Project Access and Credentials
Applies to: all AppWizzy hosted VM projects
Project access has two layers. Your AppWizzy account controls the project page, while the selected template provides its supported access methods.
Protect both layers. Template credentials can grant access to project data and tools.
AppWizzy account access
Sign in to AppWizzy to manage the project, VM lifecycle, billing, settings, and supported access controls.
The project owner controls the project. A collaborator can receive project access when the account and template support collaboration.
The interface shows only the actions available to your role. Do not share your personal AppWizzy account password with another person.
Template access methods
Each template provides its own access methods. These methods can include:
- a public or protected application URL.
- an application administrator account.
- an AppWizzy Codex password.
- a Remote Desktop VNC password.
- a Hermes dashboard username and password.
- a Hermes API key.
- an SSH private key and command.
- a personal provider login or BYOK credential.
SSH is available for hosted VMs. Browser access, Remote Desktop, mobile access, and application credentials depend on the template.
Read the selected template guide before you share or change access.
Find project credentials
Open the project overview and settings after provisioning. The available sections show the URLs, usernames, passwords, keys, and actions for that template.
Some credentials appear only after provisioning finishes. Resume a paused VM before you manage SSH access or open a hosted interface.
Use the reveal control only in a private location. Use the copy control without pasting the secret into an untrusted application.
Protect credentials
Use these practices for every project:
- Store passwords and API keys in a password manager.
- Store SSH private keys in a protected local directory.
- Do not commit secrets to Git.
- Do not paste secrets into public issues or chat messages.
- Give project access only to trusted people.
- Remove personal provider sessions before a project transfer.
- Rotate credentials after exposure or an access change.
Files inside a VM can also contain secrets. Protect environment files, browser profiles, terminal history, and authentication artifacts.
Rotate or revoke access
Use the project settings when the interface provides a rotation or revocation control.
AppWizzy Codex Desktop uses separate passwords for AppWizzy Codex and Remote Desktop. The project owner or an administrator can rotate both together.
Password rotation closes existing AppWizzy Codex and Remote Desktop sessions. Give new passwords only to current authorized users.
SSH settings provide separate controls to rotate, verify, and revoke customer SSH access. Rotation replaces the current SSH key.
Revocation removes that SSH access from the AppWizzy bastion and project VM.
Application credentials can use application-specific controls. Follow the template guide and the application documentation for those credentials.
Personal provider access
Some AI templates support a personal ChatGPT login or a provider API key through BYOK.
Your provider account controls that provider access. Remove the provider session or key when another person no longer needs it.
AppWizzy encrypts stored BYOK credentials. Browser sessions and authentication artifacts can also remain inside the VM profile.
Support access
AppWizzy staff access prompts or VM content only after you request assistance.
Identify the project and problem in your first support message. Do not include passwords, private keys, or complete access tokens.
Support will provide a secure method if sensitive information is required.