> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aseeflow.org/llms.txt
> Use this file to discover all available pages before exploring further.

# Form-Based Authentication

Form-based authentication replaces the browser's Basic dialog with a custom, branded login page. Credentials are validated against the ASEE Flow engine's Identity Service.

## Dependency

```xml theme={null}
<dependency>
  <groupId>org.springframework.boot</groupId>
  <artifactId>spring-boot-starter-security</artifactId>
</dependency>
```

This dependency is `provided` in the starter, so include it explicitly.

## Configuration

```yaml theme={null}
aseeflow:
  webadmin:
    authentication: form
```

## How it works

Unauthenticated users are redirected to the custom login page at `/aseeflow-login.html`. Credentials are submitted to `/webadmin-login`; a successful login redirects to `/webadmin`, and a failed one returns to `/aseeflow-login.html?error`.

Two separate filter chains are used — one for the WebAdmin UI (form login) and one for the REST API. The login page, its logo, and the login endpoint are reachable anonymously; everything else under the base path requires authentication. REST endpoints (`/engine-rest/**`) are protected by default and return `401` when unauthenticated; since 1.0.2 they accept the login session and HTTP Basic, so programs can call them too. Set `disable-rest-security: true` to disable — only when REST is secured elsewhere ([consequences](/webadmin/security#never-leave-the-engine-rest-api-unprotected)). Logout invalidates the session and returns to the login page.

## When to use it

Form authentication suits production web applications that want a user-friendly, branded login, and internal portals where users expect a traditional web login. It is also easy to swap for enterprise SSO ([OAuth2](/webadmin/authentication/oauth2) or [Keycloak](/webadmin/authentication/keycloak)) later.

It needs WebAdmin to serve the engine REST API itself — your Spring Boot application or ASEE Flow Run. On the Tomcat and WildFly distributions the REST API is a separate WAR that doesn't know WebAdmin's session: once you protect it, use `basic`, `oauth2` or `keycloak` there ([Production hardening](/installation/production-hardening#tomcat-and-wildfly)).

## Properties

| Property | Type | Default | Description |
| - | - | - | - |
| `aseeflow.webadmin.authentication` | String | `form` (since 1.0.2) | Set to `form` to enable this mode. |
| `aseeflow.webadmin.disable-rest-security` | Boolean | `false` | When `true`, REST endpoints are reachable without authentication — only safe when secured elsewhere; see [REST security](/webadmin/security#never-leave-the-engine-rest-api-unprotected). |


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.