Security and authentication settings
| Key | Type | Description |
|---|---|---|
email_login_enabled |
select | Enable passwordless email login with 6-digit OTP codes sent to user email addresses (requires SMTP to be configured) |
captcha_provider |
select | Captcha service provider (Turnstile, hCaptcha, Google reCAPTCHA, Friendly Captcha, or reForge Captcha) |
turnstile_enabled |
select | The Turnstile enabled of the application |
turnstile_key_pub |
text | The Turnstile key pub of the application |
turnstile_key_priv |
password | The Turnstile private key of the application |
hcaptcha_site_key |
text | The hCaptcha site key of the application |
hcaptcha_secret_key |
password | The hCaptcha secret key of the application |
recaptcha_site_key |
text | The reCAPTCHA site key of the application |
recaptcha_secret_key |
password | The reCAPTCHA secret key of the application |
recaptcha_version |
select | Use reCAPTCHA v2 (checkbox) or v3 (invisible score). Keys must match the version in Google Admin. |
recaptcha_v3_min_score |
text | Minimum v3 score (0.0–1.0). Higher is stricter. Ignored when version is v2. |
recaptcha_v3_action |
text | reCAPTCHA v3 action name (must match what the frontend sends). Use letters, numbers, underscores, and slashes only. |
friendly_captcha_site_key |
text | The Friendly Captcha site key of the application |
friendly_captcha_secret_key |
password | The Friendly Captcha secret key of the application |
reforge_captcha_site_key |
text | reForge Captcha public site key (from dashboard → Sites) |
reforge_captcha_secret_key |
password | reForge Captcha secret key (server-side only; never expose to the browser) |
reforge_captcha_widget_type |
select | reForge Captcha widget challenge type (checkbox or image) |
reforge_captcha_theme |
select | reForge Captcha widget colour theme |
reforge_captcha_size |
select | reForge Captcha widget size |
reforge_captcha_lang |
text | Optional reForge Captcha widget UI language (e.g. en, nl, de). Leave empty for default. |
reforge_captcha_min_score |
text | Minimum reForge Captcha verify score (0.0–1.0) when the verify API returns a score (stricter = higher) |
registration_enabled |
select | Can users register themselves? |
registration_require_email_verification |
select | Require users to verify their email before they can log in after registration. |
registration_device_limit_enabled |
select | Block new registrations when a browser/device already has the maximum number of panel accounts. |
registration_device_max_accounts |
number | Maximum number of accounts allowed per browser/device before registration is blocked (main account is the oldest account seen on that device). |
email_domain_blocking_enabled |
select | When enabled, registration and email changes are rejected if the address domain matches a row in Admin → Blocked email domains (suffix match). Manage the list on that page. |
abuseipdb_enabled |
select | Enable AbuseIPDB integration for registration checks, user IP scanning, and optional reporting when banning users. Get an API key at https://www.abuseipdb.com/. |
abuseipdb_api_key |
password | AbuseIPDB API key (stored encrypted). Required when AbuseIPDB is enabled. |
abuseipdb_check_on_register |
select | Check a registering user\ |
abuseipdb_min_confidence_score |
number | Minimum AbuseIPDB abuse confidence score (0-100) to treat an IP as reported. AbuseIPDB recommends 75-100 for blocking. |
abuseipdb_max_age_days |
number | Only consider AbuseIPDB reports from the last N days when checking an IP (1-365). |
abuseipdb_register_action |
select | What to do when a registering IP meets the confidence score threshold. |
require_two_fa_admins |
select | Require two-factor authentication for admins |
avatar_provider |
select | Default avatar provider for users without a custom profile picture |
avatar_custom_url |
text | Custom avatar URL template (only used when avatar provider is custom). Placeholders: {email}, {username}, {name}, {hash}, {app_url} |
user_allow_avatar_change |
select | Allow users to change their avatar |
user_allow_username_change |
select | Allow users to change their username |
user_allow_email_change |
select | Allow users to change their email address |
user_allow_first_name_change |
select | Allow users to change their first name |
user_allow_last_name_change |
select | Allow users to change their last name |
user_allow_api_keys_create |
select | Allow users to create API keys |
user_allow_account_deletion |
select | Allow users to permanently delete their own account |
user_account_deletion_mode |
select | How account deletions are processed: instant, delayed, or after active services expire |
user_account_deletion_delay_days |
text | Days to wait before hard-deleting when mode is delayed (1-365) |
user_account_deletion_verify_2fa |
select | Require two-factor authentication to confirm account deletion |
user_account_deletion_verify_email_otp |
select | Require email one-time password to confirm account deletion |