Open WebUI & Onyx
Last updated: August 2026
Onyx (formerly Danswer) focuses on a specific and important problem: connecting AI to your organization's internal knowledge across Slack, Google Drive, Confluence, Jira, GitHub, and dozens of other tools, with permission-aware retrieval. If your team's knowledge is scattered across many tools and you need AI to search across all of them while respecting access controls, that's Onyx's sweet spot.
Everything claimed here about Open WebUI is verifiable in our own documentation, linked throughout. Everything about Onyx comes from Onyx's own documentation, repository and licence terms, all linked below, and describes their project as of the date above. Onyx ships quickly, so treat anything undated as possibly out of date and check their sources before deciding.
If something here is wrong or has aged badly, including in Onyx's favour, tell us and we will correct it.
GitHub · Source Available (MIT core + Onyx Enterprise License for ee/ directories) · Self-Host Terms
What Onyx Does Well
- Enterprise connectors, 40+ by Onyx's count, with native integrations for Slack, Google Drive, Confluence, Jira, GitHub, Notion, and more
- Automatic syncing that keeps connected sources up to date without manual re-ingestion
- Permission-aware retrieval that respects source system access controls when returning search results
- Enterprise search purpose-built for searching across your organization's internal knowledge
- Multi-surface access via web app, Slack bot, Discord bot, Chrome extension, and CLI
- Managed cloud option for teams that don't want to self-host
- Custom agents with actions for building AI assistants that can take actions across connected tools
- Active development with frequent releases and community responsiveness
What Open WebUI Does Well
- Full agentic platform with builtin tools the model calls itself, MCP servers, sub-agents, timers and automations for delegated and scheduled work
- Customise practically everything, from per-model prompts, tools, knowledge and parameters to filters, pipes, actions and event functions that change behaviour anywhere in the pipeline, plus theming, banners and per-group permissions
- Full AI platform with Chat, Notes, Channels, Automations, Open Terminal, voice/video calls, and image generation
- Cloud storage in chat with Google Drive, OneDrive (personal and business) and SharePoint file pickers
- Deploy anywhere on your own infrastructure, fully air-gapped if needed
- Free community edition with unlimited users, OIDC/OAuth SSO, LDAP, RBAC, and SCIM 2.0 included
- Any model, any provider including Ollama, OpenAI, Anthropic, Google, Azure, Bedrock, and any OpenAI-compatible API
- Knowledge & RAG with 13 vector databases, 8 content extraction engines, and hybrid BM25 + vector search with cross-encoder reranking
Licensing and Paid Tiers
Both projects are free to self-host and both sell paid tiers. They place different capabilities in different tiers, so the practical question is which feature set matches the deployment you are planning.
Open WebUI is source available under the Open WebUI License, a BSD-3 clause licence with one addition: you may not remove or replace Open WebUI branding once a deployment exceeds 50 users in a rolling 30 day period, unless you hold an enterprise licence.
Onyx licenses its Community Edition core under MIT, covering chat, RAG, agents and actions. That grant is not repository-wide: Onyx's own LICENSE carves out everything under ee directories and places it under the Onyx Enterprise License instead. Taken on its own, MIT is a more permissive licence than ours, and that matters if you intend to redistribute or fork the core.
What each free self-hosted edition includes
Open WebUI's free edition against Onyx's Community Edition, the part carrying the MIT licence. Onyx's column follows its Enterprise Edition and access control documentation, and the per-tier gating in its own license_enforcement_config.py. Onyx's paid tiers are available self-hosted as well as on its cloud, so "Business" and "Enterprise" below can still mean self-hosted.
| Capability | Open WebUI (free) | Onyx Community Edition (free) |
|---|---|---|
| OIDC / OAuth single sign-on | Included | Enterprise Edition |
| SAML single sign-on | Via a trusted-header proxy that terminates SAML | Enterprise Edition native support |
| LDAP / Active Directory | Included | Not documented |
| User groups and role-based access control | Included | Business tier or above |
| Per-resource access grants (users and groups) | Included | Business tier or above |
| SCIM 2.0 provisioning | Included | Enterprise tier |
| Audit logging | Included | Not documented |
| User limit before paying | None | None |
| Giving different teams access to different documents | Separate knowledge bases, each granted to the users or groups you choose | Enterprise Edition |
| Different access to individual files inside one collection | Access applies to a knowledge base as a whole | Enterprise Edition |
| Permissions mirrored automatically from Slack, Drive or Confluence | Not a current Open WebUI feature | Enterprise Edition |
| Removing product branding | Up to 50 users; enterprise licence beyond that | Enterprise Edition |
| Dedicated support and SLAs | Enterprise licence | Enterprise Edition |
| Priority on feature requests | Enterprise licence | Enterprise Edition |
Nothing marked Included in Open WebUI's column needs a licence key, a seat count or a paid plan. They are configurable settings.
Two rows deserve care, because the distinction is easy to blur. Open WebUI gives separate teams access to separate document sets by putting them in different knowledge bases and granting each to the right groups. Onyx's paid editions go deeper for enterprise search: they can mirror source-system permissions from tools like Slack, Drive and Confluence and enforce them during retrieval. If your documents already have complex permissions in those source systems, that is a real strength of Onyx.
Dedicated support and priority on the roadmap are paid on both sides, which is how each project is funded, and neither pretends otherwise.
