Skip to content

Workspaces

A workspace holds jobs, runs, secrets, providers, MCP servers and settings, and its members work with them according to their role. Umpteenth runs one workspace for everyone until you turn on workspaces.enabled, and from then on people create their own workspaces and invite each other.

With workspaces.enabled off, the default, everyone who signs in joins the same workspace, named Default. The first person to sign in owns it, and everyone after joins as a member until an admin gives them another role.

To let people have several workspaces, turn the option on in config.yml and restart Umpteenth:

config.yml
workspaces:
enabled: true

The sidebar then shows the workspace switcher at its top. Someone who signs in without an invite gets a workspace of their own, named after them, such as Ada Lovelace’s workspace. An invite takes them straight to the workspace that invited them instead.

On a fresh instance the first person to sign in owns Default, which holds the API key from providers.anthropic_api_key. Every other workspace starts with the Anthropic provider and its models but no API key, so its admins add their own under Settings → Providers & models.

Turning the option off again signs out everyone whose session is in another workspace, and their next sign-in lands in Default, which Umpteenth recreates at start if someone deleted it. The other workspaces keep their data, and their schedules and webhooks keep running, so delete the ones you no longer need before you turn workspaces off.

Role Can
Member Create, change and run jobs, cancel and retry runs, manage secrets and MCP servers, and create API tokens of their own. Members see the providers, the settings and the member list without changing them.
Admin Everything a member can, and change providers, models and Settings → General, rename the workspace, invite and remove members, change their roles, and see and revoke every API token of the workspace.
Owner Everything an admin can, and delete the workspace or hand it over to another member. A workspace has one owner.

A member who tries something above their role gets “Only admins of the workspace can do this”.

With workspaces on, admins invite people under Settings → Members with Invite. The Invite to workspace dialog offers two kinds of invite:

  • Enter an Email and click Invite. Someone who signed in before with that address joins right away, and anyone else joins the next time they sign in with it.
  • Leave Email empty and click Create link. Umpteenth shows the link once, in the Invite link created dialog, and it works for whoever opens it first.

Pick the Role, Member or Admin, and under Expires after how long the invite lasts: 1, 7 or 30 days. Nobody joins as owner, since ownership only changes hands.

Email invites match an address only when the sign-in provider vouches for it: an OpenID Connect provider through the email_verified claim, and GitHub through the account’s verified addresses. An identity provider that leaves out email_verified can’t pick up email invites, so send its users a link.

Opening a link shows Join and the workspace’s name, with the role and who sent the invite, and Join workspace joins. Someone who opens it before signing in joins as part of signing in. A member who opens a link leaves it unused, so you can still pass it on to the person it was meant for.

Pending invites on the same page lists the email invites and unused links with their role and expiry, and the trash icon revokes one. Inviting an address again renews its invite with the new role and expiry.

Admins change a member’s role in the Role column of Settings → Members, and the change applies to that member’s next request, open pages and API tokens included. The … menu of a member offers Remove from workspace, which ends their access and stops the API tokens they created in the workspace.

The owner finds Make owner in the same menu. It makes that member the owner and you an admin, and it’s the only way the owner role changes.

With workspaces off, Remove from workspace is missing, since everyone joins again at their next sign-in. Deactivate the user under Admin → Users or at your sign-in provider instead.

Click the workspace at the top of the sidebar for the list of your workspaces, Create workspace and Members and settings. Switching opens the dashboard of the other workspace, once you save or discard any unsaved changes on the page. Your next sign-in lands in the workspace you used last.

Links in notifications name the run’s workspace, and opening one switches to it if you’re a member.

Admins and members leave a workspace with Leave workspace under Settings → General → Danger zone. The owner sees Delete workspace there instead, and hands the workspace over first to leave it. Leaving your last workspace gives you a new one of your own.

Deleting removes every job, run, secret, provider and MCP server in the workspace, and its members lose access. Umpteenth refuses while runs are active, with “The workspace has 2 active runs, wait for them to finish or cancel them first”. It deletes the runs’ files and build logs in the background afterwards.

Instance admins see everyone who signed in and every workspace, under Admin in the sidebar. You make someone an instance admin in the options of the provider they sign in with, as Sign-in shows.

Admin → Users lists every user with their workspace count and last sign-in. Deactivate signs a user out everywhere, stops their API tokens and refuses their sign-ins with “Your account has been deactivated, ask an admin to reactivate it”. Their memberships stay, so Reactivate restores their access.

Admin → Workspaces appears with workspaces on and lists every workspace with its owner and member count. Open switches you to a workspace without joining it, and the trash icon deletes one.

An instance admin has the owner’s rights in every workspace, while their API tokens get only the role of their membership.

A token acts with its creator’s role in its workspace, and it stops working once the creator leaves the workspace or an admin removes or deactivates them. REST API lists what a token can’t do.