Files
langflow/api-keys-and-authentication.html
2026-05-04 19:25:36 +00:00

365 lines
83 KiB
HTML
Raw Blame History

This file contains invisible Unicode characters

This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

<!doctype html>
<html lang="en" dir="ltr" class="docs-wrapper plugin-docs plugin-id-default docs-version-1.9.0 docs-doc-page docs-doc-id-Develop/api-keys-and-authentication" data-has-hydrated="false">
<head>
<meta charset="UTF-8">
<meta name="generator" content="Docusaurus v3.9.2">
<title data-rh="true">API keys and authentication | Langflow Documentation</title><meta data-rh="true" name="viewport" content="width=device-width,initial-scale=1"><meta data-rh="true" name="twitter:card" content="summary_large_image"><meta data-rh="true" property="og:url" content="https://docs.langflow.org/api-keys-and-authentication"><meta data-rh="true" property="og:locale" content="en"><meta data-rh="true" name="docusaurus_locale" content="en"><meta data-rh="true" name="docsearch:language" content="en"><meta data-rh="true" name="docusaurus_version" content="1.9.0"><meta data-rh="true" name="docusaurus_tag" content="docs-default-1.9.0"><meta data-rh="true" name="docsearch:version" content="1.9.0"><meta data-rh="true" name="docsearch:docusaurus_tag" content="docs-default-1.9.0"><meta data-rh="true" property="og:title" content="API keys and authentication | Langflow Documentation"><meta data-rh="true" name="description" content="Never expose Langflow ports directly to the internet without proper security measures."><meta data-rh="true" property="og:description" content="Never expose Langflow ports directly to the internet without proper security measures."><link data-rh="true" rel="icon" href="/img/favicon.ico"><link data-rh="true" rel="canonical" href="https://docs.langflow.org/api-keys-and-authentication"><link data-rh="true" rel="alternate" href="https://docs.langflow.org/api-keys-and-authentication" hreflang="en"><link data-rh="true" rel="alternate" href="https://docs.langflow.org/api-keys-and-authentication" hreflang="x-default"><link data-rh="true" rel="preconnect" href="https://UZK6BDPCVY-dsn.algolia.net" crossorigin="anonymous"><script data-rh="true" type="application/ld+json">{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"API keys and authentication","item":"https://docs.langflow.org/api-keys-and-authentication"}]}</script><link rel="preconnect" href="https://www.google-analytics.com">
<link rel="preconnect" href="https://www.googletagmanager.com">
<script async src="https://www.googletagmanager.com/gtag/js?id=G-SLQFLQ3KPT"></script>
<script>function gtag(){dataLayer.push(arguments)}window.dataLayer=window.dataLayer||[],gtag("js",new Date),gtag("config","G-SLQFLQ3KPT",{})</script>
<link rel="search" type="application/opensearchdescription+xml" title="Langflow Documentation" href="/opensearch.xml">
<script>window._ibmAnalytics={settings:{name:"DataStax",tealiumProfileName:"ibm-subsidiary"},trustarc:{privacyPolicyLink:"https://ibm.com/privacy"},"digitalData.page.services.google.enabled":!0},window.digitalData={page:{pageInfo:{ibm:{siteId:"IBM_"+_ibmAnalytics.settings.name},segment:{enabled:!0,env:"prod",key:"B04fNhD06DqDPuaRfQl5lZ2iQICdxxuh",coremetrics:!1,carbonComponentEvents:!1}},category:{primaryCategory:"PC230"}},commonProperties:{productTitle:"IBM Elite Support for Langflow",productCode:"5900BUB",productCodeType:"WWPC",UT30:"30AS5",instanceId:"docs-site",subscriptionId:"public-access",productPlanName:"Public",productPlanType:"freemium",userId:"IBMid-ANONYMOUS"}}</script>
<script src="//1.www.s81c.com/common/stats/ibm-common.js" async="true"></script>
<link rel="stylesheet" href="https://fonts.googleapis.com/css2?family=Geist:wght@300;400;500;600;700&amp;family=Geist+Mono:wght@400;500&amp;family=Sora:wght@550;600&amp;display=swap">
<script>function gtag(){dataLayer.push(arguments)}window.dataLayer=window.dataLayer||[],gtag("consent","default",{ad_storage:"denied",ad_user_data:"denied",ad_personalization:"denied",analytics_storage:"denied"})</script>
<script>!function(){function e(){if(void 0!==window.truste&&window.truste.cma){var e=window.truste.cma.callApi("getConsent",window.location.href)||{},n=1===e[2],t=1===e[3];gtag("consent","update",{ad_storage:n?"granted":"denied",ad_user_data:n?"granted":"denied",ad_personalization:n?"granted":"denied",analytics_storage:t?"granted":"denied"})}}window.addEventListener&&(window.addEventListener("cm_data_subject_consent_changed",e),window.addEventListener("cm_consent_preferences_set",e)),"complete"===document.readyState?e():window.addEventListener("load",e)}()</script><link rel="stylesheet" href="/assets/css/styles.d29a2eb4.css">
<script src="/assets/js/runtime~main.6cbdbac2.js" defer="defer"></script>
<script src="/assets/js/main.18ca0898.js" defer="defer"></script>
</head>
<body class="navigation-with-keyboard">
<svg style="display: none;"><defs>
<symbol id="theme-svg-external-link" viewBox="0 0 24 24"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"/></symbol>
</defs></svg>
<script>!function(){var t=function(){try{return new URLSearchParams(window.location.search).get("docusaurus-theme")}catch(t){}}()||function(){try{return window.localStorage.getItem("theme")}catch(t){}}();document.documentElement.setAttribute("data-theme",t||(window.matchMedia("(prefers-color-scheme: dark)").matches?"dark":"light")),document.documentElement.setAttribute("data-theme-choice",t||"system")}(),function(){try{const c=new URLSearchParams(window.location.search).entries();for(var[t,e]of c)if(t.startsWith("docusaurus-data-")){var a=t.replace("docusaurus-data-","data-");document.documentElement.setAttribute(a,e)}}catch(t){}}()</script><div id="__docusaurus"><div role="region" aria-label="Skip to main content"><a class="skipToContent_fXgn" href="#__docusaurus_skipToContent_fallback">Skip to main content</a></div><nav aria-label="Main" class="theme-layout-navbar navbar navbar--fixed-top"><div class="navbar__inner"><div class="theme-layout-navbar-left navbar__items"><button aria-label="Toggle navigation bar" aria-expanded="false" class="navbar__toggle clean-btn" type="button"><svg width="30" height="30" viewBox="0 0 30 30" aria-hidden="true"><path stroke="currentColor" stroke-linecap="round" stroke-miterlimit="10" stroke-width="2" d="M4 7h22M4 15h22M4 23h22"></path></svg></button><a class="navbar__brand" href="/"><div class="navbar__logo"><img src="/img/lf-docs-light.svg" alt="Langflow" class="themedComponent_mlkZ themedComponent--light_NVdE"><img src="/img/lf-docs-dark.svg" alt="Langflow" class="themedComponent_mlkZ themedComponent--dark_xIcU"></div></a><div class="navbar__item dropdown dropdown--hoverable"><a aria-current="page" class="navbar__link active" aria-haspopup="true" aria-expanded="false" role="button" href="/api-keys-and-authentication">1.9.x</a><ul class="dropdown__menu"><li><a class="dropdown__link" href="/next/api-keys-and-authentication">1.10.x (Next)</a></li><li><a aria-current="page" class="dropdown__link dropdown__link--active" href="/api-keys-and-authentication">1.9.x</a></li><li><a class="dropdown__link" href="/1.8.0/api-keys-and-authentication">1.8.x</a></li></ul></div></div><div class="theme-layout-navbar-right navbar__items navbar__items--right"><a href="https://github.com/langflow-ai/langflow" target="_blank" class="navbar__item navbar__link header-github-link" aria-label="GitHub" data-event="UI Interaction" data-action="clicked" data-channel="docs" data-element-id="social-github" data-namespace="header" data-platform-title="Langflow"></a><a href="https://twitter.com/langflow_ai" target="_blank" class="navbar__item navbar__link header-twitter-link" aria-label="Twitter" data-event="UI Interaction" data-action="clicked" data-channel="docs" data-element-id="social-twitter" data-namespace="header" data-platform-title="Langflow"></a><a href="https://discord.gg/EqksyE2EX9" target="_blank" class="navbar__item navbar__link header-discord-link" aria-label="Discord" data-event="UI Interaction" data-action="clicked" data-channel="docs" data-element-id="social-discord" data-namespace="header" data-platform-title="Langflow"></a><div class="toggle_MW0i colorModeToggle_DEke"><button class="clean-btn toggleButton_yw5v toggleButtonDisabled_BJd7" type="button" disabled="" title="system mode" aria-label="Switch between dark and light mode (currently system mode)"><svg viewBox="0 0 24 24" width="24" height="24" aria-hidden="true" focusable="false" role="presentation" class="toggleIcon_oIOL lightToggleIcon_SFTY"><path fill="currentColor" d="M12,9c1.65,0,3,1.35,3,3s-1.35,3-3,3s-3-1.35-3-3S10.35,9,12,9 M12,7c-2.76,0-5,2.24-5,5s2.24,5,5,5s5-2.24,5-5 S14.76,7,12,7L12,7z M2,13l2,0c0.55,0,1-0.45,1-1s-0.45-1-1-1l-2,0c-0.55,0-1,0.45-1,1S1.45,13,2,13z M20,13l2,0c0.55,0,1-0.45,1-1 s-0.45-1-1-1l-2,0c-0.55,0-1,0.45-1,1S19.45,13,20,13z M11,2v2c0,0.55,0.45,1,1,1s1-0.45,1-1V2c0-0.55-0.45-1-1-1S11,1.45,11,2z M11,20v2c0,0.55,0.45,1,1,1s1-0.45,1-1v-2c0-0.55-0.45-1-1-1C11.45,19,11,19.45,11,20z M5.99,4.58c-0.39-0.39-1.03-0.39-1.41,0 c-0.39,0.39-0.39,1.03,0,1.41l1.06,1.06c0.39,0.39,1.03,0.39,1.41,0s0.39-1.03,0-1.41L5.99,4.58z M18.36,16.95 c-0.39-0.39-1.03-0.39-1.41,0c-0.39,0.39-0.39,1.03,0,1.41l1.06,1.06c0.39,0.39,1.03,0.39,1.41,0c0.39-0.39,0.39-1.03,0-1.41 