@@PRODUCT@@

Running your own hosting brand

As a reseller you sell hosting under your own name. Your customers see your address, your logo and your colour — never CoreCP, and never each other. This page covers what you set up yourself and where the boundary is.

Written for: Reseller, Administrator

As a reseller you sell hosting under your own name. Your customers see your address, your logo and your colour — never CoreCP, and never each other. This page covers what you set up yourself and where the boundary is.

Your own address and branding

Under Branding you set, per brand, what your customers see: the name, the logo, the accent colour and the address they sign in on. That address is not cosmetic — it is where the panel actually runs for your customers:

  • the sign-in screen carries your name;
  • invitation and password-reset mail goes out under your brand, through your SMTP if you have configured one;
  • passkeys belong to your address, so a customer who registers one with you uses it only here;
  • if a customer installs the panel on their phone, your app lands on their home screen, with your name and icon.

Pick the brand in the bar at the top of the branding page. Past a handful of customers that is a search field rather than a list — deliberately.

Your branding is a screen, not a command. The assistant cannot read or change your brand, and neither can an API key or a connected AI client. That is deliberate: colours, a logo and the pages your customers show visitors are things you look at while you change them. To change something, do it here — or on the server with corectl brand set, if you would rather work on the command line.

Your customers

Customers is your list. Per customer you see the package, the websites, the usage and who has access. You create a customer, give them a package and invite the owner; the owner then invites their own people (see "Giving somebody access").

What your customer may do themselves is a deliberate boundary: create and change mailboxes, DNS records, request certificates. What sits around that — forwarders, the zone itself, adding websites, PHP versions — stays with you. That is not an accident but a decision taken per operation.

Packages

A package sets the limits: domains, mailboxes, databases, disk. Under Packages you create them and assign them. A limit is visible to the customer as a bar with a threshold — amber at 80%, red at 95% — so "full" never arrives as a surprise.

The pages your customers show to visitors

Not every website is up all the time. There is a new domain with nothing on it yet, there is a customer who has not paid, and now and then there is a site that falls over. At those moments a visitor of your customer sees a page — and that page carries your brand, not ours.

There are four of them:

WhenWhat the visitor sees
Website still empty"A website is on its way"
Account suspended"This website is temporarily unavailable"
Page does not exist"This page does not exist"
Something goes wrong"Something went wrong on this website"

You do not configure them one by one. They are built from what you fill in under Branding: your name, your tagline, your accent colour, your logo and your support address. Change your colour and all four change with it — nothing has to be published again.

What they deliberately are not: a page you can upload as HTML yourself. That sounds freer, but such a page runs on your customer's own address, and a script that ends up there reads along with your customer's visitors. The fixed layout with your brand's details gives the same result without that risk.

The pages load nothing else either: no web font, no image from another server, no analytics script. They exist precisely for the moment when something is already broken.

A suspended website

A suspended website answers with status 503 and says the absence is temporary. That matters to Google: a site that is temporarily offline with a 503 stays in the index, and one that simply returns a page does not. So do not leave an account suspended for months — for a few days it is exactly right.

A reason when you suspend

When you suspend a customer, the panel asks why. You pick from a fixed list — not paid, abuse, breach of the terms, at the customer's request, maintenance, other — and you can add a note.

That reason and that note are for you. A visitor to the website never sees them. One thing does change: if you pick not paid, the public page points at billing instead of at support. For every other reason it carries the same neutral sentence.

You see them back on the account's own page, under Plan → Availability: the reason, your note, who did it and when.

The command line does the same:

ssh root@stck1.corecp.dev
corectl account suspend customer1 --reason payment --note 'invoice 2026-0421'
corectl account unsuspend customer1

You do not see where your customer's things run

Which machine serves a website, a database or a mailbox is the platform administrator's decision. You and your customers never see that distribution; you see websites that work. That is on purpose: moving capacity around must never become a conversation with customers.

