Preferences
Global NIM defaults
Preferences control how users reach NIM, sign in, work with forms, and use data. Review these settings when preparing an environment for production or changing its access model.
External access and default experienceDirect link to External access and default experience
Access
Set the public identity of NIM
These settings affect URLs, hosted apps, SAML, and certificate validation.- External host URL
- The URL external users and services use to reach this NIM instance. Leave it empty to use
EXTERNAL_HOST_NAME, or the server FQDN when that environment variable is not set. Use the exact public hostname for Let’s Encrypt HTTP-01 validation and SAML integrations. - Default app
- The app opened when a visitor reaches the NIM Service without a specific app URL. For example, set
dashboardto open the dashboard by default. - Logout redirect
- The URL users are redirected to after they sign out. Use a trusted internal or public destination that matches your access design.
If you publish approved apps externally through NGINX, configure the same public hostname in External Host URL. See Allow External Access.
Sign-in, branding, and sessionsDirect link to Sign-in, branding, and sessions
Identity experience
Secure and personalize sign-in
Use these settings to control login behavior, MFA, branding, and session lifetime.- Modern login flow
- Set to
1to use the modern sign-in experience: users enter their username first, then NIM presents a password field or redirects them to a SAML identity provider. Set to0to use the classic flow, which shows a SAML button when a SAML provider is configured. - Multi-factor authentication
- Controls MFA for NIM accounts. When required, users enroll the first time they sign in. When optional, users can select Setup MFA from the user menu.
- Login logo
- The local image file used on the Studio and app login page. Delete the value to return to the default NIM logo.
- Login page background
- The image displayed behind the Studio and App login form. Delete the value to use no custom background image.
- Hide 'Forget password' option on the login screen
- Set to
1to hide, or0to show, the password-reset link on the login screen. - Text for 'I forgot my password' option on the login screen
- Customizes the label of the password-reset link shown on the login screen.
- Label and placeholder text for the account name field on the login screen
- Sets the label and placeholder for the account-name field, such as
UsernameorEmployee ID. - Markdown text shown on the login screen
- Markdown content shown above the login form, such as a maintenance notice or sign-in instructions.
- Session timeout for admin
- Administrator session lifetime in minutes. Minimum: 5; default: 60; maximum: 720 (12 hours).
- Session timeout for non administrators
- Non-administrator session lifetime in minutes. Minimum: 5; default: 480 (8 hours); maximum: 720 (12 hours).
- Session timeout when idle
- Idle-session timeout in minutes.
- Session warning time (seconds)
- How long before session expiration NIM warns the user. Set to
0to disable the warning. - Session ignore SAML notOnOrAfter
- Set to
0in normal operation so NIM honors the SAMLsessionNotOnOrAfterattribute. Set to1only when a reviewed integration requirement calls for it.
Customize the login logoDirect link to Customize the login logo
Select the value cell for Login logo, then choose a local image file on the NIM server. PNG, JPG, and WebP files are recommended. To remove a custom logo, select the value cell, dismiss the file picker, and press Delete.
Configure multi-factor authenticationDirect link to Configure multi-factor authentication
When MFA is required, a user enrolls during first sign-in.
When MFA is optional, users can choose Setup MFA from the user icon in the upper-right corner.
Choose a login flowDirect link to Choose a login flow
Design and data-preview defaultsDirect link to Design and data-preview defaults
Studio experience
Make design and preview work predictable
These values influence form design and how much data is shown by default.- Show borders of form grid containers
- Set to
1to show Bootstrap grid borders while designing forms, or0to hide them. Toggle this view with Ctrl + Space. - Show markdown syntax of static links
- Set to
1to display static links as[text](url)in design mode, or0to show the formatted link. - Grid default preview count
- The default number of rows, records, or documents shown in preview windows and grids. For example,
1000. - Default date (only) format
- The date display format. Supported tokens include
YY,YYYY,M,MM,MMM,D,DD,d, andddd. - Default date (and) time format
- The date-time display format. In addition to date tokens, use
H,HH,h,hh,m,mm,s,ss,SSS,Z,ZZ,A, ora.
Auditing, datasets, and app performanceDirect link to Auditing, datasets, and app performance
Performance
Balance responsiveness and processing cost
Change these values after reviewing their effect on data volume and workload.- Maximum number of auditing query threads
- The maximum worker threads used to calculate auditing-query results, from
0through10. Use0to disable worker-thread offloading. - Auditing data storage offloading
- Set to
1to enable, or0to disable, offloading of auditing-data storage. - Dataset dynamic update threshold
- When a job or app updates more system-table records than this threshold, NIM reconstructs dataset relations instead of updating them dynamically.
- Dataset index mode
- Controls multi-value indexes:
0enables and creates them when needed;1enables and pre-initializes them;2disables them. - App table validation cache enabled
- Set to
1to enable the app-table validation cache or0to disable it. The default is1. - App table validation cache timeout (sec)
- The number of seconds before cached table-validation data is removed automatically.
Advanced administrationDirect link to Advanced administration
Administration
Restrict development and change controls
Use these options deliberately and limit them to approved administrators.- Maximum anonymous error requests (minute)
- The total failed password-reset and onboarding requests allowed in one minute before NIM blocks those functions.
- Script debugging
- Set to
1to let an external project environment access the service and execute system calls. Use only for script development; set to0when finished. - Maintenance mode notification timeout
- The number of seconds before maintenance mode activates and non-administrator users are signed out.
- Configuration Scenarios administration
- Set to
1to enable, or0to disable, administration of System Configuration Scenarios in connectors.
Do not enable Script debugging in a production environment unless it is needed for an approved troubleshooting session. Disable it when the session is complete.
Browser security and MCP accessDirect link to Browser security and MCP access
Security
Protect browser sessions and AI integration access
Review these settings with the team responsible for your reverse proxy, security headers, and MCP clients.- Strict transport security enabled
- Set to
1to send the HTTP Strict Transport Security header, instructing browsers to use HTTPS for this host. Enable only after HTTPS is fully working. - Strict transport security max age
- The HSTS lifetime in seconds. The common value
31536000is one year. - Strict transport security include sub domains
- Set to
1only when every subdomain is HTTPS-ready and should be included in the HSTS policy. - Strict transport security preload
- Set to
1only after reviewing browser preload requirements and the consequences of making HTTPS mandatory for the domain. - Cross Origin Embedder Policy
- Sets the
Cross-Origin-Embedder-Policyresponse header:unsafe-nonedisables it,require-corprequires CORP-compatible resources, andcredentiallessallows no-credential cross-origin resources. - X Frame Options
- Sets the
X-Frame-Optionsheader:denyblocks framing,sameoriginallows only the same origin, andallowpermits framing from any domain. - MCP API endpoint enabled
- Set to
1to enable the MCP endpoint at/api/mcp. Keep it disabled when no approved MCP client needs access. - MCP allow customer data access
- Set to
1only when approved MCP clients need customer data. When disabled, the MCP server does not return customer data. - MCP OAuth 2.1 connector support enabled
- Set to
1to allow OAuth 2.1 connector support for MCP clients that authorize through sign-in instead of an API key.
Security headers can affect embedded content and browser behavior. MCP settings can expose NIM capabilities and, when enabled, customer data. Review the intended clients, authentication, least-privilege access, and change approval before enabling either group in production.