All pages

Accounts

The first account is an admin called admin. Admins add more under Settings → Accounts, each with its own name, password and role:

RoleSees the wallRuns actions (keys, text, power, ports, reboot)Settings, KVMs, accounts, updates, activity log
Vieweryesnono
Operatoryesyesno
Adminyesyesyes
  • An operator or viewer can be limited to some of the KVMs. The others do not exist for that account: not on the wall, not in the status, not by guessing their address.
  • With one account, signing in asks for the password only. With several, it asks for the user name too.
  • Everyone can change their own password (Settings → Security). An admin can set a new one for somebody else, which signs that account out everywhere.
  • The only admin cannot be removed or demoted, and nobody can change their own role.
  • The page hides what an account may not use, but the rule is enforced on the server: every request is checked against the role, and anything not explicitly opened to viewers or operators takes an admin.
  • The activity log records the account behind every sign-in, change and action.

Two-factor sign-in

Anyone can add a second step to their own account under Settings → Security: signing in then asks for the password and for a 6-digit code from an authenticator app (Google Authenticator, Microsoft Authenticator, 1Password, Aegis and so on). Setting it up shows a QR code to scan (and the same key as text); a code works once.

If the phone is lost, an admin can switch it off for that account under Accounts. If it was the only admin's phone, run python -m qkvm --disable-2fa NAME on the computer QKVM runs on.