Skip to main content

Open WebUI & Onyx

Last updated: July 2026

Onyx (formerly Danswer) focuses on a specific and important problem: connecting AI to your organization's internal knowledge across Slack, Google Drive, Confluence, Jira, GitHub, and dozens of other tools, with permission-aware retrieval. If your team's knowledge is scattered across many tools and you need AI to search across all of them while respecting access controls, that's Onyx's sweet spot.

How to check this page

Everything claimed here about Open WebUI is verifiable in our own documentation, linked throughout. Everything about Onyx comes from Onyx's own documentation, repository and licence terms, all linked below, and describes their project as of the date above. Onyx ships quickly, so treat anything undated as possibly out of date and check their sources before deciding.

If something here is wrong or has aged badly, including in Onyx's favour, tell us and we will correct it.

GitHub · Source Available (MIT core + Onyx Enterprise License for ee/ directories) · Self-Host Terms


What Onyx Does Well

  • Enterprise connectors, 40+ by Onyx's count, with native integrations for Slack, Google Drive, Confluence, Jira, GitHub, Notion, and more
  • Automatic syncing that keeps connected sources up to date without manual re-ingestion
  • Permission-aware retrieval that respects source system access controls when returning search results
  • Enterprise search purpose-built for searching across your organization's internal knowledge
  • Multi-surface access via web app, Slack bot, Discord bot, Chrome extension, and CLI
  • Managed cloud option for teams that don't want to self-host
  • Custom agents with actions for building AI assistants that can take actions across connected tools
  • Active development with frequent releases and community responsiveness

What Open WebUI Does Well

  • Full agentic platform with builtin tools the model calls itself, MCP servers, sub-agents, timers and automations for delegated and scheduled work
  • Customise practically everything, from per-model prompts, tools, knowledge and parameters to filters, pipes, actions and event functions that change behaviour anywhere in the pipeline, plus theming, banners and per-group permissions
  • Full AI platform with Chat, Notes, Channels, Automations, Open Terminal, voice/video calls, and image generation
  • Cloud storage in chat with Google Drive, OneDrive (personal and business) and SharePoint file pickers
  • Deploy anywhere on your own infrastructure, fully air-gapped if needed
  • Free community edition with unlimited users, OIDC/OAuth SSO, LDAP, RBAC, and SCIM 2.0 included
  • Any model, any provider including Ollama, OpenAI, Anthropic, Google, Azure, Bedrock, and any OpenAI-compatible API
  • Knowledge & RAG with 13 vector databases, 8 content extraction engines, and hybrid BM25 + vector search with cross-encoder reranking

Licensing, and Where Each Project Draws the Paid Line

Both projects are free to self-host and both sell a paid tier. They differ in which capabilities sit behind the paid tier, which matters more than the licence name when you are budgeting a rollout.

Open WebUI is source available under the Open WebUI License, a BSD-3 clause licence with one addition: you may not remove or replace Open WebUI branding once a deployment exceeds 50 users in a rolling 30 day period, unless you hold an enterprise licence. That is the restriction, stated plainly, and it is worth knowing before you standardise on it.

Onyx licenses its Community Edition core under MIT, covering chat, RAG, agents and actions. That grant is not repository-wide: Onyx's own LICENSE carves out everything under ee directories and places it under the Onyx Enterprise License instead. Taken on its own, MIT is a more permissive licence than ours, and that matters if you intend to redistribute or fork the core.

What each free self-hosted edition includes

Open WebUI's free edition against Onyx's Community Edition, the part carrying the MIT licence. Onyx's column follows its Enterprise Edition and access control documentation, and the per-tier gating in its own license_enforcement_config.py. Onyx's paid tiers are available self-hosted as well as on its cloud, so the crosses below mean "needs a paid licence", not "cloud only".

CapabilityOpen WebUI (free)Onyx Community Edition (free)
OIDC / OAuth single sign-on✅ Included❌ Enterprise Edition
SAML single sign-on⚠️ No native SAML; works via a trusted-header proxy that terminates SAML❌ Enterprise Edition (native)
LDAP / Active Directory✅ IncludedNot documented
User groups and role-based access control✅ Included❌ Business tier or above
Per-resource access grants (users and groups)✅ Included❌ Business tier or above
SCIM 2.0 provisioning✅ Included❌ Enterprise tier
Audit logging✅ IncludedNot documented
User limit before paying✅ None✅ None
Giving different teams access to different documents✅ Separate knowledge bases, each granted to the users or groups you choose❌ Enterprise Edition
Different access to individual files inside one collection❌ Access applies to a knowledge base as a whole❌ Enterprise Edition
Permissions mirrored automatically from Slack, Drive or Confluence❌ Not supported at any tier❌ Enterprise Edition
Removing product brandingℹ️ Up to 50 users, enterprise licence beyond that❌ Enterprise Edition
Dedicated support and SLAsEnterprise licence❌ Enterprise Edition
Priority on feature requests❌ Enterprise licence❌ Enterprise Edition

Nothing in Open WebUI's ✅ rows needs a licence key, a seat count or a paid plan. They are configurable settings.

Two rows deserve care, because the distinction is easy to blur. Open WebUI can absolutely give separate teams access to separate document sets, for free, by putting them in different knowledge bases and granting each to the right groups. What it cannot do is vary access within a single knowledge base, or pick permissions up automatically from Slack, Drive or Confluence. Onyx can do both, but only on its Enterprise Edition, and its free Community Edition has no user groups at all, so it cannot do the simpler thing either.

Dedicated support and priority on the roadmap are paid on both sides, which is how each project is funded, and neither pretends otherwise.

