# Accounts

The list view shows username, primary domain, plan, webserver type, status, disk usage, and a kebab menu (View, Edit, Suspend, Terminate). Filters: search, status, plan, webserver, reseller.

### Create Wizard

| Field | Required | Notes |
|---|---|---|
| Username | yes | 3–16 chars, lowercase letters and digits, starting with a letter (no underscore). Becomes the Linux user. |
| Primary domain | yes | Not checked against DNS — the account is created whatever the name resolves to. Auto SSL's Let's Encrypt order succeeds only once the name points at the server; a failed order is listed on the account page as a setup step that did not finish. A name another account already serves (as its primary domain, an addon, a parked domain or a subdomain) is refused with `409 ACCOUNT_EXISTS` — on create and when an account's primary domain is changed; nothing is changed then. |
| Plan | yes | Or "Custom" to pick package limits manually. |
| Webserver type | yes | `nginx`, `nginx_apache`, `openlitespeed`, `litespeed` (last two require the matching plugin active). `apache` (Apache alone) is listed only on a server installed with Apache alone; on an nginx or nginx + Apache server an API request for `apache` gets `nginx_apache` (Apache behind nginx), because nginx holds the public ports and an Apache-only site would get no traffic. |
| PHP version | yes | One of `config.php.installed_versions`. Default = `config.php.default_version`. |
| Account IP | optional | Defaults to primary server IP. Pick a secondary IP for SNI separation. |
| Password | yes | At least 8 characters and at most 72 bytes (UTF-8; a character outside ASCII counts as more than one byte). Bcrypt-hashed, copy-on-create dialog shows it once. The same limit applies to the account password dialog. |
| Email | optional | Used for password reset and notifications. |
| Auto SSL | yes | Orders a Let's Encrypt certificate for the primary domain in the background after the account is created, with no DNS check of its own (see *Primary domain*); a failed order does not undo the account and is listed on the account page as a setup step that did not finish. Turning it off later on the edit form takes the primary domain back to plain HTTP and deletes its certificate. |
| Setup mail + DNS | yes | Provisions Postfix virtual mailboxes, OpenDKIM key, PowerDNS zone. |

The wizard runs server-side as a single transaction — failures roll the user back (no orphaned Linux user, no orphaned vhost).

### Account Detail

There are no tabs; the page is made of cards: the actions (Edit Account, Login to Client Panel, Change Password, Change IP Address, Suspend / Unsuspend, Terminate), Usage Trends (disk, CPU, memory), usage against the package (disk, bandwidth, CPU, memory, processes, domains, databases, email accounts, FTP accounts), Account Information — its Home Directory row opens the File Manager at the account's home — and Package Limits (plus Reseller Limits for a reseller). The account's domains, databases, mailboxes and files are managed on their own pages (§ 11).

### Suspend / Unsuspend / Terminate

- **Suspend** stops mail delivery, rewrites the vhost of the primary domain and of every addon, subdomain and parked domain to a 503 page, blocks SSH, disables every FTP user of the account (the daemon refuses their next login), and reflects in the Linux account flags. A domain whose suspended vhost fails the web server's configuration test is left as it was and named in the audit entry (`vhosts_left_serving`); the rest are suspended.
- **While suspended** the account's domains keep serving the 503 page whatever is changed on them: a PHP version, SSL, redirect, WAF or custom vhost change is saved into the configuration the suspension keeps aside and takes effect when the account is unsuspended. No domain can be added to a suspended account — an addon, subdomain or parked domain is refused with `403 ACCOUNT_SUSPENDED` until the account is unsuspended.
- **Unsuspend** restores the vhosts the suspension took down, with the changes made during the suspension, the credentials, the FTP users and the account's own SSH / Shell Access setting (an account created without a shell does not gain one).
- **Change Password** also gives the account's default FTP user (`<user>_<user>`) the new password; FTP users the account added itself keep theirs.
- **Terminate** is destructive and runs the cascade: SSL → DNS → DB → FTP → PHP-FPM pool → vhost → backups → user; the account's panel notifications and notification settings go with it, so an account created later under the same username starts with none. It runs after a plain confirmation dialog that warns the data is deleted for good; nothing has to be typed.

### Reseller Toggle

Any account can become a reseller. Once flagged, the account gains its own scoped account tree and can be given a **Reseller ACL plan** (see § 5). Assigning a plan is optional: a reseller with no plan is unrestricted. Choose **No ACL Plan** in the account edit form to remove an assignment. Terminating a reseller terminates its sub-accounts with it (the confirmation dialog says so). Suspending a reseller suspends its active sub-accounts too, and unsuspending it brings back the ones that were suspended together with it. Each of those sub-accounts is suspended the way a direct suspension does it: sites, sign-in, cron, FTP logins, mail and hosted apps. A reseller that still owns sub-accounts cannot be turned back into a plain account — move or terminate them first.

### SSH / Shell Access

The account create and edit forms carry an **SSH / Shell Access** switch. It sets the Linux
login shell of the account's system user and, when off, also refuses the account at the SSH
server itself — so no shell, no SFTP and no port forwarding. The site, cron jobs, the file
manager and FTP are unaffected either way: the panel runs that work with its own shell.

New accounts are created with the switch **off**. Accounts that already existed keep the shell
they have until an operator changes it; the form shows the account's real shell, not a stored
guess.

Note that an account **with** shell access can reach services listening on localhost (the
database server among them), which no per-account setting can prevent. Grant it deliberately.

**Endpoints used:** `GET /accounts`, `POST /accounts`, `GET /accounts/{u}`, `PUT /accounts/{u}`, `DELETE /accounts/{u}`, `POST /accounts/{u}/suspend`, `POST /accounts/{u}/unsuspend`, `PATCH /accounts/{u}/password`, `GET /accounts/{u}/usage`.

---
