Features
Access Control & Roles
- Details
- Category: Features
- Applicable Software: MokoNtfy
Access control & roles give you fine-grained, topic-level control over who can read and write each MokoNtfy topic. On top of the built-in owner, admin and user roles you can now build your own custom roles, bundle users into groups, lock down sensitive topics as protected, and preview exactly what any person can do on any topic — all from Site Administration.
Custom roles (RBAC)
A role is a named bundle of capabilities that you can assign to a user or to a whole group, so you can delegate a subset of administrative power without handing out full admin. Capabilities come in two kinds:
- System capabilities — server-wide powers (for example, managing users or topics).
- Topic-scoped capabilities — a capability that applies only to a topic or a pattern such as
alerts-*, so a role can be granted authority over one namespace and nothing else.
Admins and the owner already hold every capability, so roles exist to grant power to regular users and groups, never to restrict admins. Role management is owner-only — only the owner can create, edit, delete or assign roles.
Groups
Groups bundle users together so a single topic-access grant applies to every member. Grant a group read, write or read-write on a topic (or pattern) and every member inherits it; add or remove members and their access follows automatically. A user's own per-user grant always takes precedence over a group grant, so you can make a targeted exception without dissolving the group.
Topic-centric access view
Open Site Administration › Topics to browse every topic that has any access grant or reservation and see, at a glance, who can access each topic. Select a topic to list the users, groups and the Everyone grant that match it, along with the pattern that granted each one. Access is edited here through the same per-user and per-group grants used on the Access and Groups pages, so there is one consistent model however you look at it.
Protected topics
Marking a topic (or a wildcard pattern such as team-*) as protected means it requires an explicit user or group grant. The fall-through Everyone grant and the server's default access no longer reach a protected topic — but owners, admins and the topic's reservation owner always retain access. Protecting a topic removes its exact Everyone grant; a broader Everyone wildcard is left in place with a warning. Use the Protect / Unprotect buttons on a topic in the Topics view, or manage the whole registry under Protected topics.
Effective-permission preview
Not sure whether a change did what you intended? The Access preview answers “what can user X do on topic Y?” directly. Pick a user (or Anonymous, for a not-signed-in visitor) and a topic, and MokoNtfy reports read allowed/denied and write allowed/denied. The result is resolved by the real authorization engine, so it reflects roles, groups, protected topics, the Everyone grant and the default access exactly as they would apply in production.
Saved logins
Saved logins are the per-browser credential store for protected topics and servers — the feature previously shown under a different name. It is now clearly labeled and reachable by every signed-in user, so you can keep the usernames and passwords your browser uses to reach protected topics in one place.
From the command line
Everything above can also be driven from the server CLI, which is handy for scripting and automation:
ntfy role— create roles, add/remove capabilities, andassign/unassignthem to users or groups.ntfy group— create groups, managemembers, and grant group topicaccess.ntfy protect—add,removeandlistprotected topics and patterns (optionally recording a note explaining why).
Where to find it
Sign in as owner or admin and open the Site Administration area. You will find the Access, Groups, Roles (owner-only) and Topics pages there. Saved logins is available to every signed-in user from their account menu.
- Hits: 3
Accessibility Tools
- Details
- Category: Features
- Applicable Software: MokoNtfy
MokoNtfy includes the Moko accessibility drawer, a set of on-page controls that let each visitor adjust how the app looks and reads. Preferences are saved per browser and applied on every visit, so your choices persist.
Opening the drawer
A floating accessibility button (the same widget that carries the theme switch) opens a drawer with a theme group and an accessibility group. Everything below is toggled from there.
Accessibility controls
- Font size. A stepper scales the whole interface through preset sizes (85%, 90%, 100%, 110%, 120%, 130%), with the current value announced for screen readers.
- High contrast. Boosts contrast for readability.
- Invert colours. Inverts the palette. High contrast and invert are mutually exclusive — turning one on turns the other off.
- Highlight links. Makes links stand out so they're easy to spot.
- Readable font. Switches to a more legible typeface.
- Pause animations. Stops motion for a calmer, reduced-motion experience.
- Reading mode. Simplifies the view to focus on content.
Theme controls
The same drawer holds the theme switch: choose Light or Dark explicitly, or Auto to follow your operating system. The app's own theme preference stays the source of truth, so the drawer and the theme button always reflect the same choice.
Skip to content
A skip-navigation link is provided for keyboard and screen-reader users: press Tab on page load and the first focusable element is a "skip to content" link that jumps past the navigation straight to the main area.
Where preferences live
Accessibility choices are stored locally in your browser (not on the server), so they follow the browser/device rather than your account — set them once per device.
