docs: LANGFLOW_ENABLE_SUPERUSER_CLI environment variable (#9223)

* add-superuser-cli-note-and-env-var

* code-review

* env-var-link

* resolve CLI superuser confusion

---------

Co-authored-by: April M <april.murphy@datastax.com>
This commit is contained in:
Mendon Kissling 2025-07-30 12:33:01 -04:00 • committed by GitHub
commit 7123c507a7
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
3 changed files with 118 additions and 127 deletions

View file

@ -25,20 +25,25 @@ There are three types of credentials that you use in Langflow:
You can use Langflow API keys to interact with Langflow programmatically.
A Langflow API key has the same permissions and access as the user who created it.
This means your API key can only access your own flows, components, and database.
You cannot access other users' resources with your own Langflow API keys.
If you create a key as a superuser, then that key has superuser privileges within your Langflow server.
In Langflow version 1.5 and later, most API endpoints require a Langflow API key, even when `AUTO_LOGIN` is `True`.
In Langflow version 1.5 and later, most API endpoints require a Langflow API key, even when `LANGFLOW_AUTO_LOGIN` is `True`.
For more information, see [`LANGFLOW_AUTO_LOGIN`](#langflow-auto-login).
### Langflow API key permissions
A Langflow API key adopts the privileges of the user who created it.
This means that API keys you create have the same permissions and access that you do, including access to your flows, components, and Langflow database.
A Langflow API key cannot be used to access resources outside of your own Langflow server.
In single-user environments, you are always a superuser, and your Langflow API keys always have superuser privileges.
In multi-user environments, users who aren't superusers cannot use their API keys to access other users' resources.
You must [start your Langflow server with authentication enabled](#start-a-langflow-server-with-authentication-enabled) to allow user management and creation of non-superuser accounts.
### Create a Langflow API key
You can generate a Langflow API key with the UI or the CLI.
The UI-generated key is appropriate for most cases. The CLI-generated key is needed when your Langflow server is running in `--backend-only` mode.
The UI-generated key is appropriate for most development use cases. The CLI-generated key is needed when your Langflow server is running in `--backend-only` mode.
<Tabs>
<TabItem value="Langflow UI" label="Langflow UI" default>
@ -51,57 +56,23 @@ The UI-generated key is appropriate for most cases. The CLI-generated key is nee
</TabItem>
<TabItem value="Langflow CLI" label="Langflow CLI">
If you're serving your flow with `--backend-only=true`, you can't create API keys in the UI, because the frontend is not running.
If you're serving your flow with `--backend-only=true`, you can't create API keys in the UI because the frontend isn't running.
In this case, you must create API keys with the Langflow CLI.
Depending on your authentication settings, note the following requirements for creating API keys with the Langflow CLI:
1. Recommended: [Start your Langflow server with authentication enabled](#start-a-langflow-server-with-authentication-enabled).
* If `AUTO_LOGIN` is `FALSE`, you must be logged in as a superuser.
* If `AUTO LOGIN` is `TRUE`, you're already logged in as superuser.
This configuration is recommended for security reasons to prevent unauthorized API key and superuser creation, especially in production environments.
To create an API key for a user from the CLI, do the following:
However, if authentication isn't enabled (`LANGFLOW_AUTO_LOGIN=True`), all users are effectively superusers, and they can create API keys with the Langflow CLI.
1. In your `.env` file, set `AUTO_LOGIN=FALSE`, and set superuser credentials for your server.
```text
LANGFLOW_AUTO_LOGIN=False
LANGFLOW_SUPERUSER=administrator
LANGFLOW_SUPERUSER_PASSWORD=securepassword
```
2. To confirm your superuser status, call [`GET /users/whoami`](/api-users#get-current-user), and then check that the response contains `"is_superuser": true`:
```bash
curl -X GET \
"$LANGFLOW_URL/api/v1/users/whoami" \
-H "accept: application/json" \
-H "x-api-key: $LANGFLOW_API_KEY"
```
<details>
<summary>Result</summary>
```json
{
"id": "07e5b864-e367-4f52-b647-a48035ae7e5e",
"username": "langflow",
"profile_image": null,
"store_api_key": null,
"is_active": true,
"is_superuser": true,
"create_at": "2025-05-08T17:59:07.855965",
"updated_at": "2025-05-29T15:06:56.157860",
"last_login_at": "2025-05-29T15:06:56.157016",
}
```
</details>
3. Create an API key:
2. Create an API key with [`langflow api-key`](/configuration-cli#langflow-api-key):
```shell
uv run langflow api-key
```
All API keys created with the Langflow CLI have superuser privileges because the command requires superuser authentication, and Langflow API keys adopt the privileges of the user who created them.
</TabItem>
</Tabs>
@ -278,6 +249,12 @@ LANGFLOW_NEW_USER_IS_ACTIVE=False
For more information, see [Start a Langflow server with authentication enabled](#start-a-langflow-server-with-authentication-enabled).
### LANGFLOW_ENABLE_SUPERUSER_CLI {#langflow-enable-superuser-cli}
Controls the availability of the `langflow superuser` command in the Langflow CLI.
The default is `True`, but `False` is recommended to prevent unrestricted superuser creation.
For more information, see [`langflow superuser`](/configuration-cli#langflow-superuser).
## Start a Langflow server with authentication enabled
This section shows you how to use the [authentication environment variables](/api-keys-and-authentication#authentication-environment-variables) to deploy a Langflow server with authentication enabled.
@ -298,6 +275,7 @@ Additionally, you must sign in as a superuser to manage users and [create a Lang
LANGFLOW_SUPERUSER_PASSWORD=
LANGFLOW_SECRET_KEY=
LANGFLOW_NEW_USER_IS_ACTIVE=False
LANGFLOW_ENABLE_SUPERUSER_CLI=False
```
Your `.env` file can have other environment variables.
@ -322,6 +300,7 @@ Additionally, you must sign in as a superuser to manage users and [create a Lang
LANGFLOW_SUPERUSER_PASSWORD=securepassword
LANGFLOW_SECRET_KEY=dBuu...2kM2_fb
LANGFLOW_NEW_USER_IS_ACTIVE=False
LANGFLOW_ENABLE_SUPERUSER_CLI=False
```
5. Start Langflow with the configuration from your `.env` file:
@ -330,6 +309,9 @@ Additionally, you must sign in as a superuser to manage users and [create a Lang
uv run langflow run --env-file .env
```
Starting Langflow with an `.env` file automatically authenticates you as the superuser set in `LANGFLOW_SUPERUSER` and `LANGFLOW_SUPERUSER_PASSWORD`.
If you don't explicitly set these variables, the default values are `langflow` and `langflow`.
6. Verify the server is running. The default location is `http://localhost:7860`.
Next, you can add users to your Langflow server to collaborate with others on flows.