Concepts

Workspaces, roles & keys

Organizations, members, invitations, API keys and scopes.

Workspaces

Everything — inboxes, labels, webhooks, keys — belongs to a workspace (organization). Users can belong to several and switch with the workspace picker or ⌘K.

New sign-ups get their own workspace automatically. Invited users join the inviting workspace instead.

Roles

RoleCan
ownerEverything, including deleting the workspace
adminManage members, domains, labels, webhooks and API keys
memberUse inboxes: create, read, label, send (if enabled)

There is no separate instance-admin role. A self-hosted instance belongs to one team: owners and admins also run its setup (Amazon SES). On Squadmail Cloud the plan of each workspace decides its limits.

Sign-up modes

SIGNUP_MODE controls who may create accounts:

  • open — anyone (use Turnstile + email verification on public instances)
  • invite — only invited email addresses (default)
  • closed — nobody; admins add people via invitations

The very first account can always sign up.

Invitations

Settings → Members → Invite. If Amazon SES and MAIL_FROM are configured the invite is emailed; otherwise copy the invite link.

API keys

Keys look like sqm_…, are shown once, and are stored as SHA-256 hashes. Each key belongs to one workspace — no extra org header needed.

ScopeAllows
readList and read inboxes, emails, labels, stats; wait and SSE
writeCreate, update and delete inboxes and emails; manual labels
sendSend email from inboxes
adminManage keys, labels and webhooks

Key types (agent, ci, personal) are informational and help the dashboard group activity.

Two-factor authentication

Account & security → Set up 2FA (TOTP). Backup codes are shown once.

Edit this page on GitHub