Local Users
Local users are accounts stored by Sylve itself. They are useful when someone needs access to the Sylve web interface but does not need a Unix account on the node.
Creating, editing, or deleting a local user does not create, modify, or remove a system user, home directory, Unix group, SSH key, Samba identity, or filesystem ownership. Use PAM Users when the person also needs an account on the host operating system.
| Choose | When it fits |
|---|---|
| Local user | The person only needs to sign in to Sylve. |
| PAM user | The person needs a managed Unix account, SSH access, group membership, a home directory, Samba integration, or system authentication. |
Only users marked Admin can sign in to the Sylve web interface. This applies to local users, PAM users, and passkey sign-in.
Non-admin local users are still useful as named Sylve identities for notifications and contact details. They cannot sign in or manage the node, but retaining their name and email address lets notifications identify the intended recipient or owner clearly.

Create a local user
Section titled “Create a local user”Select New User and provide the account details.
| Field | Description |
|---|---|
| Full Name | A descriptive name shown in Sylve. |
| Username | The account name used to sign in. It must be unique across both local and PAM users. A username cannot be changed after the account is created. |
| An optional contact address associated with the user. | |
| Password | The Sylve password. New passwords must be 8 to 128 characters and match the confirmation field. |
| Admin | Allows the user to sign in to and administer Sylve. Leave this disabled for notification or contact-only identities that should not have web interface access. |
When editing a user, leave the password fields empty to keep the current password. Administrators can change the password of any local user, including the built-in admin account. If you change the password of the account currently signed in, Sylve signs that session out and asks you to authenticate again with the new password.

Manage local users
Section titled “Manage local users”The actions menu lets you edit a user, manage their passkeys, or delete the account. Deleting a local user removes its Sylve record and its Sylve authentication state. It does not affect any operating-system account because local users never create one.
The built-in admin account and root are protected from deletion. Keep at least one reachable administrator account before changing or removing other administrators.
Passkeys
Section titled “Passkeys”Passkeys let an administrator sign in with the browser or device authenticator instead of entering their password. Open Passkeys from the user’s actions menu, give the passkey a recognizable label, then complete the browser prompt.
Passkey registration is available only for active administrators with Sylve credentials. Existing passkeys can still be removed from the user record. Registration requires HTTPS and a browser or device that supports WebAuthn.