Documentation
Everything you can do with this panel, in plain words — from your first sign-in to moving a whole server across.
94 articles
Start here
Working with long listsEvery list in the panel — your accounts, the audit log, your servers — works the same way. That is deliberate: learn one and you have learned all of them. This page explains how, and above all what the list is actually promising you. BecausSigning in, switching and finding your wayThis page covers the three things you do every day: signing in, switching between accounts or roles, and getting around.What needs attentionOne block sits at the top of your overview. On the front page it is called Needs attention; on a hosting account's screen and on a server's it is called Health, because there it answers the whole question and not only the complaints. It is My servicesMy services answers one question: is my hosting all right, and if not, what do I press? You will find it in the sidebar, in the slot an administrator has Servers in. That is not a coincidence — that slot used to show the machines your hosti
Getting started
Working with long listsEvery list in the panel — your accounts, the audit log, your servers — works the same way. That is deliberate: learn one and you have learned all of them. This page explains how, and above all what the list is actually promising you. BecausSigning in, switching and finding your wayThis page covers the three things you do every day: signing in, switching between accounts or roles, and getting around.What needs attentionOne block sits at the top of your overview. On the front page it is called Needs attention; on a hosting account's screen and on a server's it is called Health, because there it answers the whole question and not only the complaints. It is My servicesMy services answers one question: is my hosting all right, and if not, what do I press? You will find it in the sidebar, in the slot an administrator has Servers in. That is not a coincidence — that slot used to show the machines your hostiSearching the panelThere is a search box at the top of every screen. It is always there — on your phone as much as on your laptop — and nothing needs to be opened first. Type part of a domain name, a mail address, a database name or a customer name, and the pYour internet address is blocked — how to get back inSuddenly nothing works. Your website does not load, your mail client keeps trying to connect, your FTP program gets no answer. And a colleague somewhere else has no trouble at all.What you can do yourselfYou have a hosting account with a hosting company. For most things you do not have to call them: your mail, your DNS and your security certificates are yours to run, in the panel, without waiting for anybody.Reading your notificationsThere is a bell in the top right of the panel. It holds what has happened to your hosting: an account that was created, a backup that failed, a disk filling up, a server that stopped reporting.Securing your accountYour hosting account holds your websites, your mail and your data. This page covers what you can set up to protect it, in the order it is worth doing: a passkey, then recovery codes, then the rest.Install on your phoneYou can put the panel on your home screen, like an app from the App Store or Google Play. You get its own icon, it opens without an address bar, and you can receive notifications when something happens to your servers or your account.Finding help and seeing what changedThis documentation lives inside the panel: you never leave for another website, and it works offline on your phone. The same texts are also on a public site, so you can send a link to somebody who does not have an account (yet). This page e
Websites
Installing WordPressFrom an empty domain to a working WordPress site, and then properly under management in the panel. This page is about that first step and about the things you want to arrange straight after it. What you can do with a site once it stands — uYour WordPress sitesThe panel keeps an eye on your WordPress installations: which ones exist, whether they are up to date, and whether any of them has a known security hole.Installing and looking after applicationsAn application is the software your website actually is: WordPress, a forum, tomorrow a shop or an analytics package. You will find them under Accounts → your account → Applications.Making a test environmentA test environment — usually called staging — is a complete second copy of your website on an address of its own, where you can break things. Try the new theme, update the plugin you do not trust, rewrite the checkout page. Nobody is lookinExtra names and subdomainsOne website can answer on more than one name. You registered mycompany.com, later mycompany.co.uk as well, and you want both to show the same site. Or you have mycompany.com and want shop.mycompany.com beside it as a separate webshop. ThosePassword-protect a folderSometimes there is something on your website that is not for everybody. The new site that is not finished. A folder of quotes for one client. The handbook only your staff should read. You can put such a folder behind a user name and a passwPHP settings for a websitePHP is the program that runs your website's code. Almost every site works on the default settings, and you never have to touch this screen. You come here when something specific asks you to: a webshop that wants more memory for an import, aReading logsWhen a website does something odd, the answer is nearly always in a log. Who came by, what the server sent back, where PHP tripped over itself. In CoreCP you read those logs straight from the panel — no SSH session to open, no file to downlSSL and certificatesThe padlock in the address bar. A certificate encrypts the traffic between your visitor and your site, and lets the browser prove it is really talking to your domain. For most people the good news is that there is nothing to do here. This pInfected files and the website cacheTwo things that live next to each other on a server that scans for malware and caches pages: what the scanner found in your files, and how to clear the cache of your website when a change is not showing up.Visitors of your websiteHow many people come to your site, what do they read, and where do they come from? That is under Statistics in CoreCP, and there is nothing to install for it. No script in your pages, no cookie on your visitor, no extra service to sign up fManaging DNS recordsDNS is the address book of the internet: it tells the rest of the world where
