Production accounts and private workspaces
Local work and production access
| Installation | Access |
|---|---|
| Local (QUAY_ENV=local, the default) | Opens the editors directly; no registration or approval. |
| Production (QUAY_ENV=production) | Public 3D home; verified and approved accounts enter the editors. |
The server configuration chooses the mode. A visitor cannot enable local access with a URL parameter. Production authorization protects the API as well as the interface.
Register and enter the studio
- Choose Request access on the public homepage. Enter your name, email and a password of 15–128 characters.
- Open the verification email and confirm the address. The verification link is single-use and expires after 24 hours.
- Sign in to inspect your account status. You can resend verification if needed.
- Wait for administrator approval. Refresh the status or sign in again after approval. Only a verified, approved account can open the editors.
Approval changes revoke existing sessions, so a new login may be required. Each member receives a private project/resource workspace. Knowing another user’s project or asset UUID does not grant access. Shared material and library scope refer to resources within a workspace; they are not invitations to other accounts.
Recover or change a password
Choose Password forgotten, request a link and check your mailbox and spam folder. Responses are deliberately generic whether or not an address is registered. Reset links expire after one hour and can be used once. Resetting a password revokes previous sessions but does not bypass approval or suspension.
From Account, changing a password requires the current one. Sign in again afterward. Logout clears the editor’s private browser cache; save durable work before leaving. Expired or suspended sessions cannot continue calling protected APIs.
Approve, suspend or reject users
The reserved initial superadministrator is ricardo@ricardopiana.com. It is initialized on the trusted server, never claimed by public signup. There is no default password.
Open Account → User management, search by name/email and inspect verification status. Approve only after email verification. Suspend temporarily or reject an account to revoke access; stored projects remain intact. The superadministrator cannot suspend itself through these controls.
Account administration does not provide a project browser for other users’ private work. Server filesystem administrators can still read stored files: this is application isolation, not per-user encryption. The existing root data belongs to the initial superadministrator.
Account email and website contact are separate
Account verification and recovery use the server SMTP settings. A RAMS website contact form uses its explicitly configured endpoint. Configure and test both separately. No password or provider key belongs in a browser build, screenshot or .qway project.
See the production installation guide for HTTPS, SMTP, trusted bootstrap, backups and updates.