Concepts
Workspaces, roles & keys
Organizations, members, invitations, API keys and scopes.
Workspaces
Everything — inboxes, labels, webhooks, keys — belongs to a workspace (organization). Users can belong to several and switch with the workspace picker or ⌘K.
New sign-ups get their own workspace automatically. Invited users join the inviting workspace instead.
Roles
| Role | Can |
|---|---|
owner | Everything, including deleting the workspace |
admin | Manage members, domains, labels, webhooks and API keys |
member | Use inboxes: create, read, label, send (if enabled) |
There is no separate instance-admin role. A self-hosted instance belongs to one team: owners and admins also run its setup (Amazon SES). On Squadmail Cloud the plan of each workspace decides its limits.
Sign-up modes
SIGNUP_MODE controls who may create accounts:
open— anyone (use Turnstile + email verification on public instances)invite— only invited email addresses (default)closed— nobody; admins add people via invitations
The very first account can always sign up.
Invitations
Settings → Members → Invite. If Amazon SES and MAIL_FROM are configured the invite is emailed; otherwise copy the invite link.
API keys
Keys look like sqm_…, are shown once, and are stored as SHA-256 hashes. Each key belongs to one workspace — no extra org header needed.
| Scope | Allows |
|---|---|
read | List and read inboxes, emails, labels, stats; wait and SSE |
write | Create, update and delete inboxes and emails; manual labels |
send | Send email from inboxes |
admin | Manage keys, labels and webhooks |
Key types (agent, ci, personal) are informational and help the dashboard group activity.
Two-factor authentication
Account & security → Set up 2FA (TOTP). Backup codes are shown once.