Admin portal
The admin portal holds the settings that apply to your whole installation rather than to one project: the API keys every project can use, how Repave sends email, what an implementation run can spend, who can sign in, and the license.
Only administrators see it. Choose Admin portal on the home page, beside Your Projects, or open the account menu (the person icon at the top right) and choose it there. It opens on API keys; the side menu has Email, Budgets, Users and License, and All projects takes you back.
Who is an administrator
- On a new installation, the first account created becomes the administrator. On a Google
Cloud Marketplace installation that is
admin@repave.local, which first boot creates for you. - On an installation upgraded to this release, the earliest account became the administrator.
- Administrators make other users administrators from Users.
There is always at least one active administrator: Repave refuses a change that would leave none, and an administrator cannot change their own access — another administrator has to.
If you are ever left without one — every administrator disabled, or locked out — someone with shell
access to the host can restore admin@repave.local with
npm run bootstrap-admin -- --reset: it sets a new password and makes the account an administrator
again. See GCP Marketplace for the full command.
Someone who is not an administrator and opens an admin portal link is told which addresses to ask for access.
API keys
Keys set here are used by every project that does not set its own. A project's own key always wins, so a project that bills to a different account keeps working exactly as before.
| Card | What it provides |
|---|---|
| Anthropic | API key, auth token, and base URL |
| OpenAI | API key |
| Google Gemini | AI Studio key, Vertex key, Vertex service account, project and region |
| Claude on Vertex AI | GCP project, region, and service account |
| TypeSafe (Jev) | API key |
Each card is used as a whole. A project that sets any field of a card — say, only an Anthropic auth token — uses its own values for that whole card and none of the organization's, so an organization base URL is never paired with a project's key.
Each card tells you how many projects use it: "Used by 7 of 9 projects. 2 set their own."
- Keys are write-only. Once saved, a key is never shown again, only "Key saved". Enter a new one to replace it, or choose Clear and save to remove it.
- Removing a key that projects use asks first, and says how many projects will be left without one. Their agent jobs fail until each sets its own key, or you add a new one here.
- Keys are stored encrypted.
- TypeSafe keys are checked when you save. A key TypeSafe rejects is not saved. On an installation that cannot reach api.typesafe.ai, the key is saved and the card says agents will not use Jev until it can.
- If some projects could not be updated on the model gateway when you save, the key is still saved and the page names those projects. They retry on their own before their next agent job.
In a project's settings, a field that uses the organization's key reads Using organization key. In Anthropic API (direct) mode, remember the key is placed in the project's agent containers, as a project's own key would be.
Email
Repave sends two kinds of email: password resets, and invitations to a project. Both go through one SMTP server you set up here — your mail provider's SMTP endpoint (Google Workspace, Microsoft 365, Amazon SES, SendGrid and the like all offer one), or your organization's own relay on an installation without internet access.
| Field | |
|---|---|
| Host | The SMTP server, e.g. smtp.acme.com |
| Port | 587 unless your provider says otherwise |
| Username, Password | If your server needs a login; an internal relay often does not. The password is stored encrypted and never shown again. |
| From address | What the emails come from, e.g. Repave <repave@acme.com> |
Port 465 connects with TLS; any other port upgrades to TLS when the server offers it.
After saving, Send test email sends one to you through what you saved. If it fails, the page shows the mail server's own reason — usually a wrong login, or a server that does not accept mail from this host.
With email set up:
- The sign-in page offers Forgot password?. The reset link works once and expires in 1 hour.
- Inviting someone to a project emails them the invitation. The project's Team page still shows the invitation link to copy, in case the email does not arrive.
Without it, nothing stops working: invitations are shared by copying their link, and an administrator resets a password from Users.
Budgets
Budgets limit what agents can spend, at three levels. An agent stops at whichever limit it reaches first, and the message it stops with says which one that was.
