# Users not allowed to create organizations\[solved\]

**URL:** https://vaultwarden.discourse.group/t/users-not-allowed-to-create-organizations-solved/3423
**Category:** Help
**Created:** [March 7, 2024, 4:24pm UTC](https://vaultwarden.discourse.group/t/users-not-allowed-to-create-organizations-solved/3423 "2024-03-07T16:24:01Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![manoca](https://avatars.discourse-cdn.com/v4/letter/m/94ad74/32.png) [@manoca](https://vaultwarden.discourse.group/u/manoca)
#### Post date: [March 7, 2024, 4:24pm UTC](https://vaultwarden.discourse.group/t/users-not-allowed-to-create-organizations-solved/3423/1 "2024-03-07T16:24:01Z")

</div>

And the struggle to get vaultwarden up and running continues (this is the third day I’m trying to get it to run properly). Now I am not able to create organizations to share my credentials with others. On the webpage I get an error message as well as on the serverside logs:

```auto
[2024-03-07 17:20:53.022][vaultwarden::api::core::organizations][ERROR] User not allowed to create organizations
[2024-03-07 17:20:53.023][response][INFO] (create_organization) POST /api/organizations => 400 Bad Request

```

I do have the following line in my .env file:

```auto

ORG_CREATION_USERS=

```

which should allow every user to create organizations? No? What am I doing wrong again?

---

<div class="post-metadata">

### Author: ![stefan0xC](https://yyz2.discourse-cdn.com/free1/user_avatar/vaultwarden.discourse.group/stefan0xc/32/1765_2.png) [@stefan0xC](https://vaultwarden.discourse.group/u/stefan0xC)
#### Post date: [March 7, 2024, 6:00pm UTC](https://vaultwarden.discourse.group/t/users-not-allowed-to-create-organizations-solved/3423/2 "2024-03-07T18:00:26Z")

</div>

If you have used the `/admin` panel to save your configuration (ie. you have a `data/config.json` file) the environment variables might be overwritten. Cf.

> **[Configuration overview](https://github.com/dani-garcia/vaultwarden/wiki/Configuration-overview#using-the-admin-page)**
>
> Unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden\_rs - dani-garcia/vaultwarden

Can you post the generated support string from the diagnostics page?

---

<div class="post-metadata">

### Author: ![manoca](https://avatars.discourse-cdn.com/v4/letter/m/94ad74/32.png) [@manoca](https://vaultwarden.discourse.group/u/manoca)
#### Post date: [March 7, 2024, 9:18pm UTC](https://vaultwarden.discourse.group/t/users-not-allowed-to-create-organizations-solved/3423/3 "2024-03-07T21:18:47Z")

</div>

Thanks a lot for your response. It is a bright shimmer in the darkness of vaultwarden iliteracy 🙂  
So I’ve checked for the config.json an indeed there is an org\_create\_user entry set. I deleted this line and restarted vaultwarden but the error still persists. Here is a grep through config.json as it is set now:

```auto
[manoca@vw data]$ cat config.json |grep org
  "invitation_org_name": "Vaultwarden",
[manoca@vw data]$

```

as you can see the only remaining “org” entry is the invitation\_org\_name (whatever that is). The error on serverside Logfile continues to be:

```auto
[2024-03-07 22:14:23.326][vaultwarden::api::core::organizations][ERROR] User not allowed to create organizations
[2024-03-07 22:14:23.326][response][INFO] (create_organization) POST /api/organizations => 400 Bad Request

```

as well as the error message at client(browser)side continues to state:  
 ![image](https://global.discourse-cdn.com/free1/uploads/vaultwarden/original/2X/e/e92a579bbd49ff16aacbc1db865e2cc8822ac948.png)

Here is the support string from diagnostics page as you asked for:

````auto
### Your environment (Generated via diagnostics page)
* Vaultwarden version: v1.30.5
* Web-vault version: v2024.1.2b
* OS/Arch: linux/x86_64
* Running within a container: false (Base: Not applicable)
* Environment settings overridden: true
* Uses a reverse proxy: true
* IP Header check: false (X-Forwarded-For)
* Internet access: true
* Internet access via a proxy: false
* DNS Check: true
* Browser/Server Time Check: false
* Server/NTP Time Check: true
* Domain Configuration Check: true
* HTTPS Check: true
* Database type: SQLite
* Database version: 3.44.0
* Clients used: 
* Reverse proxy and version: 
* Other relevant information: 

### Config (Generated via diagnostics page)
<details><summary>Show Running Config</summary>

**Environment settings which are overridden:** DOMAIN, SIGNUPS_ALLOWED, ADMIN_TOKEN, SMTP_HOST, SMTP_PORT, SMTP_FROM, SMTP_FROM_NAME, SMTP_USERNAME, SMTP_PASSWORD, SMTP_TIMEOUT