Looking inside a customer's account

If you hold the sign in as right, you can sign in as a customer within your own brand to help them. It is visible (a banner at the top of the screen for both of you), lasts at most an hour, and a number of things are blocked: passwords, two-step verification, secrets, billing and adding people. Everything is logged under both names.

The right is off by default and granted on the panel server:

ssh root@panel1.corecp.dev
corecp-panel admin impersonation allow support@yourbrand.com

What you cannot see

The separation between brands is not a setting but a property of the system. A session belongs to the address it was created on; there is no window into another brand, not even for the same person with the same email address. Two resellers with the same customer learn nothing about each other.

What you change, you see at once — in both modes at the same time

At the top of the branding page your brand is shown the way your customers get it. Not one colour swatch, but six real little screens:

LightDark
Sign-in screenyour logo, your name, your three sentences, your linksthe same, in dark mode
Dashboardthe sidebar in your colour with your logo, a card with buttonsthe same
Tab stripyour favicon between two other tabsthe same

Everything below works straight through: type a different product name and it changes in both sign-in screens as you type. You do not have to save to look. Only when it is right do you press Save; until then nothing has changed for your customers.

The bar at the bottom is where you save

You save from a bar that stays at the bottom of the screen. There used to be a button at the top right, and that was the problem: this page is well over a screen long, so that button was out of sight most of the time.

The bar names the brand you are editing, says whether anything is still unsaved, and tells you in advance when a confirmation will be asked for this record. If your save is refused, the reason appears right beside the button instead of somewhere at the top of the page.

If you leave with unsaved changes the page warns you. Three things are the exception: logos, the favicon and the certificate take effect immediately — a file you pick has already been sent.

That is why the page is laid out this way: a brand is something you look at, not something you fill in and then hope about.

The warning for a colour that does not work

Pick an accent that differs too little from the background and a yellow note appears under the colour fields — with the theme and the measured difference in it, for example "Light theme: the accent and the background differ by only 1.09:1". It also tells you when the label on your buttons flips from white to near-black, because at that moment every button in the panel changes at once.

It is a warning, not a refusal. You can save it; the panel always keeps the label on your buttons legible. We only tell you what we see, because you are looking at this page in one mode and your customers are in the other.

The same watch applies to your logo: upload a dark mark and we measure its average brightness against the colour of the sidebar it will sit on. If it disappears into it, we say so — naming the theme it happens in.

Two logos: one for light, one for dark

Your panel has a light mode and a dark mode, and your customer picks. One logo that works on both often does not exist: a dark wordmark disappears into the dark sidebar, and a white one is invisible on white.

So you can upload two:

  • Logo (light) — used everywhere, and the fallback.
  • Logo (dark) — used only when your customer has the panel in dark mode.

Upload only the light one and nothing changes: it is shown in both modes. Remove the dark one later and the panel falls back to the light one — your customer never sees a broken image.

To check from a terminal what is actually stored:

curl -s https://panel.yourbrand.com/api/v1/branding | python3 -m json.tool
{
  "product_name": "Van Eijk Hosting",
  "logo_url": "/brand/logo/6b1f…",
  "logo_dark_url": "/brand/logo/9c4a…",
  "favicon_url": "/brand/favicon/22e7…/icon-32"
}

No logo_dark_url means you have only the light mark — which is fine.

Your own icon in the browser tab

The small picture in a browser tab is called a favicon. You upload one, and the panel makes the sizes a browser and a phone need for you: a 32-pixel square for the tab and a 180-pixel one for an iPhone home screen.

What you can upload:

FileWhat happens
PNG or JPEGThe panel scales it to 32 and 180 pixels. Give it square, and at least 180 pixels across.
ICOUsed as it is — that format already contains several sizes.
SVGUsed as it is; modern browsers draw it sharp at any size.

128 KB at most. An SVG is checked as strictly as your logo: if it carries script the file is refused rather than "cleaned up".

