Dashboard and deployment
Manage users, devices and access, and hand out installers that join your server.
Open your server's address in a browser and sign in. Administrators see every page. Other users see Devices, Add computers (for groups they manage) and Account.
Accounts: personal or organization
Everything on a server belongs to an account: its users, groups, computers, installers and audit log. Accounts cannot see each other. When you create an account you choose its kind:
| Kind | For | How access works |
|---|---|---|
| Personal | One person and their own computers | You reach every computer in the account. Groups only organise them. Per computer you decide whether it can be connected to and whether it can connect to your other computers. |
| Organization | Several people | Its admins add users, put computers in groups and grant each user a level on groups. Users sign in with their own username in the app and reach only the computers granted to them. The same two switches apply per computer. |
The first account on a new server is created in the dashboard (or with humble-server create-admin). Further accounts can be
created only on a server started with --open-signup, such as a public one; on your own server, admins add users instead.
A server set up before accounts existed becomes one organization account when it is upgraded.
In Account, admins can rename the account and turn off Allow connecting from other computers: then signing in only lets you connect from computers that were added to the account (the app proves which computer it runs on with that computer's own key).
A typical first setup
- Create a group on Groups, for example "Office".
- Add each computer: sign in on the app's Computers page and press Add this computer, or create an installer for the group on Add computers and run it on each computer.
- Add your colleagues on Users.
- On Access, grant each colleague a level on the group.
- Everyone signs in on the Computers page of the desktop app and connects.
Devices
Devices are listed by group with a green dot when online. Use the search box to filter by name, ID or system.
- Connect opens the desktop app on your computer and starts a session. The desktop app must be installed and signed in to this server.
- Details shows the system, processor, memory, uptime, logged-in user and last address. If you manage the device you can rename it, move it to another group, remove it from the server, and set its two switches: Can be connected to (off: nobody can connect to it) and Can connect to other computers (off: it can still be reached, but signing in on it does not let anyone connect from it to the account's other computers).
- The Connect to a device box at the top takes any 9-digit ID.
Groups
A group is a set of devices that share the same access rules. A device is in one group at a time. Deleting a group does not delete its devices; they become ungrouped, and only administrators can reach ungrouped devices without a password.
Users
There are two roles:
- admin can do everything and can connect to every enrolled device.
- user sees and reaches only the groups they have been granted.
From this page you can add users, change a role, set a new password for someone, or delete a user. Setting a new password signs that user out everywhere. A personal account has one user and no Users or Access pages.
Access
A grant gives one user a level on one group.
| Level | The user can |
|---|---|
| View only | See the screen. No mouse, keyboard, files or clipboard. |
| Control | Full remote control, file transfer and clipboard. |
| Manage | Everything in Control, plus rename, move and remove the group's devices, and create installers for the group. |
A user with a grant connects without a password. A user without one can still connect to a device if they know the password shown on its screen, exactly as with a direct connection.
Deploy: installers that join your server
An installer carries a code that enrolls the computer into a group. Create one on the Deploy page:
- Give it a label and pick the target group.
- Optionally limit how many computers may use it, and when it expires. The default expiry is 168 hours (one week).
- Press Create installer. The page then shows each way to use it, with copy buttons.
| Method | For | What the person does |
|---|---|---|
Windows installer (.exe) | Non-technical users | Downloads the file, double-clicks it and approves the Windows prompt. It installs the app and the background service and enrolls the computer. |
| PowerShell command | Windows administrators | Pastes one line into an Administrator PowerShell window. |
| Terminal command | Ubuntu, Arch, Omarchy and macOS | Pastes one line into a terminal as their normal user. It asks for the sudo password, installs the app and the background service, and enrolls the computer. |
| MSI property | Group Policy, Intune and similar tools | msiexec /i humble.msi /qn ENROLL=<code> |
| Existing install | A computer that already has Humble | Runs humble enroll <code>, or pastes the code under Settings → Orchestration server and presses Enroll. |
After enrolling, the computer appears on the Devices page within a few seconds.
Anyone who has an installer or its code can add a computer to that group until it expires, reaches its limit or is revoked. Share installers only with people you trust, prefer a limit and an expiry, and press Revoke when a rollout is finished. Revoking does not remove computers that are already enrolled.
The Windows installer, PowerShell and terminal methods need the app binaries on the server. See Enable installer generation.
Quick support: an ID without enrolling
For a one-off session with someone who is not part of your organisation:
- They open Settings → Orchestration server in the desktop app, type your server's address and press Get ID.
- Their main page now shows a 9-digit ID and a password. They read both out to you.
- You sign in on your Computers page, type the ID, and enter the password when asked.
Quick-support devices belong to no account and always require their password, even for administrators. Anyone can reach one
with its ID and password, without an account; the server limits such attempts per address and per device, and the device pauses
password sessions after five wrong passwords in a minute. This is what the Humble Support app uses. Turn the feature off with
--adhoc false on the server.
Account: password and two-factor sign-in
- Change password needs your current password.
- Two-factor sign-in: press Set up 2FA, add the secret shown to an authenticator app, then enter the 6-digit code to confirm. From then on the dashboard and the desktop app ask for a code when you sign in.
- If someone loses their authenticator, an administrator on the server machine can run
humble-server reset-password <name> --password "…", which also turns off their two-factor sign-in.
Audit log
Administrators can see the most recent 500 events: sign-ins and failed sign-ins, enrollments, sessions started (who, to which device, from which address), and changes to users, groups, grants and installers.