Skip to content

Users and sessions

Create the accounts your crew signs in with, and see or end the sign-ins on record.

Administrators only

Everything on this page lives behind the Admin tab, which only appears for accounts with the Admin role. If you are signed in as an Operator, the tab is not in your top bar at all — and the command palette's Go to Admin still takes you to the panel, but all it says is Admin access required.

Opening the Admin tab

Click Admin in the top bar, to the right of Monitor. On a narrow window the tab strip collapses into the menu button — Admin is in there with the other tabs.

Inside, a two-way switch at the top selects Users or Sessions.

Users

The Users view lists every account on this machine.

Column Shows
Username What the person types to sign in
Display Name The name shown to collaborators — on avatars, name pills and lock indicators. A dash means none is set.
Role admin or operator
Last Login When that account last signed in, or a dash if it never has
Actions Edit and Delete

An empty table reads No users found.

Roles

There are two.

Role Can
Operator Everything involved in building and running a show — media, scene, alignment, masking, playback, monitoring
Admin All of the above, plus the Admin tab: creating, editing and deleting accounts, and revoking sessions

Operator is the right default. Give someone Admin only if they need to manage accounts.

Add an account

  1. Click Add User. The Create User dialog opens.
  2. Fill in Username. This is what they type at sign-in, and it must not match an existing account.
  3. Fill in Password. It is required for a new account.
  4. Optionally fill in Display Name. This is what the rest of the crew sees, so a first name is usually better than a login handle. Leave it blank and your collaborators see the username instead.
  5. Choose a RoleOperator or Admin.
  6. Click Create User.

The dialog closes and the new account appears in the table.

Note

If the dialog stays open and the table does not change, the username is already taken. Usernames must be unique. Change it and submit again.

Edit an account

Click Edit on the account's row. The dialog opens as Edit User, pre-filled.

  • Username, Display Name and Role can all be changed.
  • Password reads Password (leave blank to keep current). Type a new one only to reset it; leave it empty and the existing password is untouched.

Click Save Changes to apply, or Cancel to discard.

Tip

There is no "forgot password" flow — the person cannot reset it themselves. When someone is locked out, edit their account, set a new password, and tell them what it is.

Delete an account

Click Delete on the row and confirm Delete UserAre you sure you want to delete this user?

Deleting an account also ends any session it has open, so the credentials stop working immediately. Two guards apply:

  • The last remaining Admin account cannot be deleted, so nobody can lock everyone out of the Admin tab.
  • Deletion is not undoable. To take away access temporarily, change the password instead.

Sessions

The Sessions view lists every sign-in still on record — at most one row per account, since an account can only be signed in one place at a time.

Column Shows
User The username. Your own row is highlighted and carries a You badge.
Role admin or operator
Created When that sign-in happened
Expires In What is left before it lapses — 13d 4h while it is days away, 4h 20m in the last day, then plain minutes, and Expired once the deadline passes
Actions Revoke

Below the table: Sessions expire automatically after 2 weeks. The two weeks are counted from the sign-in and are not extended by using Moonshine, so a machine left signed in eventually lands back on the sign-in screen. Signing in again starts a fresh two weeks.

Click Refresh to re-read the list. Rows disappear on their own when a session is revoked, but a sign-in that happens while you are looking at the table only shows up after a refresh.

A sign-in stays on this list until it is revoked or expires — closing the browser does not remove it. If there are none at all, the table reads No active sessions.

Revoke a session

Click Revoke on the row. The session stops being valid at once: that window stops receiving updates, nothing it sends is accepted any more, and reloading it lands on the sign-in screen. Any lock it was holding lapses within a few minutes, because a revoked session can no longer keep its claims alive.

Revoking your own session asks first — Revoke SessionThis will log you out. Are you sure? Revoking someone else's takes effect at once, with no confirmation, so read the row before you click.

Reach for this when:

  • A device was left signed in somewhere you no longer control.
  • Someone has gone home still holding a projector, and closing their browser is not an option.
  • You want to clear out a stale sign-in before the show.

Tip

Revoking is not the quickest way to free a stuck lock. Closing the holder's browser window releases their claims straight away; revoking their session takes a few minutes to have the same effect. See Locks.

Note

Revoking does not delete or disable the account — the person can sign straight back in with the same credentials. Change or remove the account if you need to actually stop them.

  • Presence — the display names and colors these accounts appear as
  • Locks — what a revoked session releases
  • First launch — signing in for the first time