Users & Security
Straden is a private, invite-only workspace. This page covers accounts, roles, sign-in security and API tokens.
First-run setup
Until the first account exists, every page redirects to the setup wizard (/setup). Enter a name, email and password to create the first admin — their email is marked verified automatically. Once setup is complete the wizard disappears, and there is no public registration.
You can skip the wizard by setting STRADEN_ADMIN_EMAIL and STRADEN_ADMIN_PASSWORD (plus optional STRADEN_ADMIN_NAME) before the first start. See Self-hosting.
Roles
| Role | Can |
|---|---|
| Admin | Everything, plus AI Integrations, Insights Model, Users, the Horizon queue dashboard and the log viewer |
| Member | Projects, tests, scripts, runs, connectors, repositories, their own profile and API tokens |
All projects are shared by everyone on the instance.
Managing users
Admins manage accounts under Settings → Users. The table shows each user's role, whether two-factor is enabled and when they last signed in.
- Add user — name, email and an admin toggle. Leave generate password on to create a 16-character password that is shown once, or set one yourself. New users are verified immediately; no email is sent, so share the credentials securely.
- Edit — change name, email or role.
- Reset password — generates a new password, shown once.
- Delete — removes the user and revokes their API tokens.
There must always be at least one admin, and you can't remove your own admin access or delete yourself from this page.
Recovering access
If every admin is locked out, run this on the server:
BASHdocker compose exec app php artisan straden:admin you@example.com
It creates the account (or promotes an existing one), resets the password and prints it. Use --password= to choose one and --name= to name a new account.
Signing in
- Email and password, with Remember me.
- Passkeys — sign in with Touch ID, Windows Hello or a security key.
- Forgot password sends a reset link (requires mail settings).
- Login is limited to 5 attempts per minute per email and IP address.
Your account
| Settings page | What it does |
|---|---|
| Profile | Name and email. Changing the email asks you to verify it again. You can also delete your account here. |
| Appearance | Straden uses a single light theme. |
| Security | Change password, set up two-factor and manage passkeys. You'll be asked to confirm your password first. |
| API tokens | Tokens for the MCP server. |
Password rules
In production, passwords need at least 12 characters with upper and lower case letters, numbers and symbols, and are checked against known data breaches.
Two-factor authentication
- Go to Settings → Security → Enable two-factor.
- Scan the QR code (or enter the setup key) in an authenticator app.
- Confirm with a 6-digit code.
- Save your recovery codes. Each works once, and you can regenerate them at any time.
At the login challenge you can switch between an authentication code and a recovery code.
Passkeys
Add or remove passkeys under Settings → Security. Password managers that support the /.well-known/passkey-endpoints standard can link straight to that page.
API tokens
Every user can create tokens under Settings → API tokens for MCP clients. Each token has a name, a set of abilities (mcp:read, mcp:write, mcp:run) and an expiry (30, 90, 365 days or never). The token is shown once, along with a ready-to-paste claude mcp add command. The token list shows when each token was last used, and you can revoke tokens at any time.
Encryption
AI provider keys are encrypted with the instance's APP_KEY. Back up the storage volume, which holds the generated key.