Sub-users & teams
The dashboard exposes two related concepts:
Sub-users — credentials your traffic uses against the proxy gateway. Per-product.
Team members — humans with dashboard / API access. Per-account.
They serve different purposes — read both sections.
Sub-users (proxy credentials)
Sub-users are how you slice quota and isolate workloads. Each is an independent set of credentials and limits.
Create
Left nav → {Product} → Sub-users → Create sub-user.
Fill in label (your name for it, e.g.
acme-staging), then concurrent and RPS caps.Click Create.
Copy the issued name and password immediately — we show the password only once.
[screenshot: sub-user creation success modal showing one-time password]
Configure
Each sub-user has:
Label
Editable any time
Status
active or disabled. Disabled = all proxy requests return 403
Concurrent max
Per-product cap, ≤ plan limit
RPS max
Per-product cap, ≤ plan limit
Whitelisted IPs
See Whitelisting IPs
Sticky session count
Read-only — how many active sticky sessions
Rotate password
{Sub-user} → Reset password → new password shown once. Old keeps working for 60 seconds.
Delete
{Sub-user} → Settings → Delete. All bandwidth attribution stops; any open connections drain within 60 seconds.
Deleting a sub-user with an ISP batch bound to it requires unbinding the batch first.
Multiple sub-users per product?
Use them to segment workloads:
One per customer (if you're reselling)
One per environment (dev / staging / prod)
One per scraping target (so a noisy target doesn't impact others' quotas)
One per team
Bandwidth still pools across sub-users of the same product, but the per-sub-user concurrent and RPS caps give you isolation.
Team members (dashboard / API access)
Distinct from sub-users — these are people who log into the dashboard or issue API tokens.
Invite
Settings → Team → Invite member.
Email + role.
Send. They get an invite link valid for 7 days.
Roles
Owner
Everything, including billing changes and account deletion (one per account)
Admin
Sub-users, orders, whitelists, traffic, API tokens, team invites — no billing changes
Operator
Sub-users, orders, whitelists, traffic — no team or API token management
Viewer
Read-only on everything except billing
Billing
Read all + manage billing (invoices, payment methods, subscriptions)
You can assign multiple roles to one member (e.g. Operator + Billing).
Transfer ownership
Owner: Settings → Team → Transfer ownership → {new owner}. The new owner accepts via email; you become Admin. Useful when the founding account holder is leaving.
Single sign-on (SSO)
Enterprise plan only. Settings → SSO supports OIDC and SAML 2.0. Map IdP groups to roles in the SSO config.
Audit log
Every action a team member takes (create sub-user, place order, rotate password, change billing) appears in Settings → Audit log. Filterable by member, action type, and date.
Retained 365 days. Export to CSV from the same page.
Sub-user vs team member at a glance
What it identifies
A traffic source / credential
A human (or service account)
Used by
Proxy gateway
Dashboard + API
Has password?
Yes (one-time shown)
Email + own password
Per-product?
Yes
No (account-level)
MFA support?
n/a
Yes (TOTP)
Last updated
Was this helpful?