Skip to content

Users

Frameleaf supports many people on one server, each with their own library. As an administrator you manage them in the Command Center: select Settings in the sidebar, then open Users.

The list shows each account’s role, status, number of items and Storage used / quota. You can search by name or email, filter to Active, Administrators or Deleted accounts, and sort by name, newest first or storage used. Select an account to open its details.

A new server has no accounts. The first person to set it up becomes the administrator, using the setup code the server prints on its console. See Setting up a new server.

  1. In Users, select Create account.
  2. Enter their Email, Name, an Initial password and Confirm password.
  3. Optionally:
    • set a Storage quota (GiB). Leave it blank for no limit.
    • set a Storage label, used as their folder name on disk (see below).
    • choose the Role: User or Administrator.
    • turn on Require a password change at the next sign-in.
    • set an Initial six-digit PIN for Locked content, if they need one before their first sign-in. Its owner can change it later.
    • turn on Send a welcome email. This only appears once email is set up.
  4. Select Create account.

Invite people with their Frameleaf account

Section titled “Invite people with their Frameleaf account”

When your server is linked to Frameleaf Cloud, you can invite people from your Frameleaf account instead of creating a password for them. An invited person gets their own account and library the first time they use Sign in with Frameleaf, on the web or in the Frameleaf app. Being invited doesn’t show them your library; share items, albums or Spaces with them for that.

New invited accounts start with the Storage quota for invited accounts, set in Settings, then Access & security, then Sign in with Frameleaf. It’s unlimited by default, so their phone can back up straight away. The setting only applies to accounts created after you change it, and the server’s owner is never given it.

When you or Frameleaf Cloud remove someone’s access, their Frameleaf sign-ins on your server end. Their account and library stay until you delete the account.

See Share a server with people.

Open an account and select Edit account to change its name, email, avatar colour, role, quota or storage label, then Save account. If someone else changed the account since you opened it, you’re asked to reopen it to see the latest details.

You can’t delete your own administrator account or remove your own administrator role from the session you’re signed in with.

A quota limits how much a person can upload. Once they reach it, new uploads stop; their existing photos stay.

  • Leave the quota blank for no limit.
  • A quota of 0 blocks new uploads while keeping existing photos.
  • A quota doesn’t reserve disk space, so you can set quotas that add up to more than your disk holds.
  • Files in external libraries don’t count towards a quota.

By default each person’s files are stored in a folder named after their account ID. A storage label replaces that with a name you choose, using letters, numbers, hyphens or underscores. It’s used by the storage template.

Changing the label doesn’t move files that are already stored. Run the Storage Template Migration job when you’re ready.

Allow casting controls whether the account can use Google Cast. When it’s off, the person can’t turn casting back on themselves.

  1. Open the account and select Reset password.
  2. Select Generate temporary password.
  3. Copy the temporary password and give it to them. It’s shown only once.

Their old password stops working, and they must choose a new one when they next sign in.

Under Locked folder PIN:

  • Reset PIN clears the person’s PIN so they can set a new one after signing in.
  • Set PIN sets a new six-digit PIN for them.

Either way, every device signed in to the account is signed out of Locked content. Their protected photos stay protected.

Signed-in devices lists the devices signed in to the account, with when each was last seen. Select Sign out to sign a device out; it needs to sign in again to see the library.

If the account is connected to your OAuth provider, its details show Connected. Accounts set to Sign-in provider only have no password.

  1. Open the account and select Delete account.
  2. Type the account’s email to confirm.

Deleting signs out the account’s devices and starts a recovery period, 7 days by default. During that time the account shows as Deleted and its files stay on the server. Select Restore account to bring it back; devices that were signed out need to sign in again.

After the recovery period the account, its originals and its library entries are removed permanently. The deletion job runs at midnight. Change the length in Settings, then Storage & originals, then User Settings, then Delete delay. Changes apply from the job’s next run.

If you’re locked out of the only administrator account, reset its password from the server:

Terminal window
docker compose exec immich-server frameleaf-admin reset-admin-password

You’re asked for a new password (leave it empty to generate one) and whether to sign out existing sessions. The same tool can list users, and grant or revoke administrator rights. The last two ask for the person’s email:

Terminal window
docker compose exec immich-server frameleaf-admin list-users
docker compose exec immich-server frameleaf-admin grant-admin
docker compose exec immich-server frameleaf-admin revoke-admin

See Server commands for the rest.

Library analytics in the Command Center shows storage used across accounts, and each account has a View analytics link. See Command Center.