Skip to main content
Version: 2.0.13

Users

Manage users: Add, Delete, Suspend, Unsuspend, etc.

List Users​

To list all users, use the following command:

opencli user-list
Example output
# opencli user-list
+----+----------------+-------------------+----------------+----------------+-------+---------------------+
| id | username | email | plan_name | server | owner | registered_date |
+----+----------------+-------------------+----------------+----------------+-------+---------------------+
| 1 | stefan | [email protected] | Developer Plus | stefan | NULL | 2025-12-25 14:49:38 |
| 2 | panel | [email protected] | Developer Plus | panel | NULL | 2025-12-25 14:50:18 |
| 6 | emailfilterapi | emailfilterapi | Developer Plus | emailfilterapi | NULL | 2026-01-28 12:25:41 |
+----+----------------+-------------------+----------------+----------------+-------+---------------------+

You can also format the data as JSON:

opencli user-list --json
Example output
{
"data": [
{
"id": 1000,
"username": "stefan",
"context": "stefan",
"owner": "root",
"package": {
"name": "Developer Plus",
"owner": "root"
},
"email": "[email protected]",
"locale_code": "EN_us"
},
{
"id": 1001,
"username": "panel",
"context": "panel",
"owner": "root",
"package": {
"name": "Developer Plus",
"owner": "root"
},
"email": "[email protected]",
"locale_code": "EN_us"
},
{
"id": 1002,
"username": "emailfilterapi",
"context": "emailfilterapi",
"owner": "root",
"package": {
"name": "Developer Plus",
"owner": "root"
},
"email": "emailfilterapi",
"locale_code": "EN_us"
}
],
"metadata": {
"result": "ok"
}
}

To display only user count:

opencli user-list --total
Example output
# opencli user-list --total
Total number of users: 3

or:

opencli user-list --total --json
Example output
#opencli user-list --total --json
3

List all users Quotas​

opencli user-list --quota
Example output
{
"timestamp": "2026-04-01T10:16:01Z",
"users": [
{"username":"stefan","uid":1000,"home_path":"/home/stefan/","disk_used":269744,"disk_soft":5120000,"disk_hard":5120000,"inodes_used":130,"inodes_soft":1000000,"inodes_hard":1000000},
{"username":"pejcic","uid":1001,"home_path":"/home/pejcic/","disk_used":550216,"disk_soft":5120000,"disk_hard":5120000,"inodes_used":143,"inodes_soft":1000000,"inodes_hard":1000000},
{"username":"demo","uid":1002,"home_path":"/home/demo/","disk_used":4138604,"disk_soft":10240000,"disk_hard":10240000,"inodes_used":74889,"inodes_soft":1000000,"inodes_hard":1000000}
]
}

Add User​

opencli user-add <USERNAME> <PASSWORD|generate> <EMAIL> "<PLAN_NAME>" [--send-email] [--debug] [--reseller=<RESELLER_USERNAME>] [--private-note=<NOTE>] [--webserver=<TYPE>] [--sql=<mysql|mariadb>] [--no-sentinel]

To create a new user run the following command:

opencli user-add <USERNAME> <PASSWORD> <EMAIL> <PLAN_NAME>

Example:

opencli user-add stefan pejcic324 [email protected] 'Default Plan Nginx'
Example output
# opencli user-add stefan pejcic324 [email protected] 'Default Plan Nginx'
[✔] Successfully added user stefan with password: pejcic324
TIP

Provide generate as password to generate a strong random password.

Optional flags:

  • --send-email - send an email with login credentials to the user's email address.
  • --private-note=<NOTE> - save a private note for this user (visible only in OpenAdmin).
  • --reseller=<RESELLER_USERNAME> - assign a reseller as the owner of this user.
  • --webserver=<TYPE> - webserver to use: nginx, apache, openresty, openlitespeed or litespeed, optionally prefixed with varnish+ (e.g. varnish+nginx). Defaults to the plan/server setting.
  • --sql=<mysql|mariadb> - database type to use.
  • --no-sentinel - don't send the user_create notification.
  • --skip-images - don't pull container images for the new user.
  • --debug - display verbose information.

