Authenticate into self-hosted Tracecat with basic email-and-password sign-in: configure user accounts, password policies, and admin bootstrap for small deployments.
In production, use OIDC or SAML SSO. Basic auth is meant for local development only.
Set the first superadmin’s email before anyone signs in. Until it is set, nobody can register, and the first account must match it. It takes one case-sensitive email address, so use the exact casing your identity provider sends.
Deployment
Setting
Docker Compose
TRACECAT__AUTH_SUPERADMIN_EMAIL in .env
AWS ECS Fargate
TF_VAR_auth_superadmin_email, or auth_superadmin_email in your .tfvars
Kubernetes
tracecat.auth.superadminEmail in values.yaml
Basic auth: sign up with that email, then log in.
SSO: log in through your identity provider. Tracecat creates the account on first login.
The account becomes superadmin and owner of the default organization.
Wrong credentials fail at login with 400 and LOGIN_BAD_CREDENTIALS. A password shorter than TRACECAT__AUTH_MIN_PASSWORD_LENGTH fails with 400 and the code UPDATE_USER_INVALID_PASSWORD.A superadmin resets another account’s password with the same body at PATCH /users/{user_id}, and a non-superadmin session gets 403. Accounts created by OIDC or SAML sign-in hold a generated password and authenticate at the identity provider, so reset those there.