Documentation menuAccounts and packages

Accounts and packages

You create hosting accounts under Server Admin → Accounts, set their limits with packages, and suspend, terminate or rename them from the same area. The Community edition allows up to 3 hosting accounts; archiving and restoring terminated accounts and some package limits require the Pro edition.

Last updated:

On this page
  1. Creating an account
    1. Account limit in the Community edition
    2. Choosing the home volume
  2. Packages
  3. Suspending and unsuspending
  4. Passwords and password policy
  5. Demo accounts
  6. Bulk actions
  7. Terminating an account
  8. Deleted accounts and restore (Pro)
  9. Renaming the username or domain

#Creating an account

New accounts are created on Server Admin → Accounts → Create Account. bipanel sets up a system user, home directory, PHP-FPM pool, Apache virtual host and DNS zone automatically; if any step fails, the completed steps are rolled back so no half-created account is left behind.

FieldRule
DomainMust not be registered to another account on the server
Username2–16 characters, starts with a lowercase letter, a-z and 0-9 only; reserved names and existing system user or group names are rejected
Password8–128 characters; no spaces, quotes or backslashes. Used for panel, SSH and FTP logins
Hosting packageA package or No package (unlimited); an account without a package has no quotas
PHP versionFalls back to the package default, then the server default
SSH / terminal accessWeb terminal and (on server installs) SSH
Account ownerThe server administrator or a reseller

The same form offers Require a password change at first sign-in and Demo account. Make this account a reseller depends on the reseller feature, which is part of the Pro edition; see Resellers, teams and branding.

The contents of Server Admin → Accounts → Skeleton Directory are copied into every new home directory. If the skeleton is empty, a default welcome page is created. Resellers can keep their own skeleton; when a reseller's skeleton is empty, the server-wide one is used.

#Account limit in the Community edition

The Community edition allows at most 3 hosting accounts; every account with a home directory counts. Once the limit is reached, new account requests are refused while existing accounts keep running. In the Pro edition the limit comes from your license plan; see pricing and Licensing.

#Choosing the home volume

When more than one usable home volume is registered on the server (for example /home2 on an extra disk), the server administrator picks a Home volume in the Home directory location section while creating the account. The home directory becomes <volume>/<username>. Without a choice, the placement policy decides: the default volume, or the one with the most free space. Accounts created by resellers are always placed by the policy. Home volumes are added in the Disk Manager.

#Packages

Packages are managed on Server Admin → Accounts → Packages. A fresh install comes with four sample packages: Başlangıç, Standart, Pro and Sınırsız (starter, standard, pro and unlimited; "Pro" here is only a package name). Limits left empty are unlimited, and any change to a package applies immediately to every account using it.

GroupLimits
QuotasAddon domains, subdomains, aliases, MySQL databases, email accounts, mailbox quota, FTP accounts, cron jobs, Node.js / Python apps
Resource limitsDisk quota, monthly bandwidth, CPU limit (100 = one core, minimum 5), memory limit (minimum 128 MB), process limit (minimum 20)
Pro onlyFile limit (inodes, minimum 1000), disk I/O limit (MB/s), Redis and Memcached memory, container and image limits
OtherDefault PHP version, SSH / terminal access, feature list

When bandwidth is used up has two options: Notify only or Suspend until the end of the month; a suspended account reopens automatically at the start of the month. Tools unchecked in the Features list are hidden in the panel of every account on that package.

A package that accounts are using cannot be deleted; move those accounts to another package first. Packages created by a reseller get the reseller's username as a name prefix.

On a Docker/Railway installation, per-account CPU and memory limits (cgroups) cannot be applied and disk usage is only monitored; the platform limits resources. See Monitoring, limits and statistics.

#Suspending and unsuspending

The Suspend button on the account page stops an account, with an optional reason. A suspended account's sites show a suspension page, its apps and cron jobs stop, its open sessions end and the user cannot log in to the panel; because the system password is locked, password logins over SSH and FTP stop working too. No data is deleted. Unsuspend restores everything.