Example:

opencli user-add stefan generate [email protected] 'Default Plan Nginx' --webserver=varnish+nginx --sql=mariadb --send-email
Example output
# opencli user-add stefan generate [email protected] 'Default Plan Nginx' --webserver=varnish+nginx --sql=mariadb --send-email
[✔] Successfully added user stefan with password: k3Vq9XbT2mWz4LpR

Create user for Reseller​

opencli user-add <USERNAME> <PASSWORD> <EMAIL> "<PLAN_NAME>" --reseller=<RESELLER_USERNAME>
Example output
# opencli user-add client1 'StrongPass1' [email protected] 'Default Plan Nginx' --reseller=reseller1
[✔] Successfully added user client1 with password: StrongPass1

Transfer User​

To transfer user account to another server:

opencli user-transfer --account <OPENPANEL_USER> --host <DESTINATION_IP> --username <DESTINATION_SSH_USERNAME> --password <DESTINATION_SSH_PASSWORD> [--port 22] [--force] [--live-transfer]
Example output
# opencli user-transfer --account stefan --host 203.0.113.20 --username root --password 'DestinationPass'
Import started, log file: /var/log/openpanel/admin/transfers/stefan_203.0.113.20_2026-09-24_10-30-00.log
[2026-09-24 10:30:00] Testing SSH connection to [email protected]...
[2026-09-24 10:30:01] SSH connection established, starting transfer process..
[2026-09-24 10:30:01] Log file: /var/log/openpanel/admin/transfers/stefan_203.0.113.20_2026-09-24_10-30-00.log
[2026-09-24 10:30:01] PID: 48213
[2026-09-24 10:30:02] Resolved context for stefan: stefan
[2026-09-24 10:30:03] Importing new plan...
[2026-09-24 10:30:03] Importing user into database...
[2026-09-24 10:30:03] Listing features on remote server ...
[2026-09-24 10:30:03] Copying feature set 'default.txt' to remote server
[2026-09-24 10:30:04] Creating system user (stefan) on remote server ...
[2026-09-24 10:30:05] Syncing files for user stefan (context: stefan) ...
...
[2026-09-24 10:31:10] Importing sites ...
[2026-09-24 10:31:10] Site imported: example.com
[2026-09-24 10:31:11] Enabling rootless podman for stefan on destination ...
[2026-09-24 10:31:12] Restoring FTP accounts for stefan (context: stefan) ...
[2026-09-24 10:31:13] [FTP] restored [email protected] -> /var/www/html/example.com
[2026-09-24 10:31:13] FTP accounts restored for context stefan.
[2026-09-24 10:31:15] Syncing mail data ...
[2026-09-24 10:31:16] Syncing maildir /var/mail/example.com → /var/mail/example.com ...
[2026-09-24 10:31:17] Checking podman context ....
[2026-09-24 10:31:17] Starting containers inside podman context on remote server ...
[2026-09-24 10:32:01] Reloading services on 203.0.113.20 server ...
[2026-09-24 10:32:12] Reloading mailserver and webmail on 203.0.113.20 server ...
[2026-09-24 10:32:20] Recalculating disk and inodes usage for all users on 203.0.113.20 ...
[2026-09-24 10:32:20] Elapsed time: 0h 2m 20s
[2026-09-24 10:32:20] SUCCESS: Transfer process for user stefan completed.
  • --account - OpenPanel username to transfer.
  • -h, --host - destination server IP.
  • -u, --username - SSH user on the destination server (default root).
  • --password - SSH password for the destination server, leave it out to use SSH keys.
  • --port - SSH port on the destination server (default 22).
  • --force - overwrite the account if the username already exists on the destination server.
  • --live-transfer - suspend the account after the transfer and forward DNS to the new server.

