Inside the VPSNine panel

The account side of my.vpsnine.com is built. Sign-up, two-factor, SSH keys, API tokens, sessions and an activity log, and why it looks like a terminal.

There's no server to order yet. There is a panel, though, and it opens at my.vpsnine.com with launch.

We wanted accounts finished before servers. This is what you'll find when it opens.

It looks like a terminal

Most people who rent a VPS spend their day in one, so the panel looks like one too. Headings, buttons and tables are set in a monospace font. Each box on a page has a title set like a shell command. That's decoration, not documentation: the commands vps9 really takes are in Install the vps9 command-line tool. Go to a page that doesn't exist and you get cd: /whatever: No such file or directory.

Every form is a plain HTML form that posts to the server, so the panel works with JavaScript turned off. The one exception is the serial console, which runs a terminal in the page. The panel has no analytics, and it sends a strict content security policy, which mostly means a browser won't run scripts we didn't put there.

Signing up and logging in

Sign-up wants an email and a password of at least 12 characters. We check new passwords against a list of common ones, and refuse your own email address as a password. That comes up more often than you'd think.

Then we send a confirmation link. Opening it doesn't confirm anything by itself; you have to press a Verify email button. That's because many corporate mail systems open every link in every email to scan it, and they'd burn the link before you ever saw it. One extra click felt like a fair price. The button also only works while you're logged in to the account the link was sent for, so whoever confirms the address has to know the password too. Otherwise someone could sign up with your address and wait for you to press the link out of habit.

Password resets work the same way, and the links last an hour.

Sign-up, "forgot password" and resend all give the same answer, at the same speed, whether or not the email address has an account.

Two-factor

You can turn on two-factor with any normal authenticator app. When you do, you get ten recovery codes, shown exactly once. Each one gets you in a single time if your phone dies.

We store those codes so that even a copy of our database wouldn't let someone work them out. Wrong 2FA codes are rate-limited per login and per account. And we email you whenever 2FA is switched on or off, in case it wasn't you.

Sessions and the activity log

The account page lists every browser that's logged in, with its rough device, address and when it was last seen. You can sign out any one of them, or press sign out everywhere else. Changing your password does that for you.

There's also an activity log of the last 50 security events: logins, failed logins, password changes, 2FA changes, keys and tokens added or removed. If it's all your own logins, nothing's wrong.

SSH keys and API tokens

You can save your SSH public keys now (Ed25519, ECDSA, or RSA of 2048 bits or more), so they're ready to drop onto your first server. If you paste a private key by mistake, we refuse it and don't echo it back to the page.

API tokens are read-only or read-write, can expire after 30 days, 90 days or a year (or never, if you insist), and are shown once. We only keep a hash. Every new token triggers an email.

When this post went up, the API covered only your account and SSH keys. It now covers servers, firewalls, snapshots, reverse DNS and invoices as well. The API quickstart has curl examples.

Servers

The server side has been built since: ordering and billing, a serial console in the browser, a firewall screen, snapshots, reverse DNS, support tickets and the vps9 CLI. Until orders open, the Servers page still says "No servers yet. Orders open at launch."

Be first when orders open

Join the waitlist and we'll send you one email when VPSNine launches. Pick a plan if you already know which one you want, and we'll size the first servers around it.