Protecting Your Panel Account With a Strong Password
Your GuavaHost account controls every file, backup, and setting on your server, so protecting it with a strong, unique password and careful login habits is the single most important security step you can take.
4 min read · Updated Sep 24, 2026 · By GuavaHost Team
Why the account matters so much
One GuavaHost account opens everything: your control panel at customer.guavahost.com, where you run your servers and where services can be changed or cancelled, and the classic game panel at panel.guavahost.com, which uses the same sign-in (see Using the classic game panel). Whoever signs in as you has full control. They can browse and delete files on the Files tab, delete or restore backups on the Backups page, change your startup settings, or even reinstall the server. No DDoS protection or whitelist helps if an attacker simply signs in as you, so the password is the real front door.
Build a strong password
A good password is long and unique before it is complicated:
- Make it long. A passphrase of four or five random words is both strong and easy to remember.
- Make it unique. Never reuse the password from your email, your game account, or another site.
- Avoid the obvious, such as your username, your server name, or
password123. - Use a password manager to generate and store a random password so you never have to memorize it.
Reusing a password is the most common way accounts get taken over, because one leak from an unrelated website hands attackers your login everywhere.
Never share your login
Do not give your master password to co-owners or staff. If someone needs access to help run the server, hand it out through in-game roles and permissions, or invite them through People in your server's menu (Giving a friend access with sub-users), rather than sharing your account credentials, and keep the top-level login to yourself. Sharing a password means you can no longer tell who made a change or undo it cleanly.
Watch out for phishing
Attackers often skip the password entirely and just trick you into typing it. Stay safe:
- Only ever enter your login on the real sites: customer.guavahost.com, guavahost.com and panel.guavahost.com. All three use the same GuavaHost sign-in.
- Be suspicious of Discord DMs or emails claiming to be staff and asking you to "verify" your account on a link.
- GuavaHost staff will never ask for your password.
One account, every way in
Turn on two-factor authentication
Two-factor authentication adds a six-digit code from an app on your phone to every sign-in, so a stolen password alone is not enough to get in.
- In your control panel, open Account settings.
- In the Two-factor authentication card, click Set up authenticator.
- Scan the QR code with an authenticator app (or use Can't scan it? Enter a setup key), enter the six-digit code, and click Enable authenticator.
- Save the recovery code it shows you somewhere safe. It is your way back in if you lose your phone.
From then on, signing in with your password or with Google, Discord or GitHub also asks for the code.
One account, every way in
Because your control panel and the classic game panel share one GuavaHost account, one strong password protects both. Keep an eye on the other ways in, too:
- Google, Discord or GitHub sign-in. If you connected one of these, that account can sign you in to GuavaHost as well, so protect it with its own strong password and two-step verification. You can see and remove connected providers in Account settings under Connected accounts. See Sign in with Google, Discord or GitHub.
- Your email inbox. Password reset links go to your account email, so a secure inbox keeps your GuavaHost account secure.
- SFTP. File transfer apps use the separate SFTP password you set on your server's Settings tab, described in Uploading files with SFTP, not your GuavaHost password. Treat it with the same care.
If you think you have been compromised
- Change your password immediately from a device you trust, under Account settings in Password & security (or with Forgot your password? on the sign-in page). Changing it ends every other signed-in session, so sign in again with the new password.
- The menu under your name at the bottom of the control panel's sidebar also has Sign out of all devices, which ends remembered sign-ins on your other devices. Changing your password is the stronger step, so do that first.
- Check Connected accounts and unlink any provider you do not recognise, and turn on Two-factor authentication if it is off.
- Open Activity (under More in each server's menu) to see who started, stopped or changed what, and check People for anyone you did not invite. Change your SFTP password too.
- Restore a clean backup from the Backups page if files were changed.
- Contact support through guavahost.com/support or Discord so the team can help you lock things down.
Still stuck? Jump into our Discord at discord.gg/GuavaHost and the team will help you out.
- account
- password
- panel
- security
Still need help? Our team is online 24/7 to answer questions.