// Engineering Log

What is Open WebUI: a unified interface for local and cloud neural networks

Published on 2026-09-22

What is Open WebUI

Open WebUI is a web interface for working with language models that you install on your own server or computer. It looks and works like a familiar chat with a neural network, but connects to multiple sources at once: to local models via Ollama and to cloud APIs compatible with OpenAI. The user opens it in a browser and selects a model from a list, and conversation data is stored on your server.

The project started as Ollama WebUI — a frontend for Ollama, a tool for running models on your own hardware — and over time grew into an independent platform with document search, accounts and roles. The current version as of September 2026 is 0.11.4.

Why you need it

  • All models in one window. Local Ollama models, OpenAI, OpenRouter, Mistral and any services with an OpenAI-compatible API are connected as separate sources. You can send one request to multiple models and compare responses.
  • Privacy. With a local model, the request text and uploaded documents do not leave the server. For cloud models, of course, data goes to the API provider.
  • Shared access for a team. Instead of distributing personal API keys to employees, the administrator connects models once and grants access through user accounts.

Installation via Docker

The official documentation offers several options. The simplest is the image with bundled Ollama: the UI and models run in a single container.

CPU only:

bash
docker run -d -p 3000:8080 \
  -v ollama:/root/.ollama \
  -v open-webui:/app/backend/data \
  -e WEBUI_SECRET_KEY=long-random-key \
  --name open-webui --restart always \
  ghcr.io/open-webui/open-webui:ollama

With an NVIDIA GPU add the --gpus=all flag (NVIDIA Container Toolkit required).

If Ollama is already running on another server, use the main image and pass Ollama’s address via an environment variable:

bash
docker run -d -p 3000:8080 \
  -e OLLAMA_BASE_URL=http://10.0.0.5:11434 \
  -e WEBUI_SECRET_KEY=long-random-key \
  -v open-webui:/app/backend/data \
  --name open-webui --restart always \
  ghcr.io/open-webui/open-webui:main

After startup the UI is available on port 3000. The first registered account becomes an administrator, so register immediately after launching, before opening access to others.

Data is stored in the open-webui volume (conversations, users, uploaded files); Ollama models are in the ollama volume. For backup, it’s sufficient to save these volumes.

Chat with documents (RAG)

Open WebUI can answer based on the content of uploaded files: PDF, text documents, Markdown. Files are split into chunks, indexed, and when asked the model receives relevant snippets as context. Documents can be uploaded directly into the chat or collected into a knowledge base and attached to conversations. Web search is connected separately via search services, including its own SearXNG.

Answer quality with documents depends on the model and chunking settings. Small local models handle long context worse, so for working with lengthy regulations it’s sensible to test several models on real questions.

Users and roles

The interface supports multiple users: administrator, regular users and accounts pending approval. The administrator decides which models are visible to which groups, can disable open registration and enable login via an external provider (OAuth, OIDC). For a small team this solves the question “who has what access to the models” without a separate product.

License

Open WebUI is distributed under a modified BSD 3-Clause license with an additional branding condition. Replacing or hiding the Open WebUI name and logo is allowed only in three cases:

  • if the deployment has no more than 50 end users in any rolling 30-day period;
  • with written permission from the copyright holder;
  • under a corporate license that explicitly allows it.

Otherwise changing the branding is considered a license violation. For internal use without modifying the interface this condition changes nothing, but if you plan to embed Open WebUI into your product under your own name, you should take it into account in advance.

Security

  • Do not expose the interface to the Internet without protection. At minimum — HTTPS via a reverse proxy, open registration disabled and strong passwords. More secure — access only via VPN.
  • Set WEBUI_SECRET_KEY. This key signs sessions; without a persistent value users will have to log in again after a restart.
  • Store cloud API keys only in the administrator settings, not in users’ personal profiles.
  • Update the image. The project evolves quickly; security fixes are released in new versions.

Common mistakes

  • Exposing the interface publicly and forgetting that the first registered user becomes the administrator.
  • Expecting a small local model to match large cloud models: for complex tasks 7–8-billion-parameter models are noticeably weaker.
  • Keeping the data volume without a backup: conversations and knowledge bases are lost with it.
  • Installing everything on a weak server without a GPU and being surprised by the speed: local models are demanding of memory and CPU.

When Open WebUI is suitable

It’s convenient if you need a single chat for a team with access control, if it’s important to work with local models without sending data outside, or if you want to compare multiple models in one window. If you need a single cloud model for one person, it’s simpler to use the provider’s website.

// Contact

Need help?

Get in touch with me and I'll help solve the problem

I reply within one business day (03:00-13:00 GMT)

Или оставьте заявку здесь:

Confirm that you are not a bot.

Write and get a quick reply