Skip to content

Settings ​

Everything panel-wide that isn't its own admin page lives under /admin/settings, split into eleven category tabs. Saving any category requires the settings.update permission.

Unsaved changes stay in the form while you switch between settings tabs. Leaving settings with a draft prompts you to confirm. These drafts live only in the current page session; save each tab to keep its changes after a reload.

INFO

The Application tab has an Advanced mode toggle in the top right. It reveals the fields marked advanced below, and the preference is saved to your account, so it follows you to other devices.

Application ​

FieldDescription
NameThe name of this panel installation
LanguageThe panel's default language
IconURL of the panel icon; suggests files uploaded under Assets
Icon (Light Mode)Optional separate icon for light mode (advanced)
BannerOptional banner image URL, also suggested from Assets
Banner (Light Mode)Optional separate banner for light mode (advanced)
URLThe public URL of the panel
Additional URLsOther addresses the panel is also reachable at, up to 32 (advanced). See Additional URLs
Session CookieName of the session cookie (advanced)
Session Duration (seconds)How long login sessions last (advanced)
Two-Factor Authentication RequirementWho must enable 2FA: Admins, All Users, or None. Affected users without 2FA are blocked from everything except setting it up and logging out
Email Two-FactorLet users receive a one-time login code by email as a second factor. Requires a mail transport
Accepted Two-Factor MethodsWhich enrolled factors satisfy the requirement above: TOTP, Security Key, and/or Email. Defaults to TOTP and security keys
Require Email VerificationNew accounts must open a verification link before they can use the panel, including SFTP and SSH. Requires a mail transport
Enable TelemetryAllow Calagopus to collect limited and anonymous usage data to help improve the application. What is collected and published
Enable RegistrationLet anyone create an account on this panel
Enable Password LoginLet users sign in with a username and password. Turning it off leaves OAuth providers and security keys as the only way in

Preview Telemetry (requires stats.read) shows the payload your panel would send, so you can judge for yourself. The receiving server adds two fields the panel does not send, so they are not in the preview: the country the submission arrived from, and its arrival time. Telemetry covers both, and what gets published. Disabling telemetry asks for confirmation.

Enabling registration also asks for confirmation and points out that doing it without a captcha configured may be a mistake.

Turning Enable Password Login off asks for confirmation too, because it reaches further than the login page. With it off, local registration, the forgot-password flow and SFTP password authentication all stop working as well, and everyone needs an OAuth provider or a security key to get in.

Public key authentication over SFTP keeps working. The per-account Password Login switch disappears while the panel-wide one is off, since there's nothing left for it to decide.

Four combinations are rejected when you save, with an error rather than a silent fix:

  • "at least one two-factor method must be accepted while two-factor is required" - you cleared Accepted Two-Factor Methods while the requirement is anything other than None.
  • "email two-factor and email verification require a mail transport to be configured" - one of the two email options is on while Mail is set to no transport.
  • "an enabled oauth provider is required before password login can be disabled" - there is nothing left to sign in with, so turning off Enable Password Login would lock out the whole panel.
  • "a link to an enabled oauth provider or a security key is required before password login can be disabled" - the panel has a way in, but you do not. Link your own account first, or register a security key.

Additional URLs ​

A panel served under more than one address, say a public domain and a LAN address, lists the extra ones here. URL stays the main address. For each request the panel looks at the host it came in on, and if it matches one of the configured URLs (host and port), it uses that URL instead of the main one for:

  • the session cookie's Secure flag, so an http:// LAN address can log in next to an https:// main URL,
  • OAuth redirects, so a login started on one address comes back to it,
  • links in the emails users trigger themselves: verification, password reset and email change,
  • console WebSocket, download and upload links for a node that runs through the panel's /wings-proxy.

Links in emails the Panel sends on its own, avatars, and other files kept in filesystem storage use the main URL. Browsers on an additional address must be able to reach it. Pairing and enrollment use the configured Panel URL matching the request host, unless you supply an explicit Panel URL override. A host that matches nothing falls back to the main URL, so a spoofed Host header cannot inject an unconfigured address. Behind a reverse proxy, the Panel reads X-Forwarded-Host only from addresses listed in APP_TRUSTED_PROXIES.

Trailing slashes are stripped and duplicates of the main URL are dropped on save. Two more things need setting up per address: every URL needs its own redirect URL registered with each OAuth provider (the provider page lists one per configured URL), and security keys only work on addresses under the RP Id.

Metadata ​

Controls the <head> of the panel's own page: what search engines record and what a link to your panel looks like when it is pasted into Discord, Slack, or a social app. These values are rendered into the HTML the panel serves, so they apply before anyone logs in.

FieldDescription
DescriptionShown under the title in search results and link previews. Left empty it falls back to "Manage your game servers and services with name."
Preview ImageThe image shown in link previews (og:image). Suggests files uploaded under Assets. Must be a PNG or JPEG, not an SVG, since most preview scrapers refuse SVG. A bare path is resolved against the panel URL; a full http(s):// address is used as is. Empty falls back to the panel's android-chrome-512x512.png
Twitter Card TypeSummary for a small square thumbnail, or Summary with Large Image for a full-width banner
Theme ColorHex color that tints the browser UI on mobile and the accent bar on some link previews. Defaults to #6c5ce7
Allow Search Engine IndexingOn sends robots: index, follow; off sends noindex, nofollow

Autofill fills Description and Preview Image with the defaults described above, which is the quickest way back to a working starting point.

