Users and sessions¶
Create the accounts your crew signs in with, and see or end the sign-ins on record.
Administrators only
Everything on this page lives behind the Admin tab, which only appears for accounts with the Admin role. If you are signed in as an Operator, the tab is not in your top bar at all — and the command palette's Go to Admin still takes you to the panel, but all it says is Admin access required.
Opening the Admin tab¶
Click Admin in the top bar, to the right of Monitor. On a narrow window the tab strip collapses into the menu button — Admin is in there with the other tabs.
Inside, a two-way switch at the top selects Users or Sessions.
Users¶
The Users view lists every account on this machine.
| Column | Shows |
|---|---|
| Username | What the person types to sign in |
| Display Name | The name shown to collaborators — on avatars, name pills and lock indicators. A dash means none is set. |
| Role | admin or operator |
| Last Login | When that account last signed in, or a dash if it never has |
| Actions | Edit and Delete |
An empty table reads No users found.
Roles¶
There are two.
| Role | Can |
|---|---|
| Operator | Everything involved in building and running a show — media, scene, alignment, masking, playback, monitoring |
| Admin | All of the above, plus the Admin tab: creating, editing and deleting accounts, and revoking sessions |
Operator is the right default. Give someone Admin only if they need to manage accounts.
Add an account¶
- Click Add User. The Create User dialog opens.
- Fill in Username. This is what they type at sign-in, and it must not match an existing account.
- Fill in Password. It is required for a new account.
- Optionally fill in Display Name. This is what the rest of the crew sees, so a first name is usually better than a login handle. Leave it blank and your collaborators see the username instead.
- Choose a Role — Operator or Admin.
- Click Create User.
The dialog closes and the new account appears in the table.
Note
If the dialog stays open and the table does not change, the username is already taken. Usernames must be unique. Change it and submit again.
Edit an account¶
Click Edit on the account's row. The dialog opens as Edit User, pre-filled.
- Username, Display Name and Role can all be changed.
- Password reads Password (leave blank to keep current). Type a new one only to reset it; leave it empty and the existing password is untouched.
Click Save Changes to apply, or Cancel to discard.
Tip
There is no "forgot password" flow — the person cannot reset it themselves. When someone is locked out, edit their account, set a new password, and tell them what it is.
Delete an account¶
Click Delete on the row and confirm Delete User — Are you sure you want to delete this user?
Deleting an account also ends any session it has open, so the credentials stop working immediately. Two guards apply:
- The last remaining Admin account cannot be deleted, so nobody can lock everyone out of the Admin tab.
- Deletion is not undoable. To take away access temporarily, change the password instead.
Sessions¶
The Sessions view lists every sign-in still on record — at most one row per account, since an account can only be signed in one place at a time.
| Column | Shows |
|---|---|
| User | The username. Your own row is highlighted and carries a You badge. |
| Role | admin or operator |
| Created | When that sign-in happened |
| Expires In | What is left before it lapses — 13d 4h while it is days away, 4h 20m in the last day, then plain minutes, and Expired once the deadline passes |
| Actions | Revoke |
Below the table: Sessions expire automatically after 2 weeks. The two weeks are counted from the sign-in and are not extended by using Moonshine, so a machine left signed in eventually lands back on the sign-in screen. Signing in again starts a fresh two weeks.
Click Refresh to re-read the list. Rows disappear on their own when a session is revoked, but a sign-in that happens while you are looking at the table only shows up after a refresh.
A sign-in stays on this list until it is revoked or expires — closing the browser does not remove it. If there are none at all, the table reads No active sessions.
Revoke a session¶
Click Revoke on the row. The session stops being valid at once: that window stops receiving updates, nothing it sends is accepted any more, and reloading it lands on the sign-in screen. Any lock it was holding lapses within a few minutes, because a revoked session can no longer keep its claims alive.
Revoking your own session asks first — Revoke Session — This will log you out. Are you sure? Revoking someone else's takes effect at once, with no confirmation, so read the row before you click.
Reach for this when:
- A device was left signed in somewhere you no longer control.
- Someone has gone home still holding a projector, and closing their browser is not an option.
- You want to clear out a stale sign-in before the show.
Tip
Revoking is not the quickest way to free a stuck lock. Closing the holder's browser window releases their claims straight away; revoking their session takes a few minutes to have the same effect. See Locks.
Note
Revoking does not delete or disable the account — the person can sign straight back in with the same credentials. Change or remove the account if you need to actually stop them.
Related pages¶
- Presence — the display names and colors these accounts appear as
- Locks — what a revoked session releases
- First launch — signing in for the first time