> ## Documentation Index
> Fetch the complete documentation index at: https://ayakaleaf-pro.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# User management

## Creating an administrator user

Overleaf Toolkit deployments:

```bash title="Overleaf Toolkit" wrap theme={null}
$ bin/docker-compose exec sharelatex /bin/bash -ce "cd /overleaf/services/web && node modules/server-ce-scripts/scripts/create-user --admin --email=joe@example.com"
```

Legacy docker-compose.yml deployments:

```bash title="Legacy docker-compose" wrap theme={null}
$ docker exec sharelatex /bin/bash -ce "cd /overleaf/services/web && node modules/server-ce-scripts/scripts/create-user --admin --email=joe@example.com"
```

The command will create a user with the provided email address if they don't already exist, and make them an administrator. The command output includes a URL to visit where you can set the password for this user and log in for the first time.

<Info>
  For a programmatic approach you can use the same script to create regular users as well as administrators. For regular users omit the --admin flag.
</Info>

If you use internal accounts for authentication and need to elevate an existing user to an instance admin or revoke admin permissions, do the following:

<Steps>
  <Step title="Via the Admin UI">
    * Log in as an existing administrator.
    * Click Admin -> Manage Users.
    * Search for the user and click on their email address.
    * Scroll down to the Site Admin section and click the (show) link.
    * Check the box Is Site Admin.
    * Click Save to finish.
  </Step>
</Steps>

***

## Deleting users

It is generally advisable not to delete accounts unless they are no longer required. Deleting an account removes the account and causes collaborators to lose access to projects. There is currently no way to deactivate accounts — they either exist with their data retained or are deleted.

By default, accounts are soft-deleted. For information about permanently removing users from your instance see `ENABLE_CRON_RESOURCE_DELETION` in the [Environment variables](/on-premises/configuration/overleaf-toolkit/environment-variables) guide.

<Info>
  Accounts are soft-deleted by default. See `ENABLE_CRON_RESOURCE_DELETION` for permanent deletion behavior.
</Info>

### Via Admin -> Manage Users

<Steps>
  <Step title="">
    * Log in as an administrator.
    * Click Admin -> Manage Users.
    * Search for the user and check the box next to their email address.
    * Click the bin icon.
    * Click Delete to confirm.
  </Step>
</Steps>

### Via the command line

User accounts (and their projects) can be deleted using the following commands.

Overleaf Toolkit deployments:

```bash title="Overleaf Toolkit" theme={null}
$ bin/docker-compose exec sharelatex /bin/bash -ce "cd /overleaf/services/web && node modules/server-ce-scripts/scripts/delete-user.mjs --email=joe@example.com"
```

Legacy docker-compose.yml deployments:

```bash title="Legacy docker-compose" theme={null}
$ docker exec sharelatex /bin/bash -ce "cd /overleaf/services/web && node modules/server-ce-scripts/scripts/delete-user.mjs --email=joe@example.com"
```

<Danger>
  The deletion script uses a hard-coded force option that ensures deletion proceeds even if the account deletion email fails to send (e.g., when the user's email is no longer in service).
</Danger>

<Info>
  Since version 5.5.0, the option --skip-email can be used to prevent sending an informative email to the deleted user.
</Info>

***

## Restoring a soft-deleted user

If a user has only been soft-deleted, you can restore their account and projects.

<Steps>
  <Step title="">
    * Log in as an administrator.
    * Click Admin -> Manage Users.
    * Search for the user you want to restore.
    * Click the Display deleted users button.
    * Click on the deleted user's email address.
    * Click Recover This Account.
    * Click Recover to confirm.
  </Step>
</Steps>

<Danger>
  When ENABLE\_CRON\_RESOURCE\_DELETION is set to true, soft-deleted accounts can be restored within a 90-day window. After 90 days, account recovery is not possible.
</Danger>

***

## Counting users

You can obtain user counts via the admin UI at [https://you-instance-url/admin/user#license](https://you-instance-url/admin/user#license). For programmatic checks and exports, the following examples may help.

Total number of users:

```bash title="Total number of users" theme={null}
echo 'db.users.countDocuments()' | docker exec -i mongo mongosh --quiet localhost/sharelatex
# overleaf [direct: primary] sharelatex> 16
```

Total number of users using the metrics endpoint:

```bash title="Num active users from metrics" theme={null}
docker exec sharelatex curl http://127.0.0.1:3000/metrics | grep num_active_users
# # HELP num_active_users num_active_users
# # TYPE num_active_users gauge
# num_active_users{app="web-api",host="b3ae4ff549d8"} 16
```

Total number of active users (example: users active within last 365 days):

```bash title="Total number of active users" theme={null}
echo 'db.users.countDocuments({ lastActive: { $gte: new Date(new Date().getTime() - (365 * 24 * 60 * 60 * 1000)) } })' | docker exec -i mongo mongosh --quiet localhost/sharelatex
# overleaf [direct: primary] sharelatex> 10
```

***

## Updating user account information

How account updates are performed depends on whether SSO is enabled.

* If SSO is not used:
  * Administrators can modify user account information via Admin -> Manage Users (email, first name, last name, and generate a password reset link).
  * Regular users can update their own details via Account -> Account Settings (including changing password and generating Git authentication tokens).
* If SSO is used:
  * Server Pro can be configured to update a user's first and last name during login based on the authentication system.
  * When OVERLEAF\_SAML\_UPDATE\_USER\_DETAILS\_ON\_LOGIN or OVERLEAF\_LDAP\_UPDATE\_USER\_DETAILS\_ON\_LOGIN are true, the user details form on [https://your-instance-url/user/settings](https://your-instance-url/user/settings) is disabled and first/last name can only be set in your identity management system.

For more details see:

* SAML 2.0 configuration: [https://docs.overleaf.com/on-premises/configuration/overleaf-toolkit/server-pro-only-configuration/saml-2.0](https://docs.overleaf.com/on-premises/configuration/overleaf-toolkit/server-pro-only-configuration/saml-2.0)
* LDAP configuration: [https://docs.overleaf.com/on-premises/configuration/overleaf-toolkit/server-pro-only-configuration/ldap](https://docs.overleaf.com/on-premises/configuration/overleaf-toolkit/server-pro-only-configuration/ldap)

***

Last updated 4 months ago

This documentation page contains links to external guides and configuration pages. All links and query parameters are preserved as in the original content.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.