had to be configured before the image would run. It does not: the vector client is built on first use behind a lock, the speech engine raises only when one is asked for, and extraction raises per file, so an instance starts and holds a conversation with none of it in place and each feature asks for what it needs when it is reached. The entry now says that. The image size entry gains the slim build leaving behind the tool that installed its packages and the source maps built beside the interface. Fixed gains the source attached to a reply opening only where it points at a web address, which sits with the document preview correction, both being about where a link in something the model handed back is allowed to go. Portuguese (Brazil) joins the translation entry. * chore: add the BuildKit entry and fold the install tool into the size entry The install tool now leaves every image rather than only the slim one, since it is mounted for the install step instead of being installed and removed, so the size entry names it among what the image no longer carries and the slim clause keeps only the source maps. Changed records what building the image yourself now takes: the BuildKit builder, which the syntax line alone did not require before, and reach to the registry that tool is fetched from. * chore: add the webhook picture and nameless tool call entries to 0.11.4 Fixed gains the channel webhook picture that anyone signed in could fetch, or be sent onward to, without belonging to the channel, which sits directly below the model picture entry, the two being the same gap on two routes. It also gains the tool call arriving with no name at all, which was kept as it came, written into the stored message and handed back on the next turn for the endpoint to refuse, and now fails once where it starts. The line uninstalling the install tool is not recorded: it went in the same breath as the mount that made it unnecessary, and the size entry already says the tool no longer ships. * chore: add the tool server request entry to 0.11.4 Fixed records a tool call to an OpenAPI tool server repeating in the body the arguments already placed in the address, which a server checking its input strictly refused, so reading worked and writing through any such address did not. It is placed high, a whole class of tool call failing outright costing more than the corrections below it. * chore: bring the 0.11.4 date up to the newest change it records The date was set when the section was opened and left there while entries kept arriving, so it sat three days behind the last commit it covers. * chore: add the sign-in form setting entry to 0.11.4 Added records the sign-in form becoming something an administrator can switch off from the authentication settings. The setting itself is not new, having been available since before this release as a value read at startup; what is new is reaching it without restarting the server, so it is recorded as an addition rather than a change to how signing in works. The date on the section already stands at the day of this change. * chore: add the slim backend narrowing entry to 0.11.4 Changed gains the set of things slim will work with at all, which is a separate matter from the entry above it: that one says the local models are gone and a service is asked for when a feature reaches for one, this one says which databases, vector stores and file stores remain, and that being pointed at anything else stops the server before it starts rather than at first use. The browser-driven page reader goes with them. It sits directly below the entry it qualifies. * chore: say which slim limits stop the server and which do not The entry put refusing to start against all three limits. Only two behave that way: the database check raises while the module is read, and the storage provider is chosen by a call made as the module is read. The vector store is built on first use, so pointing slim at anything but PostgreSQL for it fails when something searches, not at startup. The sentence now separates them. * chore: soften the slim backend entry and cover the browser speech runtime * chore: lead the 0.11.4 sections with the slimming entries * chore: cover the slim web search and code interpreter changes * chore: split the slim limits into their own entries and cover the PDF removal * chore: fold the dropped Gemini SDK into the tool imports entry * chore: rewrite the changed entries and cover git leaving the slim image * chore: drop the entry for the unused PDF endpoint * chore: cover the tool export scoping and the terminal command echo * chore: lead with the slim image download size * chore: cover the model registry rewrite fix * chore: cover the playwright media skip and lead the registry entry with the cost * chore: lead the playwright entry with the speed gain * chore: drop the build and picture entries and retitle the tool imports one * chore: write the measured image sizes and retitle the page