Skip to content

🔐 Security

Three layers protect your VMs: tokens decide what the app may do, two-factor authentication protects sign-in, and an optional app lock protects the app on the device.

Access Tokens


🔑 Tokens

Token Access
Master token Everything, including managing tokens
Scoped — Admin Configure and manage the VMs it covers. With access to all VMs it can also create and clone VMs, and use templates, networks and images if those permissions are granted
Scoped — Operator View and control the VMs it covers (start, stop, screen, console). It can't change configuration, take snapshots, rename or delete

The app hides screens and actions your token doesn't allow.

Access Tokens

With the master token, open More → Security → Access Tokens (iPad: Security → Access Tokens). Each token shows its role, VM access and when it was last used.

Tap + to create a token:

Field Description
Label A name for the token
Role Operator or Admin
VM Access All VMs, or pick specific VMs
Expires Optional expiry date
Extended Permissions Templates, Networks, Images — Admin tokens with access to all VMs only

Important: The secret is shown once, when the token is created. Copy it and store it safely. If it is lost, use Rotate Secret to issue a new one.

Tap a token to Edit, Rotate Secret or Revoke it.


🛡️ Two-Factor Authentication

Open More → Security → Two-Factor Auth to protect your token's sign-in with a 6-digit code from an authenticator app.

  1. Tap Set Up 2FA
  2. Scan the QR code, or tap Copy Secret or Open in Authenticator App
  3. Enter the 6-digit code to enable it
  4. Save your recovery codes — each works once

Once enabled, the app asks for a code when it connects. You can Regenerate Recovery Codes or Disable 2FA at any time. A recovery code can be typed in place of the 6-digit code.


🔒 App Lock

Turn on Require Face ID / Touch ID in Settings. The app then asks for Face ID, Touch ID or your device passcode when it opens and after a minute in the background. It is off by default. Changing the setting requires authentication.