INFO

noindex is a request, not an access control. It asks well-behaved crawlers to stay out; it does not hide the panel. Keep a private panel behind real authentication rather than relying on this switch.

Storage ​

Where the panel stores uploaded files such as profile pictures and admin assets. Pick a Driver:

  • Filesystem: a single Path on the panel's disk.
  • S3: Access Key, Secret Key, Bucket, Region, Public URL, Endpoint, and a Using path-style URLs toggle. The assets/, avatars/, and publicdata/ subdirectories must be publicly accessible over the Public URL; that's where admin assets, user avatars, and extension public data are served from.

WARNING

Changing the driver makes the panel look for existing assets in the new location. Move them over manually, or they'll turn up missing.

Mail ​

How the panel sends email. Pick a Provider:

ProviderFields
NoneOutgoing email disabled
SMTPHost, Port, TLS Mode (None, STARTTLS, or Implicit TLS), Skip Certificate Validation, HELO/EHLO Domain, Username, Password, From Address, From Name
Sendmail CommandCommand, From Address, From Name
FilesystemPath, From Address, From Name; writes messages to files under the path instead of sending them

HELO/EHLO Domain is the name the panel announces itself with when it opens the SMTP connection. Left empty it sends [127.0.0.1], which providers like Google Workspace reject; set it to the panel's own domain in that case.

Send Test Email opens a small modal, prefilled with your own address, to verify the configuration actually delivers.

Mail Templates ​

The emails the panel sends, editable per template. The tab requires email-templates.read; saving requires email-templates.update.

Pick a template from the Templates sidebar to edit its Subject, an Enabled toggle, and the HTML content in the editor. The built-in templates cover account creation, password resets, email verification, login codes for email two-factor, the connection test, being added to or removed from a server, and server installs and restores.

The Available Variables box lists everything you can reference in that template. Templates use the MiniJinja syntax: variables as {{ variable }}, control structures like {% if %} and {% for %}.

Reset to default discards your custom template and restores the built-in one. This cannot be undone.

Variables and Languages ​

Every user receives mail in the language set on their account. Addresses that do not belong to a user get the panel's default language. A template has one layout for all of them: the wording lives in Variables, small text fragments the template references as {{ vars.name }}, and each variable can carry a value per language.

The Variables section below the subject lists the fragments a template uses. Built-in templates ship with System variables such as greeting, intro, button and footer, with translations maintained alongside the panel's own. Pick a language from the selector on a variable to see and edit its value for that language. An empty field uses the default shown inside it, so you only have to fill in what you want to change.

When a user's language has no value of its own, the panel uses your English value if you set one, then the built-in translation for that language, then the built-in English text. So once you customise a variable in English, every language without its own value gets that English wording. Fill in the other languages you serve.

A variable's value is itself a MiniJinja snippet and can use the same variables as the template, for example Hello {{ user.username }},. The rendered fragment is inserted into the template as is, so HTML inside a variable works, while values like {{ user.username }} inside it are escaped. The subject is rendered as plain text, so keep HTML out of variables you use there.

Add Variable creates a Custom variable for the current template, which you can reference from the template's content or subject. Use the reset icon on a system variable to drop your values for every language, and the delete icon to remove a custom one.

Global Variables in the sidebar holds variables that every template can reference, handy for a shared signature or support address. A template variable with the same name takes precedence over a global one.

The language variable holds the language code a mail is rendered in, which the built-in templates put on the <html> tag.

Captcha ​

Captcha protection for the panel; set this up before you enable registration. When configured, the captcha renders on the login, register, and forgot-password pages and in the server subuser invite modal. Pick a Provider:

ProviderFields
NoneNo captcha
TurnstileSite Key, Secret Key
reCAPTCHASite Key, Secret Key, a V3 toggle, and Score Threshold when V3 is on
hCaptchaSite Key, Secret Key
Friendly CaptchaSite Key, API Key
CapInstance URL, Site Key, Secret Key

For Cap, enter the Instance URL of your Cap server, such as https://cap.example.com, and its site and secret keys. The URL must use HTTP or HTTPS and cannot contain embedded credentials, a query string, or a fragment.

Cap settings with instance URL and key fields

For reCAPTCHA V3, Score Threshold is the minimum accepted score, from 0 to 1, with a default of 0.5. Scores below it are rejected; increasing it makes the check stricter. It does not affect reCAPTCHA V2.

reCAPTCHA V3 score threshold

Webauthn ​

The settings behind Security Keys and the login page's passkey options.