loader entry * chore: state only how much smaller the images are * chore: retitle the per-language wording entry * chore: retitle the terminal tabs entry * chore: fold the translation coverage entry into translation updates * chore: date the 0.11.4 section 2026-09-07 * chore: cover continuing a reply in a temporary chat * chore: write the connection listing role check as a security fix * chore: keep the connection listing fix brief * chore: fold the continue reply refinements into its entry * chore: note the llama.cpp continuation flags * chore: cover cookie forwarding and the note save on navigation * chore: cover the model access denial logging * chore: cover the tool step merge and the model list filters * chore: cover three fixes from 29494, 29493 and 29325 * chore: note the terminal pane open and collapse behaviour * chore: cover the settings save rework * chore: write the settings clobbering fix and trim the api note * chore: name what the interface permission was blocking * chore: cover the account menu row highlight * chore: cover diff blocks, note formatting, tika 4 and the oauth session expiry * chore: cover folder upload and the file browser selection fixes * chore: cover file comparison and the query link submit * chore: cover the task list height cap * chore: add the server side of the tool call match fix * chore: cover the exa result length cap * chore: cover the modal shortcut, build stamp and sticky code headings * chore: cover knowledge listing order, terminal proxy headers and stale tool links * chore: cover the forwarded auth type header and terminal attachment name clashes * chore: cover the misleading model editor permission error * chore: cover the thread notification and overlapping select chevrons * chore: cover the OpenAI and Ollama proxy header stripping * chore: cover stopping every task attached to a chat * chore: cover code blocks in channel structured output replies * chore: cover whitespace in model ids and knowledge folder deletion * chore: cover automation schedule times and mention IDs * chore: cover the latest translation fills * chore: note the further pt-BR translation pass * chore: cover the follow-up suggestion in the message box * chore: cover notification target names, MCP tool paging and the stop follow-up * chore: cover thinking blocks, channel terminals and custom header encoding * chore: cover link schemes, spellcheck, dotless hosts and webhook pictures * chore: cover tool images, stopped replies, sync errors and terminal proxy limits * chore: cover malformed tool calls and the direct connection note * chore: cover the langchain community removal and broken streams * chore: cover the empty page upload message * chore: cover embed rendering and two memory leaks * chore: cover the sign-in limiter, socket cleanup and stored tool images * docs: changelog entries for terminal skills * docs: cover the skills:create command and the streaming append option * docs: cover the model editor save button fix * docs: fold the skill save location refinements into the skills:create entry * docs: cover model backgrounds, note range edits and the playwright websocket fix * docs: link the autoscroll follow-up commit * docs: cover the responses tool strictness and attachment-only fixes * docs: widen the non-blocking search entry to the knowledge grep tool * docs: cover branch descent, checkbox defaults, fork folders, search logging and file access * docs: cover the direct connection guidance note * docs: cover tag text leaking into streamed replies * docs: SVG attachments, Docling conversion failures, title generation logging * docs: chat unblocked after a failed reply * docs: directory provisioning patch handling * docs: settings search matches individual settings * docs: Staan search, Excel in the code interpreter, pgvector index training, terminal tool gating * docs: Responses API tool calling * docs: vector search recall and connections, forking, bundled packages, chat import, image connection checks * docs: message pair shortcut no longer sends the input * docs: shortcut recording, note sharing, unarchiving from search, skill saves, recommended badge * docs: workspace exports cover every prompt and model * docs: terminal instructions file, sign-in roles, folders, feedback, admin forms * docs: session revocation, sidebar bulk actions, speech file types, source metadata keys * docs: model fallback, shared note traffic, recurrence counts, RE2 search, Redis task expiry, direct connection events Add the entries for the commits since the last pass: the chat model fallback (#29757) and the shared-note co-editing traffic drop (#28185) in Added, with the Staan count fix (#30303) folded into the Staan entry and Italian added to the translation entry. Fixed covers the schedule recurrence and count parsing (#29262), the RE2-backed file searches, the Redis task expiry and stalled recurrence guards, the direct-connection events travelling between workers, the