- 01Dashboard
Enable 2FA and save recovery codes.
- 02Shell
Manage authorised public SSH keys.
- 03Files
Keep independent copies and inspect backup coverage.
Dashboard two-factor authentication
Open Security Centre
Select the shell if required and enter the current dashboard password for sensitive actions.
Start authenticator setup
Follow the setup controls, scan the QR code with your authenticator and enter a current code to enable 2FA. Do not share the QR code or setup secret.
Save recovery codes
Store them somewhere secure outside this shell. Replacing recovery codes invalidates the older set; security changes can sign out other sessions.
Public SSH keys
Generate and protect a key pair on your own device. In Security Centre, add only the public SSH key and a useful label; confirm using your dashboard password. The matching private key stays on your device. Removing a key prevents future key logins but does not close an already open SSH session. Keep a working recovery method before removing your only key.
What the panel backups cover
Request file recovery
Inspect the available copies
Open Backups & Restore. Read the backup time, integrity/coverage details and any stale status or warnings.
Choose the copy and explain the need
Submit a recovery request with the affected paths and the problem. Approval is a review decision, not an immediate restore.
Wait for actual recovery
Staff stage and inspect an approved copy and arrange manual recovery. Check the request status and completion notes; do not assume approved means your files have been restored.
Keep your own backup
Download important files using SFTP and retain a separate copy outside the VPS. Copy website sources and app configurations before editing or fresh installation. A home copy may omit sockets or unreadable files and can include changing files; it does not promise an application-consistent database or live-session restore.
If you suspect compromise
Contact staff promptly with your username, approximate time and the issue. Never send passwords, private keys, recovery codes or verification links. Review public keys and running applications, and follow staff advice on resetting credentials and ending sessions.
You are protected when
- 2FA is enabled and recovery codes are stored independently.
- You recognise all authorised SSH keys.
- Important files have a separate off-server copy.
- You understand the coverage of a backup before requesting recovery.
Read this topic in the wiki ↗ · Documentation hub ↗
Reference and helpChecked against the current customer-panel implementation and DWShells signup and rules. For assigned values and eligibility, use your dashboard. Need help? Join #DWShells on DarkWorld IRC or contact staff. Do not send credentials.