> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aseeflow.org/llms.txt
> Use this file to discover all available pages before exploring further.

# WebAdmin Authentication

WebAdmin ships with four authentication modes. Select one with the `aseeflow.webadmin.authentication` property; each mode activates its own pre-configured Spring Security filter chains for the UI and the REST API.

```yaml theme={null}
aseeflow:
  webadmin:
    authentication: basic   # basic | form | oauth2 | keycloak
```

## Choosing a mode

| Mode | Best for | Login experience |
| - | - | - |
| [Basic](/webadmin/authentication/basic) | Development, internal tools, API clients | Browser HTTP Basic dialog |
| [Form](/webadmin/authentication/form) | Production web UIs needing a branded login | Custom login page |
| [OAuth2](/webadmin/authentication/oauth2) | Enterprise SSO with any OIDC provider | Redirect to your identity provider |
| [Keycloak](/webadmin/authentication/keycloak) | Keycloak SSO with full user/group sync | Redirect to Keycloak |

Basic and Form validate credentials against the engine's [Identity Service](/user-guide/process-engine/identity-service). OAuth2 and Keycloak delegate authentication to an external identity provider; Keycloak adds an identity provider plugin that synchronizes users and groups into the engine.

## Common notes

* **REST security** is enabled by default in every mode. Setting `aseeflow.webadmin.disable-rest-security: true` leaves `/engine-rest/**` unprotected — only safe when another layer secures it (for example a separate WAR — see [Deployment](/webadmin/deployment)). Understand the consequences first: [Never leave the engine REST API unprotected](/webadmin/security#never-leave-the-engine-rest-api-unprotected).
* The required security dependencies are declared as `provided` in the starter, so you must add them explicitly in your application. Each mode's page lists what it needs.
* For OAuth2 and Keycloak, the `user-name-attribute` and group claim settings are critical — they map identity-provider users and groups onto engine user and group IDs that your [authorizations](/user-guide/process-engine/authorization-service) rely on.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.