DocsOpen WebUI

Open WebUI

Install Open WebUI from the App Store, create the admin account, connect OpenAI, Anthropic or other API providers, manage users, and back up chats.

Open WebUI is a self-hosted, ChatGPT-style chat interface. It has multiple users, chat history, document upload and per-model settings, and talks to any OpenAI-compatible API. Use it when you or a team want one private chat app on your own domain, paid per use with your own API keys instead of per-seat subscriptions. Open WebUI does not run models itself; on ZoPanel it connects to model providers over the internet.

Requirements

Item Value
Image ghcr.io/open-webui/open-webui:0.11
Memory limit 2048 MB, 1 CPU. The install dialog warns that the app needs about 2 GB of RAM or more.
Free disk to install about 7.9 GB (the image is about 4.7 GB)
Domain a domain or subdomain pointed to the server, for example chat.example.com
API key from at least one provider (OpenAI, Anthropic, DeepSeek, OpenRouter…). You pay the provider directly.

Docker must be installed (App Store → Install Docker). Customers need a package that allows Docker apps and has 2048 MB of RAM (MB) free for apps; see App limits for customers.

Install

  1. Point the domain's A record to the server.

  2. Open App Store and click Install on the Open WebUI card.

  3. Fill in the dialog:

    Field What to enter
    Domain for example chat.example.com, without http://
    Owner Administrators only: the hosting account the app belongs to
    Free SSL (Let's Encrypt) Leave it on
  4. Click Install and follow the task log.

There are no install-time fields; you add API keys inside Open WebUI. ZoPanel sets:

Variable Value
WEBUI_URL https://<your domain>
WEBUI_SECRET_KEY a random key that signs logins, so sessions survive restarts and updates
ENABLE_OLLAMA_API false: an Ollama on the same server is unreachable from the container (see Network limits)

The first start takes one to two minutes or more: Open WebUI prepares its database and downloads the models it uses for document search. While it starts, the site shows a "busy" page that reloads by itself.

Create the admin account behind the setup lock

The first account created in Open WebUI becomes its administrator, so ZoPanel keeps a new install private. Visitors see "This app is being set up".

  1. Open Websites, choose the domain and go to the Docker tab.
  2. When the status is running, click Open the app (only for me).
  3. Click Get started and create the account (name, email, password). It becomes the Admin.
  4. Configure a provider (next section) and sign-ups.
  5. Back on the Docker tab, click Setup finished — open to everyone.

Connect model providers

  1. In Open WebUI, open Admin Panel → Settings → Connections.

  2. Under OpenAI API, click + to add a connection.

  3. Enter the provider's base URL and API key, then save:

    Provider Base URL
    OpenAI https://api.openai.com/v1
    Anthropic (OpenAI-compatible endpoint) https://api.anthropic.com/v1
    DeepSeek https://api.deepseek.com/v1
    OpenRouter https://openrouter.ai/api/v1
  4. Open a new chat and pick a model from the model list. If the list is empty, check the key and the URL.

The keys are stored in Open WebUI's database on your server. Set spending limits in each provider's dashboard: every user's chats are billed to your key.

To reduce memory and CPU use, you can let a provider create document embeddings instead of the local model: Admin Panel → Settings → Documents, change the embedding engine to your OpenAI-compatible provider.

Users and sign-ups

  • Sign-up and the role new users get are set in Admin Panel → Settings → General. With the default role Pending, a new account cannot chat until an admin approves it.
  • Approve people in Admin Panel → Users: change their role from pending to user (or admin).
  • To keep the app for invited people only, turn sign-ups off and add users yourself in Admin Panel → Users.
  • Groups and per-model access control which users see which models.

Check these settings before you open the app to everyone: Open WebUI's sign-up behaviour has changed between versions.

Where your data lives

/var/lib/zopanel-apps/<instance>/data/

<instance> is the domain with dots replaced by hyphens (chat.example.com → chat-example-com). The folder is mounted at /app/backend/data in the container and holds the SQLite database webui.db (users, chats, settings, API connections), uploaded files, the vector database for documents and downloaded model caches. Only root and the container can read it.