Admin: drawer placement, size & layout
An administrator can control where the accessibility drawer sits and how it looks for every visitor from Site Administration → Accessibility. Changes take effect on the next load — no rebuild or restart. The options mirror the MokoOnyx theme:
- Placement — which screen edge and vertical anchor the handle sits at: Right–Center (default), Right–Top, Right–Bottom, Left–Center, Left–Top, or Left–Bottom.
- Control layout — how the controls are arranged inside the panel: Stacked (column, default), Inline (row), or Grid (2-column).
- Panel size — the width of the open panel: Slim, Narrow, Normal (default), or Wide.
- Open on load — whether the drawer opens automatically when the app loads (default off).
These are saved on the server and apply to everyone, including before sign-in.
When you Save on the Accessibility settings page, MokoNtfy reloads automatically so your new placement, layout and size apply right away — you no longer need to refresh the page manually.
Printing
Any page can be printed cleanly. A Print action is available both in the topic action bar (the printer icon) and in the accessibility drawer ("Print page"). Both open your browser's print dialog against a print stylesheet that hides the app chrome (top bar, side navigation, buttons, the accessibility drawer) and lays out the visible notifications for paper.
- Hits: 3
Guided Welcome Tour
- Details
- Category: Features
- Applicable Software: MokoNtfy
To help you get started, MokoNtfy includes a short guided tour that walks you through the main parts of the interface.
First sign-in
The tour starts automatically the first time you sign in, highlighting where to subscribe to topics, where notifications appear, and where your account settings live.
Shown once
The tour is shown once per user. Because the “seen” state is synced to your account, it won't pop up again on your other browsers or devices after you've been through it.
Replay any time
You can take the tour again whenever you like: open the profile menu (top-right) and choose Take the tour.
- Hits: 3
Quiet Hours
- Details
- Category: Features
- Applicable Software: MokoNtfy
Quiet hours silence lower-priority notifications during a nightly window so you are not woken by routine alerts, while still letting the important ones through.
What it does
During quiet hours, MokoNtfy holds notifications of priority 3 (Default) or lower so they do not make a sound or pop up. They still arrive and are waiting for you when quiet hours end. Genuinely important messages break through immediately: any notification sent at priority 4 (High) or priority 5 (Max / Urgent) is delivered normally, even during quiet hours.
Defaults
- Quiet hours are on by default.
- The default window is 18:00 to 06:00 (6:00 PM to 6:00 AM), interpreted in your local time.
Timezone
You can set the timezone used to evaluate the window, so quiet hours line up with your actual day regardless of where the server lives or where you travel.
It follows you across devices
Your quiet-hours settings are synced to your account, so they apply consistently everywhere you are signed in — change them once and every device honors the same window.
Where to find it
Open Settings › Notifications and look for Quiet hours. From there you can turn it on or off, set the start and end times, and choose your timezone.
- Hits: 5
Site Administration Area
- Details
- Category: Features
- Applicable Software: MokoNtfy
MokoNtfy has a dedicated Site Administration area for administrators, keeping site-wide settings and access control separate from your personal account. It is available to users with the admin or owner role — owner is the higher role, and both can open it. A few controls are further restricted to owner only (noted below).
Getting there
Open the profile menu (top-right) and choose Site Administration. This entry appears for admin and owner accounts. The area lives at /admin, and the whole section is gated once — anonymous users are sent to the app and signed-in non-admins to their account page.
What's inside
The console is organized into two groups.
Access & Roles
- Access — principal-first access control: pick a user or group and manage the topic grants (read, write, read-write, or deny) attached to it.
- Topics — a topic-centric ACL view. Lists every topic that has any grant or reservation and shows who can access it — the users, groups and the Everyone grant that match, plus the pattern that granted each. Read-only.
- Groups — create groups and manage their members and topic-access grants, so one grant applies to every member.
- Roles (owner-only) — role-based access control. Build custom roles that bundle capabilities (system-wide or topic-scoped) and assign them to users or groups. Only the owner sees this card and can open the page — it is the anti-self-escalation guard for delegated admin power.
Server
- Users — manage server user accounts (create, edit role/tier, remove).
- Server info — instance-level server details and status.
- Branding — change the app's displayed name, theme colors and font, and the favicon / app icon, live. See White-Label Branding for details.
- Accessibility — set the placement, control layout and panel size of the accessibility + theme drawer for every visitor (and whether it opens on load). See Accessibility Tools for details.
- Google Approvals — review and approve (or reject) new accounts created via Sign in with Google. (Shown when Google sign-in is enabled.)
- Tours — manage the in-app guided tours.
A convenience link to your personal Saved logins (per-browser credentials for protected topics and servers) also appears here, though that page is reachable by every signed-in user, not just admins.
Personal settings are separate
Your own Account and Settings pages remain where they were and are unchanged — Site Administration only gathers the site-wide controls. If you have bookmarked the old locations, the legacy /account/branding and /account/google-approvals URLs automatically redirect into the new Site Administration area.
- Hits: 4