How to sign in for the first time and keep your recovery codes

How-to Getting started logintotpsecond factorrecovery codes

Sign in to the admin interface with the generated password and your authenticator app, and store the one-time recovery codes safely.

The second factor (TOTP) is mandatory for admins and resellers and optional for clients. The installer shows the secret and the recovery codes only once.

Steps

  1. Add the second-factor secret printed by the installer to an authenticator app (any TOTP app works).
  2. Store the recovery codes somewhere safe, outside the server. Each code works once.
  3. Open https://<your-hostname>:2087, enter the user admin, the generated password and the 6-digit code.
  4. Change the generated password from your account page. Changing your password or second factor closes all your sessions.
  5. Optionally issue a real certificate for the panel's hostname so the browser stops warning.

FAQ

Why does the browser warn me?

Until you issue a certificate for the panel's hostname it uses a self-signed one. Point the hostname at the node and issue one, or accept it once.

Where do customers sign in?

At https://<your-hostname>:2083. The two interfaces are separate applications on separate ports, and each rejects the other's role.

Last updated: 2026-10-10