Passkeys and secure sign-in
On the Account page, Secure sign-in box, every user (administrator, reseller or client) can protect their sign-in with passkeys, an authenticator app and recovery codes.
Passkeys
A passkey is a key that stays on your device: Face ID or Touch ID on the Mac and iPhone, Windows Hello, your Android phone, a password manager (1Password, Bitwarden) or a USB/NFC security key. It cannot be guessed nor stolen by a fake page, because it only works on the panel's real address.
- Add a passkey and give it a name to recognise it. You can have more than one (for example computer and phone): that is recommended, so if you lose one you sign in with the other.
- On the sign-in page Sign in with a passkey signs you in without a password: the browser offers the accounts it knows and asks for the PIN or fingerprint.
- Passkeys work when the panel is opened by its name (for example
https://panel.example.com:8443), not by IP address: set the name in Panel certificate. A passkey works for the name you created it with.
Authenticator app
With Set up the app you scan a QR code with Google Authenticator, Microsoft Authenticator, 1Password, Bitwarden or a similar app; then type the 6-digit code to confirm. From then on, after the password the panel asks for the code the app shows (it changes every 30 seconds and works once).
The second step
When you have at least one passkey or the app on, the password alone no longer signs in: after the password the panel asks for the passkey or the app code. Wrong attempts are throttled like the password.
Recovery codes
With the first method the panel shows 10 recovery codes, only once: keep them in a password manager or on paper. Each works once and replaces passkeys and app if you lose them. New codes generates them again (the old ones stop working). To remove a passkey or the app, or to generate new codes, the panel asks for the password again.
If you lose everything
- An administrator (or the reseller for its clients) opens the account in Accounts and presses Reset secure sign-in: passkeys, app and codes are removed and the user signs in with the password again.
- For an administrator, on the server:
panel-agent user reset-mfa <name>.
Sign-in links created by the panel (for example from WHMCS or when switching between linked servers) still work: they are already a verified sign-in.