Skip to content

First run ​

Create the administrator account before inviting other users. The default authentication mode is local.

Choose an authentication mode ​

ModeBest for
localExcaliDash accounts
hybridLocal accounts and OpenID Connect
oidc_enforcedOpenID Connect only
disabledPersonal use in isolated environments only

Do not expose disabled authentication publicly

AUTH_MODE=disabled gives every visitor the same identity and access.

Create the administrator ​

Use the arrows to follow each screen of the default local-account setup. If authentication is already enabled, start at the administrator form.

Setup codes expire after 15 minutes by default.

Invite users ​

Open Admin to create another local account or enable self-registration.

For OpenID Connect (OIDC), configure the provider before signing in. OIDC_FIRST_USER_ADMIN=true makes the first provisioned OIDC user an administrator.

Your workspace ​

Use the arrows to explore an established example workspace, drawing sharing, and live collaboration.

Sample drawing credits.

Securing your instance ​

Before exposing ExcaliDash beyond a local machine:

  • Terminate TLS at a trusted reverse proxy.
  • Set stable JWT_SECRET and CSRF_SECRET values.
  • Keep TRUST_PROXY=false unless requests always pass through a trusted proxy.
  • Persist the database and test a restore procedure.
  • Keep frontend and backend image tags aligned.

Next: Configure authentication.

Self-hosted, open source, and built around Excalidraw.