Authentication
Lakehousecat's authentication system provides user identity management, role-based access control, and optional external identity provider integration.
Core Components
| Component | Description |
|---|---|
| Users | Invite, activate, and manage user accounts |
| Roles | Three production roles: Administrator, Builder, User |
| Groups | Organize users and assign permissions to models, datasources, and content |
| Identity Providers | Optional OAuth/OIDC integration for Single Sign-On |
Default Authentication
By default, users authenticate with an email address and password. Accounts are invitation-based — users cannot self-register. An Administrator must invite each user, who then activates their account via a time-limited email link.
Multi-Factor Authentication
MFA is available to all users and can be configured from Account → Security. Lakehousecat supports TOTP-based MFA compatible with any standard authenticator app (Google Authenticator, Authy, etc.).
Session Tokens
Session tokens are JWT-based. The token lifetime is configurable via the Operator:
spec:
auth:
jwt:
expiresIn: "2d" # e.g., "2d", "24h", "30m"
Access Control
All permissions in Lakehousecat are managed through groups. A user's role defines their baseline capabilities; groups control access to specific objects (Custom Models, Data Sources, Dashboards, Charts).