> ## Documentation Index
> Fetch the complete documentation index at: https://3to1go.docs.thesteau.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Sign-in and accounts

> First sign-in, account controls, password changes, and sessions in Central and Edge.

Central and Edge each have their **own** web UI and their own accounts. Signing in to one does not sign you in to the other.

<Tabs>
  <Tab title="Central">
    <Frame caption="Central's sign-in dialog.">
      <img src="https://mintcdn.com/3to1go/M9bMqD6QUOXKJ3Bp/images/sign-in/central-sign-in.png?fit=max&auto=format&n=M9bMqD6QUOXKJ3Bp&q=85&s=651d55c597f7dd509eacccdb5220f113" alt="Central Sign In dialog with username and password fields" width="660" height="495" data-path="images/sign-in/central-sign-in.png" />
    </Frame>
  </Tab>

  <Tab title="Edge">
    <Frame caption="Edge's separate sign-in dialog.">
      <img src="https://mintcdn.com/3to1go/M9bMqD6QUOXKJ3Bp/images/sign-in/edge-sign-in.png?fit=max&auto=format&n=M9bMqD6QUOXKJ3Bp&q=85&s=2de7465192999dea00e7474863de5d62" alt="Edge Sign In dialog with username and password fields" width="660" height="495" data-path="images/sign-in/edge-sign-in.png" />
    </Frame>
  </Tab>
</Tabs>

## The first admin account

When an app starts with no user accounts, it creates an `admin` user. Its password is:

* the value of `INITIAL_ADMIN_PASSWORD` in that app's `.env`, if set, or
* `admin`, if unset, empty, or only whitespace.

The first admin must change its password before continuing, **even when you set a custom `INITIAL_ADMIN_PASSWORD`**. Using `admin` as any account's password also requires a password change.

<Warning>
  `INITIAL_ADMIN_PASSWORD` is only read when the first admin is created. Changing it later does **not** change an existing password. To recover a locked Central account, see [Reset the admin password](/central/reset-admin-password).
</Warning>

In Central, `POSTGRES_PASSWORD` is the database password, not your sign-in password.

## Accounts are for one operator

Sign-in exists so one operator can manage the app and keep unauthorized entrants out. Both apps currently include account management and an admin flag, but they aren't designed for separate tenants or per-user ownership of backups.

Click **Admin** in either app to open **Users & Access**:

* Admins can add accounts, edit usernames, reset another account's password, assign admin access to other accounts, and remove other accounts.
* Non-admin accounts can view their own account and edit their own username. Non-admin does not mean read-only access to the app.
* The original admin account cannot be removed or lose admin access, and the `admin` username cannot be renamed. You cannot change your own admin access.

An admin reset signs the target account out of its existing sessions and requires a password change. Creating an additional account with a non-default password does **not** automatically require a first-sign-in password change.

<Tabs>
  <Tab title="Central">
    <Frame caption="Users & Access in Central, with an example additional account.">
      <img src="https://mintcdn.com/3to1go/M9bMqD6QUOXKJ3Bp/images/sign-in/central-users.png?fit=max&auto=format&n=M9bMqD6QUOXKJ3Bp&q=85&s=953cfaaec7add06c94018c4923c8e3c4" alt="Central Users and Access dialog showing admin and operator accounts, password reset, admin access, and Add User controls" width="1080" height="990" data-path="images/sign-in/central-users.png" />
    </Frame>
  </Tab>

  <Tab title="Edge">
    <Frame caption="Users & Access in Edge. These accounts belong to this Edge only.">
      <img src="https://mintcdn.com/3to1go/M9bMqD6QUOXKJ3Bp/images/sign-in/edge-users.png?fit=max&auto=format&n=M9bMqD6QUOXKJ3Bp&q=85&s=bd57fea357826f8e1c25581f5871296a" alt="Edge Users and Access dialog showing local admin and operator accounts and account management controls" width="1140" height="933" data-path="images/sign-in/edge-users.png" />
    </Frame>
  </Tab>
</Tabs>

## Change your password

Open **Admin**, then **Change My Password**. Enter your current password and the new password twice. Passwords must be at least five characters and cannot consist only of spaces.

The same dialog appears when a password change is required. Changing your own password keeps your existing sessions signed in.

<Frame caption="Change My Password in Central; Edge provides the same fields.">
  <img src="https://mintcdn.com/3to1go/M9bMqD6QUOXKJ3Bp/images/sign-in/central-change-password.png?fit=max&auto=format&n=M9bMqD6QUOXKJ3Bp&q=85&s=aac1fbe737a42966d3d46305b537611e" alt="Change Password dialog with current password, new password, and confirmation fields" width="660" height="606" data-path="images/sign-in/central-change-password.png" />
</Frame>

## Sessions and sign-out

Sessions expire seven days after sign-in. Use **Admin → Sign Out** to end the current session; this does not sign out other browsers. Central and Edge use separate session cookies, both marked `HttpOnly` and `SameSite=Lax`.

## Session cookies over HTTPS

If you serve an app over HTTPS (for example behind a reverse proxy), set this in its `.env` so the session cookie is only sent over secure connections:

```sh .env theme={null}
SESSION_COOKIE_SECURE=true
```

Accepted "on" values are `1`, `true`, `yes`, and `on`. Anything else, or leaving it unset, keeps the cookie usable over plain HTTP.

<Note>
  Edge's settings dialog warns when its UI is served over plain HTTP. The UI connection and Edge's connection to Central are separate: use HTTPS for both the Edge UI and `CENTRAL_URL` to protect credentials on both connections.
</Note>
