First Run Setup
On your first visit to OpenCode Manager, you'll complete a guided setup process.
Interactive Setup
When no admin account exists, you'll be automatically redirected to the setup page.
Step 1: Create Admin Account
Fill in your account details:
- Name - Your display name
- Email - Used for login
- Password - At least 8 characters (required)
Click Create Admin Account to continue.
Step 2: Configure Provider (Optional)
After account creation, configure an AI provider:
- Navigate to Settings > Providers
- Select a provider
- Enter API key or connect via OAuth
- Save configuration
You can skip this and configure providers later.
Pre-Configured Admin
For automated or headless deployments, skip interactive setup by setting environment variables:
# In docker-compose.yml or .env
ADMIN_EMAIL=admin@example.com
ADMIN_PASSWORD=your-secure-password
When these are set:
- Admin user is created automatically on first startup
- Setup wizard is skipped
- Registration is disabled, so no new accounts can be created
ADMIN_PASSWORDsets the password only when the admin is first created, or whenADMIN_PASSWORD_RESET=true; changing it later has no effect otherwise
Adding Passkeys
After initial setup, you can add passkey authentication for passwordless login:
- Go to Settings > Account
- Optionally enter a passkey name (e.g., "MacBook Touch ID")
- Click Add Passkey
- Follow your browser/device prompts
Passkeys provide:
- Passwordless login
- Phishing-resistant authentication
- Biometric support (Touch ID, Face ID, Windows Hello)
Password Reset
If you forget your password:
- Set environment variables:
ADMIN_EMAIL=your@email.com
ADMIN_PASSWORD=new-password
ADMIN_PASSWORD_RESET=true
- Recreate the container so it picks up the new environment variables:
docker compose up -d --force-recreate app
-
Log in with new password
-
Important: Remove
ADMIN_PASSWORD_RESET=trueand recreate the container again:
docker compose up -d --force-recreate app
Security Recommendations
Production Deployments
- Keep
AUTH_SECRETstable. Docker generates a strong one and keeps it in the data volume; outside Docker, set it yourself - Use HTTPS with valid SSL certificate
- Use strong, unique passwords
- Enable passkey authentication
- Regularly rotate API keys
Generate AUTH_SECRET
Only needed outside Docker, or to manage the secret yourself:
openssl rand -base64 32
Add to your environment:
AUTH_SECRET=your-generated-secret-here
Next Steps
- Configure OAuth Providers - Enable social login
- Environment Variables - All configuration options
- Features Overview - Explore capabilities