← Help · updated 2026-09-28

Team members: invites, roles and access

Dashboard → Members is owner-only — a Member doesn't see the Members link in the nav, and the page 404s if they open the URL directly. Only an account's owner(s) can invite, remove, or change anyone's role.

Inviting someone

Enter an email and pick a role (Member or Owner), then Send invite. The invite is emailed as a link and is only good for 7 days; it can only be accepted by someone signed in with that exact email (case-insensitive) and a verified email address — signing in as a different account doesn't let you claim someone else's invite. An account can have at most 5 members total, owners included — both sending a new invite and accepting one are refused past that limit. A pending invite can be revoked from this page any time before it's accepted.

Accepting an invite

The link opens /invite?token=.... Not signed in yet: it prompts you to log in or sign up first, then re-open the same link. Signed in: one Accept invite click adds you to that account at the role the invite was sent with, and switches your session into it. If you're already a member of other accounts, an account switcher appears in the nav once you belong to more than one.

Logging in opens the account you last switched to or joined in this browser, as long as you're still a member of it. Otherwise — a different browser or device, or you've been removed since — you land in your own account. If that account has no servers, its Servers page lists the other accounts you belong to, each with a Switch button.

When you belong to more than one account, the pages that act on the active one — authorizing the CLI, API keys, Wallet and New server — name that account at the top and offer a switch, because a key, a payment or a new server goes to whichever account is active. Opening one of those pages from a link while signed out (the CLI login, a link in an email or on the site) always starts in your own account.

What a Member can and can't do

The panel has two whole-account roles — Owner and Member — and both reach every server on the account. The difference is enforced on the server, by a role check inside each RPC, and reinforced in the panel by the four pages (Wallet, Members, API keys, CLI login) that 404 outright for a Member.

A Member can: create, start, stop, restart and resize a server's RAM; everything under Files, Console, Players (whitelist, op, ban, kick), Mods/Plugins, Backups, Schedules and Database; link and unlink a Discord server; and attach a server to, or detach it from, an existing network.

A Member cannot: delete a server; switch a server's plan between Flat and Metered; switch, reset or delete a world; enable, rotate or disable SFTP; create or delete a network, or change its auth mode; do anything on the Wallet page (top up, auto top-up, spend cap — the page isn't even visible to them); manage members or invites; create or revoke API keys; or approve a CLI device-code login.

There's a third role, limited, for someone who should reach only specific servers rather than the whole account — see Give someone access to one server.

Worth knowing: the panel doesn't yet hide every control a Member is refused. Only Delete server and the Flat/Metered plan switch are removed from their view; the Worlds tab and the SFTP controls are still rendered, and pressing one of those fails with a permission error instead of never being offered. The API is what decides in every case — the button being visible is not permission.

And regardless of any of this: a Member can create servers and run up usage against the account's wallet even though they can never see the wallet itself.

Revoking access

Remove on a member's row removes them from the account entirely — they lose access to every server on it immediately. Make member / Make owner toggles a role in place. The panel hides both controls on your own row (so you can't casually remove or demote yourself by mistake) and on the last remaining owner's row. The server enforces two rules on its own: the last owner can't be removed or demoted, so an account can never end up with zero owners; and neither can the account holder (below). For anyone else, self-removal is blocked only in the panel's own UI, not on the server.

The account holder — the person who signed up and created the account — is protected: their row is labelled account holder and shows no Remove or role controls (if the holder was demoted before this protection existed, the row offers only Make owner, to put them back), and the server refuses to remove them or change their role from Owner, whoever asks (including the holder themselves). Other owners can still remove or demote each other, and the holder can remove any co-owner. Without this, a co-owner removing the holder would leave the holder locked out of their own account, because it's the one signing in falls back to.

Recent changes at the bottom of the page lists who removed whom, role changes, changes to a limited member's servers, and accepted invites, each with its time. Sending or revoking an invite isn't listed there. The list starts when this history was added to TrueTick — anything earlier wasn't recorded, so an empty list doesn't mean nothing ever changed. People are shown by their current email address, including someone who has since left the account.

Troubleshooting

"I get kicked every time" / the owner has to re-invite me. First open the account menu (top right): if Switch account lists the account, you still have access — you're just looking at your own account. Pick it there. If it isn't listed, you were removed; the owner can see who did it under Members → Recent changes. With the Owner role, anyone else who's an owner can remove you — Member is enough to run the servers.

"invite is for a different email." You accepted the link while signed into an account whose email doesn't match who the invite was sent to — log in as that email (or verify it) and try the link again.

Invite link says it's expired or already used. Invites expire after 7 days and can only be accepted once; ask the owner to revoke the old one and send a fresh invite.

"cannot remove the account holder" / "cannot demote the account holder" / "this is your own account". The person you tried to change signed up for this account, and it can't be taken from them (see Revoking access). The last message means someone invited you into your own account; there's nothing to accept, since you're already its owner.

Can't invite anyone new / can't accept an invite. The account is at its 5-member cap, owner included — remove someone first, or the invite is refused with "member limit reached" either way.

A team member can't see Wallet, Members, or API keys. Expected for the Member role — those pages are owner-only and simply aren't in their nav.

In the panel: Dashboard → Members