# First Login and Initial Setup

After installation the panel is reachable at `https://YOUR_SERVER/{lang}/admin/login/`. Default language is detected from the browser; the topbar language switcher persists the choice. Signing in keeps that language unless the profile carries an explicit language preference (Settings → Profile → Language Preference; **Automatic** is the default).

The colour theme follows the operating system until the topbar sun/moon toggle picks one; the choice is kept by the browser. The sidebar opens collapsed to its icons at 1024 px and wider until the topbar toggle expands it; the choice is kept with the admin account, so it outlasts signing out and is restored at the next sign-in in any browser. A client panel opened with **Login to Client Panel** does not change that account's own choice. Below 1024 px the sidebar becomes a drawer behind the topbar's menu button. A horizontal swipe across the page also opens it (to the right; to the left in right-to-left languages) and a swipe back closes it, as do Esc, the overlay and choosing a page; a swipe that starts on a table or another area that scrolls sideways scrolls that area instead.

The sidebar holds the pages used day to day, in five groups: **Management** (Accounts, Plans, Resellers), **Hosting** (Domains, DNS, SSL, Email, Databases, FTP), **Tools** (File Manager, the Python and Node.js apps while their plugins are active, Cron Jobs, Migration), **Server** (Services, Backups, Logs) and **Security** (Firewall, Fail2Ban, ModSecurity WAF). **Settings**, pinned to the bottom of the sidebar, opens the settings hub (§16). The pages reached from the hub — PHP, Spam Filter, Banned Words and Plugins among them — have no sidebar entry of their own; **Settings** stays highlighted while one of them is open. The command palette (Ctrl/⌘ K) lists Settings, PHP, Spam Filter, Banned Words and Plugins too.

The account menu at the right of the topbar opens Profile and White Label and signs you out. It also links to this documentation site: **Documentation** opens `https://whost.wisecp.com/` in a new tab; it is hidden while white-label branding is active, so the panel does not name WHost.

| Step | Action | Notes |
|---|---|---|
| 1 | Activate license | Sign in with the admin password first. When activation is required, the panel then opens on the license page, which shows that no license is active and holds the key form; that sign-in's session submits the key and opens nothing else in the panel until a key is accepted. The agent verifies the license with the license service; a rejected key shows the service's reason. A key that was activated before — a reinstalled server — is answered with "This license key is already registered to an installation": reissue the license with your license provider, then enter it again (see the installation guide, *Reinstalling a server under the same key*). After a successful activation the license page shows the active license and the rest of the panel opens. |
| 2 | Change default password | Settings → Profile → Password. The default password is shown once at install time; rotating it is the first hardening step. |
| 3 | Enroll 2FA | Settings → Profile → Security. Choose TOTP (Google Authenticator / 1Password / Authy) or email OTP. Backup codes are issued once — store them outside the panel. |
| 4 | Configure SMTP | Settings → Notifications → Email. Required for password reset emails and admin notifications. Send a test email before saving. Until a relay is set, the panel mails through the server's own mail service as `whost@<server hostname>`; that service only accepts the address while the hostname resolves in public DNS. |
| 5 | Set IP whitelist | Settings → Security → Admin IP whitelist. Optional but strongly recommended for production. |

Settings → License shows the masked license key, status and expiry date. `ACTIVE` and `GRACE` allow normal panel use; `NOT_ACTIVATED` and `SUSPENDED` redirect an existing admin session's operational pages to license management; your customers' client panel pages show a "The control panel is temporarily unavailable" notice instead, which names no license detail (their websites and mail keep running). Signing in never contacts the license service: the panel reports the state of the last check. The agent checks the license when it starts and about once a day; **Verify Now** on the license page checks it at once, so sign-ins never use up the service's per-license rate limit and a slow or unreachable license service never blocks a sign-in.

Changing the system clock backward does not extend the remaining grace period.
Restarting the agent within the same operating-system boot preserves elapsed
license time. An operating-system reboot, or an older cache without a clock
anchor, requires an online license check before cached grace is available.

Restored caches must retain their signed license assertion and expiry. An
incomplete or modified assertion requires online verification; its local HMAC
alone cannot restore activation or grace access.

**Endpoints used:** `POST /license/activate`, `PATCH /admin/profile/password`, `POST /admin/profile/2fa/setup` + `/enable`, `PUT /admin/notifications/settings`, `POST /admin/notifications/test-email`.

---
