# Authentication for Web Admin page

**URL:** <https://forums.screenly.io/t/authentication-for-web-admin-page/207>\
**Category:** Anthias\
**Created:** [December 6, 2019, 4:55am UTC](https://forums.screenly.io/t/authentication-for-web-admin-page/207 "2019-12-06T04:55:29Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sky\_Paladin](https://avatars.discourse-cdn.com/v4/letter/s/57b2e6/32.png) [@Sky\_Paladin](https://forums.screenly.io/u/Sky_Paladin)\
**Post date:** [December 6, 2019, 4:55am UTC](https://forums.screenly.io/t/authentication-for-web-admin-page/207/1 "2019-12-06T04:55:29Z")

</div>

I’m trying to protect the Web Admin page (where you can set what assets to play, apply some settings, etc).

Reading the instructions, my understanding is I should be able to modify the ~/.screenly/screenly.conf file and amend the basic auth section to something like this:

```
[auth_basic]
password = world
user = hello

```

However after stopping the service and rebooting, nothing appears to have changed.

I’ve also found this website ([http://g9online.blogspot.com/2015/08/using-raspberry-pi-and-screenly-ose-as.html](http://g9online.blogspot.com/2015/08/using-raspberry-pi-and-screenly-ose-as.html)) that proposes replacing the existing server.py with another file from elsewhere. However it seems that server.py is quite old and when I tried that alternate option, the player stalled before the screenly log in screen.

It seems there must be another step I’m missing. Can anybody who has got their basic auth working please tell me what they did? Thank you.

---

<div class="post-metadata">

**Author:** ![Sky\_Paladin](https://avatars.discourse-cdn.com/v4/letter/s/57b2e6/32.png) [@Sky\_Paladin](https://forums.screenly.io/u/Sky_Paladin)\
**Post date:** [December 9, 2019, 11:14pm UTC](https://forums.screenly.io/t/authentication-for-web-admin-page/207/2 "2019-12-09T23:14:22Z")

</div>

I have been able to come to a satisfactory outcome using the sites-enabled section of the nginx platform that Screenly operates with.

The solution is shamelessly taken [here](https://www.digitalocean.com/community/tutorials/how-to-set-up-password-authentication-with-nginx-on-ubuntu-14-04) and presented in full with context below.

1 - Create a password file with Apache 2 utils;

> sudo apt-get update  
> sudo apt-get install apache2-utils  
> sudo htpasswd -c /etc/nginx/.htpasswd sammy

Substitute ‘sammy’ for whatever account name you wish to use. Upon executing this statement you will be asked to specify a password.

Confirm it worked with:

> cat /etc/nginx/.htpasswd

If all is well, you should see your new username displayed with a string of gibberish that represents your password.

2 - Modify the sites-enabled file

> sudo nano /etc/nginx/sites-enabled/screenly.conf

In location /  
Add as the first entry:

> try\_files $uri $uri/ =404;  
> auth\_basic “Restricted Content”;  
> auth\_basic\_user\_file /etc/nginx/.htpasswd;

Exit and save.

3 - Restart your service;

> sudo service nginx restart

4 - Navigate to your Screenly OSE web admin page and confirm a password is prompted for.

I found this far easier to implement than trying to splice together the server.py files as indicated above.

---

<div class="post-metadata">

**Author:** ![ealmonte32](https://yyz1.discourse-cdn.com/flex029/user_avatar/forums.screenly.io/ealmonte32/32/228_2.png) [@ealmonte32](https://forums.screenly.io/u/ealmonte32)\
**Post date:** [December 11, 2019, 4:35am UTC](https://forums.screenly.io/t/authentication-for-web-admin-page/207/3 "2019-12-11T04:35:00Z")

</div>

hmm, do you mean the section here where you can do this simply from the webUI?

 ![Screen Shot 2019-12-10 at 11.34.18 PM](https://canada1.discourse-cdn.com/flex029/uploads/screenly/original/1X/bad6796b60fee451e63ae5e898a08aa5d8f34b3c.png) ![Screen Shot 2019-12-10 at 11.34.33 PM](https://canada1.discourse-cdn.com/flex029/uploads/screenly/original/1X/07918ad0cd52872d5a0f7dca0e95376145f46d6b.png)

---

<div class="post-metadata">

**Author:** ![Sky\_Paladin](https://avatars.discourse-cdn.com/v4/letter/s/57b2e6/32.png) [@Sky\_Paladin](https://forums.screenly.io/u/Sky_Paladin)\
**Post date:** [December 11, 2019, 11:00pm UTC](https://forums.screenly.io/t/authentication-for-web-admin-page/207/4 "2019-12-11T23:00:41Z")

</div>

…

Yes. Exactly that.

I can’t believe after all those google searches I never saw this, but there it is. Unbelievable.

Thank you - it’ll be easier to just set that in future than having to ssh into the Pi’s after the fact and update the sites-enabled.

---

<div class="post-metadata">

**Author:** ![vpetersson](https://yyz1.discourse-cdn.com/flex029/user_avatar/forums.screenly.io/vpetersson/32/8_2.png) [@vpetersson](https://forums.screenly.io/u/vpetersson)\
**Post date:** [June 9, 2026, 7:13am UTC](https://forums.screenly.io/t/authentication-for-web-admin-page/207/5 "2026-06-09T07:13:25Z")

</div>

Good news, you no longer need to edit any config files for this. Anthias lets you turn on a username and password for the web page directly in Settings, under Authentication. Just pick Basic auth and set your login. Marking this as solved.