L18.36,16.95z M19.42,5.99c0.39-0.39,0.39-1.03,0-1.41c-0.39-0.39-1.03-0.39-1.41,0l-1.06,1.06c-0.39,0.39-0.39,1.03,0,1.41 s1.03,0.39,1.41,0L19.42,5.99z M7.05,18.36c0.39-0.39,0.39-1.03,0-1.41c-0.39-0.39-1.03-0.39-1.41,0l-1.06,1.06 c-0.39,0.39-0.39,1.03,0,1.41s1.03,0.39,1.41,0L7.05,18.36z"></path></svg><svg viewBox="0 0 24 24" width="24" height="24" aria-hidden="true" focusable="false" role="presentation" class="toggleIcon_oIOL darkToggleIcon_ekgs"><path fill="currentColor" d="M9.37,5.51C9.19,6.15,9.1,6.82,9.1,7.5c0,4.08,3.32,7.4,7.4,7.4c0.68,0,1.35-0.09,1.99-0.27C17.45,17.19,14.93,19,12,19 c-3.86,0-7-3.14-7-7C5,9.07,6.81,6.55,9.37,5.51z M12,3c-4.97,0-9,4.03-9,9s4.03,9,9,9s9-4.03,9-9c0-0.46-0.04-0.92-0.1-1.36 c-0.98,1.37-2.58,2.26-4.4,2.26c-2.98,0-5.4-2.42-5.4-5.4c0-1.81,0.89-3.42,2.26-4.4C12.92,3.04,12.46,3,12,3L12,3z"></path></svg><svg viewBox="0 0 24 24" width="24" height="24" aria-hidden="true" focusable="false" role="presentation" class="toggleIcon_oIOL systemToggleIcon_yi_a"><path fill="currentColor" d="m12 21c4.971 0 9-4.029 9-9s-4.029-9-9-9-9 4.029-9 9 4.029 9 9 9zm4.95-13.95c1.313 1.313 2.05 3.093 2.05 4.95s-0.738 3.637-2.05 4.95c-1.313 1.313-3.093 2.05-4.95 2.05v-14c1.857 0 3.637 0.737 4.95 2.05z"></path></svg></button></div><div class="navbarSearchContainer_Bca1"><button type="button" class="DocSearch DocSearch-Button" aria-label="Search (Meta+k)" aria-keyshortcuts="Meta+k"><span class="DocSearch-Button-Container"><svg width="20" height="20" class="DocSearch-Search-Icon" viewBox="0 0 24 24" aria-hidden="true"><circle cx="11" cy="11" r="8" stroke="currentColor" fill="none" stroke-width="1.4"></circle><path d="m21 21-4.3-4.3" stroke="currentColor" fill="none" stroke-linecap="round" stroke-linejoin="round"></path></svg><span class="DocSearch-Button-Placeholder">Search</span></span><span class="DocSearch-Button-Keys"></span></button></div></div></div><div role="presentation" class="navbar-sidebar__backdrop"></div></nav><div id="__docusaurus_skipToContent_fallback" class="theme-layout-main main-wrapper mainWrapper_z2l0"><div class="docsWrapper_hBAB"><button aria-label="Scroll back to top" class="clean-btn theme-back-to-top-button backToTopButton_sjWU" type="button"></button><div class="docRoot_UBD9"><aside aria-label="Documentation sidebar" class="theme-doc-sidebar-container docSidebarContainer_RSuS"><div class="sidebarViewport_pYEE"><div class="sidebar_njMd"><nav aria-label="Docs sidebar" class="menu thin-scrollbar menu_SIkG"><ul class="theme-doc-sidebar-menu menu__list"><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-1 sidebar-group-divider"><div class="sidebar-group-label">Build</div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed sidebar-category-with-icon sidebar-icon-rocket"><div class="menu__list-item-collapsible"><a class="categoryLink_byQd menu__link menu__link--sublist menu__link--sublist-caret" role="button" aria-expanded="false" href="/"><span title="Get started" class="categoryLinkLabel_W154">Get started</span></a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed sidebar-category-with-icon sidebar-icon-workflow"><div class="menu__list-item-collapsible"><a class="categoryLink_byQd menu__link menu__link--sublist menu__link--sublist-caret" role="button" aria-expanded="false" href="/concepts-overview"><span title="Flows" class="categoryLinkLabel_W154">Flows</span></a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed sidebar-category-with-icon sidebar-icon-bot"><div class="menu__list-item-collapsible"><a class="categoryLink_byQd menu__link menu__link--sublist menu__link--sublist-caret" role="button" aria-expanded="false" href="/agents"><span title="Agents" class="categoryLinkLabel_W154">Agents</span></a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed sidebar-category-with-icon sidebar-icon-plug"><div class="menu__list-item-collapsible"><a class="categoryLink_byQd menu__link menu__link--sublist menu__link--sublist-caret" role="button" aria-expanded="false" href="/mcp-client"><span title="Model Context Protocol (MCP)" class="categoryLinkLabel_W154">Model Context Protocol (MCP)</span></a></div></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-1 sidebar-group-divider"><div class="sidebar-group-label">Develop & Deploy</div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item sidebar-category-with-icon sidebar-icon-code"><div class="menu__list-item-collapsible"><a class="categoryLink_byQd menu__link menu__link--sublist menu__link--sublist-caret menu__link--active" role="button" aria-expanded="true" href="/api-keys-and-authentication"><span title="Develop" class="categoryLinkLabel_W154">Develop</span></a></div><ul class="menu__list"><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link menu__link--active" aria-current="page" tabindex="0" href="/api-keys-and-authentication"><span title="API keys and authentication" class="linkLabel_WmDU">API keys and authentication</span></a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/jwt-authentication"><span title="JWT authentication" class="linkLabel_WmDU">JWT authentication</span></a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/install-custom-dependencies"><span title="Install custom dependencies" class="linkLabel_WmDU">Install custom dependencies</span></a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/configuration-global-variables"><span title="Global variables" class="linkLabel_WmDU">Global variables</span></a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/environment-variables"><span title="Environment variables" class="linkLabel_WmDU">Environment variables</span></a></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="categoryLink_byQd menu__link menu__link--sublist menu__link--sublist-caret" role="button" aria-expanded="false" tabindex="0" href="/concepts-file-management"><span title="Storage and memory" class="categoryLinkLabel_W154">Storage and memory</span></a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="categoryLink_byQd menu__link menu__link--sublist menu__link--sublist-caret" role="button" aria-expanded="false" tabindex="0" href="/logging"><span title="Observability" class="categoryLinkLabel_W154">Observability</span></a></div></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/data-types"><span title="Use Langflow data types" class="linkLabel_WmDU">Use Langflow data types</span></a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/concepts-voice-mode"><span title="Use voice mode" class="linkLabel_WmDU">Use voice mode</span></a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/configuration-cli"><span title="Use the Langflow CLI" class="linkLabel_WmDU">Use the Langflow CLI</span></a></li></ul></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed sidebar-category-with-icon sidebar-icon-cloud"><div class="menu__list-item-collapsible"><a class="categoryLink_byQd menu__link menu__link--sublist menu__link--sublist-caret" role="button" aria-expanded="false" href="/deployment-overview"><span title="Deploy" class="categoryLinkLabel_W154">Deploy</span></a></div></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-1 sidebar-group-divider"><div class="sidebar-group-label">Reference</div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed sidebar-category-with-icon sidebar-icon-blocks"><div class="menu__list-item-collapsible"><a class="categoryLink_byQd menu__link menu__link--sublist menu__link--sublist-caret" role="button" aria-expanded="false" href="/concepts-components"><span title="Components reference" class="categoryLinkLabel_W154">Components reference</span></a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed sidebar-category-with-icon sidebar-icon-fileCode"><div class="menu__list-item-collapsible"><a class="categoryLink_byQd menu__link menu__link--sublist menu__link--sublist-caret" role="button" aria-expanded="false" href="/api-reference-api-examples"><span title="API reference" class="categoryLinkLabel_W154">API reference</span></a></div></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-1 sidebar-group-divider"><div class="sidebar-group-label">Community</div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed sidebar-category-with-icon sidebar-icon-gitPR"><div class="menu__list-item-collapsible"><a class="categoryLink_byQd menu__link menu__link--sublist menu__link--sublist-caret" role="button" aria-expanded="false" href="/contributing-community"><span title="Contribute" class="categoryLinkLabel_W154">Contribute</span></a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed sidebar-category-with-icon sidebar-icon-helpCircle"><div class="menu__list-item-collapsible"><a class="categoryLink_byQd menu__link menu__link--sublist menu__link--sublist-caret" role="button" aria-expanded="false" href="/troubleshoot"><span title="Support" class="categoryLinkLabel_W154">Support</span></a></div></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-1 sidebar-ad">
<a href="https://www.langflow.org/desktop" target="_blank" rel="noopener noreferrer" class="menu__link">
<svg width="18" height="18" viewBox="0 0 24 24" fill="none" xmlns="http://www.w3.org/2000/svg" aria-hidden="true">
<g clip-path="url(#clip0_1645_37)">
