Your profile and security
Your profile is personal to your account. It follows you between organisations; your role does not.
Profile#
Update your name and avatar from the profile screen.
SSH keys#
You can attach SSH public keys to your account and use them to sign in instead of a password.
- Add a key by pasting the public half. Never paste a private key — into CloudPilot or anywhere else.
- Revoke a key when you stop using the machine it lives on. Revoking takes effect immediately.
List and revoke keys from the same screen. Review them occasionally: an old key on a laptop you no longer own is a way in that nobody is watching.
A key here signs you in to CloudPilot. It does not give you SSH access to your servers, and removing it does not remove your access to a machine. Server access is managed on the server.
Sessions#
Sessions refresh in the background so you are not logged out constantly, and signing out ends the session rather than leaving a token alive until it expires.
Sign out from shared or borrowed devices rather than just closing the tab.
New-device verification#
Logging in from a device CloudPilot has not seen before triggers an emailed code. Known devices are not challenged every time.
Keep your email address current — it is how you get back in on a new machine.
If you think your account is compromised#
In this order:
- Change your password, or revoke the SSH key if that is how you sign in.
- Revoke any keys you do not recognise.
- Check the audit log for actions you did not take.
- Check your team list for members or invites you did not create.
- Rotate anything that account could have read — webhook URLs, database credentials it had access to.
Then tell support.
Raise a ticket and someone will pick it up. Sign in with the same account you use for the panel.
Raise a ticket