← All settings

Security

Security and authentication settings

46 keys security
KeyTypeDescription
email_login_enabled select Enable passwordless email login with 6-digit OTP codes sent to user email addresses (requires SMTP to be configured)
captcha_provider select Captcha service provider (Turnstile, hCaptcha, Google reCAPTCHA, Friendly Captcha, or reForge Captcha)
turnstile_enabled select The Turnstile enabled of the application
turnstile_key_pub text The Turnstile key pub of the application
turnstile_key_priv password The Turnstile private key of the application
hcaptcha_site_key text The hCaptcha site key of the application
hcaptcha_secret_key password The hCaptcha secret key of the application
recaptcha_site_key text The reCAPTCHA site key of the application
recaptcha_secret_key password The reCAPTCHA secret key of the application
recaptcha_version select Use reCAPTCHA v2 (checkbox) or v3 (invisible score). Keys must match the version in Google Admin.
recaptcha_v3_min_score text Minimum v3 score (0.0–1.0). Higher is stricter. Ignored when version is v2.
recaptcha_v3_action text reCAPTCHA v3 action name (must match what the frontend sends). Use letters, numbers, underscores, and slashes only.
friendly_captcha_site_key text The Friendly Captcha site key of the application
friendly_captcha_secret_key password The Friendly Captcha secret key of the application
reforge_captcha_site_key text reForge Captcha public site key (from dashboard → Sites)
reforge_captcha_secret_key password reForge Captcha secret key (server-side only; never expose to the browser)
reforge_captcha_widget_type select reForge Captcha widget challenge type (checkbox or image)
reforge_captcha_theme select reForge Captcha widget colour theme
reforge_captcha_size select reForge Captcha widget size
reforge_captcha_lang text Optional reForge Captcha widget UI language (e.g. en, nl, de). Leave empty for default.
reforge_captcha_min_score text Minimum reForge Captcha verify score (0.0–1.0) when the verify API returns a score (stricter = higher)
registration_enabled select Can users register themselves?
registration_require_email_verification select Require users to verify their email before they can log in after registration.
registration_device_limit_enabled select Block new registrations when a browser/device already has the maximum number of panel accounts.
registration_device_max_accounts number Maximum number of accounts allowed per browser/device before registration is blocked (main account is the oldest account seen on that device).
email_domain_blocking_enabled select When enabled, registration and email changes are rejected if the address domain matches a row in Admin → Blocked email domains (suffix match). Manage the list on that page.
abuseipdb_enabled select Enable AbuseIPDB integration for registration checks, user IP scanning, and optional reporting when banning users. Get an API key at https://www.abuseipdb.com/.
abuseipdb_api_key password AbuseIPDB API key (stored encrypted). Required when AbuseIPDB is enabled.
abuseipdb_check_on_register select Check a registering user\
abuseipdb_min_confidence_score number Minimum AbuseIPDB abuse confidence score (0-100) to treat an IP as reported. AbuseIPDB recommends 75-100 for blocking.
abuseipdb_max_age_days number Only consider AbuseIPDB reports from the last N days when checking an IP (1-365).
abuseipdb_register_action select What to do when a registering IP meets the confidence score threshold.
require_two_fa_admins select Require two-factor authentication for admins
avatar_provider select Default avatar provider for users without a custom profile picture
avatar_custom_url text Custom avatar URL template (only used when avatar provider is custom). Placeholders: {email}, {username}, {name}, {hash}, {app_url}
user_allow_avatar_change select Allow users to change their avatar
user_allow_username_change select Allow users to change their username
user_allow_email_change select Allow users to change their email address
user_allow_first_name_change select Allow users to change their first name
user_allow_last_name_change select Allow users to change their last name
user_allow_api_keys_create select Allow users to create API keys
user_allow_account_deletion select Allow users to permanently delete their own account
user_account_deletion_mode select How account deletions are processed: instant, delayed, or after active services expire
user_account_deletion_delay_days text Days to wait before hard-deleting when mode is delayed (1-365)
user_account_deletion_verify_2fa select Require two-factor authentication to confirm account deletion
user_account_deletion_verify_email_otp select Require email one-time password to confirm account deletion