# Settings category: Security

- **Id:** `security`
- **Icon:** `shield`
- **Count:** 46

Security and authentication settings

| Key | Type | Description | Options |
| --- | --- | --- | --- |
| `email_login_enabled` | select | Enable passwordless email login with 6-digit OTP codes sent to user email addresses (requires SMTP to be configured) | `true`, `false` |
| `captcha_provider` | select | Captcha service provider (Turnstile, hCaptcha, Google reCAPTCHA, Friendly Captcha, or reForge Captcha) | `turnstile`, `hcaptcha`, `recaptcha`, `friendlycaptcha`, `reforge` |
| `turnstile_enabled` | select | The Turnstile enabled of the application | `true`, `false` |
| `turnstile_key_pub` | text | The Turnstile key pub of the application | — |
| `turnstile_key_priv` | password | The Turnstile private key of the application | — |
| `hcaptcha_site_key` | text | The hCaptcha site key of the application | — |
| `hcaptcha_secret_key` | password | The hCaptcha secret key of the application | — |
| `recaptcha_site_key` | text | The reCAPTCHA site key of the application | — |
| `recaptcha_secret_key` | password | The reCAPTCHA secret key of the application | — |
| `recaptcha_version` | select | Use reCAPTCHA v2 (checkbox) or v3 (invisible score). Keys must match the version in Google Admin. | `v2`, `v3` |
| `recaptcha_v3_min_score` | text | Minimum v3 score (0.0–1.0). Higher is stricter. Ignored when version is v2. | — |
| `recaptcha_v3_action` | text | reCAPTCHA v3 action name (must match what the frontend sends). Use letters, numbers, underscores, and slashes only. | — |
| `friendly_captcha_site_key` | text | The Friendly Captcha site key of the application | — |
| `friendly_captcha_secret_key` | password | The Friendly Captcha secret key of the application | — |
| `reforge_captcha_site_key` | text | reForge Captcha public site key (from dashboard → Sites) | — |
| `reforge_captcha_secret_key` | password | reForge Captcha secret key (server-side only; never expose to the browser) | — |
| `reforge_captcha_widget_type` | select | reForge Captcha widget challenge type (checkbox or image) | `checkbox`, `image` |
| `reforge_captcha_theme` | select | reForge Captcha widget colour theme | `auto`, `dark`, `light` |
| `reforge_captcha_size` | select | reForge Captcha widget size | `normal`, `compact` |
| `reforge_captcha_lang` | text | Optional reForge Captcha widget UI language (e.g. en, nl, de). Leave empty for default. | — |
| `reforge_captcha_min_score` | text | Minimum reForge Captcha verify score (0.0–1.0) when the verify API returns a score (stricter = higher) | — |
| `registration_enabled` | select | Can users register themselves? | `true`, `false` |
| `registration_require_email_verification` | select | Require users to verify their email before they can log in after registration. | `true`, `false` |
| `registration_device_limit_enabled` | select | Block new registrations when a browser/device already has the maximum number of panel accounts. | `true`, `false` |
| `registration_device_max_accounts` | number | Maximum number of accounts allowed per browser/device before registration is blocked (main account is the oldest account seen on that device). | — |
| `email_domain_blocking_enabled` | select | When enabled, registration and email changes are rejected if the address domain matches a row in Admin → Blocked email domains (suffix match). Manage the list on that page. | `true`, `false` |
| `abuseipdb_enabled` | select | Enable AbuseIPDB integration for registration checks, user IP scanning, and optional reporting when banning users. Get an API key at https://www.abuseipdb.com/. | `true`, `false` |
| `abuseipdb_api_key` | password | AbuseIPDB API key (stored encrypted). Required when AbuseIPDB is enabled. | — |
| `abuseipdb_check_on_register` | select | Check a registering user\ | `true`, `false` |
| `abuseipdb_min_confidence_score` | number | Minimum AbuseIPDB abuse confidence score (0-100) to treat an IP as reported. AbuseIPDB recommends 75-100 for blocking. | — |
| `abuseipdb_max_age_days` | number | Only consider AbuseIPDB reports from the last N days when checking an IP (1-365). | — |
| `abuseipdb_register_action` | select | What to do when a registering IP meets the confidence score threshold. | `block`, `log`, `auto_ban` |
| `require_two_fa_admins` | select | Require two-factor authentication for admins | `true`, `false` |
| `avatar_provider` | select | Default avatar provider for users without a custom profile picture | `gravatar`, `panel_logo`, `ui_avatars`, `robohash`, `dicebear`, `custom` |
| `avatar_custom_url` | text | Custom avatar URL template (only used when avatar provider is custom). Placeholders: {email}, {username}, {name}, {hash}, {app_url} | — |
| `user_allow_avatar_change` | select | Allow users to change their avatar | `true`, `false` |
| `user_allow_username_change` | select | Allow users to change their username | `true`, `false` |
| `user_allow_email_change` | select | Allow users to change their email address | `true`, `false` |
| `user_allow_first_name_change` | select | Allow users to change their first name | `true`, `false` |
| `user_allow_last_name_change` | select | Allow users to change their last name | `true`, `false` |
| `user_allow_api_keys_create` | select | Allow users to create API keys | `true`, `false` |
| `user_allow_account_deletion` | select | Allow users to permanently delete their own account | `true`, `false` |
| `user_account_deletion_mode` | select | How account deletions are processed: instant, delayed, or after active services expire | `instant`, `delayed`, `after_services` |
| `user_account_deletion_delay_days` | text | Days to wait before hard-deleting when mode is delayed (1-365) | — |
| `user_account_deletion_verify_2fa` | select | Require two-factor authentication to confirm account deletion | `true`, `false` |
| `user_account_deletion_verify_email_otp` | select | Require email one-time password to confirm account deletion | `true`, `false` |