```json
{
  "_duo_akey": null,
  "_enable_duo": true,
  "_enable_email_2fa": true,
  "_enable_smtp": true,
  "_enable_yubico": true,
  "_icon_service_csp": "",
  "_icon_service_url": "",
  "_ip_header_enabled": true,
  "_smtp_img_src": "cid:",
  "admin_ratelimit_max_burst": 3,
  "admin_ratelimit_seconds": 300,
  "admin_session_lifetime": 20,
  "admin_token": "***",
  "allowed_iframe_ancestors": "",
  "attachments_folder": "data/attachments",
  "auth_request_purge_schedule": "30 * * * * *",
  "authenticator_disable_time_drift": false,
  "data_folder": "data",
  "database_conn_init": "",
  "database_max_conns": 10,
  "database_timeout": 30,
  "database_url": " ***************",
  "db_connection_retries": 15,
  "disable_2fa_remember": false,
  "disable_admin_token": false,
  "disable_icon_download": false,
  "domain": " *****://***************************",
  "domain_origin": " *****://***************************",
  "domain_path": "",
  "domain_set": true,
  "duo_host": null,
  "duo_ikey": null,
  "duo_skey": null,
  "email_attempts_limit": 3,
  "email_change_allowed": true,
  "email_expiration_time": 600,
  "email_token_size": 6,
  "emergency_access_allowed": true,
  "emergency_notification_reminder_schedule": "0 3 * * * *",
  "emergency_request_timeout_schedule": "0 7 * * * *",
  "enable_db_wal": true,
  "event_cleanup_schedule": "0 10 0 * * *",
  "events_days_retain": null,
  "experimental_client_feature_flags": "fido2-vault-credentials",
  "extended_logging": true,
  "helo_name": null,
  "hibp_api_key": null,
  "icon_blacklist_non_global_ips": true,
  "icon_blacklist_regex": null,
  "icon_cache_folder": "data/icon_cache",
  "icon_cache_negttl": 259200,
  "icon_cache_ttl": 2592000,
  "icon_download_timeout": 10,
  "icon_redirect_code": 302,
  "icon_service": "internal",
  "incomplete_2fa_schedule": "30 * * * * *",
  "incomplete_2fa_time_limit": 3,
  "invitation_expiration_hours": 120,
  "invitation_org_name": "Vaultwarden",
  "invitations_allowed": true,
  "ip_header": "X-Real-IP",
  "job_poll_interval_ms": 30000,
  "log_file": null,
  "log_level": "Info",
  "log_timestamp_format": "%Y-%m-%d %H:%M:%S.%3f",
  "login_ratelimit_max_burst": 10,
  "login_ratelimit_seconds": 60,
  "org_attachment_limit": null,
  "org_creation_users": " ****************************",
  "org_events_enabled": false,
  "org_groups_enabled": false,
  "password_hints_allowed": true,
  "password_iterations": 600000,
  "push_enabled": false,
  "push_identity_uri": "https://identity.bitwarden.com",
  "push_installation_id": "***",
  "push_installation_key": "***",
  "push_relay_uri": "https://push.bitwarden.com",
  "reload_templates": false,
  "require_device_email": false,
  "rsa_key_filename": "data/rsa_key",
  "send_purge_schedule": "0 5 * * * *",
  "sendmail_command": null,
  "sends_allowed": true,
  "sends_folder": "data/sends",
  "show_password_hint": false,
  "signups_allowed": true,
  "signups_domains_whitelist": "",
  "signups_verify": false,
  "signups_verify_resend_limit": 6,
  "signups_verify_resend_time": 3600,
  "smtp_accept_invalid_certs": false,
  "smtp_accept_invalid_hostnames": false,
  "smtp_auth_mechanism": null,
  "smtp_debug": false,
  "smtp_embed_images": true,
  "smtp_explicit_tls": false,
  "smtp_from": " ***************************",
  "smtp_from_name": "Vaultwarden",
  "smtp_host": " **********************",
  "smtp_password": "***",
  "smtp_port": 587,
  "smtp_security": "starttls",
  "smtp_ssl": true,
  "smtp_timeout": 15,
  "smtp_username": " ***************************",
  "templates_folder": "data/templates",
  "tmp_folder": "data/tmp",
  "trash_auto_delete_days": null,
  "trash_purge_schedule": "0 5 0 * * *",
  "use_sendmail": false,
  "use_syslog": false,
  "user_attachment_limit": null,
  "user_send_limit": null,
  "web_vault_enabled": true,
  "web_vault_folder": "web-vault/",
  "websocket_address": "0.0.0.0",
  "websocket_enabled": false,
  "websocket_port": 3012,
  "yubico_client_id": null,
  "yubico_secret_key": null,
  "yubico_server": null
}

````