<path d="M12 17H20C21.1046 17 22 16.1046 22 15V13M12 17H4C2.89543 17 2 16.1046 2 15V5C2 3.89543 2.89543 3 4 3H10M12 17V21M8 21H12M12 21H16M11.75 10.2917H13.2083L16.125 7.375H17.5833L20.5 4.45833H21.9583M16.125 11.75H17.5833L20.5 8.83333H21.9583M11.75 5.91667H13.2083L16.125 3H17.5833" stroke="currentColor" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/>
</g>
<defs>
<clipPath id="clip0_1645_37">
<rect width="24" height="24" fill="white"/>
</clipPath>
</defs>
</svg>
<div class="sidebar-ad-text-container">
<span class="sidebar-ad-text">Get started in minutes</span>
<span class="sidebar-ad-text sidebar-ad-text-gradient">Download Langflow Desktop</span>
</div>
</a>
</li></ul></nav></div></div></aside><main class="docMainContainer_TBSr"><div class="container padding-top--md padding-bottom--lg"><div class="row"><div class="col docItemCol_z5aJ"><div class="docItemContainer_c0TR"><article><nav class="theme-doc-breadcrumbs breadcrumbsContainer_Z_bl" aria-label="Breadcrumbs"><ul class="breadcrumbs"><li class="breadcrumbs__item"><a aria-label="Home page" class="breadcrumbs__link" href="/"><svg viewBox="0 0 24 24" aria-hidden="true" focusable="false" role="presentation" class="breadcrumbHomeIcon_xK9p"><path d="M10 19v-5h4v5c0 .55.45 1 1 1h3c.55 0 1-.45 1-1v-7h1.7c.46 0 .68-.57.33-.87L12.67 3.6c-.38-.34-.96-.34-1.34 0l-8.36 7.53c-.34.3-.13.87.33.87H5v7c0 .55.45 1 1 1h3c.55 0 1-.45 1-1z" fill="currentColor"></path></svg></a></li><li class="breadcrumbs__item"><span class="breadcrumbs__link">Develop</span></li><li class="breadcrumbs__item breadcrumbs__item--active"><span class="breadcrumbs__link">API keys and authentication</span></li></ul></nav><div class="docMetaRow_c2hx"><div class="root_Eutc"><button type="button" class="button_gpNY"><span aria-hidden="true" class="icon_Bm9L"><svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-copy"><rect width="14" height="14" x="8" y="8" rx="2" ry="2"></rect><path d="M4 16c-1.1 0-2-.9-2-2V4c0-1.1.9-2 2-2h10c1.1 0 2 .9 2 2"></path></svg></span><span class="label_LzDG">Copy page</span></button></div><span class="theme-doc-version-badge badge badge--secondary">Version: 1.9.x</span></div><div class="tocCollapsible_ETCw theme-doc-toc-mobile tocMobile_ITEo"><button type="button" class="clean-btn tocCollapsibleButton_TO0P">On this page</button></div><div class="theme-doc-markdown markdown"><header><h1>API keys and authentication</h1></header><style>[data-ch-theme="github-dark"] { --ch-t-colorScheme: dark;--ch-t-foreground: #c9d1d9;--ch-t-background: #0d1117;--ch-t-lighter-inlineBackground: #0d1117e6;--ch-t-editor-background: #0d1117;--ch-t-editor-foreground: #c9d1d9;--ch-t-editor-lineHighlightBackground: #6e76811a;--ch-t-editor-rangeHighlightBackground: #ffffff0b;--ch-t-editor-infoForeground: #3794FF;--ch-t-editor-selectionBackground: #264F78;--ch-t-focusBorder: #1f6feb;--ch-t-tab-activeBackground: #0d1117;--ch-t-tab-activeForeground: #c9d1d9;--ch-t-tab-inactiveBackground: #010409;--ch-t-tab-inactiveForeground: #8b949e;--ch-t-tab-border: #30363d;--ch-t-tab-activeBorder: #0d1117;--ch-t-editorGroup-border: #30363d;--ch-t-editorGroupHeader-tabsBackground: #010409;--ch-t-editorLineNumber-foreground: #6e7681;--ch-t-input-background: #0d1117;--ch-t-input-foreground: #c9d1d9;--ch-t-input-border: #30363d;--ch-t-icon-foreground: #8b949e;--ch-t-sideBar-background: #010409;--ch-t-sideBar-foreground: #c9d1d9;--ch-t-sideBar-border: #30363d;--ch-t-list-activeSelectionBackground: #6e768166;--ch-t-list-activeSelectionForeground: #c9d1d9;--ch-t-list-hoverBackground: #6e76811a;--ch-t-list-hoverForeground: #c9d1d9; }</style>
<!-- -->
<div class="theme-admonition theme-admonition-warning admonition_xJq3 alert alert--warning"><div class="admonitionHeading_Gvgb"><span class="admonitionIcon_Rf37"><svg viewBox="0 0 16 16"><path fill-rule="evenodd" d="M8.893 1.5c-.183-.31-.52-.5-.887-.5s-.703.19-.886.5L.138 13.499a.98.98 0 0 0 0 1.001c.193.31.53.501.886.501h13.964c.367 0 .704-.19.877-.5a1.03 1.03 0 0 0 .01-1.002L8.893 1.5zm.133 11.497H6.987v-2.003h2.039v2.003zm0-3.004H6.987V5.987h2.039v4.006z"></path></svg></span>warning</div><div class="admonitionContent_BuS1"><p>Never expose Langflow ports directly to the internet without proper security measures.
Set <code>LANGFLOW_AUTO_LOGIN=False</code>, use a non-default <code>LANGFLOW_SECRET_KEY</code>, and deploy your Langflow server behind a reverse proxy with authentication enabled.
For more information, see <a href="#start-a-langflow-server-with-authentication-enabled" class="">Start a Langflow server with authentication enabled</a>.</p></div></div>
<p>Authentication credentials help prevent unauthorized access to your Langflow server, flows, and services connected through components.</p>
<p>There are three types of credentials that you use in Langflow:</p>
<ul>
<li class=""><a href="#langflow-api-keys" class="">Langflow API keys</a>: For authentication with the Langflow API and authorizing server-side Langflow actions like running flows and uploading files.</li>
<li class=""><a href="#component-api-keys" class="">Component API keys</a>: For authentication between Langflow and a service connected through a component, such as a model provider or third-party API.</li>
<li class=""><a href="#authentication-environment-variables" class="">Authentication environment variables</a>: These environment variables configure how Langflow handles user authentication and authorization.</li>
</ul>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="langflow-api-keys">Langflow API keys<a href="#langflow-api-keys" class="hash-link" aria-label="Direct link to Langflow API keys" title="Direct link to Langflow API keys" translate="no"></a></h2>
<p>You can use Langflow API keys to interact with Langflow programmatically.</p>
<p>By default, most Langflow API endpoints, such as <code>/v1/run/$FLOW_ID</code>, require authentication with a Langflow API key.</p>
<p>Langflow validates API keys against keys stored in the database, but you can configure Langflow to validate API keys against an environment variable instead.
For more information, see <a href="#langflow-api-key-source" class=""><code>LANGFLOW_API_KEY_SOURCE</code></a>.</p>
<p>To require API key authentication for flow webhook endpoints, use the <a class="" href="/webhook#require-authentication-for-webhooks"><code>LANGFLOW_WEBHOOK_AUTH_ENABLE</code></a> environment variable.
To configure authentication for Langflow MCP servers, see <a class="" href="/mcp-server">Use Langflow as an MCP server</a>.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="langflow-api-key-permissions">Langflow API key permissions<a href="#langflow-api-key-permissions" class="hash-link" aria-label="Direct link to Langflow API key permissions" title="Direct link to Langflow API key permissions" translate="no"></a></h3>
<p>A Langflow API key adopts the privileges of the user who created it.
This means that API keys you create have the same permissions and access that you do, including access to your flows, components, and Langflow database.
A Langflow API key cannot be used to access resources outside of your own Langflow server.</p>
<p>In single-user environments, you are always a superuser, and your Langflow API keys always have superuser privileges.</p>
<p>In multi-user environments, users who aren&#x27;t superusers cannot use their API keys to access other users&#x27; resources.
Superusers can only run their own flows, and cannot run flows owned by other users.
You must <a href="#start-a-langflow-server-with-authentication-enabled" class="">start your Langflow server with authentication enabled</a> to allow superusers to manage users and create non-superuser accounts.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="create-a-langflow-api-key">Create a Langflow API key<a href="#create-a-langflow-api-key" class="hash-link" aria-label="Direct link to Create a Langflow API key" title="Direct link to Create a Langflow API key" translate="no"></a></h3>
<p>You can generate a Langflow API key in your Langflow <strong>Settings</strong> or with the Langflow CLI.</p>
<p>The CLI option is required if your Langflow server is running in <code>--backend-only</code> mode.</p>
<div class="theme-tabs-container tabs-container tabList__CuJ"><ul role="tablist" aria-orientation="horizontal" class="tabs"><li role="tab" tabindex="0" aria-selected="true" class="tabs__item tabItem_LNqP tabs__item--active">Langflow Settings</li><li role="tab" tabindex="-1" aria-selected="false" class="tabs__item tabItem_LNqP">Langflow CLI</li></ul><div class="margin-top--md"><div role="tabpanel" class="tabItem_Ymn6"><ol>
<li class="">In the Langflow header, click your profile icon, and then select <strong>Settings</strong>.</li>
<li class="">Click <strong>Langflow API Keys</strong>, and then click <strong>Add New</strong>.</li>
<li class="">Name your key, and then click <strong>Create API Key</strong>.</li>
<li class="">Copy the API key and store it securely.</li>
</ol></div><div role="tabpanel" class="tabItem_Ymn6" hidden=""><p>If you&#x27;re serving your flow with <code>--backend-only=true</code>, you can&#x27;t create API keys in your Langflow <strong>Settings</strong> because the frontend isn&#x27;t running.
