CloudPilot Support

Your profile and security

Your profile is personal to your account. It follows you between organisations; your role does not.

Profile#

Update your name and avatar from the profile screen.

SSH keys#

You can attach SSH public keys to your account and use them to sign in instead of a password.

  • Add a key by pasting the public half. Never paste a private key — into CloudPilot or anywhere else.
  • Revoke a key when you stop using the machine it lives on. Revoking takes effect immediately.

List and revoke keys from the same screen. Review them occasionally: an old key on a laptop you no longer own is a way in that nobody is watching.

Account keys and server keys are different

A key here signs you in to CloudPilot. It does not give you SSH access to your servers, and removing it does not remove your access to a machine. Server access is managed on the server.

Sessions#

Sessions refresh in the background so you are not logged out constantly, and signing out ends the session rather than leaving a token alive until it expires.

Sign out from shared or borrowed devices rather than just closing the tab.

New-device verification#

Logging in from a device CloudPilot has not seen before triggers an emailed code. Known devices are not challenged every time.

Keep your email address current — it is how you get back in on a new machine.

If you think your account is compromised#

In this order:

  1. Change your password, or revoke the SSH key if that is how you sign in.
  2. Revoke any keys you do not recognise.
  3. Check the audit log for actions you did not take.
  4. Check your team list for members or invites you did not create.
  5. Rotate anything that account could have read — webhook URLs, database credentials it had access to.

Then tell support.

Did this not answer your question?

Raise a ticket and someone will pick it up. Sign in with the same account you use for the panel.

Raise a ticket