English
Admin
IPA Harbor admin account, Passkeys, and the Settings page. Paths match Feature guide; Apple ID (ipatool) sign-in is covered in Apple ID login troubleshooting.
Setup
On first visit to a new container, open /setup to create the IPA Harbor admin account.
Init PIN
You must enter ADMIN_INIT_PIN from your docker run / Compose environment (or from the deploy wizard output).
- Local trials often use a documented default — change it for any public deployment
- Store the PIN safely; it is used for recovery flows
After setup
- Sign in at
/loginwith the username and password you chose - Optional: register a Passkey in Settings (the
/settingspage) - Bind an Apple ID in the web UI for ipatool downloads (see Apple ID login troubleshooting for sign-in and network notes)
Recovery
For the full forgot-password flow (ADMIN_RECOVERY_ENABLED, /recover, init PIN), see Forgot admin password.
Passkey login
Passkey (WebAuthn) is optional for IPA Harbor admin login. Password login remains available. Apple ID login is unchanged.
Requirements
- Secure context: HTTPS in production, or
http://localhostfor development. - Matching Origin in both
ALLOWED_DOMAINSandWEBAUTHN_ALLOWED_ORIGINS.
Minimum configuration
| Variable | Description |
|---|---|
WEBAUTHN_RP_ID | Site domain without port, e.g. example.com |
WEBAUTHN_ALLOWED_ORIGINS | Comma-separated list, e.g. https://example.com,http://localhost:5173 |
Origins must match the browser address bar exactly (scheme, host, port).
CORS and WebAuthn
If the page loads but Passkey register/login fails, compare ALLOWED_DOMAINS with WEBAUTHN_ALLOWED_ORIGINS.
Management
After setup, add or remove Passkeys in Settings. You cannot delete the last Passkey if it would leave you with no sign-in method.
Localhost
When the Origin is http://localhost:*, the RP ID is localhost, not your production domain.
Settings
Signed-in admins can change IPA Harbor behavior from /settings (Settings in the nav).
Common options
| Area | Notes |
|---|---|
| Store region / language | Affects search and display |
| OTA install | Enable Safari install; requires HTTPS — OTA install |
| App screenshots | Optional loading of screenshot assets |
| Passkeys | Add/remove admin Passkeys — see Passkey login above |
| Version info | IPA Harbor app version; expand to see probed ipatool version from /v1/admin/status |
| Check for updates | Compares running image tag with Docker Hub (IPA Harbor release, not App Store) |
Apple ID vs admin
Apple ID session (ipatool) is separate from admin JWT. Logging out of one does not always log out the other.