Setting up emailEverything to do with email lives on one page: mailboxes, aliases, forwarders, vacation replies and the button to webmail. This page walks through them one by one.Making sure your email arrivesYou can set a mailbox up perfectly and still land in your customer's spam folder. Not because you did something wrong, but because the receiving side — Gmail, Outlook, a corporate mail server — is asking itself whether your mail is really fMail security — DMARC reports, MTA-STS and DNSSECA domain's Mail security page answers three questions you cannot answer by looking in your own mailbox:Mailing listsOne address that reaches everybody. You write toWhere your email went"I sent a quote this morning and the customer says nothing arrived." That is the question this screen exists for. It shows, per message, what the mail server did with it: accepted, deferred, bounced or refused — and when it went wrong, whatHow much mail your account sendsOutgoing mail is easy to forget about until it goes wrong. This screen shows, per domain, what went out, what is still waiting and what never arrived — and it warns you when a domain suddenly sends far more than it usually does, which almosMail that is held backOn some servers there is an extra machine in front of the mail server: a mail gateway. All mail for your domain arrives there first, is checked there, and only then goes on to your mailbox. What looks suspicious does not go on — it stays onMessages we send youSometimes the panel writes to you without being asked. Not because you requested something, but because something happened that you need to know about: your disk is filling up, a certificate cannot be renewed, a backup failed, or somebody sThe mail queuePost the server has accepted but not yet delivered sits in the queue. Usually for a few seconds and you never notice. Sometimes something stays: the receiving server will not take it, a customer's script handed in four thousand messages at Setting your notifications and e-mailThe panel keeps you informed: a disk filling up, a backup that failed, somebody signing into your account from a new device. On Settings → Notifications you decide what you hear about and where it arrives.
Files, databases and access
Databases and phpMyAdminNearly every website keeps its content in a database: WordPress, a webshop, a forum. This page shows how to create one, who may reach it, and how to look inside.Files, FTP and SSHThere are three ways to reach the files of your account: the file manager in the panel, an FTP client, and SFTP/SSH with a key. This page covers all three and says which one you want when.Scheduled tasksA scheduled task is a command the server runs for you at fixed times, whether or not anybody is signed in. A cleanup script at three in the morning, an import every ten minutes, a newsletter on the first of the month: those are all scheduleDeploying with GitA website that comes out of a Git repository does not need FTP any more. You bring the repository in once, and from then on publishing is one button: the server writes out a copy of exactly one commit into a directory of its own and points Your data in the panelThe panel keeps a record of you: how you sign in, where you were signed in from, what it has told you, and what you asked it to do. This page says what that record holds, how long each part of it is kept, and how to get a copy.Your own backupsYour hosting company almost certainly backs up the whole server. Those backups exist for disasters — a broken disk, a lost machine. They are not there to get you out of Tuesday afternoon, when a plugin update wrecked your site. That is whatThe web terminalA terminal in your browser: the same shell you would get over SSH, without installing an SSH client or carrying a key. Useful from a borrowed laptop, and the quickest route to wp-cli, mysqldump, or simply having a look at what is in a log f
Accounts and access
Creating a hosting accountOne page creates the customer, their first website and their panel login together. You reach it from Accounts → Create account. Everything that is not in the first two blocks has a sensible default and starts folded away, so you can go straGiving somebody accessYou can let other people look at, or work in, your account without sharing your password. You invite them at their own email address, choose what they may do, and change or withdraw that later.Running your own hosting brandAs a reseller you sell hosting under your own name. Your customers see your address, your logo and your colour — never CoreCP, and never each other. This page covers what you set up yourself and where the boundary is.Seeing what a customer seesTwo tools answer the question "why can this person not do that?", and they are not the same size. Reach for the small one first.Keeping spam outEvery mailbox on the server is filtered, from the moment it is created, without anybody switching anything on. This page is about the three things you can change when the default is not quite right for you: how hard the filter looks, what iYour account's settings and