Upload nothing and the panel uses your logo in the tab. That works, but a logo that turns into a grey smudge at 32 pixels is exactly why this field exists.

What your customers read on the sign-in screen

The sign-in screen is the first thing a customer sees of you. You fill in:

  • Three sentences saying what you deliver. Each has a Dutch and an English version, because your customers pick their own language. Leave them empty and our own three appear — but all three, never a mixture.
  • Help and Documentation: two addresses of your own.
  • Up to four links of your own under the form: your status page, your terms.

Every address has to start with https://. An http:// address is refused, and so is anything that is not an ordinary link (javascript:, data:) — these end up on your customer's page, and a link is the only thing that belongs there.

Fill in nothing and nothing is shown. We deliberately do not put our own help page there: your customer should be knocking on your door, not ours.

Your brand in the mail we send on your behalf

System mail — an invitation, a password reset, a warning that a disk is filling up — goes out under your brand. Three fields decide how:

FieldWhat it does
Sender nameThe name in front of the address, for example "Van Eijk Support". Empty = your product name.
Logo in mailLight (the default) or dark. A message has a light background, so the light mark is right almost always.
Accent in mailThe colour of the button in the message. Empty = your ordinary accent colour.

The address a message comes from is not set here: it follows your own SMTP settings, because a sender address we are not allowed to sign lands in a spam folder. The name in front of it is entirely yours.

An administrator can see on the panel server what such a message looks like in your brand, without anything being sent:

ssh root@panel1.corecp.dev \
  'corecp-panel mail preview --realm <group-id> --kind quota.disk --out /tmp/preview'
realm 4f1c…: product "Van Eijk Hosting", sender "Van Eijk Support" <notifications@…>,
             logo "https://panel.yourbrand.com/brand/logo/6b1f…", accent #5b3df5
wrote 2 files to /tmp/preview

Leave one of the three empty and the panel takes that one field from the platform branding — per field, not per brand. So a customer's inbox never gets half a brand.

Back to the default

At the bottom of the page is a danger zone with one button: Back to the default. It returns this group's brand to the panel's standard appearance in one go. Name, subtitle, colours, frame settings, logos, favicon, sign-in texts, links and mail settings are all cleared. That brand's app icons go with them, so anybody who had the panel on their home screen sees it under the default brand afterwards.

Two things stay: your own panel hostname and the certificate for it. That is deliberate — removing an address is a different decision with a different price (your customers' existing links and bookmarks). If you want those gone too, empty the hostname field and save.

The button asks for the brand's name before it does anything, because this cannot be undone from the panel. One line goes into the audit log, naming the hostname that stayed.

# The line the reset left behind, naming the hostname that stayed
ssh root@panel1.example.com \
  'corecp-panel audit export --since 0 --limit 5000' | grep branding.reset

See also

  • Giving somebody access
  • What you can do yourself
  • Securing your account

Uploading your own logo — what may and may not be in it

You may upload an SVG, because it stays sharp on any screen. An SVG is not really a picture though: it is a small document, and a document can do more than draw. So it is inspected at upload time, and not when a visitor asks for the page.

Refused:

What is in itWhy it is not allowed
A <script> elementThat runs code on every visitor's page.
An attribute such as onload= or onclick=The same thing, written more briefly.
A reference to another address (http://…)Then your visitor's page fetches something from a third party.
ssh root@stck1.corecp.dev 'corectl brand set vaneijk --logo-svg /tmp/logo.svg'
refused: the SVG carries an event handler attribute (onload)

If your file is refused, open it in a text editor and take those lines out — or export it again with interactivity switched off. If that is not possible, use a PNG, which by its nature can be nothing but a picture.

Your accent colour is looked at the same way: it is a colour code of the form #rrggbb or the brand is not saved. There is no middle ground there, precisely because that colour ends up literally in the styling of your pages.