Every run
Every agent job — implementing, fixing, merging, opening a pull request, revising, writing tests — is a run.
| Control | |
|---|---|
| Let users set a budget for a run and for each agent | On by default. Off, the Implement dialog has no budget field, and the Budget column in a project's agent defaults is read-only. |
| Maximum per run | Off by default. On, no run can spend more than this amount. |
What a run's spend limit is:
| Users set a budget | Maximum | The run stops at |
|---|---|---|
| Yes | None | The budget the user chose in the Implement dialog, else the agent's budget in the project's agent defaults, or nowhere if neither is set |
| Yes | Set | That budget, which can be lower than the maximum but not higher. A run with no budget gets the maximum. |
| No | Set | The maximum. The Implement dialog shows it, read-only. |
| No | None | Nowhere: runs are not limited |
The limit applies however a run starts, including conductor runs, automatic fixes and runs that waited for a slot. A run already going picks up a change at its next step, and so does a run you continue or resume. A run stopped at its budget is reset to continue: it gets the same budget again, counted from the reset, so each stretch of a run stays within the maximum — but a reset run spends it again, so the maximum limits a stretch, not the whole run. Anyone who can edit the project can reset a run, even when users may not set budgets, because a reset chooses no amount. A job can be continued 5 times in all, whether after a reset or a timeout, so one run spends at most six times the maximum. To limit what all of a feature's or project's work can cost, set a maximum per feature or per project.
Per feature
Maximum per feature limits everything a feature costs over its whole life: implementing it, fixing it, merging it, its pull requests, revisions, written tests, and every retry. A module's own runs count toward the module in the same way. The maximum applies to every feature; when one reaches it, anyone who can edit the project can raise the budget for that feature, or that module, alone.
Per project
Maximum per project limits everything a project costs over its whole life. It never resets, and only an administrator can raise it, so it is the limit on everything else. The table under it lists every project with what it has spent and its budget; Raise… gives one project a higher budget of its own, marked (raised). Lowering the maximum below what a project has already spent stops new agent work in that project — a deliberate brake.
When a limit is reached
Stopped work always says which budget stopped it, by how much, that its work so far is kept, and what to do next.
| Budget reached | What stops | Who continues it | How |
|---|---|---|---|
| Run | that run | anyone who can edit the project | Reset and continue on the stopped work |
| Feature or module | every agent for that feature or module | anyone who can edit the project | Raise budget… on the feature's or module's page; a feature's stopped work then continues straight away, a module's run is retried |
| Project | every agent in the project | an administrator | Raise budget… on the banner every page of the project shows, or Raise… in the table here; then Continue on each stopped piece of work |
- Running agents stop within a few turns of a budget, and nothing new that runs an agent can start for that feature, module or project until its budget is raised. Work that runs no agent — starting a preview, pulling source — carries on.
- A new budget must be more than what has already been spent; everything spent so far still counts.
- A run stopped on a model whose spend can't be measured cannot be reset: it would stop again on its first turn.
With any maximum set, agents must use a Claude model. Repave measures spend only for Claude models, so a Codex or Gemini run could not be held to a limit. The Implement dialog says so and will not start one. A run whose model is set by the project's agent defaults stops on its first turn if that model turns out not to be Claude, and the run says why; adding budget will not restart it. Without a maximum, nothing changes for Codex or Gemini runs.
Users
Everyone who can sign in, with their role, whether they are active, and how many projects they belong to. From a user's row you can:
- Make admin or Remove admin
- Disable — they can no longer sign in, and anyone already signed in as them is signed out within a minute. Their projects and memberships are kept.
- Enable — undoes Disable.
- Reset password — emails the user a link to choose a new password. Without email set up, it gives you the link to hand to them yourself. It works once and expires in 1 hour. You never see or set anyone's password.
Each change applies immediately and can be undone the same way, so none asks for confirmation.
Users lists people who already have an account. To bring in someone new, invite them to a project from its Team page (see Project settings); once they have signed up, they appear here and you can make them an administrator.
License
The license's status, and importing a new license file. Only an administrator can replace a license the installation already runs on. The very first license, on an installation that has none yet, can be imported before anyone has an account.