ApiaryActiveLive
Try: pause · settings · learn · wipe
← Community / Reading Room
OW
craft · 14 min read

Open WebUI + Ollama Setup for Beginners

Companion pieces:

By Austin Little

Ollama gives you local models. A terminal chat proves they work. Most people still want a browser window that feels like a normal chat app — model picker, history, a place to drop a file. Open WebUI is the open-source front end beginners ask for. This guide walks a free, local-first setup: Ollama on the machine, Open WebUI from official docs, first admin account, first message — without a paid plan, without deploying to the public internet, and without pretending version numbers never move.

AI disclosure. This page was drafted with AI assistance and edited for Apiary. We don't invent quotes, stats, people, or events. If something looks off, tell Austin — that's the point of a living hive.

What you are building (and what you are not)

Building: a chat UI on your computer that talks to models running through Ollama on the same machine (or a machine you control). Chats and settings live in a local data volume or data directory you control.

Not building: a public website for strangers, a guaranteed HIPAA setup, or a one-click "enterprise" mesh. Keeping the UI on localhost is a feature for beginners.

Not requiring: a credit card, a cloud AI subscription, or Apiary to be online. This stack works offline for inference after models are downloaded (update checks and first pulls still want network).

Companion pieces:

Prerequisites (honest)

  • A computer from the last several years (see RAM notes below)
  • Permission to install software (your machine, not a locked school laptop without approval)
  • For the recommended path: Docker installed and running (Docker Desktop on Windows/Mac is the usual beginner route)
  • Willingness to copy commands carefully from official docs when tags change

RAM / disk reality:

  • 8GB RAM: small models only; close browsers; Open WebUI itself needs some RAM on top of the model
  • 16GB: comfortable for many writing-sized models
  • 32GB+: room to grow
  • Disk: leave multi-gigabyte free for models plus Docker images

If Docker feels like too much on day one, Open WebUI also documents a Python install (pip install open-webui then open-webui serve) and other methods. Docker is what their quick start recommends for most people.

Step 1 — Install Ollama first

Open WebUI does not ship your brain. Ollama (or another provider you configure) does.

  1. Go to ollama.com and download for macOS, Windows, or Linux.
  2. Install and open the app (on Linux, ollama serve if the server is not already running — see Ollama docs).
  3. Pull a starter model from a terminal:
ollama pull <model-tag-from-current-docs>

Official quickstart examples move.

  1. Prove chat works:
ollama run <model-tag-from-current-docs>

Type a sentence. Get a reply. Type /bye to leave. If this fails, fix Ollama before you touch Open WebUI. A pretty UI cannot rescue a missing model server.

Default local API endpoint: http://localhost:11434.

Step 2 — Pick an Open WebUI install method

From the Open WebUI Quick Start:

  • Docker — officially supported and recommended for most users
  • Python — fine for lighter or manual setups (Python 3.11/3.12 per their docs; 3.13 called out as not supported yet at time of docs fetch)
  • Kubernetes / Helm — overkill for a beginner home chat
  • Desktop app / Pinokio — exists; production-minded folks still pointed at Docker or Python

Beginners on one home computer: Docker.

Generate a secret key (do this once)

Open WebUI docs tell you to set WEBUI_SECRET_KEY and keep it stable. Without a fixed key, recreating the container can log everyone out. Their documented generator:

openssl rand -hex 32

Save the output in your password manager. You will paste it into the docker run or Compose file.

Step 3 — Docker run (standard beginner command pattern)

Official pattern (from Open WebUI quick start): pull/start the ghcr.io/open-webui/open-webui:main image, map port 3000 on your machine to 8080 in the container, mount a named volume for data, allow the container to reach Ollama on the host, set the secret key, restart policy on.

Illustrative command shape (replace the secret; confirm against current docs before you paste into production habits):

docker run -d -p 3000:8080 \
  --add-host=host.docker.internal:host-gateway \
  -v open-webui:/app/backend/data \
  -e WEBUI_SECRET_KEY=YOUR_SECRET_HERE \
  --name open-webui \
  --restart always \
  ghcr.io/open-webui/open-webui:main

What the important flags mean (per their docs table):

Docker Compose alternative

Their docs also show a Compose file with the same port, volume, extra_hosts for host.docker.internal, and WEBUI_SECRET_KEY. Flow:

  1. Save docker-compose.yml with the official skeleton
  2. Put your secret in the environment section
  3. docker compose up -d
  4. Update later with docker compose pull then docker compose up -d

Compose is easier to re-read six months later than a long docker run buried in shell history.

