Users and account recovery
Every Aldus account belongs to one server. There is no Aldus cloud account, email signup, or password-reset service. The household administrator creates access; each reader then chooses credentials the administrator does not know.
Add a reader
Section titled “Add a reader”- Open More → Users and select Add user.
- Enter a provisional username and display name. You can also add a private administrator note so the person remains recognizable if they change their username. Leave global administrator access off for an ordinary reader.
- Choose the libraries this reader can access. Request permission starts off; enabling it still requires approval.
- Create the account and save the temporary username and password. The password cannot be shown again. If library assignment failed, retry it before sharing the credentials.
- Use Share sign-in details on the app or Copy sign-in details on the web to hand off the server address and credentials privately.
- On first sign-in, the reader chooses their final username, display name, and password before entering their libraries.
Later, open User details → Library access to change roles or request permissions.
The final username stays fixed after setup because KOReader and OPDS devices use it when authenticating. A reader can change their display name and password from Account.
Manage library access
Section titled “Manage library access”Open More → Users, select an account, and use the Library access grid. A Reader can consume books. An Editor can also manage works and requests. An Owner can additionally manage that library’s members and settings. Global administrators can access and manage every library unless exclusive grants limit them.
For a reader, the same grid controls whether they can request missing formats, skip approval, or choose releases directly. In a multi-library household, Include in exclusive access limits the account to the libraries marked that way. Aldus prevents removing the final owner from a library until another owner has been assigned.
Change administrator access
Section titled “Change administrator access”Open a user’s details and choose Make administrator or Remove administrator access. This keeps the same account, reading history, and collections. Aldus prevents removing the last enabled administrator. Exclusive library grants still limit effective library access.
Reset a reader’s password
Section titled “Reset a reader’s password”Open More → Users, select the account, and choose Reset password. Aldus immediately revokes that account’s app and browser sessions and shows a new one-time password. The reader signs in with it, then chooses final credentials again.
Reader-device credentials are separate. If a KOReader or OPDS credential may also be compromised, the reader should revoke it under Account → KOReader and OPDS after recovering the account.
Disable or remove access
Section titled “Disable or remove access”Disabling an account prevents login and revokes every app session. It does not erase the account, reading history, collections, or reader-device credentials. Re-enable it when the same person should regain access.
Readers can permanently remove their own account under Account → Delete account. Regular accounts confirm deletion with their current password; temporary demo guests do not have a password and use the confirmation dialog only. The final enabled administrator cannot delete their own account until another administrator exists.
Recover the only administrator
Section titled “Recover the only administrator”If the sole administrator forgets their password, use host access. Stop the service first so only the recovery command opens the database:
docker compose stop aldusdocker compose run --rm aldus reset-password --username YOUR_USERNAMEdocker compose up -dThe command prints a one-time password and revokes every existing session for that administrator. Sign in and finish account setup immediately. It works only for an existing administrator and does not expose recovery over the network.
Sessions and backups
Section titled “Sessions and backups”Sign out removes only the current app or browser session. Sign out everywhere removes all Aldus app and browser sessions for the account while leaving KOReader and OPDS credentials connected.
Backups retain user password hashes and reader-credential verifiers so accounts still exist after recovery, but active sessions are removed from the backup snapshot. Everyone signs in again after a restore. Treat every backup as sensitive account and library data, store it with restricted access, and keep an off-host copy.
Shared family devices
Section titled “Shared family devices”Use Account → Switch reader to remember the current reader’s name and return to sign-in. Choose a remembered name and enter that reader’s password. Switching requires a server connection. Aldus does not store account passwords or use a local PIN as server authorization. On sign-in, Remember my name on this device controls whether a name shortcut is saved. Forget removes only that shortcut; it does not delete an account or downloaded books. Downloads and queued progress remain scoped to the original reader. Switching does not share reading history, and it does not promise to erase already downloaded files remotely.