Brute-force locks are held in memory and reset when the server restarts. Use this tab to unlock accounts that have been temporarily locked after too many failed login attempts.
—
Fully Locked
—
Failed Attempts (not locked)
—
Total Records
Accounts with Login Failures
Loading...
Brute-Force Protection
Controls how many failed login attempts are allowed before temporarily locking an account. Changes take effect immediately without restart.
Rate Limits (max requests)
Note: Max values take effect immediately. The time window (15 min / 1 hr) is fixed and requires a server restart to change.
How Rate Limiting Works
Limits are per IP address, not per account.
Hitting a limit returns HTTP 429 with a clear error message.
Admin routes (/api/admin/*) are exempt from IP blocks.