[tls] enabled = false. This console works only over loopback or behind a TLS terminator. Behind a terminator, sign-in already works normally, and this notice does not block it — kumi cannot tell that host apart from a bare LAN browser. On plain HTTP with neither, your browser drops the session cookie: sign in from localhost, or put a TLS terminator in front of kumi.