IME guard while renaming a chat, the S3 content-encoding image handling (#29623) and the sixteen interface and workspace fixes. * docs: issue references on the fix entries, general improvements without links Append the issue or discussion each fix PR carries in its body to its changelog entry, and drop every link from the general improvements entry, which never carries any. * docs: model pool cache, message round trips, folder backgrounds, delete shortcut, chat variables Cover the eight newest dev commits: the per-worker model pool cache (#28176) and the single-message chat read and write (#28184) in Added, and in Fixed the knowledge directory scoping, model sharing surviving a save, the folder background on creation (#30218), the Delete Chat shortcut working wherever the chat was opened from (#30165) and chat variables a prompt no longer declares (#30173). * docs: searchapi results and errors, blocked groups saving, timer owner checks, terminal access rechecks Cover the four commits still missing from the last pass: the searchapi.io fix (#30308, with its issue), the OAuth blocked groups save round trip (3fc1146c1, typed comma lists never took effect), the due-timer owner role check (#30220) and the terminal session access recheck, which folds its in-cycle introduction (a1189a2d7) and the cross-worker rework (e8bd0661d) into one entry. * docs: issue and pull references on the knowledge directory and model sharing entries The knowledge directory scoping is the landed form of #29887 and the model sharing fix traces to #30093, which closes #30087; both entries carried only their commit links. * docs: memory review gating, channel message quotes, knowledge filter, tool result flushing, localized suggestions Cover the last dev batch: the background memory review now stops when memory is switched off or the account is barred (#30309), a deleted channel message clears the quotes pointing at it (#30314, #30313), the knowledge File content filter applies on the first click (#30211, #30210), tool results are published when the round finishes instead of waiting on the stream throttle, with channel and continuation replies no longer carrying picture data a tool handed the model, and a fresh install now suggests starter prompts in the interface language, with a way back to the defaults from the model defaults panel. * docs: playground image edit request shape The Images playground edit call wrapped its fields under a heading the endpoint never read, so every edit came back rejected; the request now carries them flat (c07fa08b9). * docs: same-origin diagrams and SVG, read-only folders on the empty-chat page, placeholder translations Cover the latest dev batch: diagrams and SVG previews only follow same-origin and data references and a diagram reaching outside is refused (#30271), the empty-chat page no longer shows folder edit controls for a folder shared read-only (ee3ece1e2), and translated strings that had their placeholder names localized or their braces lost are restored across the thirteen locales (#30326).
Open WebUI 👋
Open WebUI is a home for AI, a self-hosted AI platform that's extensible, feature-rich, user-friendly, and built to run entirely offline. With support for Ollama and OpenAI-compatible APIs, it gives you a powerful, provider-agnostic interface for both local and cloud-based models.
Passionate about open-source AI? Join our team →
Tip
Looking for an Enterprise Plan? – Speak with Our Sales Team Today!
For more information, be sure to check out our Open WebUI Documentation.
Key Features of Open WebUI ⭐
-
🚀 Effortless Setup: Install seamlessly via pip, uv, Docker, or Kubernetes (kubectl, kustomize, or helm), with
:ollamaand:cudatagged images available for container deployments. -
🤝 Broad Model & API Integration: Connect any OpenAI-compatible API alongside local Ollama models. Point the API URL at LMStudio, GroqCloud, Mistral, OpenRouter, vLLM, and more to mix and match providers freely.
-
🔐 Granular RBAC & User Groups: Administrators define detailed roles, groups, and permissions, giving each user exactly the access they need. Secure by default, with tailored experiences per group.
-
🧩 Plugin Support: Extend Open WebUI with Filters, Actions, Pipes, Tools, and Skills. Connect external services through MCP, MCPO, and OpenAPI tool servers. Build custom integrations, rate limits, approval flows, data connections, and more.
-
🤖 Models & Agents: Wrap any base model with custom instructions, tools, and knowledge to build specialized agents. Supports dynamic variables, per-user/group access control, and community preset imports via Open WebUI Community.
-
⚡ Agentic Execution with Open Terminal: Give your agents a terminal and filesystem to carry out multi-step tasks. Let them analyze data, run scripts, fix errors, and produce files directly in chat. Scale to teams with Terminals (Enterprise) for per-user isolated environments, resource limits, and automatic lifecycle management.