In this case, you must create API keys with the Langflow CLI.</p><ol>
<li class="">
<p>Recommended: <a href="#start-a-langflow-server-with-authentication-enabled" class="">Start your Langflow server with authentication enabled</a>.</p>
<p>The Langflow team recommends enabling authentication for security reasons to prevent unauthorized creation of API keys and superusers, especially in production environments.
If authentication isn&#x27;t enabled (<code>LANGFLOW_AUTO_LOGIN=True</code>), all users are effectively superusers, and they can create API keys with the Langflow CLI.</p>
</li>
<li class="">
<p>Create an API key with <a class="" href="/configuration-cli#langflow-api-key"><code>langflow api-key</code></a>:</p>
<div class="ch-codeblock not-prose" data-ch-theme="github-dark"><div class="ch-code-wrapper ch-code" data-ch-measured="false"><code class="ch-code-scroll-parent"><br><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>uv run langflow api-key</span></div></div><br></code></div></div>
<p>All API keys created with the Langflow CLI have superuser privileges because the command requires superuser authentication, and Langflow API keys adopt the privileges of the user who created them.</p>
</li>
</ol></div></div></div>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="use-a-langflow-api-key">Use a Langflow API key<a href="#use-a-langflow-api-key" class="hash-link" aria-label="Direct link to Use a Langflow API key" title="Direct link to Use a Langflow API key" translate="no"></a></h3>
<p>To authenticate Langflow API requests, pass your Langflow API key an <code>x-api-key</code> header or query parameter.</p>
<div class="theme-tabs-container tabs-container tabList__CuJ"><ul role="tablist" aria-orientation="horizontal" class="tabs"><li role="tab" tabindex="0" aria-selected="true" class="tabs__item tabItem_LNqP tabs__item--active">HTTP header</li><li role="tab" tabindex="-1" aria-selected="false" class="tabs__item tabItem_LNqP">Query parameter</li></ul><div class="margin-top--md"><div role="tabpanel" class="tabItem_Ymn6"><div class="ch-codeblock not-prose" data-ch-theme="github-dark"><div class="ch-code-wrapper ch-code" data-ch-measured="false"><code class="ch-code-scroll-parent"><br><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>curl -X POST \</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span> &quot;http://$LANGFLOW_SERVER_ADDRESS/api/v1/run/$FLOW_ID?stream=false&quot; \</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span> -H &quot;Content-Type: application/json&quot; \</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span> -H &quot;x-api-key: $LANGFLOW_API_KEY&quot; \</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span> -d &#x27;{&quot;inputs&quot;: {&quot;text&quot;:&quot;&quot;}, &quot;tweaks&quot;: {}}&#x27;</span></div></div><br></code></div></div></div><div role="tabpanel" class="tabItem_Ymn6" hidden=""><div class="ch-codeblock not-prose" data-ch-theme="github-dark"><div class="ch-code-wrapper ch-code" data-ch-measured="false"><code class="ch-code-scroll-parent"><br><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>curl -X POST \</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span> &quot;http://$LANGFLOW_SERVER_ADDRESS/api/v1/run/$FLOW_ID?x-api-key=$LANGFLOW_API_KEY&quot; \</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span> -H &quot;Content-Type: application/json&quot; \</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span> -d &#x27;{&quot;inputs&quot;: {&quot;text&quot;:&quot;&quot;}, &quot;tweaks&quot;: {}}&#x27;</span></div></div><br></code></div></div></div></div></div>
<p>For more information about forming Langflow API requests, see <a class="" href="/api-reference-api-examples">Get started with the Langflow API</a> and <a class="" href="/concepts-publish">Trigger flows with the Langflow API</a>.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="track-api-key-usage">Track API key usage<a href="#track-api-key-usage" class="hash-link" aria-label="Direct link to Track API key usage" title="Direct link to Track API key usage" translate="no"></a></h3>
<p>By default, Langflow tracks API key usage through <code>total_uses</code> and <code>last_used_at</code> records in your <a class="" href="/memory">Langflow database</a>.</p>
<p>To disable API key tracking, set <code>LANGFLOW_DISABLE_TRACK_APIKEY_USAGE=True</code> in your <a class="" href="/environment-variables">Langflow environment variables</a>.
This can help avoid database contention during periods of high concurrency.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="revoke-an-api-key">Revoke an API key<a href="#revoke-an-api-key" class="hash-link" aria-label="Direct link to Revoke an API key" title="Direct link to Revoke an API key" translate="no"></a></h3>
<p>To revoke and delete an API key, do the following:</p>
<ol>
<li class="">In the Langflow header, click your profile icon, and then select <strong>Settings</strong>.</li>
<li class="">Click <strong>Langflow API Keys</strong>.</li>
<li class="">Select the keys you want to delete, and then click <svg xmlns="http://www.w3.org/2000/svg" width="16" height="16" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-trash2 lf-inline-icon" aria-hidden="true" focusable="false" role="presentation"><path d="M3 6h18"></path><path d="M19 6v14c0 1-1 2-2 2H7c-1 0-2-1-2-2V6"></path><path d="M8 6V4c0-1 1-2 2-2h4c1 0 2 1 2 2v2"></path><line x1="10" x2="10" y1="11" y2="17"></line><line x1="14" x2="14" y1="11" y2="17"></line></svg> <strong>Delete</strong>.</li>
</ol>
<p>This action immediately invalidates the key and prevents it from being used again.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="component-api-keys">Component API keys<a href="#component-api-keys" class="hash-link" aria-label="Direct link to Component API keys" title="Direct link to Component API keys" translate="no"></a></h2>
<p>Component API keys authorize access to external services that are called by components in your flows, such as model providers, databases, or third-party APIs.
These aren&#x27;t Langflow API keys or general application credentials.</p>
<p>In Langflow, you can store component API keys in global variables in your <strong>Settings</strong> or import them from your runtime environment.
For more information, see <a class="" href="/configuration-global-variables">Global variables</a>.</p>
<p>You create and manage component API keys within the service provider&#x27;s platform.
Langflow only stores the encrypted key value or a secure reference to a key stored elsewhere; it doesn&#x27;t manage the actual credentials at the source.
This means that deleting a global variable from Langflow doesn&#x27;t delete or invalidate the actual API key in the service provider&#x27;s system.
You must delete or rotate component API keys directly using the service provider&#x27;s interface or API.</p>
<p>For added security, you can set <code>LANGFLOW_REMOVE_API_KEYS=True</code> to omit API keys and tokens from flow data in your <a class="" href="/memory">Langflow database</a>.
Additionally, when <a class="" href="/concepts-flows-import">exporting flows</a>, you can choose to omit API keys from the exported flow JSON.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="authentication-environment-variables">Authentication environment variables<a href="#authentication-environment-variables" class="hash-link" aria-label="Direct link to Authentication environment variables" title="Direct link to Authentication environment variables" translate="no"></a></h2>
<p>This section describes the available authentication configuration variables.</p>
<p>You can use the <a href="https://github.com/langflow-ai/langflow/blob/main/.env.example" target="_blank" rel="noopener noreferrer" class=""><code>.env.example</code></a> file in the Langflow repository as a template for your own <code>.env</code> file.</p>
<p>For JWT authentication configuration, including algorithm selection and key management, see <a class="" href="/jwt-authentication">JWT authentication</a>.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="langflow-auto-login">LANGFLOW_AUTO_LOGIN<a href="#langflow-auto-login" class="hash-link" aria-label="Direct link to LANGFLOW_AUTO_LOGIN" title="Direct link to LANGFLOW_AUTO_LOGIN" translate="no"></a></h3>
<p>This variable controls whether authentication is required to access your Langflow server, including the visual editor, API, and Langflow CLI:</p>
<ul>
<li class="">
<p>If <code>LANGFLOW_AUTO_LOGIN=False</code>, automatic login is disabled. Users must sign in to the visual editor, authenticate as a superuser to run certain Langflow CLI commands, and use a Langflow API key for Langflow API requests.
If <code>false</code>, the Langflow team recommends that you also explicitly set <a href="#langflow-superuser" class=""><code>LANGFLOW_SUPERUSER</code> and <code>LANGFLOW_SUPERUSER_PASSWORD</code></a> to avoid using the insecure default values.</p>
</li>
<li class="">
<p>If <code>LANGFLOW_AUTO_LOGIN=True</code> (default), all API requests require authentication with a Langflow API key, but the visual editor automatically signs in all users as superusers, and Langflow uses <em>only</em> the default <a class="" href="/api-keys-and-authentication#langflow-superuser">superuser credentials</a>.
All users access the same visual editor environment without password protection, they can run all Langflow CLI commands as superusers, and Langflow automatically authenticates internal requests between the backend and frontend based on the users&#x27; superuser privileges.
If you also want to bypass authentication for Langflow API requests in addition to other bypassed authentication, see <a class="" href="/api-keys-and-authentication#langflow-skip-auth-auto-login"><code>LANGFLOW_SKIP_AUTH_AUTO_LOGIN</code></a>.</p>
</li>
</ul>
<p>Langflow doesn&#x27;t allow users to simultaneously edit the same flow in real time.
If two users edit the same flow, Langflow saves only the work of the most recent editor based on the state of that user&#x27;s <a class="" href="/concepts-overview#workspace">workspace</a>. Any changes made by the other user in the interim are overwritten.</p>
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="langflow-skip-auth-auto-login">Default authentication enforcement and LANGFLOW_SKIP_AUTH_AUTO_LOGIN<a href="#langflow-skip-auth-auto-login" class="hash-link" aria-label="Direct link to Default authentication enforcement and LANGFLOW_SKIP_AUTH_AUTO_LOGIN" title="Direct link to Default authentication enforcement and LANGFLOW_SKIP_AUTH_AUTO_LOGIN" translate="no"></a></h4>
<p>In Langflow version 1.6, the default settings are <code>LANGFLOW_AUTO_LOGIN=True</code> and <code>LANGFLOW_SKIP_AUTH_AUTO_LOGIN=False</code>.
