# First Login

Open the panel URL provided by your hosting administrator. The exact host is server-specific, but the URL pattern looks like `https://your-server.example.com/en/client/login/`.

The browser language is auto-detected on first visit, and the language switcher in the topbar remembers your choice across sessions.

The colour theme follows your operating system until the topbar sun/moon toggle picks one; the choice is kept by the browser. The sidebar opens collapsed to its icons at 1024 px and wider until the topbar toggle expands it; the choice is kept with your account, so it outlasts signing out and is restored at your next sign-in in any browser. Below 1024 px the sidebar becomes a drawer behind the topbar's menu button. A horizontal swipe across the page also opens it (to the right; to the left in right-to-left languages) and a swipe back closes it, as do Esc, the overlay and choosing a page; a swipe that starts on a table or another area that scrolls sideways scrolls that area instead.

### Sign-in flow

1. Enter your **username** (or the email address registered to the account) and **password**. Both were sent to you by the hosting administrator after account creation.
2. If two-factor authentication (2FA) is enabled on your account, you are prompted for a **6-digit code** from your authenticator app or for an email-OTP code. Enter it within ~30 seconds.
3. On success the panel loads the **Dashboard**. The first run may also show a one-time tour for the major sidebar items.
4. If your hosting administrator requires two-factor authentication and your account has none yet, the sign-in lands on **Settings → Security** with the enrolment dialog open and a notice explaining why; the other pages redirect there until the second factor is active. Signing out is still possible.

### Enrolling 2FA (recommended)

Go to **Settings → Security → Two-factor authentication → Enable**. The enrollment dialog walks you through:

1. **Scan the QR code** with an authenticator app (Google Authenticator, Authy, 1Password, Microsoft Authenticator). If your app cannot scan, copy the displayed secret manually.
2. **Verify by entering the current 6-digit code** the app shows. The code must arrive within 30 seconds — clock skew on the phone can cause it to fail.
3. **Save your 8 backup codes** somewhere safe (each is a one-time code in `XXXX-XXXX-XXXX` form; once used it becomes invalid). The codes are shown only once; you will need them if you lose access to the authenticator.
4. Confirm with the "Saved!" button — 2FA is now active. Next login asks for username, password, and a 6-digit code.

### Password rules

- Minimum 12 characters
- At least 3 of: lowercase letters, uppercase letters, digits, symbols
- May not be a common dictionary password
- At most 72 bytes (UTF-8): a character outside ASCII counts as more than one byte
- The password input has a live strength meter and an in-place generator (click the wand icon)

### Forgot password

Click **Forgot password** on the login screen. Enter your registered email address. The form always says "If the account exists, an email has been sent" — it deliberately does not reveal whether your address is registered.

- The reset link is valid for **30 minutes** (TTL).
- If the same address is registered on more than one hosting account, you receive one link per account and each message names the account it resets.
- The link opens the **Set a new password** page: enter the new password twice (at least 8 characters, at most 72 bytes, different from the current one). A link is spent on first use; an expired, used or incomplete link says so and offers the way back to the sign-in page, where you can request a fresh one. Sessions opened before the reset are ended.
- The page opens in the language the panel uses in your browser (the one you last chose there, otherwise the server's default language or your browser's); changing the language on the page keeps the link.
- Check your spam folder if the email does not arrive within ~5 minutes.
- Following the link lets you set a new password; all other sessions are logged out automatically.

### Session timeout

Idle sessions log out after **30 minutes** of inactivity. Active use refreshes the session window. Closing the browser tab does not log you out — you stay signed in until the idle timer fires or you click **Log out** in the topbar avatar menu.

---
