# Quick start

> Your first 15 minutes with ZoPanel: sign in, secure the admin login, give the panel a trusted domain, then create a package, an account and a website.

Source: https://zopanel.net/docs/quick-start  
Updated: 2026-10-07

This guide takes you from a freshly installed server to a first hosted website. It assumes the installer has finished and printed the panel URL and admin password (see [Install ZoPanel](/docs/install)).

## 1. Sign in

1. Open `https://YOUR-SERVER-IP:8888` in your browser.
2. The panel uses a self-signed certificate until you set a panel domain, so the browser shows a warning. Continue to the site.
3. Sign in with the username (`admin` unless you chose another) and the password printed by the installer.

If you lost the password, reset it on the server:

```bash
zopanel ctl reset-password admin
```

## 2. Secure the administrator login

Open **My account** from the user menu at the top right.

### Change the password

Under **Change password**, enter the current password and a new one of at least 8 characters, then click **Update password**.

### Choose your own login name

Bots try `admin` first. Under **Login name**, enter a hard-to-guess name and click **Change login name**. Use the new name the next time you sign in.

### Turn on two-factor authentication

1. Under **Two-factor authentication**, click **Enable 2FA**.
2. Scan the QR code with Google Authenticator, Authy, 1Password or a similar app.
3. Enter the 6-digit code and click **Verify & enable**.
4. Save the **recovery codes** somewhere safe. Each one signs you in once if you lose your phone, and they are shown only now.

If you ever lose both your phone and the recovery codes, an administrator with root access can run `zopanel ctl disable-2fa USER`.

To make 2FA mandatory for others, go to **Settings → General → Require two-factor authentication** and choose **Administrators and resellers** or **Everyone**.

## 3. Give the panel a domain and SSL

1. Create an A record for a domain such as `panel.example.com` pointing to the server's IP.
2. Go to **Settings → General**.
3. Fill in **Administrator email** (used for Let's Encrypt registration and notifications) and click **Save**. The certificate cannot be requested without it.
4. In **Panel domain & SSL**, enter the domain in **Panel domain**.
5. Click **Issue certificate**. A task requests a Let's Encrypt certificate.
6. Open the panel at `https://panel.example.com:8888`. The browser warning is gone, and the certificate renews automatically.

You can also limit who can open the panel in **Restrict panel access**; see [Panel settings](/docs/panel-settings).

## 4. Create a package

A package is a resource plan that you assign to hosting accounts. The installer created one named `Default` (10 websites, 10 databases, 10 GB disk, 1 GB RAM, one CPU core). To create your own:

1. Go to **Packages** and click **New package**.
2. Enter a **Package name**, for example `Starter`.
3. Set the limits: websites, databases, **Disk (MB)**, **CPU (%)** (100 = one full core), **RAM (MB)**, **PHP memory_limit (MB)**, **PHP workers** and the others. For most limits `0` means unlimited.
4. Turn **SFTP** on so the customer can upload files.
5. Click **Save**.

See [Packages and limits](/docs/packages-limits) for every field.

## 5. Create a hosting account

Each account gets its own Linux user, home directory, PHP and resource limits.

1. Go to **Accounts** and click **New account**.
2. Enter a **Username** (3-16 lowercase letters and digits; it cannot be changed later), an **Email** and a **Password**. The password is used for both the panel and SFTP.
3. Keep the **Role** as **Customer**. (**Reseller** needs a Pro license.)
4. Choose the **Package** you created.
5. Click **Create**. The panel shows the details to send to your customer, including the **Panel URL**.

The Free plan allows up to 3 hosting accounts, 10 websites and 10 databases on the server. See [Licensing](/docs/licensing).

## 6. Add a website

1. Point the domain's A record to the server's IP (do this first so SSL can be issued straight away).
2. Go to **Websites** and click **New website**.
3. Choose the **Owner**: the account you just created.
4. Enter the **Domain** without `http://`, for example `example.com`.
5. Choose the **Website type**: WordPress, PHP, Laravel, HTML, Node / Proxy or Git deploy.
6. Pick a **PHP version** and keep **Free SSL (Let's Encrypt)** on.
7. Click **Create website**.

For WordPress, ZoPanel creates the database and installs WordPress for you. The full walkthrough, including DNS and file uploads, is in [Your first website](/docs/first-website).

## What to do next

- Install the optional components you need (mail, DNS, WAF and more) from **Components**: see [Optional components](/docs/components).
- Set up alerts by Telegram, email or webhook in **Settings → Alerts**.
- Review the **Security Center** on the **Security** page and the suggestions on the **Tuning** page; many come with a one-click fix.
- Turn on **Automatic updates** in **Settings → Updates**: see [Updating ZoPanel](/docs/updating).
