Users & groups
Overview
The central user directory allows users to use the same username and password across apps.
For information on configuring app access control and SSO integration, see Access control.
Users
New users can be added in the Users view.

An invitation email can optionally be sent to the user's primary email.

Click a user in the list to open the user page. Changes to the profile, role, and groups on the user page are saved immediately.
The actions menu (...) on the user page has less common actions: reset password, disable, and remove.
If the user has not accepted the invitation yet, the user page shows an Invitation field with a button to send the invitation again.
Removing a user revokes all app access. Apps often maintain their own login sessions and may not log out the user immediately. For this reason, you should disable the user inside apps as well.
Valid usernames
Allowed characters in usernames:
- Alphanumeric characters
.(dot)-(hyphen)
Choose usernames carefully. Generic words like error, pull, 404 may be reserved by apps.
App access
Click App access on the user page to see the apps and why the user has access.
Each app lists a reason:
All users- The app has no access restrictionGroup- The user is in a group allowed to use the appUser ACL- The user is listed in the app's access restrictionOperator- The user is an app operatorAdmin- Admins can access every app

App passwords
Admins can create app passwords that authenticate as a user from the user page. A password can log in to the dashboard, to email, or to specific apps. These are useful for scripts and automation, such as import/export jobs or CI, and for signing in as that user. Admins can also create them on their own user page. This keeps the passwords of all users in one place.
Admins manage these passwords, not the user. The user cannot see or revoke them in their profile. Any admin with a role equal to or higher than the user's role can list and remove them. The password remains when the admin who created it is removed.
Groups
Groups organize users and control app access. Assign groups to apps to restrict access.

When adding a group, you can assign users and apps:

Access restrictions can also be set in the app's configure dialog:

Valid group names
Allowed characters in group names:
- Alphanumeric characters
.(dot)-(hyphen)
Roles
Roles define user permissions.

User
Users can log in to the dashboard and access their assigned apps. They can edit their profile (name, password, avatar).
To allow a user to manage specific apps, see App Operator.
User manager
User Managers can add, edit, and remove users and groups. New users receive the User role by default. User Managers cannot modify existing user roles.
Mail manager
Mail Managers can manage mailboxes and mailbox forwarding, in addition to managing users.
Mail Managers cannot access email server logs for security reasons.
Admin
Admins can manage apps and users. Admins can:
- Log in to any app regardless of
Access Controlsettings - Create app passwords that log in as a user
- Access user data via File Manager or Web Terminal
- Configure branding, networking, domains, services, etc.
- Access mail server logs
To give a user control over specific apps only, use App Operator.
Superadmin
Superadmins have all admin capabilities plus:
- Manage subscription
- Manage backup storage and policy
- Open support tickets
The superadmin role is for those responsible for server administration and billing.
The Manage Subscription button in Settings automatically logs in to the Cloudron.io account.
Password reset
Users can reset their own passwords from the link in the login screen - https://my.example.com/passwordreset.html.
Alternately, admins can email password reset links to other users with Reset password in the actions menu of the user page:

If email delivery fails, the password reset link can be copied and sent through other means.

Superadmin password reset
Generate a one-time superadmin password via SSH:
sudo cloudron-support --owner-login
The command prints a one-time password. It bypasses 2FA, which is useful when the superadmin has lost their 2FA device. The password stops working after it is used.
Reset 2FA
If a user loses their 2FA device, admins can reset 2FA from the user page.

Once reset, the user can log in with just their password and set up 2FA again.
If the superadmin loses their 2FA device, see superadmin password reset to generate a one-time password that bypasses 2FA.
Disable user
Use Disable in the actions menu of the user page to disable a user. This invalidates all dashboard sessions and logs them out. The user may still have access to apps they were logged into. Check if the app provides a logout feature.

Disabling a user blocks login access but does not delete any app data.