Timberdocs

Using Timber

Users & roles

Timber has accounts for the people who run the site — not for members or subscribers. The public site has no sign-up and no visitor accounts. Everyone signs in at /padmin with an email and password.

The three roles#

AdministratorEditorRead-only
Dashboard✅ full✅ their posts✅ full (view)
Posts — write, edit, publish, schedule, delete✅✅👁 view
Media — upload and add alt text✅✅👁 view
Delete media files✅——
Pages, Playground (designs), Forms, Menus, Blocks✅—👁 view
Design, SEO, Privacy, Site settings, Redirects✅—👁 view
Emails, Integrations, Data, Files, Code editor, Migrator✅——
Users — add, change roles, disable, delete✅——
Their own profile and password✅✅✅
  • Administrator can do everything.
  • Editor can only manage posts (and upload the images those posts need). They can't touch pages, design, forms, settings or other people's accounts.
  • Read-only can look around — dashboard, posts, pages, designs, form submissions, SEO and other settings screens — but every change is switched off, both in the screens and on the server. Perfect for a stakeholder, an auditor or a client who wants to see but not touch. They can't open screens that expose raw data or secrets (Emails, Integrations, Data, Files, Code editor).

Managing users#

Admin → Users (also under Admin Tools):

  • Add user: name, email, role and a starting password. Use Generate a strong password, then share it with them securely. They can change it from Your profile.
  • Edit: change name, email or role, set a new password, or disable the account to block sign-in without deleting it.
  • Delete: removes the account.

Safeguards#

  • There is always at least one active administrator: you can't demote, disable or delete the last one.
  • You can't disable or delete yourself.
  • Emails are unique.
  • Changing someone's password (or yours) signs that account out everywhere else. Disabling an account ends its sessions immediately.

Signing in#

  • Email + password at /padmin, with the same throttling as before: 5 wrong tries from an IP locks sign-in for 10 minutes.
  • Sessions last up to 8 hours idle or 7 days total.
  • Your profile (bottom of the sidebar) lets everyone change their name, email and password.

Upgrading from a single-passcode install#

If you had a site from before accounts existed, nothing breaks. The first time Timber runs it converts your old passcode into one Administrator account: the email is your admin/site email from the settings, and the password is your existing passcode. Sign in with that, then add colleagues.

Locked out?#

On the server:

php _dev/reset-password.php "new password"                       # first active administrator
php _dev/reset-password.php editor@example.com "new password"    # a specific account
php _dev/reset-password.php --add-admin you@example.com "password"   # create an administrator

What roles don't cover#

Roles are about the admin. They don't (yet) support per-page permissions, "authors can only edit their own posts", approval workflows or an audit log. See the roadmap.

Timber is open source. Built by indies, for indies. © 2026