Password-protected apps
You can add an authentication page in front of your app to limit who can access it. With theauth= keyword argument in the launch() method, you can provide a tuple with a username and password, or a list of acceptable username/password tuples.
Single user authentication
Here’s an example that provides password-based authentication for a single user named “admin”:Multiple users
For multiple users, provide a list of tuples:Custom authentication function
For more complex authentication handling, pass a function that takes a username and password as arguments and returnsTrue to allow access, False otherwise.
Here’s an example of a function that accepts any login where the username and password are the same:
User-specific content
If you have multiple users, you may wish to customize the content shown depending on the logged-in user. You can retrieve the logged-in user by accessing the network request directly and reading the.username attribute:
Logout functionality
If users visit the/logout page of your Gradio app, they will automatically be logged out and session cookies deleted. This allows you to add logout functionality to your app:
/logout logs the user out from all sessions (e.g., if they are logged in from multiple browsers or devices). To log out only from the current session, add the query parameter all_session=false (i.e., /logout?all_session=false).
For authentication to work properly, third-party cookies must be enabled in your browser. This is not the case by default for Safari or Chrome Incognito Mode.
OAuth with Hugging Face
Gradio natively supports OAuth login via Hugging Face. This allows you to easily add a “Sign in with Hugging Face” button to your demo, which gives you access to the user’s HF username and other profile information.Setting up OAuth
To enable OAuth, you must sethf_oauth: true as a Space metadata in your README.md file. This registers your Space as an OAuth application on Hugging Face.
Adding login button
Next, usegr.LoginButton to add a login button to your Gradio app:
Accessing user profile
Once a user is logged in, you can retrieve their profile by adding a parameter of typegr.OAuthProfile to any Gradio function. The user profile will be automatically injected:
Accessing user token
If you want to perform actions on behalf of the user (e.g., list user’s private repos, create repo, etc.), you can retrieve the user token by adding a parameter of typegr.OAuthToken:
You must define which scopes you will use in your Space metadata. See the Hugging Face documentation for more details on available scopes.
Local development with OAuth
OAuth features are only available when your app runs in a Space. However, you can test OAuth features locally by logging in to Hugging Face on your machine:HF_TOKEN environment variable with one of your access tokens. You can generate a new token in your settings page.
OAuth with external providers
It is also possible to authenticate with external OAuth providers (e.g., Google OAuth) in your Gradio apps. To do this, you must first mount your Gradio app within a FastAPI app.Authentication dependency
You must write an authentication function that gets the user’s username from the OAuth provider and returns it. This function should be passed to theauth_dependency parameter in gr.mount_gradio_app.
The function should:
- Accept a single parameter: the FastAPI
Request - Return either a string (representing a user’s username) or
None - If a string is returned, the user will be able to access the Gradio app
- If
Noneis returned, access will be denied
Simple example
Here’s a simplistic example:Google OAuth example
Here’s a more complete example showing how to add Google OAuth to a Gradio app:- A login demo that displays a login button (accessible to any user)
- The main demo that is only accessible to logged-in users