This enforces authentication for API requests only, as explained in the preceding section.</p>
<p>For temporary backwards compatibility, you can revert to the fully unauthenticated behavior from earlier versions by setting both variables to <code>true</code>.
However, a future release will set <code>LANGFLOW_AUTO_LOGIN=False</code> and remove <code>LANGFLOW_SKIP_AUTH_AUTO_LOGIN</code>.
At that point, Langflow will strictly enforce API key authentication for API requests, and you can manually disable authentication for some features, like the visual editor, by setting <code>LANGFLOW_AUTO_LOGIN=True</code>.</p>
<details class="details_lb9f alert alert--info details_b_Ee" data-collapsed="true"><summary>Authentication enforcement in earlier versions</summary><div><div class="collapsibleContent_i85q"><p>Langflow version 1.5 was the first version that could enforce authentication for Langflow API requests, regardless of the value of <code>LANGFLOW_AUTO_LOGIN</code>.
As a temporary bypass for backwards compatibility, this version added the <code>LANGFLOW_SKIP_AUTH_AUTO_LOGIN</code> environment variable and set both variables to <code>true</code> by default to preserve the fully unauthenticated behavior from earlier versions.
This allowed users to upgrade to version 1.5 with no change in the authentication behavior.</p><p>In Langflow versions earlier than 1.5, Langflow API requests didn&#x27;t require authentication.
Additionally, the default setting of <code>LANGFLOW_AUTO_LOGIN=True</code> automatically granted all users superuser privileges in the visual editor, and it allowed all users to run all Langflow CLI commands as superusers.</p></div></div></details>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="langflow-enable-superuser-cli">LANGFLOW_ENABLE_SUPERUSER_CLI<a href="#langflow-enable-superuser-cli" class="hash-link" aria-label="Direct link to LANGFLOW_ENABLE_SUPERUSER_CLI" title="Direct link to LANGFLOW_ENABLE_SUPERUSER_CLI" translate="no"></a></h3>
<p>Controls the availability of the <code>langflow superuser</code> command in the Langflow CLI.
The default is <code>true</code>, but <code>false</code> is recommended to prevent unrestricted superuser creation.
For more information, see <a class="" href="/configuration-cli#langflow-superuser"><code>langflow superuser</code></a>.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="langflow-superuser">LANGFLOW_SUPERUSER and LANGFLOW_SUPERUSER_PASSWORD<a href="#langflow-superuser" class="hash-link" aria-label="Direct link to LANGFLOW_SUPERUSER and LANGFLOW_SUPERUSER_PASSWORD" title="Direct link to LANGFLOW_SUPERUSER and LANGFLOW_SUPERUSER_PASSWORD" translate="no"></a></h3>
<p>These variables specify the username and password for the Langflow server&#x27;s superuser.</p>
<div class="ch-codeblock not-prose" data-ch-theme="github-dark"><div class="ch-code-wrapper ch-code" data-ch-measured="false"><code class="ch-code-scroll-parent"><br><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>LANGFLOW_SUPERUSER=administrator</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>LANGFLOW_SUPERUSER_PASSWORD=securepassword</span></div></div><br></code></div></div>
<p>They are required if <code>LANGFLOW_AUTO_LOGIN=False</code>.
Otherwise, they aren&#x27;t relevant.</p>
<p>When you <a href="#start-a-langflow-server-with-authentication-enabled" class="">start a Langflow server with authentication enabled</a>, if these variables are required but <em>not</em> set, then Langflow uses the default values of <code>langflow</code> and <code>langflow</code>.
These defaults don&#x27;t apply when using the Langflow CLI command <a class="" href="/configuration-cli#langflow-superuser"><code>langflow superuser</code></a>.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="langflow-secret-key">LANGFLOW_SECRET_KEY<a href="#langflow-secret-key" class="hash-link" aria-label="Direct link to LANGFLOW_SECRET_KEY" title="Direct link to LANGFLOW_SECRET_KEY" translate="no"></a></h3>
<p>This environment variable stores a secret key used for encrypting sensitive data like API keys and for JWT signing when using the HS256 algorithm.
Langflow uses the <a href="https://pypi.org/project/cryptography/" target="_blank" rel="noopener noreferrer" class="">Fernet</a> library for secret key encryption.
For JWT-specific configuration, see <a class="" href="/jwt-authentication">JWT authentication</a>.</p>
<p>If no secret key is provided, Langflow automatically generates one.</p>
<p>However, you should generate and explicitly set your own key in production environments.
This is particularly important for multi-instance deployments like Kubernetes to ensure consistent encryption across instances.</p>
<p>To generate a secret encryption key for <code>LANGFLOW_SECRET_KEY</code>, do the following:</p>
<ol>
<li class="">
<p>Run the command to generate and copy a secret to the clipboard.</p>
<div class="theme-tabs-container tabs-container tabList__CuJ"><ul role="tablist" aria-orientation="horizontal" class="tabs"><li role="tab" tabindex="0" aria-selected="true" class="tabs__item tabItem_LNqP tabs__item--active">macOS or Linux</li><li role="tab" tabindex="-1" aria-selected="false" class="tabs__item tabItem_LNqP">Windows</li></ul><div class="margin-top--md"><div role="tabpanel" class="tabItem_Ymn6"><ul>
<li class="">
<p><strong>macOS</strong>: Generate a secret key and copy it to the clipboard:</p>
<div class="ch-codeblock not-prose" data-ch-theme="github-dark"><div class="ch-code-wrapper ch-code" data-ch-measured="false"><code class="ch-code-scroll-parent"><br><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>python3 -c &quot;from secrets import token_urlsafe; print(f&#x27;LANGFLOW_SECRET_KEY={token_urlsafe(32)}&#x27;)&quot; | pbcopy</span></div></div><br></code></div></div>
</li>
<li class="">
<p><strong>Linux</strong>: Generate a secret key and copy it to the clipboard:</p>
<div class="ch-codeblock not-prose" data-ch-theme="github-dark"><div class="ch-code-wrapper ch-code" data-ch-measured="false"><code class="ch-code-scroll-parent"><br><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>python3 -c &quot;from secrets import token_urlsafe; print(f&#x27;LANGFLOW_SECRET_KEY={token_urlsafe(32)}&#x27;)&quot; | xclip -selection clipboard</span></div></div><br></code></div></div>
</li>
<li class="">
<p><strong>Unix</strong>: Generate a secret key and print it to the terminal to manually copy it:</p>
<div class="ch-codeblock not-prose" data-ch-theme="github-dark"><div class="ch-code-wrapper ch-code" data-ch-measured="false"><code class="ch-code-scroll-parent"><br><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>python3 -c &quot;from secrets import token_urlsafe; print(f&#x27;LANGFLOW_SECRET_KEY={token_urlsafe(32)}&#x27;)&quot;</span></div></div><br></code></div></div>
</li>
</ul></div><div role="tabpanel" class="tabItem_Ymn6" hidden=""><ul>
<li class="">
<p>Generate a secret key and copy it to the clipboard:</p>
<div class="ch-codeblock not-prose" data-ch-theme="github-dark"><div class="ch-code-wrapper ch-code" data-ch-measured="false"><code class="ch-code-scroll-parent"><br><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>python -c &quot;from secrets import token_urlsafe; print(f&#x27;LANGFLOW_SECRET_KEY={token_urlsafe(32)}&#x27;)&quot;</span></div></div><br></code></div></div>
</li>
<li class="">
<p>Generate a secret key and print it to the terminal to manually copy it:</p>
<div class="ch-codeblock not-prose" data-ch-theme="github-dark"><div class="ch-code-wrapper ch-code" data-ch-measured="false"><code class="ch-code-scroll-parent"><br><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span></span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span># Or just print</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>python -c &quot;from secrets import token_urlsafe; print(f&#x27;LANGFLOW_SECRET_KEY={token_urlsafe(32)}&#x27;)&quot;</span></div></div><br></code></div></div>
</li>
</ul></div></div></div>
</li>
<li class="">
<p>Paste the value into your <code>.env</code> file:</p>
<div class="ch-codeblock not-prose" data-ch-theme="github-dark"><div class="ch-code-wrapper ch-code" data-ch-measured="false"><code class="ch-code-scroll-parent"><br><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>LANGFLOW_SECRET_KEY=dBuu...2kM2_fb</span></div></div><br></code></div></div>
<p>If you&#x27;re running Langflow on Docker, reference the <code>LANGFLOW_SECRET_KEY</code> from your <code>.env</code> file in the <code>docker-compose.yml</code> file like this:</p>
<div class="ch-codeblock not-prose" data-ch-theme="github-dark"><div class="ch-code-wrapper ch-code" data-ch-measured="false"><code class="ch-code-scroll-parent"><br><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>environment:</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span> - LANGFLOW_SECRET_KEY=${LANGFLOW_SECRET_KEY}</span></div></div><br></code></div></div>
</li>
</ol>
<h4 class="anchor anchorTargetStickyNavbar_Vzrq" id="rotating-the-secret-key">Rotate the secret key<a href="#rotating-the-secret-key" class="hash-link" aria-label="Direct link to Rotate the secret key" title="Direct link to Rotate the secret key" translate="no"></a></h4>
<p>Rotate <code>LANGFLOW_SECRET_KEY</code> if the key might have been compromised and as part of your routine credential management practices.