The destination server needs OpenPanel installed. Files, databases, domains, sites, DNS zones, SSL, FTP and email accounts (Enterprise) are copied, and containers are recreated on the destination from the user's volumes. If a plan with the same name already exists on the destination it's reused, and the log shows a warning when its feature set differs from the source. Progress is written to /var/log/openpanel/admin/transfers/.

Backup User​

To create a full account .tar.gz backup of a single user (files, databases, mail, and configuration):

opencli user-backup --account <USER> [--output <DIR>] [--quiet]
Example output
# opencli user-backup --account stefan
[2026-09-24 10:30:00] Backup started log: /var/log/openpanel/admin/backups/stefan_backup_20260924_103000.log (PID: 48213)
[2026-09-24 10:30:00] Account: stefan Context: stefan UID:1001 GID:1001 Plan: Default Plan Nginx
[2026-09-24 10:30:00] Checking disk space ...
[2026-09-24 10:30:00] Source size (~812 MB via du)
[2026-09-24 10:30:00] Free at dest (~48210 MB at /backup)
[2026-09-24 10:30:00] Disk space OK.
[2026-09-24 10:30:00] Writing manifest ...
[2026-09-24 10:30:00] Exporting panel DB rows ...
...
[2026-09-24 10:30:02] Streaming /home/stefan → homedir/ ...
...

═══════════════════════════════════════════════════════════════
BACKUP COMPLETE — stefan_20260924_103000.tar.gz
═══════════════════════════════════════════════════════════════
Archive: /backup/stefan_20260924_103000.tar.gz
Size: 402M
Compression: pigz
Time taken: 0h 1m 12s

Contents:
Plan: "Default Plan Nginx"
Domains (2): example.com example.net
Sites: 1
Feature set: default
FTP accounts: 2
Home dir: homedir/ (source ~812 MB)
Containers: nginx php-fpm-8.3 mysql
  • --output <DIR> - custom destination directory for the archive (defaults to the location configured for backups).
  • --quiet - only log to file, don't print progress to stdout.

Restore User​

To restore a user account from a .tar.gz backup created with user-backup:

opencli user-restore --file <ARCHIVE> [--force] [--new-username=<NAME>] [--temp-dir=<PATH>] [--quiet]
Example output
# opencli user-restore --file /backup/stefan_20260924_103000.tar.gz
Import started, log file: /var/log/openpanel/admin/imports/openpanel-import_20260924_110000.log
[2026-09-24 11:00:00] Log file: /var/log/openpanel/admin/imports/openpanel-import_20260924_110000.log
[2026-09-24 11:00:00] PID: 51234
[2026-09-24 11:00:00] Archive: /backup/stefan_20260924_103000.tar.gz
[2026-09-24 11:00:00] Checking disk space for extraction ...
[2026-09-24 11:00:00] Extracting archive ...
[2026-09-24 11:00:09] Restoring 'stefan' (context: stefan) format v2
[2026-09-24 11:00:09] Restoring system user (stefan) ...
[2026-09-24 11:00:10] Restoring /home/stefan ...
[2026-09-24 11:00:31] Restoring panel DB rows ...
[2026-09-24 11:00:31] Plan 'Default Plan Nginx' exists (ID: 1) — reusing.
[2026-09-24 11:00:31] User row ready (ID: 7).
[2026-09-24 11:00:31] Restoring domains ...
[2026-09-24 11:00:31] Domain restored: example.com
[2026-09-24 11:00:31] Domain restored: example.net
[2026-09-24 11:00:31] Restoring FTP accounts ...
[2026-09-24 11:00:32] FTP user restored: [email protected]
...
[2026-09-24 11:00:40] Reloading services ...
[2026-09-24 11:00:41] Recalculating quotas ...

═══════════════════════════════════════════════════════════════
RESTORE COMPLETE — stefan
═══════════════════════════════════════════════════════════════
Archive: stefan_20260924_103000.tar.gz
Time taken: 0h 0m 41s

Restored:
System user: stefan [created]
Home directory: /home/stefan/ (812M)
...
  • --force - overwrite the account if a user with the same username already exists.
  • --new-username=<NAME> - restore under a different username than the one in the backup.
  • --temp-dir=<PATH> - directory to extract the archive into during restore (must be empty). Defaults to /tmp/.
  • --quiet - only log to file, don't print progress to stdout.

