Subshell Docs

Sign-in and origin errors

Identify whether a sign-in failure comes from account credentials, browser origins, or a sign-in provider.

Admin password issues

Use the administrator email address and password chosen during server setup. These are separate from your machine's OS password and your coding agent's provider account.

A password is rejected

  1. Confirm that you opened the intended Subshell instance. Accounts and passwords belong to that instance.
  2. Check the email address, Caps Lock, and whether your password manager supplied an older password.
  3. Check the reported error. Invalid origin concerns the browser address; resetting the password does not fix it.
  4. If password sign-in is unavailable, use another enabled sign-in method linked to your account. Disabling the email provider's sign-in option prevents ordinary password sign-in even when the password is correct. See Sign-in providers.

Closing registration does not prevent existing accounts from signing in.

You forgot the admin password

If another administrator can sign in, ask them to open Server Settings → Users in the dashboard sidebar, open your account's ⋯ menu, and choose Reset password. This applies to accounts with a password login and signs out all of that account's existing sessions. An administrator cannot use this action on their own account; changing your own password requires the current password. Open the profile menu at the bottom of the dashboard sidebar, choose Account settings, and use Change password.

If no administrator can sign in, follow Account recovery. You need access to the server host's configuration and the email address of an existing administrator. Recovery does not create a new admin account.

Recovery changes the password

Signing in with SUBSHELL_EMERGENCY_PASSWORD overwrites the administrator's stored password. Remove the emergency value from every configuration layer that supplies it, restart the server, and verify the recovery warning clears.

An emergency password is rejected

Use Files and paths to locate the running instance's configuration. Verify that you changed the correct server's configuration, restarted its process, and entered the existing administrator's email and the exact configured emergency value. A process environment value overrides one saved in config.env.

Follow the full Account recovery procedure, including disabling recovery afterward. Do not widen trusted origins to fix an incorrect password.

Invalid origin

A page can load while an authentication request returns Invalid origin. Compare the browser's scheme, hostname, and port with the effective trusted origins.

If you can sign in as an administrator, open Server Settings → Networking in the server dashboard's sidebar. In the Addresses card, edit Other addresses browsers will use to add the intended browser origin.

If you cannot sign in, run subshell-server configure on the server host instead. Use Files and paths to locate its active configuration. A wildcard bind does not trust arbitrary names. Network plugin records contribute their own addresses live.

Loopback on another device

localhost and 127.0.0.1 refer to the device making the request. Choose a LAN or mesh address when opening a server from another machine.

Changing only an installer download hostname does not necessarily change the server URL baked into its instructions. Select the correct address in Add node before copying its command.

Passkeys

Passkeys use the configured APP_BASE_URL hostname. A different trusted alias does not make the credential valid there. Use the configured address and a secure browser context.

Provider failures

Check whether the provider is enabled for sign-in, whether it permits registration, and whether a new account awaits approval. Registration and existing-account sign-in are separate policies.

For OIDC, verify issuer discovery, credentials, and the callback for the provider's first configured entry origin. Keep an existing admin session while testing changes.

Next steps

Read Addresses and trusted origins and Sign-in providers. Use Account recovery only when credential recovery is required.

Edit on GitHub

Last updated on

On this page