Skip to main content
Gradio provides several ways to add authentication to your app, from simple password protection to OAuth integration with Hugging Face and external providers.

Password-protected apps

You can add an authentication page in front of your app to limit who can access it. With the auth= keyword argument in the launch() method, you can provide a tuple with a username and password, or a list of acceptable username/password tuples.

Single user authentication

Here’s an example that provides password-based authentication for a single user named “admin”:

Multiple users

For multiple users, provide a list of tuples:

Custom authentication function

For more complex authentication handling, pass a function that takes a username and password as arguments and returns True to allow access, False otherwise. Here’s an example of a function that accepts any login where the username and password are the same:

User-specific content

If you have multiple users, you may wish to customize the content shown depending on the logged-in user. You can retrieve the logged-in user by accessing the network request directly and reading the .username attribute:

Logout functionality

If users visit the /logout page of your Gradio app, they will automatically be logged out and session cookies deleted. This allows you to add logout functionality to your app:
By default, visiting /logout logs the user out from all sessions (e.g., if they are logged in from multiple browsers or devices). To log out only from the current session, add the query parameter all_session=false (i.e., /logout?all_session=false).
Gradio’s built-in authentication provides a straightforward and basic layer of access control but does not offer robust security features for applications that require stringent access controls (e.g., multi-factor authentication, rate limiting, or automatic lockout policies).
For authentication to work properly, third-party cookies must be enabled in your browser. This is not the case by default for Safari or Chrome Incognito Mode.

OAuth with Hugging Face

Gradio natively supports OAuth login via Hugging Face. This allows you to easily add a “Sign in with Hugging Face” button to your demo, which gives you access to the user’s HF username and other profile information.

Setting up OAuth

To enable OAuth, you must set hf_oauth: true as a Space metadata in your README.md file. This registers your Space as an OAuth application on Hugging Face.

Adding login button

Next, use gr.LoginButton to add a login button to your Gradio app:

Accessing user profile

Once a user is logged in, you can retrieve their profile by adding a parameter of type gr.OAuthProfile to any Gradio function. The user profile will be automatically injected:

Accessing user token

If you want to perform actions on behalf of the user (e.g., list user’s private repos, create repo, etc.), you can retrieve the user token by adding a parameter of type gr.OAuthToken:
You must define which scopes you will use in your Space metadata. See the Hugging Face documentation for more details on available scopes.

Local development with OAuth

OAuth features are only available when your app runs in a Space. However, you can test OAuth features locally by logging in to Hugging Face on your machine:
Or set the HF_TOKEN environment variable with one of your access tokens. You can generate a new token in your settings page.
Adding a gr.LoginButton does not restrict users from using your app. Users who have not logged in with Hugging Face can still access and run events in your Gradio app - the difference is that the gr.OAuthProfile or gr.OAuthToken will be None in the corresponding functions.

OAuth with external providers

It is also possible to authenticate with external OAuth providers (e.g., Google OAuth) in your Gradio apps. To do this, you must first mount your Gradio app within a FastAPI app.

Authentication dependency

You must write an authentication function that gets the user’s username from the OAuth provider and returns it. This function should be passed to the auth_dependency parameter in gr.mount_gradio_app. The function should:
  • Accept a single parameter: the FastAPI Request
  • Return either a string (representing a user’s username) or None
  • If a string is returned, the user will be able to access the Gradio app
  • If None is returned, access will be denied

Simple example

Here’s a simplistic example:

Google OAuth example

Here’s a more complete example showing how to add Google OAuth to a Gradio app:
In this example, there are two separate Gradio apps:
  1. A login demo that displays a login button (accessible to any user)
  2. The main demo that is only accessible to logged-in users
You can try this example out on this Space.