# Workspace Settings

Workspace settings are available from the sidebar under **Settings**. The settings panel groups the main workspace controls into focused sections.

## General

URL: `/@name/settings/general`

| Setting | Description | Rules |
|---|---|---|
| **Workspace Name** | URL-safe identifier | Alpha-dash, max 16 chars, unique |
| **Workspace Label** | Display name shown in the manager | Required, max 255 chars |
| **Workspace Email** | Billing and notification contact; destination for forms using workspace email | Required, valid email |
| **Workspace Avatar** | Profile image for the workspace | Uploaded from the workspace's files |

### Danger zone

The **Delete Workspace** button permanently removes the workspace and all its data. You must type the workspace name to confirm.

## Authentication

Authentication settings have two pages: **Source** and **Hosted Login**.

### Source

URL: `/@name/settings/auth/source`

Controls whether workspace authentication is enabled and which content type is used as the user source.

| Setting | Description |
|---|---|
| **Enabled** | Master toggle for workspace authentication |
| **User Source** | Content Bucket and content type that stores authenticating users |

### Hosted Login

URL: `/@name/settings/auth/hosted-login`

Hosted login provides a Viresso-managed login and verification page for your app.

| Setting | Description |
|---|---|
| **Status** | Turn hosted login pages on or off |
| **Allowed Origin** | Browser origin allowed to use hosted login |
| **Redirect URL** | Fixed URL users return to after login; it must use the allowed origin |
| **Appearance** | Background, button, and text colors for hosted login pages |

See [API Access](/docs/platform/api-access) for API key authentication.
See [Hosted Login](/docs/platform/hosted-login) for the hosted login setup flow.

## Notifications

URL: `/@name/settings/notifications`

Three toggles control which email notifications the workspace sends:

| Toggle | Effect |
|---|---|
| **Email Notifications** | Master toggle for optional workspace notification emails. Billing and account security emails are still sent. |
| **Workspace Access** | Emails when users are added, removed, or their role changes |
| **Webhook Dispatches** | Emails when a webhook delivery succeeds or fails |

These toggles control optional workspace notifications. Transactional API emails and form-answer emails configured through a form’s **Submit action** are independent of them. Change a form’s delivery destination in **Forms → Settings**. See [Forms](/docs/platform/forms#submit-action).

## Webhooks

URL: `/@name/settings/webhooks`

Webhooks send HTTP POST requests to a URL when entry events occur.

| Setting | Description |
|---|---|
| **Name** | Unique identifier within the workspace |
| **URL** | Endpoint that receives webhook payloads |
| **Events** | One or more events that trigger the webhook |

### Supported events

| Event | Triggered when |
|---|---|
| `entry.created` | A published entry is created |
| `entry.updated` | A published entry is updated, published, or unpublished |
| `entry.deleted` | A published entry is deleted |
| `content_type.updated` | A content type's fields change |
| `file.updated` | A file referenced by a published entry changes |
| `file.deleted` | A file referenced by a published entry is deleted |

### Webhook payload

Each webhook POST includes the event type, timestamp, and event data. The payload is signed with HMAC-SHA256 using the webhook's secret. The signature is sent in the `X-Signature-256` header. Verify it on your endpoint to confirm the request came from Viresso.

### Webhooks and notifications

Successful and failed webhook deliveries send a notification to the workspace email if **Webhook Dispatches** notifications are enabled.

## Billing

URLs:

- Billing details: `/@name/settings/billing/details`
- Invoices: `/@name/settings/billing/invoices`

Shows billing details, your current billing period estimate, and invoice history. See [Billing and Invoices](/docs/platform/billing-and-invoices) for details.

## Audit Logs

URL: `/@name/settings/audit-logs`

Every configuration change within a workspace is logged. Audit log visibility depends on your workspace role.

Download a JSON export of the workspace's retained audit logs from this page.

## API Keys

URL: `/@name/settings/api-keys`

Manage API credentials for programmatic access. See [API Access](/docs/platform/api-access) for details.

## Access

URLs:

- Members: `/@name/settings/access/members`
- Invitations: `/@name/settings/access/invitations`

Manage team members and their roles. See [Members and Access](/docs/platform/members-and-access) for details.

## Related pages

- [Members and Access](/docs/platform/members-and-access) — Managing team members.
- [Hosted Login](/docs/platform/hosted-login) — Hosted login setup.
- [API Access](/docs/platform/api-access) — API key authentication and CORS.
- [Email Settings](/docs/platform/email-settings) — How Viresso sends email.
- [Billing and Invoices](/docs/platform/billing-and-invoices) — Understanding your invoice.