-
📝 Notes: A dedicated workspace for content outside conversations. Draft with a rich editor, use AI to rewrite selected text, and attach notes to any chat for full-context injection.
-
📢 Channels: Real-time shared spaces where your team and AI models collaborate in one timeline. Tag models to draft or critique, with threads, reactions, pins, and access control.
-
🧠 Persistent Memory: The AI remembers facts about you across conversations, carrying context from one chat to the next.
-
✅ Live Workflow & Message Flow: Watch the AI build and work through checklists in real time. Queue messages while the AI is still responding; they send automatically when it's ready.
-
📅 Calendar & AI Scheduling: Built-in personal and shared calendars with month/week/day views, recurring events, color coding, attendees, and reminders. Models manage your schedule conversationally through native function calling.
-
⏱️ Automations: Schedule prompts to run on recurring schedules, with runs surfaced on your calendar and each completed run linking back to the chat it produced.
-
📱 Responsive Design & PWA: Seamless experience across desktop, laptop, and mobile, with a Progressive Web App for native app-like feel and offline access on localhost.
-
✒️🔢 Full Markdown and LaTeX Support: Comprehensive Markdown and LaTeX capabilities for enriched interaction.
-
🎤📹 Hands-Free Voice/Video Call: Integrated voice and video calls with multiple Speech-to-Text providers (Local Whisper, OpenAI, Deepgram, Azure) and Text-to-Speech engines (Azure, ElevenLabs, OpenAI, Transformers, WebAPI).
-
💾 Persistent Artifact Storage: Built-in key-value storage API for artifacts, enabling journals, trackers, leaderboards, and collaborative tools with personal and shared data scopes.
-
📚 Local RAG Integration: Retrieval Augmented Generation backed by 9 vector databases and multiple content-extraction engines (Tika, Docling, Document Intelligence, Mistral OCR, PaddleOCR-vl, external loaders). Supports hybrid search (BM25 + vector) with reranking and full-context mode. Load documents into chat or pull them from your library with the
#command. -
🔍 Web Search for RAG: Search the web through dozens of providers including
SearXNG,Google PSE,Brave Search,Kagi,Mojeek,Tavily,Perplexity,Firecrawl,serpstack,serper,Serply,DuckDuckGo,SearchApi,SerpApi,Bing,Jina,Exa,Sougou,Azure AI Search, andOllama Cloud, injecting results directly into the conversation. -
🌐 Web Browsing Capability: Pull websites into chat with the
#command followed by a URL, or let the model fetch them on its own when needed. -
🎨 Image Generation & Editing: Create and edit images with multiple engines including OpenAI DALL·E, Gemini, ComfyUI (local), and AUTOMATIC1111 (local), supporting both generation and prompt-based editing.
-
⚙️ Multi-Model Conversations: Engage several models at once, harnessing their individual strengths in parallel for the best possible responses.
-
📊 Usage Analytics & Model Evaluation: Admin dashboards track message volume, token consumption, and cost across users and models. Evaluate models with a built-in arena, A/B testing, and ELO-based leaderboards.
-
🗄️ Flexible Database & Storage: Choose SQLite (with optional encryption) or PostgreSQL, and store files locally or on S3, Google Cloud Storage, or Azure Blob Storage.
-
🧬 Advanced Vector Database Support: Pick from 9 vector databases: ChromaDB, PGVector, Qdrant, Milvus, Elasticsearch, OpenSearch, Pinecone, S3Vector, and Oracle 23ai.
-
🪪 Enterprise Authentication & Provisioning: Full LDAP/Active Directory integration, SSO via trusted headers and OAuth providers, and SCIM 2.0 automated provisioning for identity providers like Okta, Azure AD, and Google Workspace.
-
☁️ Cloud-Native File Integration: Native Google Drive and OneDrive/SharePoint file picking for seamless document import from enterprise cloud storage.
-
🔭 Production Observability: Built-in OpenTelemetry support for traces, metrics, and logs, plugging into your existing monitoring stack.
