Skip to content

Admin ​

IPA Harbor admin account, Passkeys, and the Settings page. Paths match Feature guide; Apple ID (ipatool) sign-in is covered in Apple ID login troubleshooting.

Setup ​

On first visit to a new container, open /setup to create the IPA Harbor admin account.

Init PIN ​

You must enter ADMIN_INIT_PIN from your docker run / Compose environment (or from the deploy wizard output).

  • Local trials often use a documented default — change it for any public deployment
  • Store the PIN safely; it is used for recovery flows

After setup ​

  • Sign in at /login with the username and password you chose
  • Optional: register a Passkey in Settings (the /settings page)
  • Bind an Apple ID in the web UI for ipatool downloads (see Apple ID login troubleshooting for sign-in and network notes)

Recovery ​

For the full forgot-password flow (ADMIN_RECOVERY_ENABLED, /recover, init PIN), see Forgot admin password.

Passkey login ​

Passkey (WebAuthn) is optional for IPA Harbor admin login. Password login remains available. Apple ID login is unchanged.

Requirements ​

  • Secure context: HTTPS in production, or http://localhost for development.
  • Matching Origin in both ALLOWED_DOMAINS and WEBAUTHN_ALLOWED_ORIGINS.

Minimum configuration ​

VariableDescription
WEBAUTHN_RP_IDSite domain without port, e.g. example.com
WEBAUTHN_ALLOWED_ORIGINSComma-separated list, e.g. https://example.com,http://localhost:5173

Origins must match the browser address bar exactly (scheme, host, port).

CORS and WebAuthn

If the page loads but Passkey register/login fails, compare ALLOWED_DOMAINS with WEBAUTHN_ALLOWED_ORIGINS.

Management ​

After setup, add or remove Passkeys in Settings. You cannot delete the last Passkey if it would leave you with no sign-in method.

Localhost ​

When the Origin is http://localhost:*, the RP ID is localhost, not your production domain.

Settings ​

Signed-in admins can change IPA Harbor behavior from /settings (Settings in the nav).

Common options ​

AreaNotes
Store region / languageAffects search and display
OTA installEnable Safari install; requires HTTPS — OTA install
App screenshotsOptional loading of screenshot assets
PasskeysAdd/remove admin Passkeys — see Passkey login above
Version infoIPA Harbor app version; expand to see probed ipatool version from /v1/admin/status
Check for updatesCompares running image tag with Docker Hub (IPA Harbor release, not App Store)

Apple ID vs admin ​

Apple ID session (ipatool) is separate from admin JWT. Logging out of one does not always log out the other.