Skip to main content

Preferences

Global NIM defaults

Preferences control how users reach NIM, sign in, work with forms, and use data. Review these settings when preparing an environment for production or changing its access model.

Where to make changesIn NIM Studio, go to Configuration → Settings → Preferences. Record the current value before changing production settings.

External access and default experienceDirect link to External access and default experience

Access

Set the public identity of NIM

These settings affect URLs, hosted apps, SAML, and certificate validation.
External host URL
The URL external users and services use to reach this NIM instance. Leave it empty to use EXTERNAL_HOST_NAME, or the server FQDN when that environment variable is not set. Use the exact public hostname for Let’s Encrypt HTTP-01 validation and SAML integrations.
Default app
The app opened when a visitor reaches the NIM Service without a specific app URL. For example, set dashboard to open the dashboard by default.
Logout redirect
The URL users are redirected to after they sign out. Use a trusted internal or public destination that matches your access design.
tip

If you publish approved apps externally through NGINX, configure the same public hostname in External Host URL. See Allow External Access.

Sign-in, branding, and sessionsDirect link to Sign-in, branding, and sessions

Identity experience

Secure and personalize sign-in

Use these settings to control login behavior, MFA, branding, and session lifetime.
Modern login flow
Set to 1 to use the modern sign-in experience: users enter their username first, then NIM presents a password field or redirects them to a SAML identity provider. Set to 0 to use the classic flow, which shows a SAML button when a SAML provider is configured.
Multi-factor authentication
Controls MFA for NIM accounts. When required, users enroll the first time they sign in. When optional, users can select Setup MFA from the user menu.
Login logo
The local image file used on the Studio and app login page. Delete the value to return to the default NIM logo.
Login page background
The image displayed behind the Studio and App login form. Delete the value to use no custom background image.
Hide 'Forget password' option on the login screen
Set to 1 to hide, or 0 to show, the password-reset link on the login screen.
Text for 'I forgot my password' option on the login screen
Customizes the label of the password-reset link shown on the login screen.
Label and placeholder text for the account name field on the login screen
Sets the label and placeholder for the account-name field, such as Username or Employee ID.
Markdown text shown on the login screen
Markdown content shown above the login form, such as a maintenance notice or sign-in instructions.
Session timeout for admin
Administrator session lifetime in minutes. Minimum: 5; default: 60; maximum: 720 (12 hours).
Session timeout for non administrators
Non-administrator session lifetime in minutes. Minimum: 5; default: 480 (8 hours); maximum: 720 (12 hours).
Session timeout when idle
Idle-session timeout in minutes.
Session warning time (seconds)
How long before session expiration NIM warns the user. Set to 0 to disable the warning.
Session ignore SAML notOnOrAfter
Set to 0 in normal operation so NIM honors the SAML sessionNotOnOrAfter attribute. Set to 1 only when a reviewed integration requirement calls for it.

Select the value cell for Login logo, then choose a local image file on the NIM server. PNG, JPG, and WebP files are recommended. To remove a custom logo, select the value cell, dismiss the file picker, and press Delete.

Configure multi-factor authenticationDirect link to Configure multi-factor authentication

When MFA is required, a user enrolls during first sign-in.

When MFA is optional, users can choose Setup MFA from the user icon in the upper-right corner.

Choose a login flowDirect link to Choose a login flow

Design and data-preview defaultsDirect link to Design and data-preview defaults

Studio experience

Make design and preview work predictable

These values influence form design and how much data is shown by default.
Show borders of form grid containers
Set to 1 to show Bootstrap grid borders while designing forms, or 0 to hide them. Toggle this view with Ctrl + Space.
Show markdown syntax of static links
Set to 1 to display static links as [text](url) in design mode, or 0 to show the formatted link.
Grid default preview count
The default number of rows, records, or documents shown in preview windows and grids. For example, 1000.
Default date (only) format
The date display format. Supported tokens include YY, YYYY, M, MM, MMM, D, DD, d, and ddd.
Default date (and) time format
The date-time display format. In addition to date tokens, use H, HH, h, hh, m, mm, s, ss, SSS, Z, ZZ, A, or a.

Auditing, datasets, and app performanceDirect link to Auditing, datasets, and app performance

Performance

Balance responsiveness and processing cost

Change these values after reviewing their effect on data volume and workload.
Maximum number of auditing query threads
The maximum worker threads used to calculate auditing-query results, from 0 through 10. Use 0 to disable worker-thread offloading.
Auditing data storage offloading
Set to 1 to enable, or 0 to disable, offloading of auditing-data storage.
Dataset dynamic update threshold
When a job or app updates more system-table records than this threshold, NIM reconstructs dataset relations instead of updating them dynamically.
Dataset index mode
Controls multi-value indexes: 0 enables and creates them when needed; 1 enables and pre-initializes them; 2 disables them.
App table validation cache enabled
Set to 1 to enable the app-table validation cache or 0 to disable it. The default is 1.
App table validation cache timeout (sec)
The number of seconds before cached table-validation data is removed automatically.

Advanced administrationDirect link to Advanced administration

Administration

Restrict development and change controls

Use these options deliberately and limit them to approved administrators.
Maximum anonymous error requests (minute)
The total failed password-reset and onboarding requests allowed in one minute before NIM blocks those functions.
Script debugging
Set to 1 to let an external project environment access the service and execute system calls. Use only for script development; set to 0 when finished.
Maintenance mode notification timeout
The number of seconds before maintenance mode activates and non-administrator users are signed out.
Configuration Scenarios administration
Set to 1 to enable, or 0 to disable, administration of System Configuration Scenarios in connectors.
warning

Do not enable Script debugging in a production environment unless it is needed for an approved troubleshooting session. Disable it when the session is complete.

Browser security and MCP accessDirect link to Browser security and MCP access

Security

Protect browser sessions and AI integration access

Review these settings with the team responsible for your reverse proxy, security headers, and MCP clients.
Strict transport security enabled
Set to 1 to send the HTTP Strict Transport Security header, instructing browsers to use HTTPS for this host. Enable only after HTTPS is fully working.
Strict transport security max age
The HSTS lifetime in seconds. The common value 31536000 is one year.
Strict transport security include sub domains
Set to 1 only when every subdomain is HTTPS-ready and should be included in the HSTS policy.
Strict transport security preload
Set to 1 only after reviewing browser preload requirements and the consequences of making HTTPS mandatory for the domain.
Cross Origin Embedder Policy
Sets the Cross-Origin-Embedder-Policy response header: unsafe-none disables it, require-corp requires CORP-compatible resources, and credentialless allows no-credential cross-origin resources.
X Frame Options
Sets the X-Frame-Options header: deny blocks framing, sameorigin allows only the same origin, and allow permits framing from any domain.
MCP API endpoint enabled
Set to 1 to enable the MCP endpoint at /api/mcp. Keep it disabled when no approved MCP client needs access.
MCP allow customer data access
Set to 1 only when approved MCP clients need customer data. When disabled, the MCP server does not return customer data.
MCP OAuth 2.1 connector support enabled
Set to 1 to allow OAuth 2.1 connector support for MCP clients that authorize through sign-in instead of an API key.
Review before enabling

Security headers can affect embedded content and browser behavior. MCP settings can expose NIM capabilities and, when enabled, customer data. Review the intended clients, authentication, least-privilege access, and change approval before enabling either group in production.