You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository was archived by the owner on Apr 13, 2026. It is now read-only.
# If not using SSO, generate 1-time login URL to set up your first passkey
45
45
docker exec ttpx-web npm run generate-admin-login
46
-
47
-
# Destroy all data and start from scratch - WARNING YOU WILL LOSE YOUR DB
48
-
docker compose down
49
-
docker system prune -a --volumes
50
46
```
51
47
52
48
## Authentication
53
49
54
-
There is no support for traditional passwords. If you are using SSO, the `INITIAL_ADMIN_EMAIL` is created as a local account at initialization and should be accessible to login via your SSO provider.
50
+
### How it Works
55
51
56
-
If not using SSO, you need to generate a 1-time-login link for that same `INITIAL_ADMIN_EMAIL` user. This will allow you to login so you can add a passkey to your account. From there, continue logging in with your passkey. The `npm run generate-admin-login` command can be re-run in emergencies where you lost your admin passkey.
52
+
Let's be the change we want to see in the world. There is no support for passwords! Currently supported options are:
57
53
58
-
When creating new users in the UI, you will be presented with a similar 1-time-login link for them. They will need to register a passkey when they first login.
54
+
- Passkeys
55
+
- Google OAuth (SSO)
59
56
60
-
## Logging
57
+
The platform uses NextAuth, so adding additional SSO providers would be pretty easy.
61
58
62
-
- Server logs emit to stdout/stderr (structured JSON in production, pretty in development). Rely on Docker and the host OS for collection and rotation.
63
-
- Log level defaults: `debug` in development, `info` in production. Override with `LOG_LEVEL`.
59
+
**Admin bootstrap:**
60
+
61
+
- On first run, the application creates an admin account using `INITIAL_ADMIN_EMAIL` from your `.env`.
62
+
- If using Google SSO, just sign in with the matching Google account.
63
+
- If using passkeys, you must generate a one-time login URL (`npm run generate-admin-login`) and register a passkey for that account.
64
+
65
+
**Ongoing user management:**
66
+
67
+
- Once logged in as admin, you can create additional users.
68
+
- Google SSO users: just log in with the matching Google email.
69
+
- Passkey users: must receive a one-time login URL from the admin, then register a passkey.
64
70
65
-
## Single Sign-On (SSO)
71
+
**Recovery:**
66
72
67
-
SSO is enabled through environment variables. Users must be provisioned ahead of time; they are **not** auto-created on first SSO login.
73
+
- If locked out, re-run `npm run generate-admin-login` to obtain another single-use login URL for the initial admin account.
68
74
69
-
For a pure-SSO setup, set `INITIAL_ADMIN_EMAIL` to a value from the SSO provider. Passkeys can be enabled alongside SSO when desired.
75
+
Accounts must be created inside the platform; SSO logins for unknown emails will be rejected.
70
76
71
-
Environment variables:
77
+
### Configuration Info
78
+
79
+
Authentication options are configured in your `.env` file. The names are slightly different depending on whether you are doing local development or docker compose - the correct values are provided in the appropriate `.env-example` files.
72
80
73
81
```
74
-
# Toggle passkey provider (default: disabled)
82
+
# Enable or disable passkey authentication
75
83
AUTH_PASSKEYS_ENABLED=true
76
84
77
-
# Register Google provider when present (optional)
85
+
# Configuring the follow values will enable Google SSO
78
86
GOOGLE_CLIENT_ID=
79
87
GOOGLE_CLIENT_SECRET=
80
88
```
@@ -83,3 +91,8 @@ For Google, configure the following in the Google Cloud console:
83
91
84
92
- Authorized JavaScript origins: matches `AUTH_URL` from `.env`.
- Server logs emit to stdout/stderr (structured JSON in production, pretty in development). Rely on Docker and the host OS for collection and rotation.
98
+
- Log level defaults: `debug` in development, `info` in production. Override with `LOG_LEVEL`.
0 commit comments