capabilitiesEvery hosting account has two kinds of boundary. How much you may use — disk space, mailboxes, websites — and what you may use: mail, FTP, databases, SSH. The first are numbers, the second are switches. They live on one page, and every row Building packages and applying themA package is what a customer may use: how much disk space, how many websites, and which parts of the panel come with it. You build it once and then put customers on it.Erasing a person, and what staysA customer asks you to remove everything you hold about them. This page is how that is done in the panel, what it refuses to do, and the one thing it keeps.Where your space goesYour account is nearly full and you have no idea what is doing it. That is one of the most common hosting questions there is, and the answer is almost never what you expect: it is rarely your photos, and almost always a four-year-old mailboUsage and limitsYour hosting plan sets ceilings: how much processor time your websites may use, how much memory, how many processes at once. Most of the time you never meet them. This page is what happens when you do — and, more usefully, what was running
Platform and servers
Adding a serverFrom a bare Ubuntu server to a working role node in one command. You say in the panel what the machine is for, copy one line, paste it on the server, and watch.Platform settingsThe panel has two kinds of settings, and until recently both were called "Settings". That was confusing: your own language sat one menu entry away from the API keys of the whole platform, and the word did not say which of the two you were aWhere a website is servedA CoreCP website does not live on "a server". It has five services — its web server, its database, its mail store, its nameservers and its backup target — and each of them is placed on a machine independently. Most of the time all five landLicence and ownershipCoreCP is proprietary software. This page explains what the panel says about ownership, where the licence text lives, and — the question that comes up most — what you tell a hosting customer who asks about it.Managing a serverA server has seven sections, and as of this round they are all in one bar at the top of the page — on every one of that server's screens. Wherever you are, you are one click from the other six.Access to a serverA server administrator gets one or more machines from you. From now on you also decide how much they may do on each: watch only, use the server, configure it, or everything.Replacing an IP addressSooner or later a server has to move to a different IP address. Your provider delivers a new block, you move to another data centre, or one address ends up on a blocklist and you want rid of it. That sounds like one action, but it is not: tWhere a release comes fromMost of what you install is somebody else's code. This page shows which parts, under what terms they may be shipped, and how to read back — without taking anyone's word for it — what an installed version is actually made of.Your own nameserversIf you sell hosting under your own name, you do not want your customers to seeNameservers your whole fleet sharesEvery zone you host has to be answered by at least two nameservers, and buying two machines per server is not how anybody runs a platform. One pair of nameservers serves the whole fleet: each of your servers publishes its own zones, and botSetting the authentication policySettings → Platform security is where the panel says what it expects of a login: which second factor, how long a password has to be, and when somebody is left outside for a while after too many failed attempts. This page walks through the fChecking, exporting and watching the audit logThe audit log is this panel's evidence: who did what, when, and whether they were allowed to. This page is about the three things around it that until now you could only reach over SSH:The fleet at a glanceServers → Monitoring answers the question you start the day with: is anything wrong, and if so where. It is not a wall of graphs and not a second server list — it is the top layer of everything your machines report about themselves, with thFollowing background tasksNot everything is instant. Creating a website takes seconds, requesting a certificate half a minute, restoring a backup sometimes an hour, and migrating a whole server a night. All of that work runs on the server, not in your browser: you mIf the panel goes downThis article is about the worst case: the machine the panel runs on is gone. A fire, a deleted VM, a disk that does not come back.What the panel knows about itselfThe panel watches your servers. Every machine runs an agent that keeps an eye on its own disks, services and certificates, and the fleet screen rolls all of that up into one list.Sending diagnosticsWhen something is wrong with the panel itself, whoever looks into it always asks for roughly the same things: what doctor says, what is in the configuration, what is unhealthy right now, which tasks were running, which versions the servers IntegrationsA hosting platform talks to more than itself. There may be a mail gateway in front of your mail server, part of your DNS may live at Cloudflare, your notifications may go through a Telegram bot, your certificates come from Let's Encrypt or Managing releasesA new version of PHP, of the agent, or of the panel itself does not go to every server at once. It walks: a soak on the beta channel, then a canary machine, then the fleet in waves, with a wait between each pair and a health check that can Server profilesA profile is the shape of a machine, written down once instead of typed out per server: which roles it serves, which tools it carries, how its database and its cache are tuned, and what a new WordPress site on it starts with.The PHP policy of a serverEvery machine