Users

Users manages non-root panel identities and their matching external API access, status, credentials, DNS allocation, 2FA reset, and separate panel/API source rules.

Where to find it: SDM root sidebar > Users.

Available to: root.

What this page does

Use this page to create, find, suspend, edit, rotate, or remove accounts. SDM keeps panel and API account state coupled: a current non-root API user also needs an active panel user row. Role and existing zone access are preserved by the edit form rather than silently changed.

Before you start

Choose a unique username and least role, know which zones the account should own, and decide whether panel and API access need different source networks. Do not send credentials through an insecure ticket.

Create and edit

  • Username: 2–64 letters, digits, underscores, or hyphens.
  • Email: optional.
  • Password: leave blank to auto-generate; otherwise minimum of 12 characters and maximum 72 bytes. New username/password/API key are shown once.
  • List: filters all, active, or suspended and searches username, email, or API key. Columns include masked/revealable API key, status, allocated zones/records, created, and last login.
  • Edit: email, active state, optional new password and confirmation.
  • Security actions: regenerate API key, disable 2FA, maintain Panel Access and API Access IP/CIDR lists with optional comments, or delete the user.

Disabling an account, changing its password, disabling 2FA, or deleting it revokes relevant sessions. API key rotation invalidates the old integration key immediately.

Controls and fields

Control, Field, Or SectionWhat It DoesWhat It AffectsRecommended Usage
UsernameNew or existing SDM user name.Identifies the account for panel login, API key ownership, audit events, and zone access.Use customer/service-specific names, not shared generic accounts.
EmailOptional contact address for the user.Helps support identify ownership and escalation contacts.Set it for customer-facing accounts even if login does not require it.
PasswordInitial or replacement password.Controls panel login for that user.Generate strong values and communicate through a secure channel.
GenerateCreates a strong password in create or edit forms.Does not save until Create User or Save is clicked.Use for every new account unless importing a customer-provided secret.
Show/Hide passwordReveals or masks password fields.Only affects browser visibility.Use briefly and only in a private environment.
Create userCreates the account and automatically generates an API key.Adds a panel/API identity that can own zones and authenticate integrations.Create one user per customer or integration to keep audit history clean.
Credentials modalShows username, generated password, and API key after creation or reset.This is the one safe moment to copy secrets from the UI.Copy and store securely; do not screenshot secrets in tickets.
Copy username/password/API keyCopies a credential value to the clipboard.No backend change.Paste only into approved password vaults or customer onboarding channels.
Status filterFilters users by all, active, or suspended state.Changes visible table rows only.Use before bulk review or support investigation.
Search usersFilters by username, email, or API key text.Changes visible table rows only.Use for quick lookup during API support.
API key show/copy in tableReveals or copies an existing API key when available.No backend change, but exposes a secret to the browser user.Prefer regenerate if a key may be compromised.
EditOpens Details and IP Access Control tabs for the user.Allows account status, email, password, API key, 2FA recovery, and IP rules to be managed.Open Edit before deletion to check activity/security state.
ActiveEnables or suspends the account.Suspended users cannot authenticate normally.Suspend before delete when you need a reversible support step.
New Password / Confirm New PasswordOptional password reset fields in the edit modal.Changes the user password only when provided and matching.Leave blank when editing email or status only.
SaveStores user email, active state, and optional password reset.Changes account behavior after backend validation.Review the credentials modal if a password changed.
Regenerate API KeyCreates a new API key and invalidates the previous one.Breaks existing integrations until the new key is deployed.Use after suspected exposure or during controlled key rotation.
Disable 2FAClears the user 2FA secret for recovery.Allows the user to re-enroll or login without the old authenticator requirement depending on policy.Use only after confirming identity through support process.
Panel Login IP rulesRestrict browser login sources for the user.If rules exist, login is allowed only from matching IP/CIDR entries.Add customer VPN/office ranges and document each rule.
External API IP rulesRestrict API key usage sources for the user.If rules exist, API calls are allowed only from matching IP/CIDR entries.Use for automation servers; leave empty only when API clients have changing IPs and policy allows it.
Add IP / CIDRAdds a trusted source rule for the selected scope.Can immediately restrict login/API use if this is the first rule in that scope.Confirm current integration source IP before adding the first API rule.
CommentReason or owner note for the IP rule.Improves future audits and cleanup.Include office/VPN/server/ticket context.
Delete IP ruleRemoves one trusted source rule.May block that customer or integration from future access.Remove stale rules only after confirming replacement access.
Delete userRemoves the account after confirmation.Can break zone ownership workflows and API integrations.Prefer suspend first unless the account is definitely obsolete.

Safety notes

  • Regenerating an API key breaks integrations until the new key is deployed.
  • Deleting a user can remove access needed by customer automation. Check API Sources and audit activity first.

How to use it

  1. Select Create User and enter username/email plus a strong password or leave password blank for generation.
  2. Store the one-time credentials securely.
  3. Edit the account to set active state and separate panel/API IP rules.
  4. Assign or transfer only the intended zones from DNS Zones.
  5. Test panel login and API ping from their real source addresses, then inspect Audit.

Result and next check

The user can reach only the intended panel/API surface and owned DNS scope. Rotated, suspended, or deleted credentials no longer work, and root can trace the lifecycle in Audit.

Theme color