``` I hope it helps to solve this issue as I am really struggling here a bit ;)

edit: I just tried to set the config.json entry to a specific user and it worked! I was able to create an organization with the specific user in config.json as:

```auto
"org_creation_users": "userNameOfSpecificUser"

```

editedit: also leaving this line with an empty string works. Only when the line gets removed it stops working. So this is also valid:

```auto
"org_creation_users": ""

```

I guess this solved my issue. Thanks again to @stefan0xC for the hint with the config.json. I would not have thought of looking into that file after supplying the .env entry already!

---

<div class="post-metadata">

### Author: ![stefan0xC](https://yyz2.discourse-cdn.com/free1/user_avatar/vaultwarden.discourse.group/stefan0xc/32/1765_2.png) [@stefan0xC](https://vaultwarden.discourse.group/u/stefan0xC)
#### Post date: [March 7, 2024, 10:06pm UTC](https://vaultwarden.discourse.group/t/users-not-allowed-to-create-organizations-solved/3423/4 "2024-03-07T22:06:22Z")

</div>

> [@manoca](#):
>
> ` "org_creation_users": " ****************************",`

> [@manoca](#):
>
> Only when the line gets removed it stops working.

Since the option was still set even though you have removed the line from your `config.json`, you might also be using the `/var/lib/vaultwarden/.env` from the tutorial page you have mentioned in the other thread (could also be the other way round if you have configured your vaultwarden via OpenRC - not familiar enough with this init system though so not sure if this is possible / if not, you might have configured the environment variables somewhere else on your system).

---

<div class="post-metadata">

### Author: ![manoca](https://avatars.discourse-cdn.com/v4/letter/m/94ad74/32.png) [@manoca](https://vaultwarden.discourse.group/u/manoca)
#### Post date: [March 8, 2024, 10:41am UTC](https://vaultwarden.discourse.group/t/users-not-allowed-to-create-organizations-solved/3423/5 "2024-03-08T10:41:17Z")

</div>

I do have an .env file at /var/lig/vaultwarden. This is the file where I initially put the ORG\_CREATION\_USER= string. But I think the error here was simply human misbehaviour. After watiing for three days for me to complete the setup one of my testers was very eager to start testing the application. I talked to him yesterday and he confirmed, that he saved the webform from /admin while I was struggling with the setup. So I guess it happended as followed:

- vaultwarden started up with the correct Entry from my .env file. My testuser immediately saves the web form with a wrong entry there (as you can set the org creating user there as well). I try to create groups and run into this error as the wrong entry was made by ourself in the config.json via the weg interface.  
Long story short: it is working flawless now. Only question remaining: how should I punish my ultra eager tester 😃 ?

---

<div class="post-metadata">

### Author: ![rutherford](https://yyz2.discourse-cdn.com/free1/user_avatar/vaultwarden.discourse.group/rutherford/32/895_2.png) [@rutherford](https://vaultwarden.discourse.group/u/rutherford)
#### Post date: [August 12, 2025, 4:30pm UTC](https://vaultwarden.discourse.group/t/users-not-allowed-to-create-organizations-solved/3423/6 "2025-08-12T16:30:37Z")

</div>

I “solved” this one by using the admin page to add the user. [https://bitwarden.yoursite.com/admin](https://bitwarden.yoursite.com/admin), accessible via that long API code.

