Skip to content
How to install

Admin accounts

Everyone who signs in to the panel. password in a body is always your own, so those calls need a session, never a key. Only the owner may change the owner.

Reading needs Read only and changes need Full, unless an endpoint says otherwise. How to read this page.

Every admin, the owner first.

  • Level: Read only
  • Notes: Not over MCP
  • Returns: {items: PanelUser[]}

Add an admin with a first password they can change themselves.

  • Level: Full
  • Notes: Not over MCP
  • Input: {username, password}
  • Returns: 201 PanelUser

One admin, with their 2FA status and last sign-in.

  • Level: Read only
  • Notes: Not over MCP
  • Returns: PanelUser

Remove an admin and end their sessions; never the owner, never yourself.

  • Level: Full
  • Notes: Destructive · Not over MCP

Rename an admin; nobody is signed out.

  • Level: Full
  • Notes: Not over MCP
  • Input: {password, username}

Set the recovery email; it takes over once the link sent to it is followed.

  • Level: Full
  • Notes: Not over MCP
  • Input: {password, email}

Remove the recovery email, and any reset link still out.

  • Level: Full
  • Notes: Destructive · Not over MCP
  • Input: {password}

Set a new password; ends their other sessions, or all of them when it is someone else’s.

  • Level: Full
  • Notes: Not over MCP
  • Input: {password, newPassword}

Mint a pending 2FA secret and its QR code - your own account only.

  • Level: Full
  • Notes: Not over MCP
  • Input: {password}

Arm 2FA with a code; returns ten recovery codes, once.

  • Level: Full
  • Notes: Not over MCP
  • Input: {code}

Issue a fresh set of recovery codes - your own account only.

  • Level: Full
  • Notes: Not over MCP
  • Input: {password}

Turn 2FA off - yours, or a colleague’s who lost their phone.

  • Level: Full
  • Notes: Destructive · Not over MCP
  • Input: {password}