Admin sign-in
You're signed in to the customer view. Sign in here once more to open the admin console.
Checking the link…
Your fingerprint, face or screen lock unlocks it. No password needed.
Scan with an authenticator app, then enter the 6-digit code.
On this phone? Add to authenticator app, or type this key in by hand:
A customer is who you support: an individual (one person, one login) or a company (any number of logins). Every login and every computer belongs to one customer, and a customer's logins can never see another customer's computers. In a company, owner and admin logins see all of its computers; member logins see only computers you give them.
Logins belong to a customer. A login with no customer can sign in but sees no computers.
The green dot on Devices only proves a machine can reach the console API over 443. Taking a session needs it registered with the ID server on 21116, or riding the websocket transport. A machine can do the first and not the second — it looks online and never connects. This tab shows the difference, using checks measured on each machine by the PixelPup Doctor health check.
Choose where new alerts are sent. Each channel works on its own, so one failing never stops the others. Send test sends a clearly marked test to that one channel, even while it is switched off.
Dry run: nothing is sent on any channel. The console is running with ALERTS_DRY_RUN=true, so alerts and tests are only logged.
Loading…
Alerts fire on transitions only — a machine going unreachable, a report going stale, a critical finding appearing, antivirus or the firewall turning off, a new device showing up in MeshCentral. Anything already true when the console started was recorded silently and will not alert until it clears and comes back. One open alert per machine and rule; once resolved the same pair stays quiet for the cooldown. Every change goes out as one message on each channel switched on under Alert delivery above.
Named, allow-listed repairs only — never script text. Jobs ride the next health-agent check-in as a signed envelope (“pull”); urgent ones can be pushed through the mesh agent when push is enabled. Only paired devices ever receive a job. Auto-minting reacts to current findings and alert transitions on canary-ring hosts; Pause stops everything instantly without a restart. If self-heal is switched off on the server, this page cannot switch it back on.
Nightly window, local time. Runs only when the user has been idle for the minimum, on AC when required, at low priority, and aborts the moment the user returns. The device caches the signed policy at every check-in.
The password itself is never here, never in the console's database, never in a log line and never in the notification email. It is read live from the machine over the mesh agent and returned once to the browser that asked. Only logins on the machine-password allow-list (set on the server) may do it, a fresh second factor is required every single time, and the operator is emailed on success and on refusal.
Three separate signals, deliberately not merged into one dot. Heartbeat only proves the machine can POST to the console over 443. Registered means it is in the ID server's own peer table with a public key — that is what decides whether a session can be brokered at all. A machine can be green on heartbeat and absent from registration: online, and unreachable.
Turn Live on, then click App on a device. Every step the ID server takes appears here as it happens — the client connecting, the peer being looked up, the relay being handed over. If a connection fails, the last line before it stops is the reason.
hbbs-diagnostic-logging-ON.bat on the server, reproduce the failure, then run hbbs-debug-logging-OFF.bat to go quiet again.Every customer has a main book holding all of its computers, shown to its owner and admin logins automatically. Extra shared books give a company's member logins a subset. Books, logins and computers never cross customers.
Builds a silent MSI for one customer. Every computer it installs on gets RustDesk, the 30-minute health agent and the MeshCentral agent, then appears in that customer's address book by itself. Each download carries its own token, so you can revoke one installer without affecting others.
Group Policy: copy the MSI to a share that Domain Computers can read (use the UNC path, e.g. \\server\deploy\PixelPup.msi). Group Policy Management → edit a GPO linked to the computers' OU → Computer Configuration → Policies → Software Settings → Software installation → New → Package → Assigned. Computers install it at their next restart.
RMM / script: msiexec /i PixelPup_Client_<name>.msi /qn /norestart (run as administrator or SYSTEM).
Removing: remove the package from the GPO with “immediately uninstall”, or msiexec /x. Uninstall removes RustDesk, the MeshCentral agent and the PixelPup tasks.
Machines log to C:\ProgramData\PixelPup\Logs\client-msi.log. After the token expires or runs out, new computers still install but show up under Devices unassigned.