Settings

Access, system mail, quotas, SSO, and platform identity.

Access

When off, only existing users can sign in. Admins can still create accounts.

Unconfirmed accounts can browse the dashboard but cannot send or change configuration.

Language for this browser.

System mail

Verification, password reset, and newsletters leave from the platform domain through the same delivery engine.

Leave empty to use noreply@ the platform domain.

General quota

Shared by every workspace. 0 turns the platform cap off. Workspace and group caps still apply.

Platform identity (from env)

Domain
HELO
IP
SMTP
:
Bounce
Inbound
SPF
App
API
Track
Mode

Change these in .env and restart. HTTPS belongs on the reverse proxy. SMTP 25 and 587 stay on the host.

Single sign-on

OIDC. Authentik is the reference, Keycloak, Zitadel, Authelia, Okta, and Google work the same way.

Not set

Optional. If set, only people in this IdP group can open the admin app, and they still need an admin account.

In Authentik create an OAuth2/OIDC provider, confidential client, authorization code. Put the redirect URI above. Add scopes openid, email, profile, and groups. Map groups into the claim name you set here (Authentik’s default property is often groups).

Controls