Resellers, team access and branding
With the Pro edition you can hand accounts to resellers, give them quotas, privileges and their own brand, and build a tree of sub-resellers. Team members and administrator roles exist in both editions; Community has no resellers or white label and allows up to 3 team members per account.
On this page
#What each edition includes
| Feature | Community | Pro |
|---|---|---|
| Reseller accounts and sub-resellers | No | Yes (license must include the reseller feature) |
| Server and reseller branding (white label), themes, custom hostnames | No | Yes |
| Team members | Up to 3 per account | Unlimited |
| Administrator roles (auditor, support, operator) | Yes | Yes |
| Account owner's support access consent | Yes | Yes |
| Time-limited bipanel support access | No | Yes |
| Bulk email | Server administrator only | Administrators and resellers |
The Community edition is limited to 3 hosting accounts in total. On Pro, if your license expires or cannot be validated, existing resellers, accounts and brands keep working; only new actions such as creating resellers or editing branding stop. See Pricing for plans and Licensing for license details.
#Reseller hierarchy
Resellers sign in to Server Admin (/admin, port 2087) with their own username and see only their customers and the accounts of their sub-resellers. Every reseller also has a hosting account of its own.
The server administrator manages resellers on Accounts → Resellers:
- Choose the reseller role in the Create Account form to open a new reseller.
- Make an existing account a reseller converts a hosting account; its files and domains stay as they are. If you pick a parent reseller, the account becomes its sub-reseller.
- Removing reseller status turns the account back into a normal user. The reseller must own no accounts at that point; its packages go to the parent reseller (or the server) and its IP pool returns to the parent.
#Sub-resellers and depth
A reseller with the right privilege creates sub-resellers on the Sub-resellers page. Resellers cannot create resellers from the Create Account form. The server administrator sets how many levels are allowed with Maximum reseller depth in the Settings dialog on the Resellers page:
| Value | Meaning |
|---|---|
| 1 | Top-level resellers only, no sub-resellers |
| 2 (default) | Resellers and their sub-resellers |
| 3–10 | Deeper trees |
| Unlimited | No depth limit |
Lowering the value does not affect existing resellers; it only prevents adding new ones deeper. Accounts and sub-resellers can be moved to another reseller within the tree as long as the limits fit. A reseller can be suspended together with its whole subtree; lifting that suspension reopens only the accounts it suspended, so accounts that were suspended individually beforehand stay suspended.
#Limits and overselling
Each reseller has the following limits (an empty value means unlimited):
| Limit | Description |
|---|---|
| Maximum accounts | Total accounts in the subtree; always enforced |
| Disk (MB) and bandwidth (MB) | Sum of the account packages; enforced while overselling is off |
| Unlimited accounts | May use packages with unlimited disk or bandwidth, or create accounts without a package |
| Overselling | When on, disk and bandwidth totals may exceed the quota |
| Package features | Features the reseller may enable in its packages |
| Shared packages | Packages the parent reseller (or the server) makes available to this reseller |
A reseller's usage covers its customers, its sub-resellers and their accounts, but not the reseller's own account. A sub-reseller's effective limit is the lower of its own limit and its parent's; permissions and privileges intersect. With overselling off, the quota handed to sub-resellers counts as reserved at the parent, so a parent cannot fill that quota with its own customers and leave the sub-reseller with nothing. An action is rejected only if it pushes usage above a limit; lowering a limit later does not affect existing accounts.
#Reseller privileges
Each of these privileges can be switched on or off per reseller: create accounts, suspend and unsuspend accounts, terminate accounts, log in to the customer panel, change account package, reset account password, create and edit packages, create and manage sub-resellers, use own nameservers, assign IP addresses to accounts. A privilege removed from a parent is removed from its sub-resellers too. Resellers cannot change their own limits or suspend themselves.
#Nameservers and IP pools
A reseller with the privilege defines nameservers under its own domain (for example ns1 and ns2) on Domains → My Nameservers; zones of its accounts, and of sub-resellers without their own nameservers, use these names. The names must resolve to the server's IP addresses; if they sit under the reseller's own domain, a child nameserver (glue) record is needed at the domain registrar. The server administrator can delegate an IP pool to a reseller, who can then assign those addresses to its accounts. See DNS for details.
#Branding and white label (Pro)
The server administrator changes the panel name, logo, icon, accent color, support address, footer text and sign-in screen texts on Server → Branding. Resellers set the same fields for themselves on Accounts → Branding. Branding is inherited field by field: a customer sees its reseller's values first, then those of parent resellers, and finally the server's. The logo can be PNG, SVG, JPEG or WebP (up to 200 KB), the icon PNG, SVG or ICO (up to 64 KB).
- Themes: built-in themes (Standard and others) are read-only. Administrators and resellers create their own themes from color tokens and optional custom CSS, which is sanitized on the server. Users pick from the allowed themes on their Appearance page.
- Custom hostnames: a reseller adds names under its own domain for the panel, webmail and phpMyAdmin (for example panel.example.com). Ownership is verified with a TXT record or through a DNS zone the reseller manages, and a certificate is issued automatically once the name points to the server. Custom hostnames are served only in the Apache and Nginx + Apache web server modes, not in OpenLiteSpeed mode.
- Bulk email: on Pro, resellers can send announcements to their own customers, within the sending rate and daily count set by the server administrator. Customers can unsubscribe from announcement emails.
#In container installs
On Docker and Railway the panel already runs at the platform's public address and the platform terminates TLS. For a custom hostname you add a CNAME record to the panel's address instead of an A record; when the platform connection is configured, the name is added to the platform as a custom domain automatically. See Docker and Railway for the differences.
#Team access
Account owners invite team members by email on the Team page of the user panel. The invite link is valid for 7 days. Every member has their own password and two-factor authentication, signs in with a name in the form <member>@<account> and appears under their own name in the activity log. An optional expiry date can be set.
| Role | Scope |
|---|---|
| Administrator | Every feature in the package, except the team, support access, API tokens and the account password |
| Developer | Files, databases, domains, SSL, applications, cron, terminal and other technical tools; no email |
| Email manager | Email accounts, forwarders, filters, spam settings and mailing lists |
| Viewer | Sees everything and changes nothing; terminal, phpMyAdmin and billing information are off |
| Custom | The features you choose, optionally read-only |
The Team page is a package feature and can be turned off per package. The User Manager page shows email, FTP, Web Disk and team identities on one screen and lets the owner reset their passwords.
#Support access
On the Support Access page the account owner grants its reseller and the server staff access for up to 30 days and can revoke it at any time. If the server administrator makes consent mandatory, resellers and administrators with a limited role can enter the account only while a grant is active; full administrators can always enter, and their access is logged. Active grants are listed on the Support Access page in Server Admin.
#Administrator roles
Additional administrators are created on Server → Administrator Roles. An administrator without a role has full rights.
| Role | What it can do |
|---|---|
| Auditor | Sees all of Server Admin read-only; cannot sign in to accounts |
| Support | Sees everything, reviews logs, answers support tickets and signs in to customer accounts; cannot change server settings or sign in to administrator and reseller accounts |
| Operator | Manages services, updates, components, PHP and language versions; cannot change accounts or security settings |
On Pro, the same page can grant the bipanel support team a temporary administrator for up to 7 days with a single-use sign-in link. When the time runs out or access is revoked, the temporary administrator is removed and its sessions end immediately.
For account and package management see Accounts and packages.
Something missing or wrong on this page? Let us know.