Langflow provides a migration script that re-encrypts stored credentials and other sensitive data with a new key so you can rotate without losing access.</p>
<p>For more information, see <a href="https://github.com/langflow-ai/langflow/blob/main/SECURITY.md#secret-key-rotation" target="_blank" rel="noopener noreferrer" class="">Secret Key Rotation</a> in the Langflow Security Policy.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="langflow-new-user-is-active">LANGFLOW_NEW_USER_IS_ACTIVE<a href="#langflow-new-user-is-active" class="hash-link" aria-label="Direct link to LANGFLOW_NEW_USER_IS_ACTIVE" title="Direct link to LANGFLOW_NEW_USER_IS_ACTIVE" translate="no"></a></h3>
<p>When <code>LANGFLOW_NEW_USER_IS_ACTIVE=False</code> (default), accounts created by superusers are inactive by default and must be explicitly activated before users can sign in to the visual editor.
The superuser can also deactivate a user&#x27;s account as needed.</p>
<p>When <code>LANGFLOW_NEW_USER_IS_ACTIVE=True</code>, accounts created by superusers are automatically activated.</p>
<div class="ch-codeblock not-prose" data-ch-theme="github-dark"><div class="ch-code-wrapper ch-code" data-ch-measured="false"><code class="ch-code-scroll-parent"><br><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>LANGFLOW_NEW_USER_IS_ACTIVE=False</span></div></div><br></code></div></div>
<p>Only superusers can manage user accounts for a Langflow server, but user management only matters if your server has authentication enabled.
For more information, see <a href="#start-a-langflow-server-with-authentication-enabled" class="">Start a Langflow server with authentication enabled</a>.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="langflow-api-key-source">LANGFLOW_API_KEY_SOURCE<a href="#langflow-api-key-source" class="hash-link" aria-label="Direct link to LANGFLOW_API_KEY_SOURCE" title="Direct link to LANGFLOW_API_KEY_SOURCE" translate="no"></a></h3>
<p>This variable controls how Langflow validates API keys.</p>
<table><thead><tr><th>Value</th><th>Description</th></tr></thead><tbody><tr><td><code>db</code> (default)</td><td>Validates API keys against <a href="#langflow-api-keys" class="">Langflow API keys</a> stored in the database. This is the standard behavior where users create and manage API keys through the Langflow UI or CLI.</td></tr><tr><td><code>env</code></td><td>Validates API keys against the <code>LANGFLOW_API_KEY</code> environment variable. Useful for Kubernetes deployments, CI/CD pipelines, or any environment where you want to inject a pre-defined API key without database configuration.</td></tr></tbody></table>
<p>By default, Langflow validates the <code>x-api-key</code> header against the Langflow database with <code>LANGFLOW_API_KEY_SOURCE=db</code>.
When using database-based validation, you can create multiple keys with per-user permissions, track usage, and manage keys through the Langflow UI or CLI.</p>
<p>When <code>LANGFLOW_API_KEY_SOURCE=env</code>, Langflow validates the <code>x-api-key</code> header against the value of the <code>LANGFLOW_API_KEY</code> environment variable.
This means Langflow runs securely in stateless environments, such as with LFX or Kubernetes secrets.</p>
<p>When <code>LANGFLOW_API_KEY_SOURCE=env</code>, only a single API key can be used for the deployment. All authenticated requests use the same API key, and successful authentication grants superuser privileges.
This mode is designed for single-tenant deployments or automated systems, not multi-user environments where different users need different access levels. To rotate your keys, update the environment variable and restart the Langflow server.</p>
<p>To enable environment-based API key validation:</p>
<ol>
<li class="">
<p>In the Langflow <code>.env</code> file, set the API key source to <code>env</code>:</p>
<div class="ch-codeblock not-prose" data-ch-theme="github-dark"><div class="ch-code-wrapper ch-code" data-ch-measured="false"><code class="ch-code-scroll-parent"><br><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>LANGFLOW_API_KEY_SOURCE=env</span></div></div><br></code></div></div>
</li>
<li class="">
<p>In the Langflow <code>.env</code> file, set the API key value:</p>
<div class="ch-codeblock not-prose" data-ch-theme="github-dark"><div class="ch-code-wrapper ch-code" data-ch-measured="false"><code class="ch-code-scroll-parent"><br><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>LANGFLOW_API_KEY=your-secure-api-key</span></div></div><br></code></div></div>
</li>
<li class="">
<p>Use the API key in your requests:</p>
<div class="ch-codeblock not-prose" data-ch-theme="github-dark"><div class="ch-code-wrapper ch-code" data-ch-measured="false"><code class="ch-code-scroll-parent"><br><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>curl -X POST \</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span> &quot;http://LANGFLOW_SERVER_ADDRESS/api/v1/run/FLOW_ID?stream=false&quot; \</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span> -H &quot;Content-Type: application/json&quot; \</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span> -H &quot;x-api-key: LANGFLOW_API_KEY&quot; \</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span> -d &#x27;{&quot;inputs&quot;: {&quot;text&quot;:&quot;&quot;}, &quot;tweaks&quot;: {}}&#x27;</span></div></div><br></code></div></div>
<p>Replace <code>LANGFLOW_SERVER_ADDRESS</code>, <code>FLOW_ID</code>, and <code>LANGFLOW_API_KEY</code> with the values from your deployment.</p>
</li>
</ol>
<details class="details_lb9f alert alert--info details_b_Ee" data-collapsed="true"><summary>Kubernetes deployment example</summary><div><div class="collapsibleContent_i85q"><p>To configure an environment-based API key in a Kubernetes Secret, do the following:</p><ol>
<li class="">
<p>Create a Kubernetes Secret with your API key:</p>
<div class="ch-codeblock not-prose" data-ch-theme="github-dark"><div class="ch-code-wrapper ch-code" data-ch-measured="false"><code class="ch-code-scroll-parent"><br><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>apiVersion: v1</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>kind: Secret</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>metadata:</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span> name: langflow-api-key</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>type: Opaque</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>stringData:</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span> api-key: &quot;YOUR_API_KEY&quot;</span></div></div><br></code></div></div>
<p>Replace <code>YOUR_API_KEY</code> with the <code>LANGFLOW_API_KEY</code> value from the Langflow <code>.env</code> file.</p>
</li>
<li class="">
<p>Reference the <code>langflow-api-key</code> Secret in your Kubernetes deployment:</p>
<div class="ch-codeblock not-prose" data-ch-theme="github-dark"><div class="ch-code-wrapper ch-code" data-ch-measured="false"><code class="ch-code-scroll-parent"><br><div><span class="ch-code-line-number">_<!-- -->18</span><div style="display:inline-block;margin-left:16px"><span>apiVersion: apps/v1</span></div></div><div><span class="ch-code-line-number">_<!-- -->18</span><div style="display:inline-block;margin-left:16px"><span>kind: Deployment</span></div></div><div><span class="ch-code-line-number">_<!-- -->18</span><div style="display:inline-block;margin-left:16px"><span>metadata:</span></div></div><div><span class="ch-code-line-number">_<!-- -->18</span><div style="display:inline-block;margin-left:16px"><span> name: langflow</span></div></div><div><span class="ch-code-line-number">_<!-- -->18</span><div style="display:inline-block;margin-left:16px"><span>spec:</span></div></div><div><span class="ch-code-line-number">_<!-- -->18</span><div style="display:inline-block;margin-left:16px"><span> template:</span></div></div><div><span class="ch-code-line-number">_<!-- -->18</span><div style="display:inline-block;margin-left:16px"><span> spec:</span></div></div><div><span class="ch-code-line-number">_<!-- -->18</span><div style="display:inline-block;margin-left:16px"><span> containers:</span></div></div><div><span class="ch-code-line-number">_<!-- -->18</span><div style="display:inline-block;margin-left:16px"><span> - name: langflow</span></div></div><div><span class="ch-code-line-number">_<!-- -->18</span><div style="display:inline-block;margin-left:16px"><span> image: langflowai/langflow:latest</span></div></div><div><span class="ch-code-line-number">_<!-- -->18</span><div style="display:inline-block;margin-left:16px"><span> env:</span></div></div><div><span class="ch-code-line-number">_<!-- -->18</span><div style="display:inline-block;margin-left:16px"><span> - name: LANGFLOW_API_KEY_SOURCE</span></div></div><div><span class="ch-code-line-number">_<!-- -->18</span><div style="display:inline-block;margin-left:16px"><span> value: &quot;env&quot;</span></div></div><div><span class="ch-code-line-number">_<!-- -->18</span><div style="display:inline-block;margin-left:16px"><span> - name: LANGFLOW_API_KEY</span></div></div><div><span class="ch-code-line-number">_<!-- -->18</span><div style="display:inline-block;margin-left:16px"><span> valueFrom:</span></div></div><div><span class="ch-code-line-number">_<!-- -->18</span><div style="display:inline-block;margin-left:16px"><span> secretKeyRef:</span></div></div><div><span class="ch-code-line-number">_<!-- -->18</span><div style="display:inline-block;margin-left:16px"><span> name: langflow-api-key</span></div></div><div><span class="ch-code-line-number">_<!-- -->18</span><div style="display:inline-block;margin-left:16px"><span> key: api-key</span></div></div><br></code></div></div>
</li>
</ol></div></div></details>
<details class="details_lb9f alert alert--info details_b_Ee" data-collapsed="true"><summary>Docker Compose example</summary><div><div class="collapsibleContent_i85q"><p>To configure an environment-based API key in Docker Compose, do the following:</p><ol>
<li class="">
<p>Set the API key in your Langflow <code>.env</code> file.</p>
<div class="ch-codeblock not-prose" data-ch-theme="github-dark"><div class="ch-code-wrapper ch-code" data-ch-measured="false"><code class="ch-code-scroll-parent"><br><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>LANGFLOW_API_KEY=your-secure-api-key</span></div></div><br></code></div></div>
<p>Replace <code>YOUR_API_KEY</code> with your actual Langflow API key value.</p>
</li>
<li class="">
<p>Create or update your <code>docker-compose.yml</code> file to set <code>LANGFLOW_API_KEY_SOURCE=env</code> and reference the <code>LANGFLOW_API_KEY</code>.</p>
<div class="ch-codeblock not-prose" data-ch-theme="github-dark"><div class="ch-code-wrapper ch-code" data-ch-measured="false"><code class="ch-code-scroll-parent"><br><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>services:</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span> langflow:</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span> image: langflowai/langflow:latest</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span> environment:</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span> - LANGFLOW_API_KEY_SOURCE=env</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span> - LANGFLOW_API_KEY=${LANGFLOW_API_KEY}</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span> ports:</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span> - &quot;7860:7860&quot;</span></div></div><br></code></div></div>
</li>
</ol></div></div></details>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="cors-configuration-for-authentication">LANGFLOW_CORS_*<a href="#cors-configuration-for-authentication" class="hash-link" aria-label="Direct link to LANGFLOW_CORS_*" title="Direct link to LANGFLOW_CORS_*" translate="no"></a></h3>
<p>Cross-Origin Resource Sharing (CORS) configuration controls how authentication credentials are handled when your Langflow frontend and backend are served from different origins.
