Accounts
The first account is an admin called admin. Admins add more under Settings → Accounts, each with its own name, password and role:
| Role | Sees the wall | Runs actions (keys, text, power, ports, reboot) | Settings, KVMs, accounts, updates, activity log |
|---|---|---|---|
| Viewer | yes | no | no |
| Operator | yes | yes | no |
| Admin | yes | yes | yes |
- An operator or viewer can be limited to some of the KVMs. The others do not exist for that account: not on the wall, not in the status, not by guessing their address.
- With one account, signing in asks for the password only. With several, it asks for the user name too.
- Everyone can change their own password (Settings → Security). An admin can set a new one for somebody else, which signs that account out everywhere.
- The only admin cannot be removed or demoted, and nobody can change their own role.
- The page hides what an account may not use, but the rule is enforced on the server: every request is checked against the role, and anything not explicitly opened to viewers or operators takes an admin.
- The activity log records the account behind every sign-in, change and action.
Two-factor sign-in
Anyone can add a second step to their own account under Settings → Security: signing in then asks for the password and for a 6-digit code from an authenticator app (Google Authenticator, Microsoft Authenticator, 1Password, Aegis and so on). Setting it up shows a QR code to scan (and the same key as text); a code works once.
If the phone is lost, an admin can switch it off for that account under Accounts. If it was the only admin's phone, run python -m qkvm --disable-2fa NAME on the computer QKVM runs on.