Delete User​

To delete a user and all his data run the following command:

opencli user-delete <USERNAME>
Example output
# opencli user-delete stefan
This will permanently delete user 'stefan' and all associated data. Confirm? [Y/n]: y
User stefan deleted successfully.

add -y flag to disable prompt.

This action is irreversible and will permanently delete all user data.

Suspend User​

To suspend (temporary disable access) to user, run the follwowing command:

opencli user-suspend <USERNAME> [-y] [--debug]
Example output
# opencli user-suspend stefan
Are you sure you want to suspend OpenPanel user 'stefan'? (y/N) y
User 'stefan' suspended successfully.

add -y flag to disable prompt.

Unsuspend User​

To unsuspend (enable access) to user, run the follwowing command:

opencli user-unsuspend <USERNAME>
Example output
# opencli user-unsuspend stefan
User 'stefan' unsuspended successfully.

Rename User​

To change a username run:

opencli user-rename <USERNAME> <NEW_USERNAME>
Example output
# opencli user-rename stefan pejcic
User 'stefan' successfully renamed to 'pejcic'.

Change Email​

To change a email run:

opencli user-email <USERNAME> <NEW_EMAIL>
Example output
# opencli user-email stefan [email protected]
Success: Email for user 'stefan' updated to '[email protected]'

Change Password​

To reset the password for a OpenPanel user, you can use the user-password command:

opencli user-password <USERNAME> <NEW_PASSWORD>
Example output
# opencli user-password stefan 'NewStrongPass1'
Successfully changed password for user stefan

Provide random as password to generate a strong random password:

opencli user-password <USERNAME> random
Example output
# opencli user-password stefan random
Successfully changed password for user stefan, new random generated password is: 7kQ!vR2m#Lx9TzpA

Login as User​

This command allows you to generate an auto-login link for any OpenPanel user.

opencli user-login <USERNAME>
Example output
# opencli user-login demouser --open
https://demo.openpanel.org:2083/login_autologin?admin_token=RMWvZK1cdeRkZQJGVQv682qby9XIPr&username=demouser

To invalidate an existing token for a user:

opencli user-login <USERNAME> --delete
Example output
# opencli user-login demouser --delete
Auto-login token 'b7f3c9e2a1d84f06' for user demouser is now invalidated.

To open the link in a browser:

opencli user-login <USERNAME> --open
Example output
# opencli user-login demouser --open
https://srv.example.com:2083/login_autologin?admin_token=b7f3c9e2a1d84f06&username=demouser

Change Plan​

Command: opencli user-change_plan allows you to change plan for a user.

opencli user-change_plan <username> "<new_plan_name>"
Example output
# opencli user-change_plan stefan "Developer Plus"
[✔] Total CPU limit (4) set successfully.
[✔] Tasks ceiling set to 300 (derived from RAM; /home/stefan/TasksMax overrides).
[✔] Total RAM limit (6G) set successfully.
[✔] Disk limit (10) and inodes (1000000) applied successfully.
Changing port speed to 100 is not possible at the moment.
Plan changed successfully for user stefan from Standard plan to Developer Plus

Quota​

Command: opencli user-quota enforces and recalculates disk and inodes for specific or all users.

opencli user-quota <username|--all>
Example output
# opencli user-quota stefan
[2026-01-28 17:51:40] Processing user: stefan
[2026-01-28 17:51:40] Quota set for user stefan: 20480000 blocks (20 GB) and 2500000 inodes
[2026-01-28 17:51:40] Updating repquota file...
[2026-01-28 17:51:40] Repquota file updated successfully: /etc/openpanel/openpanel/core/users/repquota

Check / Disable 2FA​

To disable Two-Factor Authentication for a user, run the following command:

opencli user-2fa <USERNAME> [disable]
Example output
# opencli user-2fa stefan
Two-factor authentication for stefan is ENABLED.

