Users
Users manages non-root panel identities and their matching external API access, status, credentials, DNS allocation, 2FA reset, and separate panel/API source rules.
Where to find it: SDM root sidebar > Users.
Available to: root.
What this page does
Use this page to create, find, suspend, edit, rotate, or remove accounts. SDM keeps panel and API account state coupled: a current non-root API user also needs an active panel user row. Role and existing zone access are preserved by the edit form rather than silently changed.
Before you start
Choose a unique username and least role, know which zones the account should own, and decide whether panel and API access need different source networks. Do not send credentials through an insecure ticket.
Create and edit
- Username: 2–64 letters, digits, underscores, or hyphens.
- Email: optional.
- Password: leave blank to auto-generate; otherwise minimum of 12 characters and maximum 72 bytes. New username/password/API key are shown once.
- List: filters all, active, or suspended and searches username, email, or API key. Columns include masked/revealable API key, status, allocated zones/records, created, and last login.
- Edit: email, active state, optional new password and confirmation.
- Security actions: regenerate API key, disable 2FA, maintain Panel Access and API Access IP/CIDR lists with optional comments, or delete the user.
Disabling an account, changing its password, disabling 2FA, or deleting it revokes relevant sessions. API key rotation invalidates the old integration key immediately.
Controls and fields
| Control, Field, Or Section | What It Does | What It Affects | Recommended Usage |
|---|---|---|---|
| Username | New or existing SDM user name. | Identifies the account for panel login, API key ownership, audit events, and zone access. | Use customer/service-specific names, not shared generic accounts. |
| Optional contact address for the user. | Helps support identify ownership and escalation contacts. | Set it for customer-facing accounts even if login does not require it. | |
| Password | Initial or replacement password. | Controls panel login for that user. | Generate strong values and communicate through a secure channel. |
| Generate | Creates a strong password in create or edit forms. | Does not save until Create User or Save is clicked. | Use for every new account unless importing a customer-provided secret. |
| Show/Hide password | Reveals or masks password fields. | Only affects browser visibility. | Use briefly and only in a private environment. |
| Create user | Creates the account and automatically generates an API key. | Adds a panel/API identity that can own zones and authenticate integrations. | Create one user per customer or integration to keep audit history clean. |
| Credentials modal | Shows username, generated password, and API key after creation or reset. | This is the one safe moment to copy secrets from the UI. | Copy and store securely; do not screenshot secrets in tickets. |
| Copy username/password/API key | Copies a credential value to the clipboard. | No backend change. | Paste only into approved password vaults or customer onboarding channels. |
| Status filter | Filters users by all, active, or suspended state. | Changes visible table rows only. | Use before bulk review or support investigation. |
| Search users | Filters by username, email, or API key text. | Changes visible table rows only. | Use for quick lookup during API support. |
| API key show/copy in table | Reveals or copies an existing API key when available. | No backend change, but exposes a secret to the browser user. | Prefer regenerate if a key may be compromised. |
| Edit | Opens Details and IP Access Control tabs for the user. | Allows account status, email, password, API key, 2FA recovery, and IP rules to be managed. | Open Edit before deletion to check activity/security state. |
| Active | Enables or suspends the account. | Suspended users cannot authenticate normally. | Suspend before delete when you need a reversible support step. |
| New Password / Confirm New Password | Optional password reset fields in the edit modal. | Changes the user password only when provided and matching. | Leave blank when editing email or status only. |
| Save | Stores user email, active state, and optional password reset. | Changes account behavior after backend validation. | Review the credentials modal if a password changed. |
| Regenerate API Key | Creates a new API key and invalidates the previous one. | Breaks existing integrations until the new key is deployed. | Use after suspected exposure or during controlled key rotation. |
| Disable 2FA | Clears the user 2FA secret for recovery. | Allows the user to re-enroll or login without the old authenticator requirement depending on policy. | Use only after confirming identity through support process. |
| Panel Login IP rules | Restrict browser login sources for the user. | If rules exist, login is allowed only from matching IP/CIDR entries. | Add customer VPN/office ranges and document each rule. |
| External API IP rules | Restrict API key usage sources for the user. | If rules exist, API calls are allowed only from matching IP/CIDR entries. | Use for automation servers; leave empty only when API clients have changing IPs and policy allows it. |
| Add IP / CIDR | Adds a trusted source rule for the selected scope. | Can immediately restrict login/API use if this is the first rule in that scope. | Confirm current integration source IP before adding the first API rule. |
| Comment | Reason or owner note for the IP rule. | Improves future audits and cleanup. | Include office/VPN/server/ticket context. |
| Delete IP rule | Removes one trusted source rule. | May block that customer or integration from future access. | Remove stale rules only after confirming replacement access. |
| Delete user | Removes the account after confirmation. | Can break zone ownership workflows and API integrations. | Prefer suspend first unless the account is definitely obsolete. |
Safety notes
- Regenerating an API key breaks integrations until the new key is deployed.
- Deleting a user can remove access needed by customer automation. Check API Sources and audit activity first.
How to use it
- Select Create User and enter username/email plus a strong password or leave password blank for generation.
- Store the one-time credentials securely.
- Edit the account to set active state and separate panel/API IP rules.
- Assign or transfer only the intended zones from DNS Zones.
- Test panel login and API ping from their real source addresses, then inspect Audit.
Result and next check
The user can reach only the intended panel/API surface and owned DNS scope. Rotated, suspended, or deleted credentials no longer work, and root can trace the lifecycle in Audit.
Theme color