Platform settings
The panel has two kinds of settings, and until recently both were called "Settings". That was confusing: your own language sat one menu entry away from the API keys of the whole platform, and the word did not say which of the two you were a
Written for: Reseller, Administrator
The panel has two kinds of settings, and until recently both were called "Settings". That was confusing: your own language sat one menu entry away from the API keys of the whole platform, and the word did not say which of the two you were about to change.
They are two destinations now:
| Where | What is on it | Who sees it |
|---|---|---|
| My account, under your name at the bottom left | language, theme, password, two-factor authentication, passkeys, recovery codes, notifications | everybody |
| Settings, in the sidebar | the platform: General · Security · Branding · API keys · AI · Notifications | reseller and above |
This page is about the second. For the first there is Securing your account.
The tab bar
At the top of every page of the hub there is one bar of large tabs. Each tab is its own address, so you can link straight to it, bookmark it, and your browser's Back button does what you expect.
General /platform
Security /security
Branding /branding
API keys /apikeys
AI /ai
Notifications /platform/notificationsThe four middle addresses already existed and have not moved: every link you ever saved or sent to somebody still works exactly as it did.
You only see what you may open. A tab the panel would refuse you anyway is left out rather than greyed. Grey means "not yet" in CoreCP — a mail tab on an account with no website, say — and your role is not a "not yet". So a reseller sees Branding, API keys and AI; an administrator sees all six. A hosting customer does not see the hub at all, and keeps My account.
General
The first tab answers three questions.
What is this panel? The name it introduces itself by, and the build it is running. The name is a field of your branding, so it is shown here and edited under Branding — one value, one place that owns it, and a button between them. Under those two sits the copyright line, with a Read the licence button that opens the licence and the third-party components in full. More about that in Licence and ownership.
What does a new person start with? The language and theme somebody gets before they have chosen for themselves. Everybody can change it afterwards under My account; this is only the starting point.
And the rest? Every other setting that holds for the whole platform, each row saying where the value came from:
- Inherited from platform — nobody has said anything about it, this is the default out of the settings registry. The button beside it says Override.
- Set here — somebody did say something about it. The arrow beside it puts it back on the default.
That is exactly the same chip and exactly the same two actions as on the settings page of a hosting account, and that is deliberate: whoever has learned on one screen what "Inherited from plan Business" means reads it on the other without thinking.
A lower level may always narrow a value and never widen it. If a plan wants more than the platform allows, you raise it here — not there. The panel refuses it the other way round, and names the level you have to go to.
Notifications
The Notifications tab in the hub is about what the platform sends of its own accord — not about what you receive. In this version that is the three quota warnings: the percentages at which a customer is told their disk is filling up. 80, 90 and 95 by default; 0 switches a step off, which is a real setting for anyone who only wants the last warning.
What you personally receive, and through which channel, is under My account → Notifications. The page says so, with a link across, because "Notifications" appears in two places and that is exactly the kind of thing that sends you to the wrong one.
Finding a setting
If you do not know which tab something is under, press Ctrl+K (or ⌘+K on a Mac) and search for the name you use for it:
password → My account, Password section
2fa → My account, Two-factor authentication section
logo → Branding, Logo section
quota → Notifications, Quota warnings sectionYou land on the section, not at the top of a long page. And the search terms are English and Dutch at once: "tweestaps" finds the same thing as "two-factor", so you never have to switch the panel's language to find something.
On the command line
The settings registry can be read without a browser. On the panel server:
# every declared setting, and the levels it may be set at
corecp-panel settings --registry
# what one hosting account resolves to, with the origin of each value
corecp-panel settings --account web1
# which operations ask for a fresh second factor, and why
corecp-panel authz --stepupAnd over the API, with an administrator's session:
# the platform level, resolved
curl -s https://panel1.corecp.dev/api/v1/settings/platform | jq '.settings[].key'
# set one value, and put it back on the default
curl -sX PUT .../api/v1/settings/platform/web.php_default_version \
-d '{"value":"8.3","kind":"permanent"}'
curl -sX DELETE .../api/v1/settings/platform/web.php_default_versionEvery change at the platform level is in the audit log, with who made it.
What is deliberately not here
The Style guide stays a separate entry in the sidebar: it is the design system's own page, not a setting anybody switches on. And the heaviest operations — rotating the key that wraps the panel's keys, managing SSO clients, the fleet's certificate authority and break-glass — have no button on purpose. They belong on the panel server's command line, behind a sign-in stronger than a browser tab that has been open since this morning.