decides what its customers may change about their PHP. That decision lives in one file, /etc/corecp/php-policy.yaml, and this screen is that file.Tools on a serverA machine carries its roles — web, mail, dns, db, backup, ftp — and beside them it carries tools: the things your customers need in a shell but that none of the roles installs by itself. git to deploy from a repository, Composer to resolve Assigning servers to rollout wavesA new version never reaches every server at once. It walks in waves: a canary first, then wave 1, then the rest, with a wait and a health check between each pair. Which server is in which wave is your decision.Config drop-insSooner or later a machine needs one setting CoreCP does not model: anYour servers' backupsThere are two kinds of backup in CoreCP, and they belong to different people. A hosting account's backup is the customer's: they make it, to their own storage, and they put it back themselves (see Your own backups). A server's backup is youCertificates across your fleetThere are two administrator screens for certificates and they answer two different questions. Servers → the server → Certificates shows every certificate on one machine. Servers → Certificates shows what expires soon or cannot be issued, acIntegrations on a serverA CoreCP machine can carry products that are not ours: a malware scanner, a tuning agent for the database, the paid edition of the web server, an application installer. Each of them needs a licence key, and each vendor has its own idea of wRestoring a backupRestoring is the thing backups exist for, and it is also the thing you get the least practice at. So in CoreCP it is one journey of nine steps rather than three separate screens: you can see the whole decision in front of you, in the order The firewall of a serverEvery CoreCP machine has one firewall manager. By default that is CoreCP itself — no CSF, no ufw beside it — and that is a deliberate choice: two programs pulling at the same rules produce an outcome nobody can predict. Everything you are uServer settings and servicesThis screen is about the machine itself: which port you reach it on, which keys open a root session, what it runs, what shape it was given, and how to stop it gracefully. Nothing here is about a customer or a website — that lives on the accReading the server advisorEvery CoreCP server checks itself. Around fifty checks: is everything running, is there room, does the firewall agree with reality, is a certificate about to expire, and — new — is this address on a blocklist, is there a PHP release here thThe firewall in front of your websitesA server has two firewalls, and they do different jobs. The one under The firewall of a server decides which addresses may reach the machine at all. This one decides which requests may reach a website: it reads the address bar, the form somWhich versions we offerA hosting platform runs on other people's software: PHP, MariaDB, Node, LiteSpeed. Each of them has several series alive at once, and every series has an expiry date. This page explains what CoreCP offers, for how long, and what happens wheHow CoreCP versions workCoreCP has one version number. It sits at the bottom left of the panel, under the logo, and it is the same number for the panel and for the software running on your servers. A support question starts with that number, so this page explains Connecting a second panelA second brand is a second CoreCP installation. It runs the same software and installs the same packages from the same source — and shares nothing else. Its own database, its own customers, its own keys, its own certificate authority, its oAPI keysAn API key is how something other than a person talks to this panel: your billing package creating an account, a script checking a backup overnight, an integration updating DNS. You mint them under Platform → API keys.The assistant and connecting your own AIThe panel can talk to an AI in two ways: a chat inside the panel running on your own API key, and a connection that lets your own AI client (Claude, ChatGPT) work with the panel directly. This page explains how to set both up and — more impThe fleet as one picture, even when it is largeThe fleet diagram (Servers → Fleet diagram) draws what your machines do for each other: which pool they schedule from, where their backups go, which nameserver takes over from them and which gateway their mail runs through. It is not a measUsing the test setThis platform carries a complete, real test set: one reseller with a panel address of their own, three websites on three registered domains, a WordPress under toolkit management, mailboxes that really send and really receive, DNS zones, FTP
Migrating
Migrating from cPanelcPanel is the biggest source of migrations there is, so CoreCP reads its archives directly — the same cpmove archive pkgacct writes, and the full account backup a customer can make from their own cPanel without asking anybody.Running a live migrationMoving a customer off a running server onto CoreCP without the site being down for hours. This is the guided version: one wizard that puts the steps in the order somebody actually does them, may run for days, and survives you closing the laRebalancing accounts across your serverscurl -s -b cookies.txt https://panel.example.net/api/v1/account-migrations \
Reference
The CoreCP design systemEverything you see in the panel is built out of one small set of parts. This page says what those parts are, what the design decides for you, and how a new screen is put together with them.The support ID on an error messageSometimes the panel refuses something. Usually there is one sentence you can act on: an address that is not valid, a package that is full, a server that is busy for a moment. But sometimes that sentence is not enough — it says you may not d