-
⚖️ Horizontal Scalability: Redis-backed session management and WebSocket support for multi-worker, multi-node deployments behind load balancers.
-
🌐🌍 Multilingual Support: Use Open WebUI in your preferred language with i18n support. We're actively seeking contributors to expand language coverage!
-
🌟 Continuous Updates: We're committed to improving Open WebUI with regular updates, fixes, and new features.
-
🛡️ Transparent Security Process: Security reports are triaged, fixed, and published as open advisories through a documented responsible-disclosure process. See our Security Policy.
Want to learn more about Open WebUI's features? Check out our Open WebUI documentation for a comprehensive overview!
The Open WebUI Ecosystem 🌐
Open WebUI is the core, surrounded by companion apps and infrastructure that extend what your AI can do, where it can reach, and how you run it:
-
💻 Open WebUI Computer (open-webui/computer): A standalone, mobile-first computer and coding agent that runs on the machine you own. Files, terminal, and git in a browser tab, reachable from your phone. Connect it into Open WebUI as a model, or reach it from Telegram, WhatsApp, and more.
-
⚡ Open Terminal and Terminals (Enterprise) (open-webui/open-terminal & open-webui/terminals): A self-hosted computing environment that plugs into Open WebUI, giving the AI a place to write code, run it, read output, fix errors, and iterate inside the chat. Terminals gives you per-user isolated containers with separate credentials, resource limits, and network rules. Automatic lifecycle management on Docker or Kubernetes.
-
🔄 oikb (open-webui/oikb): Feed your Knowledge Bases from 45+ sources (GitHub, Confluence, ServiceNow, Salesforce, Jira, Slack, SharePoint, Notion, and more), keeping the tools your team already uses continuously in sync.
-
🖥️ Native Desktop App (open-webui/desktop): Run Open WebUI as a native app on macOS, Windows, and Linux. System-wide Spotlight chat bar with screenshot capture, push-to-talk voice, and optional fully-local inference via a built-in llama.cpp engine.
Want to learn more? Check out our Open WebUI documentation for more details!
We are incredibly grateful for the generous support of our sponsors. Their contributions help us to maintain and improve our project, ensuring we can continue to deliver quality work to our community. Thank you!
How to Install 🚀
Installation via Python pip 🐍
Open WebUI can be installed using pip, the Python package installer. Before proceeding, ensure you're using Python 3.11 to avoid compatibility issues.
-
Install Open WebUI: Open your terminal and run the following command to install Open WebUI:
pip install open-webui -
Running Open WebUI: After installation, you can start Open WebUI by executing:
open-webui serve
This will start the Open WebUI server, which you can access at http://localhost:8080
Quick Start with Docker 🐳
Note
Please note that for certain Docker environments, additional configurations might be needed. If you encounter any connection issues, our detailed guide on Open WebUI Documentation is ready to assist you.
Warning
When using Docker to install Open WebUI, make sure to include the
-v open-webui:/app/backend/datain your Docker command. This step is crucial as it ensures your database is properly mounted and prevents any loss of data.
Tip
If you wish to utilize Open WebUI with Ollama included or CUDA acceleration, we recommend utilizing our official images tagged with either
:cudaor:ollama. To enable CUDA, you must install the Nvidia CUDA container toolkit on your Linux/WSL system.
