How to onboard team members and customers¶
This guide shows you how to give someone access to Penpot at https://penpot.kup.tirol.
Penpot has no invitation-only mode that works. Access is controlled by the email domain whitelist, so onboarding always starts with the domain.
Check whether the domain is allowed¶
Read the current whitelist:
grep registrationDomainWhitelist ~/ws/pro/kup6s/dp-infra/penpot/config.yaml
If the person’s email domain is listed, skip to Invite them to a team.
Add a customer domain¶
Edit dp-infra/penpot/config.yaml and append the domain to the comma-separated list:
registrationDomainWhitelist: "kleinundpartner.at,customer.example"
Rebuild, commit, and push:
cd ~/ws/pro/kup6s/dp-infra/penpot
pnpm run build
git add config.yaml manifests
git commit -m "feat(penpot): allow customer.example to register"
git push origin main
ArgoCD syncs the change and the K3S helm controller restarts the backend. Confirm the new value reached the pod:
kubectl -n penpot get deploy penpot-backend -o jsonpath='{.spec.template.spec.containers[0].env[?(@.name=="PENPOT_REGISTRATION_DOMAIN_WHITELIST")].value}'
Warning
Never leave registrationDomainWhitelist empty.
Penpot treats an empty whitelist as disabled and then accepts registrations from any domain on the public internet.
Invite them to a team¶
Sign in at https://penpot.kup.tirol.
Open the team menu and select Invitations.
Enter the email address, choose a role, and send the invitation.
Penpot sends the invitation through Mailjet. The invited person follows the link, creates an account with that address, and lands in the team.
If sending the mail fails, check the backend log:
kubectl -n penpot logs deploy/penpot-backend | grep -i smtp
Handle a rejected registration¶
A registration that fails with email-domain-is-not-allowed means the domain is missing from the whitelist.
Add it as described above.
Penpot applies the whitelist after it validates the invitation token, so an invitation never overrides it.
Create an account without registration¶
Use the backend CLI when you need an account for a domain you do not want to whitelist:
kubectl -n penpot exec -it deploy/penpot-backend -- ./run.sh app.cli/create-profile
The command prompts for email, password, and full name.