Account & 2FA
Changing your password
On the Account page enter your current password and the new one twice. Passwords are 12 to 128 characters and common passwords are refused. The change applies to the panel and to SFTP/SSH password login at once (mailbox passwords are separate — see Email).
There is no "forgot password" link: contact your hosting provider, who can set a new one.
Two-factor authentication (TOTP)
Two-factor authentication asks for a six-digit code from an authenticator app after your password. Any TOTP app works: Aegis, FreeOTP, Google Authenticator, Microsoft Authenticator, 1Password, Bitwarden, …
Turning it on
- Click Set up two-factor authentication on the Account page.
- Scan the QR code with your app (or type the key shown next to it).
- Enter the six-digit code the app now shows and click Turn on.
- Save the eight recovery codes that appear. They are shown only this once. Each logs you in one time if your phone is lost.
Logging in — after your password, enter the current code from the app. Codes change every 30 seconds and each code can be used once; if you enter one just after using it, wait for the next. Wrong codes count towards the same lockout as wrong passwords (5 in 15 minutes).
Lost the app — enter one of your recovery codes instead of the six-digit code, then go to the Account page, turn 2FA off and set it up again to get a fresh key and new codes. The page shows how many recovery codes are left.
Turning it off requires your account password.
If both the app and the recovery codes are gone, your hosting provider can reset your account access.
Sessions
Panel sessions end after 8 hours, or after 1 hour without activity. Log out ends the session immediately.