Customer guide

For account owners and the people they invite: what you can do with your hosting account, and where to find it.

Every task below is an action you can run from its module's page, from the command palette (Ctrl K) or through the API. Dedicated screens for each area are being built.

Your security

Your Security page has your passkeys, authenticator app, recovery codes, signed-in devices, API tokens and password. Add a passkey on each device you use; end any device you do not recognise and it is signed out within seconds. API tokens are shown once, can be limited in scope, and can be revoked at any time.

Domains and websites

  • Add a domain, subdomain, alias or parked domain. Depending on your plan, a DNS zone, a website and a certificate follow automatically.
  • Sites are static, PHP or a reverse proxy to an app. Each PHP version runs as your own Linux user, separate from other accounts.
  • Change PHP settings and add nginx snippets within the allowed list; anything refused comes back with its line number. A change that breaks the site is rolled back automatically.
  • HTTPS is automatic. You can also upload your own certificate.

Mail

  • Mailboxes with quotas, aliases, forwarders, a catch-all and autoresponders.
  • DKIM, SPF, DMARC and autoconfig records are published for you when your DNS is hosted here.
  • Mail apps connect over IMAP (993) and submission (587 or 465). You can only send as the mailbox you signed in with.

Databases

  • MariaDB or MySQL and PostgreSQL databases with users at read-only, read-write or admin level.
  • Passwords are generated and shown once. Remote access is off until you add an address, and then requires TLS.
  • Export a database to a .sql.gz file in your home and import one back.
  • A Valkey instance of your own, if your plan includes one.

Files, SSH and the terminal

  • Browse, upload (resumable), edit, move, archive and extract files. Everything runs as your own Linux user.
  • Add SSH keys, with optional limits on where they can connect from, what they can run and when they expire.
  • Choose SSH off, SFTP only, or a shell, where your plan allows it.
  • Open a terminal in the browser. It is a real shell as your user; it closes after 30 minutes idle.

Containers

Deploy Docker Compose stacks or install an app from the catalogue (WordPress, Ghost, n8n, Uptime Kuma, Gitea, Nextcloud, Plausible, Metabase, SeaweedFS, Valkey). Compose options that would reach outside your account are refused with the line that caused it. Upgrades take a snapshot first and roll back on failure.

Backups and storage

  • Back up your files and databases to local storage, the server's S3 store or your own S3, B2, R2, SFTP or WebDAV storage.
  • Restore single files, a database or the whole account. A whole-account restore can be rolled back for 24 hours.
  • Create S3 buckets and access keys and use them from your own code with any S3 SDK.

Sub-users

Invite a developer, designer or client as a sub-user and give them only what they need: one site, one folder, one mailbox. Folder grants are enforced by the server, not only by the panel, so a sub-user cannot follow a link out of the folder they were given.

See also: all features and the API.