Users
User management is available to Administrators only. Navigate to Workspace → Access → Users.
Inviting a User
- Click + in the Users list
- Enter the user's email address
- Select a role (default: User)
- Submit — Lakehousecat sends an activation email with a time-limited link
The invitee clicks the activation link, sets a password, and gains access based on their assigned role.
User States
| State | Description |
|---|---|
| Pending | Invited but not yet activated |
| Active | Account activated, access granted based on role |
Account Settings
Each user can manage their own account from Profile → Account:
Profile
- Display name — shown in the UI
- Avatar — upload photo or use auto-generated initials
Security
- Password Change — update password at any time
- Multi-Factor Authentication (MFA) — TOTP-based; enabled via a toggle in the Security section
Setting up MFA
- Go to Profile → Account → Security and enable the MFA toggle
- Scan the QR code with an authenticator app (Google Authenticator, Authy, etc.) — or enter the secret key manually
- Save the provided backup codes in a secure location
- Enter the 6-digit code from the app to confirm and activate
When MFA is enabled, backup codes can be regenerated at any time from the same section. Each code is single-use.
To disable MFA, toggle it off and confirm with a 6-digit code or backup code.
Locked out of MFA?
If you lose both your authenticator device and your backup codes, /mfa/disable can't help —
it needs a code from exactly the device/codes you no longer have.
For a regular user or a second Administrator, an Administrator resets MFA on your behalf:
lhc users mfa-reset <your-user-id>
If you are the initial Administrator — the account created automatically at deployment — and there is no second Administrator to do this for you (the common case on the Free tier, which allows only one seat), the same command works against your own account when run with the instance's API key rather than a browser session:
lhc configure set --api-key <the instance's LHC_API_KEY>
lhc users mfa-reset <your-own-user-id>
This is deliberately narrow: it only ever applies to the initial admin's own account, and only when authenticated with the instance API key — not a personal one you generated yourself, and not while signed in through the UI. Every use is recorded in the audit log.
API Keys
- Session Token (JWT) — short-lived token that expires with the session; used for API calls
- API Key — persistent key for programmatic access; can be generated and regenerated
Removing a User
Click the delete icon next to a user. The last remaining Administrator cannot be deleted.
The Initial Administrator Is Protected
The initial Administrator — the account created automatically at deployment — cannot be deleted, have its role changed, or be deactivated, even by a second Administrator. This protects against locking every Admin out of the instance, which is unrecoverable on the Free tier's single-seat limit.
When you view the initial Administrator's account, the UI disables these three actions and explains why, instead of letting you attempt them and fail with a permission error.