# Settings

### Profile

| Field | Notes |
|---|---|
| Display name | Max 64 characters, shown in the topbar avatar dropdown |
| Email | Must be verified — used for password reset and notifications |
| Locale | TR, EN, and any other languages your operator enabled |
| Timezone | IANA tz database name (`Europe/Istanbul`, `UTC`, `America/New_York`) — all timestamps in the panel render in this zone |
| Avatar | PNG or JPG, ≤ 2 MB, square — 256×256 px recommended |

### Security

- **2FA enable / disable / re-enroll:** QR scan (recommended) or manual secret entry for password-manager apps
- **Backup codes:** 8 codes in `XXXX-XXXX-XXXX` form; type them with or without dashes, in any case. Each code is single-use — once used it is invalidated — and works with either 2FA method (authenticator app or e-mail). Generate a new set to invalidate the old set entirely.
- **Active sessions:** lists every signed-in browser with User-Agent, IP, and last activity timestamp. Click **Revoke** on any row to immediately log out that session.
- **Password change:** enter your current password plus the new password twice. On save, every other session is logged out (the active one stays signed in).

### API Access (resellers)

Reseller accounts can mint API keys from **Settings → API Access** (the entry appears in the account menu only for resellers). A key acts as your reseller account on the client API — the same operations your browser session can perform on your own hosting and on the sub-accounts you manage (`/api/v1/client/*`), with the same ownership checks and the same ACL plan. It cannot reach the administrator API.

- **Signing:** identical to server keys — `X-WHost-Key`, `X-WHost-Timestamp`, `X-WHost-Nonce`, `X-WHost-Signature` (HMAC-SHA256 v2, see the developer API reference). The secret is shown **once** at creation.
- **Limits:** up to 10 keys per account; an optional IP allowlist per key; revoke (keeps the row, refuses requests with `401`) or delete.
- **Browser-only actions:** password, 2FA and profile changes, and API-key management itself, are refused over a key (`403 HMAC_FORBIDDEN_FOR_CREDENTIAL_MUTATION`).
- **ACL:** your plan must grant **API Access**; if it does not, the page shows the refusal and existing keys stop working (`403 PERMISSION_DENIED`). A suspended account's keys are refused as well.
- **Access logs:** the second tab lists every request signed with your keys (time, IP, method, endpoint, status).

---