Back up

ZoPanel's website backups do not include /var/lib/zopanel-apps; the Backups card on the website's Docker tab backs up the app instead.

To back up Open WebUI, click Back up now on the Backups card of the website's Docker tab. Administrators can also set a Schedule (Off, Every day or Every week; off by default) and how many copies to Keep (1–60, default 7), then click Save. Each backup archives /var/lib/zopanel-apps/<instance>/ into /var/backups/zopanel-apps/<instance>/YYYYMMDD-HHMMSS.tar.gz, a folder only root can read that does not count toward the account's disk quota. The container is paused (not stopped) for the few seconds of the copy, so the SQLite database is consistent. Older copies beyond Keep are removed, and a failed scheduled backup sends administrators the Backup failed alert. The archive includes data/cache with the downloaded models, so it can be large.

To restore, an administrator clicks Restore next to a backup. Open WebUI is stopped and its data replaced with the archive; the current data is kept aside until the restored app starts, and put back if it does not. Changes made since the backup are lost. Each backup also has a delete button (administrators only), and deleting the app together with its files deletes its backups too. Customers can click Back up now and see the list; the schedule and restores are done by the provider. Users can also export their own chats in Settings → Chats.

The archives stay on the same server. Copy important ones off it (for example with scp or rclone from /var/backups/zopanel-apps/<instance>/) and store them encrypted, since they contain your provider API keys. To restore on another server, install Open WebUI on the same domain there, copy the archive into /var/backups/zopanel-apps/<instance>/ on the new server and click Restore on its Backups card.

Update

An administrator clicks Update to latest on the Docker tab. ZoPanel pulls the newest 0.11 image, recreates the container and keeps the data and the secret key. Newer major lines come with ZoPanel updates. Open WebUI migrates its database on start, so take a backup first (Back up now); an update cannot be undone by pulling an older image. Customers ask their provider.

Network limits

Each container is cut off from the server's loopback (127.0.0.1) and private networks, from link-local addresses and from other containers. On the server itself it reaches only ports 80, 443, 25, 465, 587 and DNS. For Open WebUI:

  • Ollama on the same server cannot be used, on localhost, the Docker bridge or the server's public IP (port 11434 is closed to containers). This is why ZoPanel turns the Ollama API off.
  • An Ollama, vLLM or other server on a private network (10.x, 172.16–31.x, 192.168.x, VPN ranges) cannot be used either.
  • Public APIs work: OpenAI, Anthropic, DeepSeek, OpenRouter, Groq, Mistral, or a model server on another machine with a public address. If you run your own model server, protect it with an API key or a reverse proxy before you expose it.
  • Web search, web page loading and tools that fetch URLs reach the public internet only.

Troubleshooting

Problem What to do
"This website is very busy right now" just after installing The app is still starting. Wait a minute or two; the page reloads by itself.
Visitors see "This app is being set up" Click Setup finished — open to everyone on the Docker tab.
No models in the model list Check the connection in Admin Panel → Settings → Connections (base URL ending in /v1, a valid key, credit on the account).
A connection to localhost, host.docker.internal or a private IP fails Blocked by design; use a public endpoint.
A new user sees "pending" Approve them in Admin Panel → Users.
Upload fails for a large file Requests through nginx are limited to the website's upload size (256 MB by default). Raise Maximum upload (MB) on the website's Tools tab → Upload size.
not enough disk space: this app needs about 7.9 GB free… Free disk space, then install again.
Open WebUI needs 2048 MB of memory; your plan has … MB… Ask your provider for more RAM (MB) or remove an app.
The container stops or restarts under load It reached the 2048 MB limit. Use a provider for embeddings and avoid large local document collections.

Read Application output on the Docker tab for errors from the app.


← Vaultwarden OpenClaw →