On Onyx Cloud as of July 2026, the Business tier is $20 per user per month and buys role-based access control and permission inheritance, but not single sign-on, SCIM or outbound webhooks. Those are Enterprise, which is a contact-us.

So the summary is this. If you are self-hosting and need managed identity, Open WebUI includes it for any number of users while Onyx's free edition does not include group-based access control at all. If you need per-document permissions mirrored from Slack or Drive, Open WebUI cannot do it and Onyx can, for a fee. If you intend to fork or redistribute, Onyx's core carries the more permissive licence.

Check both before you decide

Pricing and tiers change. These figures come from each project's own published terms on the date at the top of this page. Verify against Onyx's pricing and our licence rather than trusting either vendor's summary, including this one.


At a Glance

Open WebUIOnyx
Primary focusGeneral-purpose AI platformEnterprise search and knowledge discovery
Knowledge approachDocument upload, knowledge bases, 13 vector DBs, 8 extraction engines40+ enterprise connectors with automatic syncing
Permission handlingGroups, roles and per-resource access grants, in the free editionPermission-aware retrieval mirrored from source systems, on the paid tiers
Multi-providerAny OpenAI-compatible API + OllamaMultiple LLM provider support
ExtensibilityPython tools, MCP, OpenAPI, pipelinesFocused on connector and search ecosystem
CollaborationChannels, Notes, shared conversationsAI-powered search and Q&A
LicenseOpen WebUI License (BSD-3 plus a branding clause above 50 users)MIT for the Community Edition core; separate terms for Enterprise features, see self-host terms

For which identity and access features each free edition includes, see the table above rather than this summary.


When to Use Each

Choose Onyx if you want to connect AI to your organization's existing tools. If your team's knowledge lives in Slack, Confluence, Jira, Google Drive, and GitHub, Onyx's 40+ connectors with automatic syncing and permission-aware retrieval were built for that.

Two parts of that are worth being precise about, because they are the areas where Onyx is ahead and configuration will not close the gap:

  • Continuous sync into the knowledge base. Open WebUI connects to cloud storage at the point of use: users can pull files from Google Drive, OneDrive and SharePoint straight into a chat. What it does not do is keep a knowledge base continuously in step with those sources. Knowledge bases are populated by upload, by directory sync or through the API, and oikb extends that to repositories, buckets and wikis on a schedule, but as a separate tool rather than a connector catalogue inside the product.
  • Permission inheritance from the source system. Open WebUI grants access per knowledge base, so you separate what different teams may read by putting it in different knowledge bases. What it will not do is read permissions back out of Slack, Drive or Confluence and apply them per document automatically. Onyx can mirror a source system's access control list and enforce it at retrieval time, on its Enterprise Edition. If you are indexing a large shared Drive whose permissions already encode who may see what, that difference is the whole decision.

If either is a hard requirement, Onyx is the better fit. Note that both are Enterprise Edition features on Onyx's side, so the comparison to make is against a paid Onyx deployment rather than the free Community Edition.

Choose Open WebUI if you need a general-purpose AI platform with chat, knowledge bases, team collaboration, Python extensibility, and support for any model provider. Open WebUI includes SSO, LDAP, RBAC, SCIM 2.0 and audit logging in the free community edition, for unlimited users, which is the deciding factor for organisations that need managed identity without a per-seat contract.

They solve different problems. Onyx excels at enterprise search and connecting AI to your existing tools. Open WebUI excels as a general AI platform. Many organizations could use both.


Onyx connects AI to your enterprise knowledge. Open WebUI comes at it from a more general angle. They solve different problems, and many organizations could benefit from both.

Ready to try Open WebUI? Get started →


Frequently Asked Questions

How do Onyx and Open WebUI compare? Onyx leans into enterprise search with 40+ connectors and permission-aware retrieval. Open WebUI comes at it from a more general angle with chat, knowledge bases, team collaboration, and extensibility. Different tools for different needs.

Is Onyx open source? Partly. Onyx's Community Edition core is MIT licensed, and everything under its ee directories is excluded from that grant and carries separate enterprise terms. Additional self-host terms may also apply. Note that the licence and the price are separate questions: MIT covers the core, while single sign-on and access control sit in Onyx's paid tiers. For redistribution specifically, MIT on that core is more permissive than the Open WebUI License.

Which one gives me SSO and RBAC without paying? Open WebUI. OIDC and OAuth single sign-on, LDAP, RBAC, SCIM 2.0 provisioning and audit logging are all in the free edition, for unlimited users, with no licence key. Self-hosting Onyx, user groups, RBAC and SSO are Enterprise Edition features rather than part of the free Community Edition. On Onyx Cloud, RBAC starts at the Business tier and SSO at the Enterprise tier. If you are self-hosting for a team and identity management is a requirement, this is usually the difference that decides it.

Is Onyx free? The community edition is free to self-host. Additional self-host terms may apply. Onyx Cloud and Enterprise plans are available for teams that want managed hosting or additional features.

Can I use both Onyx and Open WebUI? Yes. They solve different problems. Onyx connects AI to your existing enterprise tools. Open WebUI also has knowledge management, team features, and extensibility built in.

Which is better for enterprise AI deployment? It depends on your needs. If your priority is searching across internal tools with permission-aware retrieval, Onyx was built for that. If you need more of a general-purpose AI platform that you can deploy on your own infrastructure, with SSO, RBAC, and SCIM included in the free edition, that is more where Open WebUI fits.


Related: Open WebUI & Dify · Open WebUI & AnythingLLM · Open WebUI & LibreChat

This content is for informational purposes only and does not constitute a warranty, guarantee, or contractual commitment. Open WebUI is provided "as is." See your license for applicable terms.