Installation with Default Configuration
-
If Ollama is on your computer, use this command:
docker run -d -p 3000:8080 --add-host=host.docker.internal:host-gateway -v open-webui:/app/backend/data --name open-webui --restart always ghcr.io/open-webui/open-webui:main -
If Ollama is on a Different Server, use this command:
To connect to Ollama on another server, change the
OLLAMA_BASE_URLto the server's URL:docker run -d -p 3000:8080 -e OLLAMA_BASE_URL=https://example.com -v open-webui:/app/backend/data --name open-webui --restart always ghcr.io/open-webui/open-webui:main -
To run Open WebUI with Nvidia GPU support, use this command:
docker run -d -p 3000:8080 --gpus all --add-host=host.docker.internal:host-gateway -v open-webui:/app/backend/data --name open-webui --restart always ghcr.io/open-webui/open-webui:cuda
Installation for OpenAI API Usage Only
-
If you're only using OpenAI API, use this command:
docker run -d -p 3000:8080 -e OPENAI_API_KEY=your_secret_key -v open-webui:/app/backend/data --name open-webui --restart always ghcr.io/open-webui/open-webui:main
Installing Open WebUI with Bundled Ollama Support
This installation method uses a single container image that bundles Open WebUI with Ollama, allowing for a streamlined setup via a single command. Choose the appropriate command based on your hardware setup:
-
With GPU Support: Utilize GPU resources by running the following command:
docker run -d -p 3000:8080 --gpus=all -v ollama:/root/.ollama -v open-webui:/app/backend/data --name open-webui --restart always ghcr.io/open-webui/open-webui:ollama -
For CPU Only: If you're not using a GPU, use this command instead:
docker run -d -p 3000:8080 -v ollama:/root/.ollama -v open-webui:/app/backend/data --name open-webui --restart always ghcr.io/open-webui/open-webui:ollama
Both commands facilitate a built-in, hassle-free installation of both Open WebUI and Ollama, ensuring that you can get everything up and running swiftly.
After installation, you can access Open WebUI at http://localhost:3000. Enjoy! 😄
Other Installation Methods
We offer various installation alternatives, including non-Docker native installation methods, Docker Compose, Kustomize, and Helm. Visit our Open WebUI Documentation or join our Discord community for comprehensive guidance.
Troubleshooting
Encountering connection issues? Our Open WebUI Documentation has got you covered. For further assistance and to join our vibrant community, visit the Open WebUI Discord.
Open WebUI: Server Connection Error
If you're experiencing connection issues, it’s often due to the WebUI docker container not being able to reach the Ollama server at 127.0.0.1:11434 (host.docker.internal:11434) inside the container . Use the --network=host flag in your docker command to resolve this. Note that the port changes from 3000 to 8080, resulting in the link: http://localhost:8080.
Example Docker Command:
docker run -d --network=host -v open-webui:/app/backend/data -e OLLAMA_BASE_URL=http://127.0.0.1:11434 --name open-webui --restart always ghcr.io/open-webui/open-webui:main
Keeping Your Docker Installation Up-to-Date
Check our Updating Guide available in our Open WebUI Documentation.
Using the Dev Branch 🌙
Warning
The
:devbranch contains the latest unstable features and changes. Use it at your own risk as it may have bugs or incomplete features.
If you want to try out the latest bleeding-edge features and are okay with occasional instability, you can use the :dev tag like this:
docker run -d -p 3000:8080 -v open-webui:/app/backend/data --name open-webui --add-host=host.docker.internal:host-gateway --restart always ghcr.io/open-webui/open-webui:dev
Offline Mode
If you are running Open WebUI in an offline environment, you can set the HF_HUB_OFFLINE environment variable to 1 to prevent attempts to download models from the internet.
export HF_HUB_OFFLINE=1
What's Next? 🌟
Discover upcoming features on our roadmap in the Open WebUI Documentation.
License 📜
This project contains code under multiple licenses. The current codebase includes components licensed under the Open WebUI License with an additional requirement to preserve the "Open WebUI" branding, as well as prior contributions under their respective original licenses. For a detailed record of license changes and the applicable terms for each section of the code, please refer to LICENSE_HISTORY. For complete and updated licensing details, please see the LICENSE and LICENSE_HISTORY files.
Support 💬
If you have any questions, suggestions, or need assistance, please open an issue or join our Open WebUI Discord community to connect with us! 🤝
Security 🛡️
If you believe you've found a security vulnerability, or something that shouldn't be disclosed publicly, please reach out confidentially through our responsible disclosure program on GitHub. We accept reports only through GitHub, not through any other platform. Thank you for helping us keep Open WebUI secure!
Star History
Created by Timothy Jaeryang Baek - Let's make Open WebUI even more amazing together! 💪
