New: one-click Cloud Apps
All documentation

Billing & account

Keeping your account secure

Two-factor authentication, sessions and API keys — the three things worth setting up before you rely on the account.

Your panel account controls everything you host with us. These are worth ten minutes.

Two-factor authentication

Turn it on in Settings → Security. You scan a code with an authenticator app, and from then on sign-in asks for a six-digit code as well as your password.

Save the recovery codes somewhere that is not your password manager, if your password manager is also the thing generating the codes. Losing both means proving who you are the slow way.

Sessions

The Security page lists everywhere you are signed in. If something looks unfamiliar, sign it out.

Signing out of a session takes effect immediately.

API keys

If you automate anything against our API, create a key in Settings → API keys rather than using your password.

  • The key is shown once. Copy it then.
  • Give it only the scopes it needs. A key that only reads does not need write access.
  • Revoke keys you are no longer using. An unused key is only a risk.

Keys are separate from your password: changing your password does not revoke them, and revoking one does not affect your sign-in.

Email address

Keep it current. Password resets, invoices, renewal notices and outage alerts all go there, and an address you no longer read is how people miss a suspension notice.

Changing it requires confirming the new address before the change takes effect.

If you think something is wrong

Change your password, sign out other sessions, and revoke API keys you do not recognise — in that order. Then open a ticket and tell us what you saw. We can look at the account's audit log, which records every action taken and from where.

Still stuck? Get in touch — a person reads every message.

Ready to deploy?

Deploy an app from the catalog in minutes. No contracts, no setup fees.