description: "How you authenticate depends on the server mode: accounts in multi-space mode, environment-variable credentials in single-space mode, or none." tags: administration references:
How you authenticate depends on how the server is running:
When the server runs in the default multi-space mode, authentication is account-based:
none, read, or write — for visitors with no account, plus per-member read/write roles. Admins can reach every space and the admin UI.Account-managed servers can connect Google Workspace, Pocket ID, or another OpenID Connect provider alongside local accounts. See Single Sign-On for web setup, user provisioning and central login.
Single-space mode serves one folder as one space, authenticated the “classic” way: a single set of credentials set via the SB_USER environment variable in username:password form.
warning Warning Single-space is considered legacy, please migrate to multi-space mode
Set SB_USER when starting the server. For the Install/Server Binary:
SB_USER=pete:1234 ./silverbullet my-space
For Install/Docker:
docker run -e SB_USER=pete:1234 ...
This allows pete to log in with password 1234. When authentication is enabled, SilverBullet shows a login page on first access.
For programmatic access via the HTTP API, you can use bearer token authentication. In single-space mode, this token is configured with an environment variable, see Install/Configuration. In multi-space mode, new API tokens can be issued via the Dashboard UI.
Alternatively, or in addition, you can use an Authentication Proxy to delegate authentication to an external system (like Authelia, Authentik, or a reverse proxy's built-in auth). This is common in more complex self-hosted setups. In accounts mode, pair a proxy with public spaces so the proxy owns identity; in single-space mode, put the proxy in front of an open server.
For all authentication-related configuration options, see Install/Configuration#Authentication.