FieldDescription
Enable Security KeysAllow users to register and sign in with security keys. Existing keys are kept and remain visible, but can't be used to sign in while this is off
Allow Usernameless LoginLet users store passkeys on their device and pick one from a list instead of typing a username
RP IdThe WebAuthn relying party ID
RP OriginThe WebAuthn relying party origin
Authentication Timeout (seconds)How long a sign-in prompt waits before giving up
Registration Timeout (seconds)How long a registration prompt waits before giving up

Autofill fills RP Id and RP Origin from the panel's own address. It refuses to run when the panel is served from a bare IP address, since WebAuthn doesn't work there.

WARNING

Changing the RP Id breaks all existing WebAuthn credentials and forces users to re-register their devices.

Server ​

Limits and behavior toggles that apply to all servers on the panel.

FieldDescription
Max File Manager View SizeLargest file the file manager will open
Max Schedule StepsMaximum number of steps per schedule
Max File Manager Content Search SizeLargest file the file-content search will look inside
Max File Manager Search ResultsCap on results returned by a file search
Max Subuser CountMaximum subusers per server
Max Backup Groups per ServerMaximum backup groups each server can have
Max Databases per Database InstanceDatabase cap per managed database instance
Max Users per Database InstanceUser cap per managed database instance
Max Firewall RulesMaximum firewall rules per server
Max Firewall Rule SourcesMaximum sources a single firewall rule may list
Max Private Connections per ServerMaximum private network connections a server may open to other servers
Max Private Ports per ServerMaximum ports a server may offer to the servers connected to it privately
Allow Overwriting Custom Docker ImageUsers can pick a different Docker image from the Eggs list even when an admin has set a custom image
Allow Viewing Installation LogsUsers with console read permission can watch installation logs; otherwise they're admin-only
Allow Acknowledging Installation FailureUsers can acknowledge a failed install and try starting the server instead of waiting for an admin
Allow Viewing Transfer ProgressUsers with console read permission can watch transfer progress logs; otherwise they're admin-only
Container PreludeThe terminal prelude used for some status-related messages in the server console

The database instance limits apply to managed databases created through database agent hosts.

User ​

Per-account limits for Dashboard features.

FieldDescription
Max Server GroupsCap on server groups per user
Max API KeysCap on API keys per user
Max Command SnippetsCap on command snippets per user
Max Security KeysCap on security keys per user
Max SSH KeysCap on SSH keys per user
Max Synced SettingsCap on how many settings an account may sync across devices
Max Synced Setting Size (bytes)Largest value a single synced setting may hold
Allow Changing LanguageIf enabled, users can change their language preferences

Below the limits, Client Route Order is a collapsible section: enable it to reorder the pages of the user dashboard sidebar for everyone. Drag entries to reorder, and use the row at the bottom to insert extra entries: a Route, a Divider, or a Redirect (a name plus an external URL). It's the same editor egg configurations use for the server sidebar.

Activity ​

Retention for the three activity logs and what gets logged.

Admin Activity Retention Days, User Activity Retention Days, and Server Activity Retention Days control how many days entries are kept in each log. The matching Retention Count fields optionally cap the number of entries kept as well.

FieldDescription
Log Server Admin ActivityLog admin activity on servers where the admin isn't an owner or subuser
Log Server Schedule ActivityLog activity done by server schedules
Hide Server Activity IPsHide IP addresses in server activity logs, even from users who hold activity.read-ip. None (the default), Admins, or All Users

Admins hides the address on entries made by an admin account or by someone impersonating a user, which keeps staff addresses out of a customer's log. All Users hides every address. Either way, a user with activity.read-ip still sees the IP on entries they made themselves (not ones made while someone impersonated them). The setting applies to the per-server Activity page for everyone, admins included; the admin and account activity logs are unaffected.

Ratelimits ​

Per-endpoint API rate limits. Each endpoint card has two values: Hits, the maximum number of requests allowed per window, and Window, the window duration in seconds.

Endpoints covered: auth/register, auth/login, auth/login/checkpoint, auth/login/checkpoint/email, auth/login/security-key, auth/password/forgot, auth/password/reset, auth/email/verify, client, client/account/email/resend-verification, client/servers/backups/create, client/servers/files/pull, client/servers/files/pull/query, remote, remote/enroll, and remote/sftp/auth.

Remote Enroll limits redemption of node enrollment codes to 10 requests per 60 seconds by default. Its settings key is remote_enroll; it is separate from the general remote API limit.

Exemptions ​

The Exemptions card below the endpoint grid lets trusted callers skip the two broad per-IP limits.

FieldDescription
Exempt IPsIP addresses or CIDR ranges that skip the client and remote limits
Exempt API KeysUUIDs of API keys that skip the client limit; a key only counts as exempt while it is enabled and used from one of its allowed IPs

Exemptions only cover the client and remote limits. The login, registration, and password limits still apply to exempt IPs, and the per-server limits (backup creation, file pulls) still apply to exempt keys, since those protect the nodes rather than the panel.

Users can copy a key's UUID from the context menu on their API Keys page. Saving refuses UUIDs that don't belong to an existing key, and a background job removes the UUIDs of keys that were deleted afterwards.

If the panel runs behind a reverse proxy, make sure APP_TRUSTED_PROXIES is set correctly, since IP exemptions match against the client address the panel resolves from the forwarded headers.