Bundled :ollama image (optional)

Open WebUI publishes an :ollama tag that bundles Ollama inside the same container, with volume mounts for both Ollama data and WebUI data. Useful if you want one container. Many beginners still prefer Ollama on the host + WebUI in Docker because Ollama's native install is simple and easy to debug alone. Either way, follow the current official command block — do not mix half of one path with half of the other.

GPU notes

Nvidia users can use the :cuda image and --gpus all (Docker) when the host is set up for it. Apple Silicon users typically run CPU/Metal via host Ollama rather than expecting Nvidia flags to apply. If GPU setup fails, CPU Ollama still works; it is just slower.

Step 4 — Open the UI and create the admin account

  1. Wait a minute on first start. Docs say to watch logs until you see startup complete if the page is blank: docker logs -f open-webui
  2. Browse to http://localhost:3000 (Docker) — Python installs often use http://localhost:8080
  3. First screen: create the admin account. That first account owns instance-wide settings.
  4. Sign-up for others is off until an admin enables it. For a solo beginner machine, leave extra sign-ups off.

Lose the admin password and you lock yourself out of instance settings — their docs point to a reset path; do not improvise by deleting the volume unless you accept losing chats.

Step 5 — Connect Ollama and pull a model from the UI

Open WebUI has no models of its own. As admin:

  1. Avatar → Settings → Admin → Connections
  2. Ollama on the same machine should be reachable at http://host.docker.internal:11434 from Docker (that is why the add-host flag exists) or http://localhost:11434 from a Python install on the host
  3. If the model list is empty, confirm Ollama is running and — when WebUI is in Docker — that Ollama is listening in a way the container can reach (their troubleshooting docs cover binding issues)
  4. Start a New Chat, pick a model, type, Enter

Admin can also pull models by typing a model name into the selector and confirming the pull when the UI offers it — still subject to disk and RAM.

Optional: cloud providers later

You can add OpenAI-compatible endpoints with a key under Connections. That is not private anymore for those prompts. Beginners who came for privacy should leave cloud connections empty until they read How to Keep AI Chats Private (Local First).

Step 6 — First-week settings that matter

Keep week one boring:

  • Theme / language under your personal settings — cosmetic
  • Do not enable network sharing until you understand authentication
  • Do not turn on every plugin on day one
  • Do send one private-ish test prompt (a journal sentence) and confirm you did not configure a cloud key
  • Do export or copy a useful reply into notes you control if it matters long-term

Advanced features (RAG, web search, tools, code interpreter) are documented in their "essentials" pages. Add them after plain chat feels solid. Each feature is another moving part and sometimes another outbound call.

Updating without losing chats

Per Open WebUI docs themes:

  1. Keep the same volume / data directory
  2. Keep the same WEBUI_SECRET_KEY
  3. Manual Docker update pattern: remove container → pull image → run again with the same flags/volume/secret
  4. Or use their documented Watchtower one-shot against the container name
  5. Back up the volume before spicy updates if the chats matter

Dev channel warning: :dev is a pre-release/nightly-style tag. Docs warn not to share a data volume between :dev and :main because migrations may not roll back cleanly. Beginners: stay on :main or a pinned version tag until you have a reason.

Python fallback (no Docker)

If Docker is blocked:

  1. Use Python 3.11 (or 3.12 per their compatibility notes)
  2. pip install open-webui
  3. open-webui serve
  4. Open http://localhost:8080
  5. Set DATA_DIR if you want a predictable data path (especially with uvx-style runners — their docs warn temp dirs can vanish)

Update with pip install -U open-webui, then restart. If you ever run multiple workers, their docs require migrating with a single worker first — advanced; solo beginners can ignore until they scale.

