Skip to main content
Version: 0.0.41

Authentication

Lakehousecat's authentication system provides user identity management, role-based access control, and optional external identity provider integration.

Core Components​

ComponentDescription
UsersInvite, activate, and manage user accounts
RolesThree production roles: Administrator, Builder, User
GroupsOrganize users and assign permissions to models, datasources, and content
Identity ProvidersOptional OAuth/OIDC integration for Single Sign-On

Default Authentication​

By default, users authenticate with an email address and password. Accounts are invitation-based — users cannot self-register. An Administrator must invite each user, who then activates their account via a time-limited email link.

Multi-Factor Authentication​

MFA is available to all users and can be configured from Account → Security. Lakehousecat supports TOTP-based MFA compatible with any standard authenticator app (Google Authenticator, Authy, etc.).

Session Tokens​

Session tokens are JWT-based. The token lifetime is configurable via the Operator:

spec:
auth:
jwt:
expiresIn: "2d" # e.g., "2d", "24h", "30m"

Access Control​

All permissions in Lakehousecat are managed through groups. A user's role defines their baseline capabilities; groups control access to specific objects (Custom Models, Data Sources, Dashboards, Charts).