Inside the VPSNine panel
The account side of my.vpsnine.com is built. Sign-up, two-factor, SSH keys, API tokens, sessions and an activity log, and why it looks like a terminal.
There's no server to order yet. There is a panel, though, and it opens at my.vpsnine.com with launch.
We wanted accounts finished before servers. This is what you'll find when it opens.
It looks like a terminal
Most people who rent a VPS spend their day in one, so the panel looks like one too. Headings, buttons and tables are set in a monospace font. Each box on a page has a title set like a shell command. That's decoration, not documentation: the commands vps9 really takes are in Install the vps9 command-line tool. Go to a page that doesn't exist and you get cd: /whatever: No such file or directory.
Every form is a plain HTML form that posts to the server, so the panel works with JavaScript turned off. The one exception is the serial console, which runs a terminal in the page. The panel has no analytics, and it sends a strict content security policy, which mostly means a browser won't run scripts we didn't put there.
Signing up and logging in
Sign-up wants an email and a password of at least 12 characters. We check new passwords against a list of common ones, and refuse your own email address as a password. That comes up more often than you'd think.
Then we send a confirmation link. Opening it doesn't confirm anything by itself; you have to press a Verify email button. That's because many corporate mail systems open every link in every email to scan it, and they'd burn the link before you ever saw it. One extra click felt like a fair price. The button also only works while you're logged in to the account the link was sent for, so whoever confirms the address has to know the password too. Otherwise someone could sign up with your address and wait for you to press the link out of habit.
Password resets work the same way, and the links last an hour.
Sign-up, "forgot password" and resend all give the same answer, at the same speed, whether or not the email address has an account.
Two-factor
You can turn on two-factor with any normal authenticator app. When you do, you get ten recovery codes, shown exactly once. Each one gets you in a single time if your phone dies.
We store those codes so that even a copy of our database wouldn't let someone work them out. Wrong 2FA codes are rate-limited per login and per account. And we email you whenever 2FA is switched on or off, in case it wasn't you.
Sessions and the activity log
The account page lists every browser that's logged in, with its rough device, address and when it was last seen. You can sign out any one of them, or press sign out everywhere else. Changing your password does that for you.
There's also an activity log of the last 50 security events: logins, failed logins, password changes, 2FA changes, keys and tokens added or removed. If it's all your own logins, nothing's wrong.
SSH keys and API tokens
You can save your SSH public keys now (Ed25519, ECDSA, or RSA of 2048 bits or more), so they're ready to drop onto your first server. If you paste a private key by mistake, we refuse it and don't echo it back to the page.
API tokens are read-only or read-write, can expire after 30 days, 90 days or a year (or never, if you insist), and are shown once. We only keep a hash. Every new token triggers an email.
When this post went up, the API covered only your account and SSH keys. It now covers servers, firewalls, snapshots, reverse DNS and invoices as well. The API quickstart has curl examples.
Servers
The server side has been built since: ordering and billing, a serial console in the browser, a firewall screen, snapshots, reverse DNS, support tickets and the vps9 CLI. Until orders open, the Servers page still says "No servers yet. Orders open at launch."