Windows notes (short)

  • Docker Desktop with WSL2 backend is the path their WSL section describes
  • Run docker commands from the WSL terminal when that is how Docker is wired
  • Ollama also has a native Windows install — get it healthy first
  • Do not fight three virtualization layers on a machine that barely has RAM; size the model down instead

Security baseline for beginners (localhost only)

  1. Keep the UI on localhost unless you have a hardening plan
  2. Strong admin password
  3. Disable open sign-ups
  4. Do not publish port 3000 to the public internet from your router "just to try from work"
  5. Treat plugins/tools as code execution risks — enable deliberately
  6. Same privacy rules card as the privacy article: no bank passwords in chats

If you later share on a home LAN, read Open WebUI's own sharing/hardening docs first. This Apiary page stops at beginner localhost on purpose — no deploy.

Troubleshooting quick list

SymptomLikely fix
Page never loadsWait for startup; docker logs -f open-webui; check port conflict
No models in selectorOllama not running; wrong base URL; container cannot reach host
Replies empty behind a proxyWebSocket issues — out of beginner scope; use plain localhost first
Logged out after every updateWEBUI_SECRET_KEY not set or changed
Disk fullOld models + Docker images; prune deliberately (ollama list, Docker system df)
Fan loud / crawl speedModel too big for RAM; pull a smaller tag

What success looks like

  • Ollama answers in a terminal
  • Open WebUI loads on localhost
  • You are admin
  • A local model appears in the picker
  • A normal English prompt gets a reply
  • No cloud key required for that reply
  • Volume persists if you restart the container

That is the whole beginner win. Everything else is optional craft.

How this fits Apiary's free bias

Apiary cares about BYO-LLM: the site should not trap you inside one rented brain. Open WebUI + Ollama is the same idea at the desktop layer — your models, your disk, your choice to add a cloud key later or never. Paid tiers remain optional for hard jobs; they are not the door tax for a usable chat window.

Practice prompts to confirm the install

Try these once on local:

  1. "Rewrite this paragraph clearer, keep my meaning: …"
  2. "Turn these bullets into a polite email draft: …"
  3. "Explain this error message in plain English: …" (scrub secrets)
  4. "Give me five title options for a blog post about local AI privacy."

If (1)–(4) work, you are ready to use the stack for real drafts. Fact-check anything important; local does not mean true.

Uninstall cleanly (if you are just testing)

Docker path theme from their docs:

  1. docker rm -f open-webui
  2. Optional: remove image
  3. Optional: docker volume rm open-webui — deletes chats and settings

Compose: docker compose down and only add -v if you intend to wipe data.

Leave Ollama installed if you still want terminal models without the UI.

FAQ

Is Open WebUI free? The software is open-source to run yourself. You pay in electricity, disk, and your time. Hosted third parties may charge; this guide is self-host local.

Do I need a GPU? No. GPU helps speed. CPU works.

Can I use this on a phone? You can open http://localhost:3000 only on the same machine. Phones on the same Wi-Fi need careful LAN sharing and hardening — not beginner homework for day one.

Is this private? Local inference with no cloud keys is private-er. Still lock your OS user, watch sync folders, and read the privacy companion article.

Docker Desktop wants an account — is that a paywall for AI? Docker's installer/account policies change; Open WebUI itself is not a $20/month chat subscription. If Docker is blocked, use the Python path from official docs.

Why not only LM Studio / other GUIs? Other local UIs are fine. This article answers the specific "Open WebUI + Ollama" search with official Open WebUI steps. Pick one home base so you are not debugging three wrappers.

Will Apiary deploy this for me? No. This is a reader DIY guide.

Cross-links

Sources (verify on publish)

  • Open WebUI Quick Start: https://docs.openwebui.com/getting-started/quick-start/
  • Ollama Quickstart: https://docs.ollama.com/quickstart

Walkthrough: from zero to first reply (narrative)

Here is the same install as a story, for readers who hate flag tables.

You sit down with a laptop that has about 16GB of RAM and twenty gigabytes free. You download Ollama from the official site and install it. You open Terminal or PowerShell, pull a small model using whatever tag the current Ollama quickstart shows, and run it. You ask it to rewrite a sentence you typed. It answers. You quit. The engine works.

Next you install Docker Desktop (or you already have it). You generate a hex secret with openssl rand -hex 32 and paste it into a password manager labeled "Open WebUI secret." You copy the official docker run block from Open WebUI’s quick start, substitute the secret, and start the container. You wait until logs look healthy. You open http://localhost:3000, create the admin user with a strong password, and ignore every temptation to expose the port to the world.