The following <code>LANGFLOW_CORS_*</code> environment variables are available:</p>
<table><thead><tr><th>Variable</th><th>Format</th><th>Default</th><th>Description</th></tr></thead><tbody><tr><td><code>LANGFLOW_CORS_ALLOW_CREDENTIALS</code></td><td>Boolean</td><td><code>True</code></td><td>Whether to allow credentials, such as cookies and authorization headers, in CORS requests.</td></tr><tr><td><code>LANGFLOW_CORS_ALLOW_HEADERS</code></td><td>List[String] or String</td><td><code>*</code></td><td>The allowed headers for CORS requests. Provide a comma-separated list of headers or use <code>*</code> to allow all headers.</td></tr><tr><td><code>LANGFLOW_CORS_ALLOW_METHODS</code></td><td>List[String] or String</td><td><code>*</code></td><td>The allowed HTTP methods for CORS requests. Provide a comma-separated list of methods or use <code>*</code> to allow all methods.</td></tr><tr><td><code>LANGFLOW_CORS_ORIGINS</code></td><td>String</td><td><code>*</code></td><td>The allowed CORS origins. Provide a comma-separated list of origins or use <code>*</code> for all origins.</td></tr></tbody></table>
<p>The default configuration enables CORS credentials and uses wildcards (<code>*</code>) to allow all origins, headers, and methods:</p>
<div class="ch-codeblock not-prose" data-ch-theme="github-dark"><div class="ch-code-wrapper ch-code" data-ch-measured="false"><code class="ch-code-scroll-parent"><br><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>LANGFLOW_CORS_ORIGINS=*</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>LANGFLOW_CORS_ALLOW_CREDENTIALS=True</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>LANGFLOW_CORS_ALLOW_HEADERS=*</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>LANGFLOW_CORS_ALLOW_METHODS=*</span></div></div><br></code></div></div>
<div class="theme-admonition theme-admonition-danger admonition_xJq3 alert alert--danger"><div class="admonitionHeading_Gvgb"><span class="admonitionIcon_Rf37"><svg viewBox="0 0 12 16"><path fill-rule="evenodd" d="M5.05.31c.81 2.17.41 3.38-.52 4.31C3.55 5.67 1.98 6.45.9 7.98c-1.45 2.05-1.7 6.53 3.53 7.7-2.2-1.16-2.67-4.52-.3-6.61-.61 2.03.53 3.33 1.94 2.86 1.39-.47 2.3.53 2.27 1.67-.02.78-.31 1.44-1.13 1.81 3.42-.59 4.78-3.42 4.78-5.56 0-2.84-2.53-3.22-1.25-5.61-1.52.13-2.03 1.13-1.89 2.75.09 1.08-1.02 1.8-1.86 1.33-.67-.41-.66-1.19-.06-1.78C8.18 5.31 8.68 2.45 5.05.32L5.03.3l.02.01z"></path></svg></span>danger</div><div class="admonitionContent_BuS1"><p>Langflow&#x27;s default CORS settings can be a security risk in production environments because any website can make requests to your Langflow API, and any website can include credentials in cross-origin requests, including authentication cookies and authorization headers.</p><p>In production deployments, specify exact origins in <code>LANGFLOW_CORS_ORIGINS</code>.
You can also specify allowed headers and methods, if needed.
For example:</p><div class="ch-codeblock not-prose" data-ch-theme="github-dark"><div class="ch-code-wrapper ch-code" data-ch-measured="false"><code class="ch-code-scroll-parent"><br><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>LANGFLOW_CORS_ORIGINS=[&quot;https://yourdomain.com&quot;,&quot;https://app.yourdomain.com&quot;]</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>LANGFLOW_CORS_ALLOW_CREDENTIALS=True</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>LANGFLOW_CORS_ALLOW_HEADERS=[&quot;Content-Type&quot;,&quot;Authorization&quot;]</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>LANGFLOW_CORS_ALLOW_METHODS=[&quot;GET&quot;,&quot;POST&quot;,&quot;PUT&quot;]</span></div></div><br></code></div></div></div></div>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="ssrf-protection">SSRF protection<a href="#ssrf-protection" class="hash-link" aria-label="Direct link to SSRF protection" title="Direct link to SSRF protection" translate="no"></a></h3>
<p>The following environment variables configure Server-Side Request Forgery (SSRF) protection for the <a class="" href="/api-request"><strong>API Request</strong> component</a>.
SSRF protection prevents requests to internal or private network resources, such as private IP ranges, loopback addresses, and cloud metadata endpoints.</p>
<table><thead><tr><th>Variable</th><th>Format</th><th>Default</th><th>Description</th></tr></thead><tbody><tr><td><code>LANGFLOW_SSRF_PROTECTION_ENABLED</code></td><td>Boolean</td><td><code>False</code></td><td>Enable SSRF protection for the <strong>API Request</strong> component. When enabled, the component blocks requests to private IP addresses. When disabled, requests are not blocked.</td></tr><tr><td><code>LANGFLOW_SSRF_ALLOWED_HOSTS</code></td><td>List[String]</td><td>Not set</td><td>A comma-separated list of allowed hosts, IP addresses, or CIDR ranges that can bypass SSRF protection checks. For example: <code>192.168.1.0/24,10.0.0.5,*.internal.company.local</code>.</td></tr></tbody></table>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="langflow-webhook-auth-enable">LANGFLOW_WEBHOOK_AUTH_ENABLE<a href="#langflow-webhook-auth-enable" class="hash-link" aria-label="Direct link to LANGFLOW_WEBHOOK_AUTH_ENABLE" title="Direct link to LANGFLOW_WEBHOOK_AUTH_ENABLE" translate="no"></a></h3>
<p>This variable controls whether API key authentication is required for webhook endpoints.</p>
<table><thead><tr><th>Variable</th><th>Format</th><th>Default</th><th>Description</th></tr></thead><tbody><tr><td><code>LANGFLOW_WEBHOOK_AUTH_ENABLE</code></td><td>Boolean</td><td><code>False</code></td><td>When <code>True</code>, webhook endpoints require API key authentication and validate that the authenticated user owns the flow being executed. When <code>False</code>, no Langflow API key is required and all requests to the webhook endpoint are treated as being sent by the flow owner.</td></tr></tbody></table>
<p>By default, webhooks run as the flow owner without authentication with <code>LANGFLOW_WEBHOOK_AUTH_ENABLE=False</code>.</p>
<p>To require API key authentication for webhooks, in your Langflow <code>.env</code> file, set <code>LANGFLOW_WEBHOOK_AUTH_ENABLE=True</code>.</p>
<p>When webhook authentication is enabled, you must provide a Langflow API key with each webhook request as an HTTP header or query parameter. For more information, see <a class="" href="/webhook#require-authentication-for-webhooks">Require authentication for webhooks</a>.</p>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="start-a-langflow-server-with-authentication-enabled">Start a Langflow server with authentication enabled<a href="#start-a-langflow-server-with-authentication-enabled" class="hash-link" aria-label="Direct link to Start a Langflow server with authentication enabled" title="Direct link to Start a Langflow server with authentication enabled" translate="no"></a></h2>
<p>This section shows you how to use the <a class="" href="/api-keys-and-authentication#authentication-environment-variables">authentication environment variables</a> to deploy a Langflow server with authentication enabled.
This involves disabling automatic login, setting superuser credentials, generating a secret encryption key, and enabling user management.</p>
<p>This configuration is recommended for any deployment where Langflow is exposed to a shared or public network, or where multiple users access the same Langflow server.</p>
<p>With authentication enabled, all users must sign in to the visual editor with valid credentials, and API requests require authentication with a Langflow API key.
Additionally, you must sign in as a superuser to manage users and <a href="#create-a-langflow-api-key" class="">create a Langflow API key</a> with superuser privileges.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="start-the-langflow-server">Start the Langflow server<a href="#start-the-langflow-server" class="hash-link" aria-label="Direct link to Start the Langflow server" title="Direct link to Start the Langflow server" translate="no"></a></h3>
<ol>
<li class="">
<p>Create a <code>.env</code> file with the following variables:</p>
<div class="ch-codeblock not-prose" data-ch-theme="github-dark"><div class="ch-code-wrapper ch-code" data-ch-measured="false"><code class="ch-code-scroll-parent"><br><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>LANGFLOW_AUTO_LOGIN=False</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>LANGFLOW_SUPERUSER=</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>LANGFLOW_SUPERUSER_PASSWORD=</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>LANGFLOW_SECRET_KEY=</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>LANGFLOW_NEW_USER_IS_ACTIVE=False</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>LANGFLOW_ENABLE_SUPERUSER_CLI=False</span></div></div><br></code></div></div>
<p>Your <code>.env</code> file can have other environment variables.
This example focuses on authentication variables.</p>
</li>
<li class="">
<p>Set <code>LANGFLOW_SUPERUSER</code> and <code>LANGFLOW_SUPERUSER_PASSWORD</code> to your desired superuser credentials.</p>
<p>For a one-time test, you can use basic credentials like <code>administrator</code> and <code>password</code>.
