Users & Security

Straden is a private, invite-only workspace. This page covers accounts, roles, sign-in security and API tokens.


First-run setup

Until the first account exists, every page redirects to the setup wizard (/setup). Enter a name, email and password to create the first admin — their email is marked verified automatically. Once setup is complete the wizard disappears, and there is no public registration.

You can skip the wizard by setting STRADEN_ADMIN_EMAIL and STRADEN_ADMIN_PASSWORD (plus optional STRADEN_ADMIN_NAME) before the first start. See Self-hosting.

Roles

RoleCan
AdminEverything, plus AI Integrations, Insights Model, Users, the Horizon queue dashboard and the log viewer
MemberProjects, tests, scripts, runs, connectors, repositories, their own profile and API tokens

All projects are shared by everyone on the instance.

Managing users

Admins manage accounts under Settings → Users. The table shows each user's role, whether two-factor is enabled and when they last signed in.

  • Add user — name, email and an admin toggle. Leave generate password on to create a 16-character password that is shown once, or set one yourself. New users are verified immediately; no email is sent, so share the credentials securely.
  • Edit — change name, email or role.
  • Reset password — generates a new password, shown once.
  • Delete — removes the user and revokes their API tokens.

There must always be at least one admin, and you can't remove your own admin access or delete yourself from this page.

Recovering access

If every admin is locked out, run this on the server:

BASH
docker compose exec app php artisan straden:admin you@example.com

It creates the account (or promotes an existing one), resets the password and prints it. Use --password= to choose one and --name= to name a new account.

Signing in

  • Email and password, with Remember me.
  • Passkeys — sign in with Touch ID, Windows Hello or a security key.
  • Forgot password sends a reset link (requires mail settings).
  • Login is limited to 5 attempts per minute per email and IP address.

Your account

Settings pageWhat it does
ProfileName and email. Changing the email asks you to verify it again. You can also delete your account here.
AppearanceStraden uses a single light theme.
SecurityChange password, set up two-factor and manage passkeys. You'll be asked to confirm your password first.
API tokensTokens for the MCP server.

Password rules

In production, passwords need at least 12 characters with upper and lower case letters, numbers and symbols, and are checked against known data breaches.

Two-factor authentication

  1. Go to Settings → Security → Enable two-factor.
  2. Scan the QR code (or enter the setup key) in an authenticator app.
  3. Confirm with a 6-digit code.
  4. Save your recovery codes. Each works once, and you can regenerate them at any time.

At the login challenge you can switch between an authentication code and a recovery code.

Passkeys

Add or remove passkeys under Settings → Security. Password managers that support the /.well-known/passkey-endpoints standard can link straight to that page.

API tokens

Every user can create tokens under Settings → API tokens for MCP clients. Each token has a name, a set of abilities (mcp:read, mcp:write, mcp:run) and an expiry (30, 90, 365 days or never). The token is shown once, along with a ready-to-paste claude mcp add command. The token list shows when each token was last used, and you can revoke tokens at any time.

Encryption

AI provider keys are encrypted with the instance's APP_KEY. Back up the storage volume, which holds the generated key.