You cannot suspend your own account. An account that was suspended together with a reseller's subtree can only be unsuspended by the server administrator or a parent reseller.

#Passwords and password policy

Reset password on the account page changes the panel, SSH and FTP passwords together and signs out open sessions. User must change it at first sign-in is useful when handing out a temporary password. While Require a password change at next sign-in is on, the user cannot continue in the panel until a new password is set; API tokens and administrator "log in as" sessions are not affected.

The server-wide password age is set on Server Admin → Security → Password Policy:

  • Maximum age: from 0 (off, the default) to 3650 days, counted from the last password change, or from account creation if the password was never changed.
  • Applies to: Account owners, Resellers and Server administrators; the first two are selected by default.

The page shows how many users have a pending change request, an expired password, or one expiring within 7 days. Demo accounts cannot change passwords, so the policy skips them.

#Demo accounts

With Demo mode on, the user panel is read-only: visitors can browse but cannot change anything, and the web terminal does not open. Demo credentials are usually shared publicly, so the account's system password is locked and the same password does not work over SSH or FTP. An administrator who enters the account with Log in to the panel can still edit it to prepare content. You cannot put your own account in demo mode.

#Bulk actions

Select accounts in the Accounts list and open Bulk actions to apply one of these at once: Change package, Suspend, Unsuspend, Change PHP version, Change owner, Require password change or clear it, Turn on demo mode or turn it off.

One request can cover up to 500 accounts. The job runs in the background and logs a result line per account; accounts already in the requested state are skipped. Changing the owner is limited to the server administrator, and resellers can only select their own accounts and use the actions their privilege list allows.

#Terminating an account

Terminate account on the account page asks you to type the account's username to confirm. You cannot delete your own account, and a reseller that still owns accounts cannot be deleted until those accounts are deleted or moved to another owner.

  • In the Community edition termination is permanent: files, databases and database users, email, apps, DNS records and the system user are removed at once. Take a backup first; see Backups and migration.
  • In the Pro edition the account is archived first and then removed. Archiving can take a few minutes depending on the account's size, and the account is suspended meanwhile. If you do not need an archive, tick Delete permanently without an archive.

#Deleted accounts and restore (Pro)

In the Pro edition, Server Admin → Accounts → Deleted Accounts lists the archives of terminated accounts; only the server administrator can open it. An archive holds a full account backup (files, databases, mailboxes, DNS zones, panel records) plus panel data that backups do not include (password hashes, custom SSL certificates, FTP accounts, API tokens), and that second part is stored encrypted.

SettingDefaultNotes
Archive terminated accountsOnWhen off, termination is permanent
Retention period30 days1–3650 days; expired archives are permanently deleted every night

Terminations made while the Pro license is not valid are not archived. Cleanup of expired archives runs regardless of the license state, so the disk space is always freed.

Restore brings the account back with its old password. If the original username now belongs to another account, you enter a new one and database names are adapted to the new prefix. If the main domain has moved to another account, remove it there first; if only other domains conflict, you can choose Restore without these domains. To delete an archive before it expires, confirm by typing the username.

#Renaming the username or domain

Server Admin → Accounts → Account Move & Rename is available to the server administrator only. Every operation first runs a preflight check and then runs step by step as a background job; if a step fails, the completed steps are rolled back. To start, you type the account's current username.

  • Username: the system user and group, home directory, panel records, MySQL databases and users with the <user>_ prefix, crontab, backups, custom certificates and app logs move to the new name. Running apps are stopped and started again. Optionally, app configuration files (wp-config.php, .env) are updated as well.
  • Domain (including the main domain): subdomains move to the new name, and the Apache configuration, DNS zone, email, redirects and logs are updated. Options: rename the document root directory, keep the old name as an alias, request a Let's Encrypt certificate for the new name, and convert FTP login names.
  • Pro: turn an addon domain into a separate account, and move a home directory to another disk. Moving to another disk works only on a server installation with rsync installed; it is not available on Docker/Railway, where home directories live on the persistent volume.

Something missing or wrong on this page? Let us know.