# opencli user-2fa stefan disable
Two-factor authentication for stefan is now DISABLED.

Assign / Remove IP to User​

To assign free IP address to a user run the following command:

opencli user-ip <USERNAME> <IP_ADDRESS>
Example output
# opencli user-ip stefan 203.0.113.11
IP successfully changed for user stefan to dedicated IP address: 203.0.113.11

To assign IP address that is currently used by another user to this user, run the following command:

opencli user-ip <USERNAME> <IP_ADDRESS> -y
Example output
# opencli user-ip stefan 203.0.113.11 -y
IP successfully changed for user stefan to dedicated IP address: 203.0.113.11

To remove dedicated IP address from a user run:

opencli user-ip <USERNAME> delete [-y]
Example output
# opencli user-ip stefan delete
IP configuration deleted for user stefan.
IP successfully changed for user stefan to shared IP address: 203.0.113.10

Add --debug to any user-ip command to display verbose information.

Check​

Check files and security for a user:

opencli user-check <USERNAME>
Example output
# opencli user-check mozda
===== Checking user: mozda =====
---- Docker Daemon Security ----
[INFO] Running for user: mozda
[WARN] Inter-container communication on default bridge is allowed
[WARN] Docker logging level is not set to 'info' ('default')
[PASS] Docker is not allowed to modify iptables
[PASS] Not using deprecated aufs storage driver
[WARN] TLS authentication for Docker daemon is NOT configured
[PASS] Docker daemon is NOT listening on TCP socket
[PASS] Experimental features are NOT enabled
[PASS] Rootless context is configured
[PASS] Containers can not get new privileges
[PASS] Google DNS resolvers are configured

---- System and User Files ----
[PASS] /home/mozda/docker-data is configured for docker data.
[PASS] home.mozda.bin.rootlesskit file exists.
[PASS] .env file exists.
[PASS] docker-compose.yml file exists.
[PASS] backup.env file exists.
[PASS] crons.ini file exists.
[PASS] custom.cnf file exists.
[PASS] default.vcl file exists.
[PASS] httpd.conf file exists.
[PASS] nginx.conf file exists.
[PASS] openresty.conf file exists.
[PASS] pma.php file exists.
[PASS] Disk usage is below quota (3.80 GB used of 4.88 GB).
[PASS] Inode usage is below quota (113350 used of 1000000).
[INFO] Checking files ownership for user: mozda (UID: 1004, GID: 1004)
[WARN] File '/home/mozda/docker-data/overlay2/25af867389efa6af7eb6120dceef0bb601796ab469af0c9c4c798671594be432/diff/var/www/html' is owned by UID:100032 instead of UID:1004
[FAIL] Some docker files in /home/mozda/docker-data/ are not owned by UID:1004

