Documentation menuResellers, teams and branding

Resellers, team access and branding

With the Pro edition you can hand accounts to resellers, give them quotas, privileges and their own brand, and build a tree of sub-resellers. Team members and administrator roles exist in both editions; Community has no resellers or white label and allows up to 3 team members per account.

Last updated:

On this page
  1. What each edition includes
  2. Reseller hierarchy
    1. Sub-resellers and depth
  3. Limits and overselling
    1. Reseller privileges
    2. Nameservers and IP pools
  4. Branding and white label (Pro)
    1. In container installs
  5. Team access
    1. Support access
    2. Administrator roles

#What each edition includes

FeatureCommunityPro
Reseller accounts and sub-resellersNoYes (license must include the reseller feature)
Server and reseller branding (white label), themes, custom hostnamesNoYes
Team membersUp to 3 per accountUnlimited
Administrator roles (auditor, support, operator)YesYes
Account owner's support access consentYesYes
Time-limited bipanel support accessNoYes
Bulk emailServer administrator onlyAdministrators and resellers

The Community edition is limited to 3 hosting accounts in total. On Pro, if your license expires or cannot be validated, existing resellers, accounts and brands keep working; only new actions such as creating resellers or editing branding stop. See Pricing for plans and Licensing for license details.

#Reseller hierarchy

Resellers sign in to Server Admin (/admin, port 2087) with their own username and see only their customers and the accounts of their sub-resellers. Every reseller also has a hosting account of its own.

The server administrator manages resellers on Accounts → Resellers:

  • Choose the reseller role in the Create Account form to open a new reseller.
  • Make an existing account a reseller converts a hosting account; its files and domains stay as they are. If you pick a parent reseller, the account becomes its sub-reseller.
  • Removing reseller status turns the account back into a normal user. The reseller must own no accounts at that point; its packages go to the parent reseller (or the server) and its IP pool returns to the parent.

#Sub-resellers and depth

A reseller with the right privilege creates sub-resellers on the Sub-resellers page. Resellers cannot create resellers from the Create Account form. The server administrator sets how many levels are allowed with Maximum reseller depth in the Settings dialog on the Resellers page:

ValueMeaning
1Top-level resellers only, no sub-resellers
2 (default)Resellers and their sub-resellers
3–10Deeper trees
UnlimitedNo depth limit

Lowering the value does not affect existing resellers; it only prevents adding new ones deeper. Accounts and sub-resellers can be moved to another reseller within the tree as long as the limits fit. A reseller can be suspended together with its whole subtree; lifting that suspension reopens only the accounts it suspended, so accounts that were suspended individually beforehand stay suspended.

#Limits and overselling

Each reseller has the following limits (an empty value means unlimited):

LimitDescription
Maximum accountsTotal accounts in the subtree; always enforced
Disk (MB) and bandwidth (MB)Sum of the account packages; enforced while overselling is off
Unlimited accountsMay use packages with unlimited disk or bandwidth, or create accounts without a package
OversellingWhen on, disk and bandwidth totals may exceed the quota
Package featuresFeatures the reseller may enable in its packages
Shared packagesPackages the parent reseller (or the server) makes available to this reseller

A reseller's usage covers its customers, its sub-resellers and their accounts, but not the reseller's own account. A sub-reseller's effective limit is the lower of its own limit and its parent's; permissions and privileges intersect. With overselling off, the quota handed to sub-resellers counts as reserved at the parent, so a parent cannot fill that quota with its own customers and leave the sub-reseller with nothing. An action is rejected only if it pushes usage above a limit; lowering a limit later does not affect existing accounts.

#Reseller privileges

Each of these privileges can be switched on or off per reseller: create accounts, suspend and unsuspend accounts, terminate accounts, log in to the customer panel, change account package, reset account password, create and edit packages, create and manage sub-resellers, use own nameservers, assign IP addresses to accounts. A privilege removed from a parent is removed from its sub-resellers too. Resellers cannot change their own limits or suspend themselves.

#Nameservers and IP pools

A reseller with the privilege defines nameservers under its own domain (for example ns1 and ns2) on Domains → My Nameservers; zones of its accounts, and of sub-resellers without their own nameservers, use these names. The names must resolve to the server's IP addresses; if they sit under the reseller's own domain, a child nameserver (glue) record is needed at the domain registrar. The server administrator can delegate an IP pool to a reseller, who can then assign those addresses to its accounts. See DNS for details.

#Branding and white label (Pro)

The server administrator changes the panel name, logo, icon, accent color, support address, footer text and sign-in screen texts on Server → Branding. Resellers set the same fields for themselves on Accounts → Branding. Branding is inherited field by field: a customer sees its reseller's values first, then those of parent resellers, and finally the server's. The logo can be PNG, SVG, JPEG or WebP (up to 200 KB), the icon PNG, SVG or ICO (up to 64 KB).

  • Themes: built-in themes (Standard and others) are read-only. Administrators and resellers create their own themes from color tokens and optional custom CSS, which is sanitized on the server. Users pick from the allowed themes on their Appearance page.
  • Custom hostnames: a reseller adds names under its own domain for the panel, webmail and phpMyAdmin (for example panel.example.com). Ownership is verified with a TXT record or through a DNS zone the reseller manages, and a certificate is issued automatically once the name points to the server. Custom hostnames are served only in the Apache and Nginx + Apache web server modes, not in OpenLiteSpeed mode.
  • Bulk email: on Pro, resellers can send announcements to their own customers, within the sending rate and daily count set by the server administrator. Customers can unsubscribe from announcement emails.

#In container installs

On Docker and Railway the panel already runs at the platform's public address and the platform terminates TLS. For a custom hostname you add a CNAME record to the panel's address instead of an A record; when the platform connection is configured, the name is added to the platform as a custom domain automatically. See Docker and Railway for the differences.

#Team access

Account owners invite team members by email on the Team page of the user panel. The invite link is valid for 7 days. Every member has their own password and two-factor authentication, signs in with a name in the form <member>@<account> and appears under their own name in the activity log. An optional expiry date can be set.

RoleScope
AdministratorEvery feature in the package, except the team, support access, API tokens and the account password
DeveloperFiles, databases, domains, SSL, applications, cron, terminal and other technical tools; no email
Email managerEmail accounts, forwarders, filters, spam settings and mailing lists
ViewerSees everything and changes nothing; terminal, phpMyAdmin and billing information are off
CustomThe features you choose, optionally read-only

The Team page is a package feature and can be turned off per package. The User Manager page shows email, FTP, Web Disk and team identities on one screen and lets the owner reset their passwords.

#Support access

On the Support Access page the account owner grants its reseller and the server staff access for up to 30 days and can revoke it at any time. If the server administrator makes consent mandatory, resellers and administrators with a limited role can enter the account only while a grant is active; full administrators can always enter, and their access is logged. Active grants are listed on the Support Access page in Server Admin.

#Administrator roles

Additional administrators are created on Server → Administrator Roles. An administrator without a role has full rights.

RoleWhat it can do
AuditorSees all of Server Admin read-only; cannot sign in to accounts
SupportSees everything, reviews logs, answers support tickets and signs in to customer accounts; cannot change server settings or sign in to administrator and reseller accounts
OperatorManages services, updates, components, PHP and language versions; cannot change accounts or security settings

On Pro, the same page can grant the bipanel support team a temporary administrator for up to 7 days with a single-use sign-in link. When the time runs out or access is revoked, the temporary administrator is removed and its sessions end immediately.

For account and package management see Accounts and packages.

Something missing or wrong on this page? Let us know.