Settings

Updated Oct 5, 2026 Markdown

Profile

Display nameMax 64 characters, shown in the topbar avatar dropdown
EmailMust be verified — used for password reset and notifications
LocaleTR, EN, and any other languages your operator enabled
TimezoneIANA tz database name (Europe/Istanbul, UTC, America/New_York) — all timestamps in the panel render in this zone
AvatarPNG or JPG, ≤ 2 MB, square — 256×256 px recommended

Security

  • 2FA enable / disable / re-enroll: QR scan (recommended) or manual secret entry for password-manager apps
  • Backup codes: 8 codes in XXXX-XXXX-XXXX form; type them with or without dashes, in any case. Each code is single-use — once used it is invalidated — and works with either 2FA method (authenticator app or e-mail). Generate a new set to invalidate the old set entirely.
  • Active sessions: lists every signed-in browser with User-Agent, IP, and last activity timestamp. Click Revoke on any row to immediately log out that session.
  • Password change: enter your current password plus the new password twice. On save, every other session is logged out (the active one stays signed in).

API Access (resellers)

Reseller accounts can mint API keys from Settings → API Access (the entry appears in the account menu only for resellers). A key acts as your reseller account on the client API — the same operations your browser session can perform on your own hosting and on the sub-accounts you manage (/api/v1/client/*), with the same ownership checks and the same ACL plan. It cannot reach the administrator API.

  • Signing: identical to server keys — X-WHost-Key, X-WHost-Timestamp, X-WHost-Nonce, X-WHost-Signature (HMAC-SHA256 v2, see the developer API reference). The secret is shown once at creation.
  • Limits: up to 10 keys per account; an optional IP allowlist per key; revoke (keeps the row, refuses requests with 401) or delete.
  • Browser-only actions: password, 2FA and profile changes, and API-key management itself, are refused over a key (403 HMAC_FORBIDDEN_FOR_CREDENTIAL_MUTATION).
  • ACL: your plan must grant API Access; if it does not, the page shows the refusal and existing keys stop working (403 PERMISSION_DENIED). A suspended account's keys are refused as well.
  • Access logs: the second tab lists every request signed with your keys (time, IP, method, endpoint, status).
Still Need Help?

Our support team is here around the clock for anything you can't find above.