---- Container Security Checks ----
[INFO] Found 2 running container(s)
---- Container: openresty ----
[PASS] openresty: Container running from OpenPanel
[PASS] openresty: Container name matches compose service name: openresty
[PASS] openresty: Container is running
[PASS] openresty: Container is running as root
[PASS] openresty: Using specific tag for image: openresty/openresty:bullseye-fat
[WARN] openresty: No HEALTHCHECK configured
[WARN] openresty: SELinux options not set
[WARN] openresty: --no-new-privileges restriction not set
[PASS] openresty: No extra Linux capabilities added
[PASS] openresty: Privileged mode is disabled
[WARN] openresty: Bind mounts under /home/ or /etc/openpanel/
[PASS] openresty: Docker socket is NOT mounted
[PASS] openresty: sshd is NOT running inside container
[PASS] openresty: Using OpenPanel network (mozda_www)
[PASS] openresty: All ports are bound to 127.0.0.1
[PASS] openresty: Memory usage is limited to .50 GB
[PASS] openresty: CPU usage is limited to .50 CPUs
[PASS] openresty: PID cgroup limit is set (100)
[WARN] openresty: Root filesystem is NOT read-only
[PASS] openresty: Host devices are NOT exposed
[WARN] openresty: Default ulimit is used
---- Container: php-fpm-8.2 ----
[PASS] php-fpm-8.2: Container running from OpenPanel
[PASS] php-fpm-8.2: Container name matches compose service name: php-fpm-8.2
[PASS] php-fpm-8.2: Container is running
[PASS] php-fpm-8.2: Container is running as root
[WARN] php-fpm-8.2: No HEALTHCHECK configured
[WARN] php-fpm-8.2: SELinux options not set
[WARN] php-fpm-8.2: --no-new-privileges restriction not set
[PASS] php-fpm-8.2: No extra Linux capabilities added
[PASS] php-fpm-8.2: Privileged mode is disabled
[WARN] php-fpm-8.2: Bind mounts under /home/ or /etc/openpanel/
[PASS] php-fpm-8.2: Docker socket is NOT mounted
[PASS] php-fpm-8.2: sshd is NOT running inside container
[PASS] php-fpm-8.2: Using OpenPanel network (mozda_db)
[PASS] php-fpm-8.2: No exposed ports
[PASS] php-fpm-8.2: Memory usage is limited to .25 GB
[PASS] php-fpm-8.2: CPU usage is limited to .12 CPUs
[PASS] php-fpm-8.2: PID cgroup limit is set (100)
[WARN] php-fpm-8.2: Root filesystem is NOT read-only
[PASS] php-fpm-8.2: Host devices are NOT exposed
[WARN] php-fpm-8.2: Default ulimit is used

===== Audit Summary =====
Total checks performed: 70
✅ Passed: 50
❌ Failed: 1
âš ī¸ Warnings: 16
â„šī¸ Info: 3

âš ī¸ Critical issues found! Please review and address failed checks.

Block IP​

Prevent specific IP addresses or CIDR ranges from accessing any user websites:

opencli user-block_ip <username> [--list='ip_here another_ip' | --delete-all]

List blocked IPs for a user:

opencli user-block_ip <username>
Example output
# opencli user-block_ip stefan
11.22.33.44
124.64.23.0/24

Block IP addresses from accessing user websites:

opencli user-block_ip <username> --list='11.22.33.44 124.64.23.0/24'
Example output
# opencli user-block_ip stefan --list='11.22.33.44 124.64.23.0/24'
Blocking IP 11.22.33.44 for user stefan...
Blocking IP 124.64.23.0/24 for user stefan...
Blocklist applied for domain 'example.com'
Blocklist applied for domain 'example.net'

Remove all blocked IP addresses for a user:

opencli user-block_ip <username> --delete-all

The blocklist is emptied and Caddy is reloaded. The command prints no output.

View login log​

View up to last 20 successfull logins for the user.

opencli user-loginlog <USERNAME> [--table|--text|--json]
Example output
# opencli user-loginlog stefan
IP Country Time
203.0.113.5 RS 2026-09-24 09:12:44
198.51.100.7 DE 2026-09-23 18:02:10

# opencli user-loginlog stefan --json
[
{
"ip": "203.0.113.5",
"country": "RS",
"time": "2026-09-24 09:12:44"
}
]

Output is shown as a table by default. Use --text for plain text or --json for JSON.

Varnish​

Check Varnish Caching status for user and enable/disable Varnish service.

opencli user-varnish <USERNAME> [enable|disable|status]

Enable Varnish:

opencli user-varnish <USERNAME> enable
Example output
# opencli user-varnish stefan enable
...
Varnish Cache is now enabled.

Disable Varnish:

opencli user-varnish <USERNAME> disable
Example output
# opencli user-varnish stefan disable
...
Varnish Cache is now disabled.

Check status:

opencli user-varnish <USERNAME> status
Example output
# opencli user-varnish stefan status
Varnish Cache is enabled.

Check short status (returns Current status: on/off):

opencli user-varnish <USERNAME>
Example output
# opencli user-varnish stefan
Current status: On
Was this helpful?