---

<div class="post-metadata">

### Author: ![vaysala507](https://avatars.discourse-cdn.com/v4/letter/v/8e7dd6/32.png) [@vaysala507](https://vaultwarden.discourse.group/u/vaysala507)
#### Post date: [January 10, 2026, 8:09pm UTC](https://vaultwarden.discourse.group/t/users-not-allowed-to-create-organizations-solved/3423/7 "2026-01-10T20:09:06Z")

</div>

Who fix please cant help, i install and have same problem about create Organization

Cannot read properties of undefined (reading ‘find’)

---

<div class="post-metadata">

### Author: ![stefan0xC](https://yyz2.discourse-cdn.com/free1/user_avatar/vaultwarden.discourse.group/stefan0xc/32/1765_2.png) [@stefan0xC](https://vaultwarden.discourse.group/u/stefan0xC)
#### Post date: [January 10, 2026, 11:59pm UTC](https://vaultwarden.discourse.group/t/users-not-allowed-to-create-organizations-solved/3423/8 "2026-01-10T23:59:35Z")

</div>

> [@vaysala507](#):
>
> Who fix please cant help, i install and have same problem about create Organization

If you look at the error message above you will see that your problem is caused by something else.

> [@vaysala507](#):
>
> Cannot read properties of undefined (reading ‘find’)

Luckily this is already fixed in [`v1.35.2`](https://github.com/dani-garcia/vaultwarden/releases/tag/1.35.2). So you need to update your Vaultwarden

> <https://github.com/dani-garcia/vaultwarden/issues/1180>
>
> Hello all,
> 
> Vaultwarden is an actively development project. Sometimes there are …a lot of updates, and sometimes a bit less.
> That could mean you might have an older version of Vaultwarden running or, you are using \`latest\` which might not have all recent fixes and patches.
> 
> Because of all these changes, most issues (not all) are probably because you do not have the Vaultwarden server updated to the latest version available which has these fixes in place.
> 
> The current latest version is: \[!\[GitHub Release\](https://img.shields.io/github/release/dani-garcia/vaultwarden.svg)\](https://github.com/dani-garcia/vaultwarden/releases/latest)
> Commits since latest release: !\[GitHub commits since tagged version\](https://img.shields.io/github/commits-since/dani-garcia/vaultwarden/latest/main)
> 
> Please make sure you have either the \`latest\` version running and checked all Closed issues or \`testing\` before reporting an issue.
> Also, check the commits done since the \`latest\` release which are in \`testing\`, it could be that a bug you run into is already fixed, but they are not yet released as a new version !\[GitHub commits since tagged version\](https://img.shields.io/github/commits-since/dani-garcia/vaultwarden/latest/main).
> 
> If after updating to the latest version and checking the commits done since the latest release of Vaultwarden and you still encounter these same issue, please go ahead and post a new topic on the \[Discussions\](https://github.com/dani-garcia/vaultwarden/discussions) or here at the issues page.
> 
> Thanks for all your support.
> 
> 
> \# New docker multi database support for Debian and Alpine
> \### Only one image: \`vaultwarden/server\`
> It contains support for SQLite, MySQL and PostgreSQL all in one! Supports AMD64, ARMv6, ARMv7 and ARMv8 (Aarch64), and all architectures support all database backends!.
> 
> \*\*Note\*\*: The old \`bitwarden\_rs\` are no longer available!
> 
> \### Which tag to use:
> \- \`vaultwarden/server:latest\`: Tracks the latest released version (i.e., tagged with a version number). Recommended for most users, and generally the most stable.
> \- \`vaultwarden/server:testing\`: Tracks the latest commits to the source repository. Recommended for users who want early access to the newest features or enhancements. Generally pretty stable, but occasional issues are unavoidable.
> \- \`vaultwarden/server:x.y.z\`: Represents a specific released version. Prefer to use latest to keep up-to-date.
> 
> \#### Alpine base
> 
> \- \`vaultwarden/server:alpine\`, \`vaultwarden/server:testing-alpine\`, \`vaultwarden/server:x.y.z-alpine\`: Functionally the same as the above images, but based on Alpine instead of Debian, which results in a smaller image and sometimes less security issues in the base image.