On Onyx Cloud as of July 2026, the Business tier is $20 per user per month and buys role-based access control and permission inheritance, but not single sign-on, SCIM or outbound webhooks. Those are Enterprise, which is a contact-us.
So the summary is this. If you are self-hosting and need managed identity in the free edition, Open WebUI includes it for any number of users. If you need per-document permissions mirrored from Slack or Drive, Onyx is designed for that in its paid editions. If you intend to fork or redistribute, Onyx's core carries the more permissive licence.
Pricing and tiers change. These figures come from each project's own published terms on the date at the top of this page. Verify against Onyx's pricing and our licence rather than trusting either vendor's summary, including this one.
At a Glance
| Open WebUI | Onyx | |
|---|---|---|
| Primary focus | General-purpose AI platform | Enterprise search and knowledge discovery |
| Knowledge approach | Document upload, knowledge bases, 13 vector DBs, 8 extraction engines | 40+ enterprise connectors with automatic syncing |
| Permission handling | Groups, roles and per-resource access grants, in the free edition | Permission-aware retrieval mirrored from source systems, on the paid tiers |
| Multi-provider | Any OpenAI-compatible API + Ollama | Multiple LLM provider support |
| Extensibility | Python tools, MCP, OpenAPI, pipelines | Focused on connector and search ecosystem |
| Collaboration | Channels, Notes, shared conversations | AI-powered search and Q&A |
| License | Open WebUI License (BSD-3 plus a branding clause above 50 users) | MIT for the Community Edition core; separate terms for Enterprise features, see self-host terms |
For which identity and access features each free edition includes, see the table above rather than this summary.
When to Use Each
Choose Onyx if you want to connect AI to your organization's existing tools. If your team's knowledge lives in Slack, Confluence, Jira, Google Drive, and GitHub, Onyx's 40+ connectors with automatic syncing and permission-aware retrieval were built for that.
Two parts of that are worth being precise about, because they are areas where Onyx has a purpose-built model:
- Continuous sync into the knowledge base. Open WebUI connects to cloud storage at the point of use: users can pull files from Google Drive, OneDrive and SharePoint straight into a chat. Knowledge bases are populated by upload, by directory sync or through the API, and oikb extends that to repositories, buckets and wikis on a schedule. Onyx builds continuous connector sync directly into the product.
- Permission inheritance from the source system. Open WebUI grants access per knowledge base, so you separate what different teams may read by putting it in different knowledge bases. Onyx can mirror a source system's access control list and enforce it at retrieval time, on its Enterprise Edition. If you are indexing a large shared Drive whose permissions already encode who may see what, that difference is the whole decision.
If either is a hard requirement, Onyx is the better fit. Note that both are Enterprise Edition features on Onyx's side, so the comparison to make is against a paid Onyx deployment rather than the free Community Edition.
Choose Open WebUI if you need a general-purpose AI platform with chat, knowledge bases, team collaboration, Python extensibility, and support for any model provider. Open WebUI includes SSO, LDAP, RBAC, SCIM 2.0 and audit logging in the free community edition, for unlimited users, which is the deciding factor for organisations that need managed identity without a per-seat contract.
They solve different problems. Onyx excels at enterprise search and connecting AI to your existing tools. Open WebUI excels as a general AI platform. Many organizations could use both.
Onyx connects AI to your enterprise knowledge. Open WebUI comes at it from a more general angle. They solve different problems, and many organizations could benefit from both.
Ready to try Open WebUI? Get started →
Frequently Asked Questions
How do Onyx and Open WebUI compare? Onyx leans into enterprise search with 40+ connectors and permission-aware retrieval. Open WebUI comes at it from a more general angle with chat, knowledge bases, team collaboration, and extensibility. Different tools for different needs.
Is Onyx open source?
Partly. Onyx's Community Edition core is MIT licensed, and everything under its ee directories is excluded from that grant and carries separate enterprise terms. Additional self-host terms may also apply. Note that the licence and the price are separate questions: MIT covers the core, while single sign-on and access control sit in Onyx's paid tiers. For redistribution specifically, MIT on that core is more permissive than the Open WebUI License.
How do SSO and RBAC compare? Open WebUI includes OIDC and OAuth single sign-on, LDAP, RBAC, SCIM 2.0 provisioning and audit logging in the free edition, for unlimited users, with no licence key. In Onyx, user groups, RBAC and SSO are paid-tier features for self-hosted deployments. On Onyx Cloud, RBAC starts at the Business tier and SSO at the Enterprise tier.
Is Onyx free? The community edition is free to self-host. Additional self-host terms may apply. Onyx Cloud and Enterprise plans are available for teams that want managed hosting or additional features.
Can I use both Onyx and Open WebUI? Yes. They solve different problems. Onyx connects AI to your existing enterprise tools. Open WebUI also has knowledge management, team features, and extensibility built in.
Which is better for enterprise AI deployment? It depends on your needs. If your priority is searching across internal tools with permission-aware retrieval, Onyx was built for that. If you need more of a general-purpose AI platform that you can deploy on your own infrastructure, with SSO, RBAC, and SCIM included in the free edition, that is more where Open WebUI fits.
Related: Open WebUI & Dify · Open WebUI & AnythingLLM · Open WebUI & LibreChat