Skip to content

Team and account

Your account (email, password, two-factor) is separate from any single customer you work with. If you manage hosting for several clients or businesses, one login can belong to every one of them, each with its own role — no separate password to remember for each.

Invite people to your team from Account → Team, with one of these roles:

Role Can do
Owner Everything, including billing and removing other members
Admin Everything except billing
Developer Sites, files, SSH, databases — no billing, no team management
Billing Invoices, payment methods and subscription changes only
Viewer Read-only access to everything the role can see

Need to give a contractor access to just one site, not your whole account? Scope their membership to specific sites when you invite them. A site-scoped member gets their role’s abilities on the sites they’re listed for, and nothing that acts on the account as a whole: they can’t create new sites, manage the team, see billing, or touch anything outside their listed sites — including being unable to widen their own access by inviting themselves to more.

Set up an authenticator app or a passkey under Account → Security. Once you add a second factor, you receive ten recovery codes — store them somewhere safe; each one signs you in once, in place of your second factor, if you ever lose access to it.

Your active sessions are listed under Account → Security, with device and location info, and you can sign any one of them out individually — useful if you ever leave yourself signed in on a shared or lost device.

For scripts and integrations, create an API token under Account → API tokens instead of using your password. Each token:

  • Is scoped to specific permissions (for example, read-only access, or just site management) — never more than you grant it
  • Can optionally be locked to a single customer
  • Expires (90 days by default if you don’t set one, and never more than a year)