# Webmail and phpMyAdmin

Single sign-on links:

### Webmail

- **URL:** `https://your-server.example.com/webmail/`
- **Engine:** Roundcube
- **SSO:** click the **Webmail** button next to a mailbox on the Email page (or the dashboard shortcut) — a one-shot token signs you in, no extra password; the signed-in session reads and sends as that mailbox
- **Token TTL:** 5 minutes, single use (a fresh click mints a new one)
- **Features:** HTML message compose, file attachments up to the mail server limit, contacts; there is no calendar

### phpMyAdmin

- **URL:** `https://your-server.example.com/phpmyadmin/`
- **SSO:** the phpMyAdmin icon on a database's row (Databases page) or the dashboard's phpMyAdmin shortcuts — same one-shot token mechanism
- **Scope:** read + write **only** on databases you own; other tenants' databases are not visible
- **Forbidden statements:** `SUPER`, `FILE`, `GRANT`, `CREATE USER` — these are panel-only operations
- **No database yet:** the dashboard's phpMyAdmin tile needs at least one database; without one it says so instead of opening a tab

Both round-trip the underlying credentials through a one-shot token; you never see the database root password or the IMAP server password.

---
