Shared Accounts
Introduction
A shared account lets other people work in your Hippius account, each signed in with their own login. You invite them by email and choose, product by product, what each one may do: your virtual machines, databases, Kubernetes clusters, GitHub Actions runners and S3.
The account stays yours. Everything a member creates belongs to your account and is paid from your balance, and the compute they launch counts against your compute quotas. Members keep their own account next to yours, and switch between the two from the profile menu.
Open it from the sidebar: Team → Members.
A shared account covers compute and S3 only. To work on files together, use Shared Drives: they have their own invitations and roles. In another account, Drive, Hub, Wallet and Referrals are hidden.
What a member can do
Each member gets a level per product. A higher level includes the lower ones.
| Level | What it allows |
|---|---|
| Viewer | Read only: see the resources, their status and their settings. |
| Operator | Act on what exists: start, stop and reboot VMs, open the browser terminal, turn VM backups on or off, restart a database, cancel or resume a Kubernetes operation, upload and delete S3 objects. |
| Admin | Create, delete and resize, restore from a backup, firewall rules, public IPv4 and published ports, Kubernetes worker pools and nodes, S3 buckets, bucket access and access keys, runner settings and the GitHub link. |
The products you can grant are Virtual Machines, Databases, Kubernetes, Runners and S3. Two groups set several at once:
- All compute: Virtual Machines, Databases, Kubernetes and Runners.
- All storage: S3.
When a group and a product both apply, the higher level wins. A product left at No access is hidden from the member's sidebar.
Two permissions sit next to the levels:
| Permission | What it allows |
|---|---|
| Manage the team | Invite, change and remove members, revoke invitations, and read the audit trail. A manager can only give access they hold themselves, can't change their own access, and can't change or remove anyone whose access goes beyond theirs. |
| Billing | Read the account's balance, invoices, compute usage and S3 plan history. Payments stay with the owner. |
What only the owner can do
Some actions stay with the owner, whatever a member's level:
- Create a Kubernetes cluster. A cluster is bound to its creator's key file, so one created by a member couldn't be opened by the owner.
- Open a cluster's kubeconfig and backups, and the node operations signed with the cluster's key file: adding or replacing nodes and accepting data loss. A Kubernetes admin can still scale a pool down, remove a node, cancel an operation and delete the cluster.
- Add money to the balance. A member is told to ask the owner.
- Buy, change or cancel an S3 or Drive plan.
- Manage the team, unless the owner gives that permission to a member. Nobody can remove the owner or change the owner's access.
A database's password, certificates and backup key are shown once, to whoever creates or restores it. If a member with Databases Admin creates a database, the member gets the credentials, not the owner. Store them where the team can find them.
Invite a member
- Go to Team → Members and click Invite member.
- Enter the person's email.
- Pick a level for each product or group, and tick Manage the team or Billing if they need it. The line at the bottom of the dialog sums up the access.
- Click Send invitation.
The person gets an email with a link. The invitation:
- is valid for 7 days;
- works once;
- is replaced if you invite the same address again: the earlier link stops working.
If the email couldn't be sent, the console says so: revoke the invitation and try again later.
Pending invitations are listed under Pending invitations, with their access and expiry date. Click Revoke to cancel one. By default, an account can have up to 50 members and pending invitations together.
Accept an invitation
Open the link in the email. The page shows who invited you, to which account, and the access you would get. Sign in if you aren't, then click Accept invitation.
The invitation is for one address. Accepting it checks that this address is one of the verified email addresses of the account you are signed in with. Signing in with Google, GitHub or Apple verifies the email address of that login.
- The address doesn't match. The page says the invitation was sent to another address. Click Sign in with another account and use the one it was sent to.
- Your account has no verified email, for example a 12-word access key login. The page asks you to confirm that the invitation was meant for you. Click Accept anyway only if it was. The audit trail records that it was accepted without an email.
Once you have joined, choose Open this account to switch to it now, or Stay in your own account.
A link that was already used, withdrawn or older than 7 days no longer works. Ask the person who invited you for a new one.
Switch accounts
Open the profile menu. Under Accounts, Your account comes first, then each account you belong to, with your product access in it. A check mark shows where you are.
While you work in another account:
- the profile card says In followed by the account's name;
- the Overview page lists what you may do in that account, with Back to your account;
- the sidebar only shows the products you have access to, and Billing and Compute Usage only with the Billing permission;
- everything you open, create and change is the account's, and each change is recorded in its audit trail.
A page that belongs to your own account, such as Drive, says Not part of this account. Switch back from the profile menu to open it.
When you launch a VM in another account with Virtual Machines Admin, you can pick your own SSH keys or the owner's, listed as Keys of the account.
Change or remove a member
On Team → Members, each member is listed with their access and who added them.
- Click Edit to change their access, then Save access.
- Click Remove to take every access away. They are moved back to their own account.
Removing a member doesn't delete anything they created: it belongs to the account.
Leave an account
A member can leave at any time:
- in the account, on Team → Members, click Leave this account;
- or, from your own account, under Accounts you belong to, click Leave.
Only a new invitation can bring your access back.
Audit trail
The Audit trail section of Team → Members lists, newest first, every change a member makes in the account and every team change, with the date, who did it, the action and, when there is one, what it was done to and the IP address. The owner and members with Manage the team can read it.
It records:
- each successful change a member makes, such as stopping a VM or creating a bucket. What was sent is never recorded;
- a member opening a VM's browser terminal;
- a member creating an S3 upload link;
- invitations created and revoked, members joining, changed, removed or leaving.
The owner's own product actions aren't recorded here.
Billing and quotas
- The owner pays. What a member launches is billed to the account, by the hour, from the owner's balance. See Compute billing.
- The owner's quotas apply. A member's launches count against the account's quotas and its 24-hour balance requirement, not the member's own.
- Alerts go to the owner. Low balance, unpaid usage and VM emails are sent to the owner only.
For developers: the API
The account API acts on your own account by default. To act in an account you are a member of, send its id in the X-Hippius-Account header, with your own token:
curl https://api.hippius.com/api/compute/vms/ \
-H "Authorization: Token YOUR_TOKEN" \
-H "X-Hippius-Account: acct_0a1b2c3d4e5f60718293"
- Account ids.
GET /api/accounts/lists your own account first, then each account you belong to, with itsid(acct_followed by 20 hex characters) and your access in it (effective, the level per product). This route ignores the header. - No header, or your own id: you act as yourself, exactly as before.
- Routes that can't be used in another account refuse the header with
account_scope_unsupported. This includes Drive and top-ups. Personal routes, such as/api/ssh-keys/, ignore it. - The VM terminal WebSocket takes the account as an
account=query parameter next totoken=. A refusal closes the socket with code4003. - Switching accounts changes what the same URLs return. Clear any cached responses.
A refusal is a 403 with a sentence in error and a code in code:
code | Meaning |
|---|---|
not_a_member | You aren't (or are no longer) a member of that account, or it doesn't exist. Drop the header. |
account_scope_unsupported | This route can't be used in another account. Don't send the header to it. |
owner_only | Only the owner can do this. |
insufficient_grant | Your level is too low. scope and level say what is needed. |
team_management_required | Needs the Manage the team permission. |
billing_required | Needs the Billing permission. |
The team itself is managed under /api/accounts/: members/, invites/ and audit/. The routes and their fields are in the interactive API docs.
Where to next
- Compute: what members can run in the account.
- Compute billing and quotas: what the account pays for.
- Shared Drives: share files in Drive.