Strong, securely-stored credentials are recommended in genuine development and production environments.</p>
</li>
<li class="">
<p>Recommended: Generate and set a <code>LANGFLOW_SECRET_KEY</code> for encrypting sensitive data.</p>
<p>If you don&#x27;t set a secret key, Langflow generates one automatically, but this isn&#x27;t recommended for production environments.</p>
<p>For instructions on generating and setting a secret key, see <a href="#langflow-secret-key" class=""><code>LANGFLOW_SECRET_KEY</code></a>.</p>
</li>
<li class="">
<p>Save your <code>.env</code> file with the populated variables. For example:</p>
<div class="ch-codeblock not-prose" data-ch-theme="github-dark"><div class="ch-code-wrapper ch-code" data-ch-measured="false"><code class="ch-code-scroll-parent"><br><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>LANGFLOW_AUTO_LOGIN=False</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>LANGFLOW_SUPERUSER=administrator</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>LANGFLOW_SUPERUSER_PASSWORD=securepassword</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>LANGFLOW_SECRET_KEY=dBuu...2kM2_fb</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>LANGFLOW_NEW_USER_IS_ACTIVE=False</span></div></div><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>LANGFLOW_ENABLE_SUPERUSER_CLI=False</span></div></div><br></code></div></div>
</li>
<li class="">
<p>Start Langflow with the configuration from your <code>.env</code> file:</p>
<div class="ch-codeblock not-prose" data-ch-theme="github-dark"><div class="ch-code-wrapper ch-code" data-ch-measured="false"><code class="ch-code-scroll-parent"><br><div><span class="ch-code-line-number">_<!-- -->10</span><div style="display:inline-block;margin-left:16px"><span>uv run langflow run --env-file .env</span></div></div><br></code></div></div>
<p>Starting Langflow with a <code>.env</code> file automatically authenticates you as the superuser set in <code>LANGFLOW_SUPERUSER</code> and <code>LANGFLOW_SUPERUSER_PASSWORD</code>.
If you don&#x27;t explicitly set these variables, the default values are <code>langflow</code> and <code>langflow</code> for system auto-login.</p>
</li>
<li class="">
<p>Verify the server is running. The default location is <code>http://localhost:7860</code>.</p>
</li>
</ol>
<p>Next, you can add users to your Langflow server to collaborate with others on flows.</p>
<h3 class="anchor anchorTargetStickyNavbar_Vzrq" id="manage-users-as-an-administrator">Manage users as an administrator<a href="#manage-users-as-an-administrator" class="hash-link" aria-label="Direct link to Manage users as an administrator" title="Direct link to Manage users as an administrator" translate="no"></a></h3>
<ol>
<li class="">
<p>To complete your first-time login as a superuser, go to <code>http://localhost:7860/login</code>.</p>
<p>If you aren&#x27;t using the default location, replace <code>localhost:7860</code> with your server&#x27;s address.</p>
</li>
<li class="">
<p>Log in with the superuser credentials you set in your <code>.env</code> (<code>LANGFLOW_SUPERUSER</code> and <code>LANGFLOW_SUPERUSER_PASSWORD</code>).</p>
</li>
<li class="">
<p>To manage users on your server, navigate to <code>/admin</code>, such as <code>http://localhost:7860/admin</code>, click your profile icon, and then click <strong>Admin Page</strong>.</p>
<p>As a superuser, you can add users, set permissions, reset passwords, and delete accounts.</p>
</li>
<li class="">
<p>To add a user, click <strong>New User</strong>, and then complete the user account form:</p>
<ol>
<li class="">Enter a username and password.</li>
<li class="">To activate the account immediately, select <strong>Active</strong>. Inactive users cannot sign in or access flows they created before becoming inactive.</li>
<li class="">Deselect <strong>Superuser</strong> if you don&#x27;t want the user to have full administrative privileges.</li>
<li class="">Click <strong>Save</strong>. The new user appears in the <strong>Admin Page</strong>.</li>
</ol>
</li>
<li class="">
<p>Send the credentials to the user so they can sign in to Langflow. The superuser sets the initial password when creating the account, so users must receive their login credentials from the superuser.</p>
</li>
<li class="">
<p>To test the new user&#x27;s access, sign out of Langflow, and then sign in with the new user&#x27;s credentials.</p>
<p>Try to access the <code>/admin</code> page.
You are redirected to the <code>/flows</code> page if the new user isn&#x27;t a superuser.</p>
</li>
</ol>
<h2 class="anchor anchorTargetStickyNavbar_Vzrq" id="see-also">See also<a href="#see-also" class="hash-link" aria-label="Direct link to See also" title="Direct link to See also" translate="no"></a></h2>
<ul>
<li class=""><a class="" href="/environment-variables">Langflow environment variables</a></li>
<li class=""><a href="https://github.com/langflow-ai/langflow/blob/main/SECURITY.md" target="_blank" rel="noopener noreferrer" class="">Langflow Security Policy</a> — reporting vulnerabilities, security configuration, and <a href="https://github.com/langflow-ai/langflow/blob/main/SECURITY.md#secret-key-rotation" target="_blank" rel="noopener noreferrer" class="">secret key rotation</a></li>
</ul></div></article><nav class="docusaurus-mt-lg pagination-nav" aria-label="Docs pages"><a class="pagination-nav__link pagination-nav__link--prev" href="/mcp-component-astra"><div class="pagination-nav__sublabel">Previous</div><div class="pagination-nav__label">Connect an Astra DB MCP server to Langflow</div></a><a class="pagination-nav__link pagination-nav__link--next" href="/jwt-authentication"><div class="pagination-nav__sublabel">Next</div><div class="pagination-nav__label">JWT authentication</div></a></nav></div></div><div class="col col--3"><div class="tableOfContents_bqdL thin-scrollbar theme-doc-toc-desktop"><ul class="table-of-contents table-of-contents__left-border"><li><a href="#langflow-api-keys" class="table-of-contents__link toc-highlight">Langflow API keys</a><ul><li><a href="#langflow-api-key-permissions" class="table-of-contents__link toc-highlight">Langflow API key permissions</a></li><li><a href="#create-a-langflow-api-key" class="table-of-contents__link toc-highlight">Create a Langflow API key</a></li><li><a href="#use-a-langflow-api-key" class="table-of-contents__link toc-highlight">Use a Langflow API key</a></li><li><a href="#track-api-key-usage" class="table-of-contents__link toc-highlight">Track API key usage</a></li><li><a href="#revoke-an-api-key" class="table-of-contents__link toc-highlight">Revoke an API key</a></li></ul></li><li><a href="#component-api-keys" class="table-of-contents__link toc-highlight">Component API keys</a></li><li><a href="#authentication-environment-variables" class="table-of-contents__link toc-highlight">Authentication environment variables</a><ul><li><a href="#langflow-auto-login" class="table-of-contents__link toc-highlight">LANGFLOW_AUTO_LOGIN</a></li><li><a href="#langflow-enable-superuser-cli" class="table-of-contents__link toc-highlight">LANGFLOW_ENABLE_SUPERUSER_CLI</a></li><li><a href="#langflow-superuser" class="table-of-contents__link toc-highlight">LANGFLOW_SUPERUSER and LANGFLOW_SUPERUSER_PASSWORD</a></li><li><a href="#langflow-secret-key" class="table-of-contents__link toc-highlight">LANGFLOW_SECRET_KEY</a></li><li><a href="#langflow-new-user-is-active" class="table-of-contents__link toc-highlight">LANGFLOW_NEW_USER_IS_ACTIVE</a></li><li><a href="#langflow-api-key-source" class="table-of-contents__link toc-highlight">LANGFLOW_API_KEY_SOURCE</a></li><li><a href="#cors-configuration-for-authentication" class="table-of-contents__link toc-highlight">LANGFLOW_CORS_*</a></li><li><a href="#ssrf-protection" class="table-of-contents__link toc-highlight">SSRF protection</a></li><li><a href="#langflow-webhook-auth-enable" class="table-of-contents__link toc-highlight">LANGFLOW_WEBHOOK_AUTH_ENABLE</a></li></ul></li><li><a href="#start-a-langflow-server-with-authentication-enabled" class="table-of-contents__link toc-highlight">Start a Langflow server with authentication enabled</a><ul><li><a href="#start-the-langflow-server" class="table-of-contents__link toc-highlight">Start the Langflow server</a></li><li><a href="#manage-users-as-an-administrator" class="table-of-contents__link toc-highlight">Manage users as an administrator</a></li></ul></li><li><a href="#see-also" class="table-of-contents__link toc-highlight">See also</a></li></ul></div></div></div></div></main></div></div></div><footer class="theme-layout-footer footer"><div class="container container-fluid"><div class="row footer__links"><div class="theme-layout-footer-column col footer__col"><div class="footer__title"></div><ul class="footer__items clean-list"><li class="footer__item"><div class="footer-links">
<span>© 2026 Langflow</span>
<span id="preferenceCenterContainer"> ·&nbsp; <a href="#" onclick='return"undefined"!=typeof window&&window.truste&&window.truste.eu&&window.truste.eu.clickListener&&window.truste.eu.clickListener(),!1' style="cursor: pointer;">Manage Privacy Choices</a></span>
</div></li></ul></div></div></div></footer><div style="position:fixed;right:21px;bottom:21px;z-index:100;display:flex;align-items:center;gap:10px;cursor:pointer"><div style="background-color:#f6f6f6;border-radius:50%;width:48px;height:48px;display:flex;align-items:center;justify-content:center;box-shadow:0 2px 4px rgba(0,0,0,0.1)"><img src="/img/langflow-icon-black-transparent.svg" style="width:40px" alt="Search"></div></div></div>
</body>
</html>