Users and roles
Signing in, multi-factor authentication, sessions and user accounts.
On this page
Signing in#
Enter your username or email address and your password, then choose Sign in. If two-factor authentication is on for your account, ONEP then asks for the 6-digit Two-factor code from your authenticator app. Choose Verify & sign in, or Back to start again. On a new appliance, first-time setup replaces the sign-in page until the administrator password is set; see First boot and network.
Two protections apply, and neither can be changed from the interface:
- Account lockout. Repeated wrong passwords lock that account for a growing period. The sign-in page then says Account locked. Try again in N minute(s). An administrator can clear a lockout; see Managing users.
- Sign-in rate limit. After 10 sign-in attempts in a minute from the same network address, ONEP answers Rate limit exceeded: Too many login attempts, try again in a minute. Everyone behind one shared internet connection shares that budget, so a whole classroom or office signing in at once can hit it together. Wait a minute and try again.
Sessions#
- One session per user. Signing in on a second browser or device ends the earlier session, which then reads Signed in on another device — this session has ended. If your session drops unexpectedly, this is the most common reason.
- Forced password change. When a password change is required, ONEP shows Set a new password before anything else. Enter your current password and a new one of at least 12 characters that differs from it. The step cannot be skipped.
- Deactivating a user ends their session immediately. Changing their role takes effect on their next request.
- Sign out is at the bottom of the sidebar, under your username and role.
Your account#
Every user has Settings › Account. On Community and Lite it holds the Password and Two-factor cards. On other editions it also holds the Profile card (username, role, email and two-factor state), API tokens where available, and AI preferences.
Password and two-factor authentication#
- Password. Enter your Current password, a New password of at least 12 characters and Confirm new, then choose Change password. You stay signed in.
- Two-factor authentication. The card shows Enabled — a code is required at login or Disabled. To turn it on, choose Set up two-factor, scan the QR code or enter the manual key in any standard authenticator app (TOTP), type the 6-digit code and choose Verify & enable. To turn it off, enter your account password and choose Disable.
ONEP issues no recovery codes, and there is no way to reset a lost authenticator from the web interface. Recovery is a console procedure on the appliance, as on other network and security appliances. If you lose your authenticator, write to hello@onep.io. On an edition with more than one account, your administrator can also arrange the reset.
API tokens#
An API tokens card lets scripts call the ONEP API as you. It appears only on installations whose license includes scripted API access. Community, Lite and Pro are used through the web interface only, and the card is not shown.
- Enter a Token name, optionally Expires in (days) (empty means it never expires), and choose scopes: read (view data), write (create and change data) or, for administrators, admin (full administrative access, including user management). Then choose Create token.
- The token is shown once. Copy it before you choose Done.
- Each token in the list shows its prefix, scopes, creation date, expiry and last use. The trash icon revokes it after you confirm; any script using it stops working at once.
AI preferences#
The Model list sets which AI model your own environment-generation requests use. Server default follows the administrator's choice in Settings › AI. If the administrator restricted the choice to one model, the list is read-only. Choose Save to apply.
Users by edition#
Community and Lite have one account, the administrator, and the Users & access tab is not shown. Pro includes more accounts. The number of accounts for each edition is on Limits per edition. Deactivated users still count; delete a user to free a seat. When every seat is in use, New user is refused with a message that says so.
Managing users#
On an edition with more than one user, administrators manage accounts in Settings › Users & access. Only an administrator can do these things, and only an administrator can reach the Settings tabs beyond their own account. The list shows User, Email, Role, Status and Last login, with a count of users above it.
| Action | How |
|---|---|
| Create a user | New user, then Username, Email, Full name, Password (at least 12 characters) and Role, then Create |
| Change a role | Pick another role in the Role list on the user's row and confirm with Change role. Choosing Administrator shows a warning that administrators can change every setting. You cannot change your own role |
| Deactivate or enable | Choose the Active or Disabled status on the row and confirm. A deactivated user is signed out at once and cannot sign in again until enabled. You cannot deactivate yourself |
| Clear a lockout | A locked user shows Locked and a Clear lockout icon. Choose it and confirm; the failed sign-in counter resets |
| Reset a password | The key icon opens Reset password. Enter a new password of at least 12 characters and choose Set password. Resetting also clears a lockout |
| See or revoke API tokens | The API tokens icon on a row expands that user's tokens, with Revoke for each. Only where the installation includes API tokens |
| Delete a user | The trash icon, then Delete user. The account is signed out and hidden and can no longer sign in. Its username and email are released for reuse. The record is kept for the audit trail. You cannot delete yourself |
With more than one page of users, Previous and Next move between pages. User changes are recorded in the audit log.
Roles#
Access is role-based. Each user has one role.
| Role | What it allows |
|---|---|
| Administrator | Everything: all environments and devices, images, users, every Settings tab and the Audit page |
| Contributor | Full control of environments and devices, packet capture, snapshots, export, import and the AI Generator. Images are view only |
| Operator | View, create, edit, delete and run environments and open their consoles, plus packet capture, snapshots, export, import and the AI Generator. Images are view only |
| Read-only | View environments, open consoles, export, and view images |