Settings is the last entry in the portal's left rail. It opens on General and has a menu of its own, in three groups: the organization, your account, and security. The same menu is a row of tabs on a phone.
| Group | Page | What it is for |
|---|---|---|
| Organization | General | The organization's name, and invitations you have received |
| Organization | Members | Who is in the organization and which workspaces they can open |
| Organization | Workspaces | Separate spaces for production, staging, or each of your clients |
| Organization | Single sign-on | Sign-in through your company's identity provider |
| Organization | API keys | Keys for the client API, and this month's request usage |
| Account | Profile | Your name and company, as shown on statements, receipts and tickets |
| Account | Appearance | System, Light or Dark theme |
| Account | Privacy | Download your information, privacy requests, analytics sharing |
| Security | Password | Change your password |
| Security | Two-factor authentication | An authenticator app, passkeys, and recovery codes |
| Security | Sessions | Every device signed in to your account |
The organization
Every account belongs to one organization, and the organization has one owner. The owner holds the balance: servers in every workspace draw from the same account credit, and only the owner adds credit, sees billing, and runs the referral programs.
Members
Open Settings → Members and choose Invite member. The person gets an emailed link and becomes a member when they accept it. Pending invitations are listed with their expiry date, and you can revoke one until it is accepted.
There are two roles:
| Role | What they can do |
|---|---|
| Owner | Everything, including billing, members, single sign-on and API keys |
| Member | Deploy and manage servers and apps in the workspaces they can open, from the shared balance. Members cannot see billing or the referral programs |
For each member, Change access sets All workspaces or a specific list. A specific list stays fixed: a workspace you create later is not added to it.
Removing a member takes away their access to the organization's workspaces and shared tickets. They get their own organization back.
Accepting an invitation closes your own organization
Joining another organization means you stop having one of your own. The portal explains what moves with you before you accept.
Workspaces
Settings → Workspaces lists every workspace in the organization. Use them to keep production, staging, or each of your own clients apart. Every workspace shares the one balance. Switch between them from the workspace switcher at the top of the left rail. The client API calls a workspace a tenant; see Client API authentication and keys.
Single sign-on
Settings → Single sign-on connects an OpenID Connect identity provider, so anyone with an email address on your company domain can continue from the sign-in page and authenticate with that provider. Only the owner can connect it, and the owner's own email has to be on the domain being registered (a personal inbox such as Gmail cannot be used). Serve WebFinger on the domain so the issuer can be found, then paste the client ID and secret from the identity provider. See Signing in and password reset.
API keys
Settings → API keys is where the owner creates and revokes client API keys. Keys belong to the organization, not to a person. A new key's secret is shown once, right after you create it. The page also shows this month's request usage against the included allowance. See Client API authentication and keys.
Your account
- Profile: your name and company, which appear on statements, receipts and tickets. The account email is the account identity, so changing it goes through support.
- Appearance: System, Light or Dark. System follows your device's setting. The choice is saved to your account, so it follows you to every device you sign in on, including these docs.
- Privacy: download a copy of your information, ask for a correction or deletion, and control analytics sharing. See Privacy and your data.
Security
- Password: changing it keeps you signed in on this device and signs out every other device.
- Two-factor authentication: an authenticator app, passkeys, or both, and your recovery codes. See Two-factor authentication and passkeys.
- Sessions: every device signed in to your account. Sign out any you do not recognize, then change your password.