Under Admin → Connections you confirm Ollama is listed. You start a new chat, select the model you already pulled, and ask for five subject lines for an email you will send tomorrow. The reply appears in the browser instead of the terminal. You copy the best line into your real mail draft. You did not create a cloud AI account. You did not enter a card. You did not deploy anything.

That afternoon is the whole product for most people.

Choice guide: Docker vs Python vs bundled image

Choose Docker if you are willing to install Docker and want the path Open WebUI documents first. Updates are image pulls. Data lives in a named volume.

Choose Python if Docker is forbidden on your machine but you can install Python 3.11 and pip packages. Data lives under DATA_DIR or the default data path they document. You must remember which virtualenv you used.

Choose the bundled :ollama image if you want one container and you accept debugging Ollama and WebUI as a pair. Read the official GPU vs CPU command blocks carefully — they differ.

Choose "not yet" if your machine has 4GB of RAM and a spinning disk that is already full. Free upgrades: delete unused downloads, or use a free cloud tier for non-private work until hardware catches up. Local UI will only frustrate you on a starved box.

Model hygiene after the UI feels good

A friendly UI makes it easy to pull five huge models "to try." Then the disk dies.

Habits:

  1. Prefer one small and one medium model until you know your RAM
  2. Remove models you have not used in a month (ollama list then delete with the current CLI delete command from Ollama docs)
  3. Do not pull a 70B-class weight on an 8GB machine because a YouTube thumbnail dared you
  4. Keep a sticky note of which model is for "fast draft" vs "slower better rewrite"

Quality is not linear with size on every task. A too-big model that swaps forever feels worse than a small model that answers now.

Family helper sticky note (optional)

If you installed this for a relative:

  1. Open the bookmark: http://localhost:3000
  2. Use the account we created
  3. Pick the model named ___
  4. Type normal English
  5. Never type bank or Medicare numbers
  6. If it breaks, call ___

Pair with the dignity guide: AI for Grandparents: Free, Safe, and Actually Useful.

What we deliberately skipped

  • Kubernetes Helm values
  • Docker Swarm stacks with external Chroma
  • Putting Open WebUI on a public VPS
  • Reverse proxies and TLS termination
  • Multi-replica Redis requirements

Those are real topics for operators. They are not beginner setup. If a tutorial tells you to open firewall ports to the whole internet on day one, close that tab and come back to localhost.

Recap checklist (print)

  • [ ] Ollama installed and ollama run works
  • [ ] Docker running (or Python path chosen)
  • [ ] WEBUI_SECRET_KEY saved
  • [ ] Container/compose up with data volume
  • [ ] http://localhost:3000 (or 8080) loads
  • [ ] Admin account created
  • [ ] Ollama connection visible
  • [ ] First local chat reply received
  • [ ] No unnecessary cloud keys added
  • [ ] Privacy rules card nearby

Closing

You do not need a subscription to get a calm chat window on top of local models. Install Ollama, run Open WebUI from official docs, keep it on localhost, create the admin account, connect the local API, send one message. When the UI feels friendly, the privacy rules from the companion article become easier to keep — because the private path is finally as convenient as the postcard cloud.

Frequently asked
Is Open WebUI free?
The software is open-source to run yourself. You pay in electricity, disk, and your time. Hosted third parties may charge; this guide is self-host local.
Do I need a GPU?
No. GPU helps speed. CPU works.
Can I use this on a phone?
You can open `http://localhost:3000` only on the same machine. Phones on the same Wi-Fi need careful LAN sharing and hardening — not beginner homework for day one.
Is this private?
Local inference with no cloud keys is private-*er*. Still lock your OS user, watch sync folders, and read the privacy companion article.
Docker Desktop wants an account — is that a paywall for AI?
Docker's installer/account policies change; Open WebUI itself is not a $20/month chat subscription. If Docker is blocked, use the Python path from official docs.
References & sources
  1. Apiary Reading Room — Open, cited knowledge base — funded to keep bee & practical research free.
From the Apiary Reading Room. Opinion & editorial — not financial advice. We don't overclaim.
More from the Reading Room