Owner

The owner role is assigned to the first user who logs into Tracecat. This user has admin rights to every workspace in the Tracecat instance.

Domain whitelist

To prevent unauthorized access to your Tracecat instance, you can configure a list of allowed domains for authentication. You can do this by setting the TRACECAT__AUTH_ALLOWED_DOMAINS environment variable. For example:

TRACECAT__AUTH_ALLOWED_DOMAINS=acme.com,acme.ai

Authentication Methods

In production, use Google OAuth or SAML SSO. Basic auth is meant for local development only.

Tracecat currently supports the following authentication methods:

  • basic: Email and Password
  • google_oauth: Google OAuth
  • saml: SAML SSO

Choose from a number of authentication methods listed below to get started.

Was this page helpful?