Start here

First run and your admin

A new instance has no accounts. The first person to prove they can read the server's log becomes the administrator, and after that first run is closed for good.

Create the first administrator

Every page of a fresh instance sends you to Create the first administrator. It asks for an email, a display name, a password of at least 12 characters, and a setup code.

The first-run page with the Where do I find it help open, listing where the setup code is for a terminal, Docker, a Linux systemd service, a macOS service and a Windows service.
The page tells you where to look for the code on each kind of host, and says 'This server looks like this' beside the one it thinks you are on. It also names the data folder it is running from (shown here as a neutral path). This is the default Overpass look.

Where the setup code is

The server prints the code to its log every time it starts, and only while no account exists. Where that log goes depends on how you started it.

You started itThe code is inStatus
In a terminalThat terminal window.Run
Dockerdocker logs <container> (or docker compose logs draughtsman).Run on Docker Desktop
Linux servicejournalctl -u draughtsmanNot run
macOS service<data folder>/logs/draughtsman.log, by default /Library/Application Support/Draughtsman/logs/draughtsman.logNot run
Windows serviceNot in any log. A file only Administrators can read, <data folder>\setup-code.txt (by default C:\ProgramData\Draughtsman\setup-code.txt); from an elevated PowerShell run draughtsman first-run-code --DRAUGHTSMAN_DATA 'C:\ProgramData\Draughtsman'. See Install, Windows.Run on Windows 11 Arm64

The line looks like this:

warn: draughtsman[0]
      ==================================================================
      First-run setup code: ZQVDE3SHGC
      Enter this on the first-run page (or POST it as setupCode to /api/auth/first-run) to create the
      administrator account. Valid only until an administrator exists; restart to get a new code.
      ==================================================================

Rules worth knowing

  • The code lives only in memory. If you restart the server before creating the account, it makes a new code and the old one stops working.
  • Wrong guesses are throttled: five from one address, then a 429 for 15 minutes.
  • Once the first administrator exists, first run is closed for everyone. There is no setup code to find afterwards and nothing reopens it.
  • The setup code is never emailed and never in a response. A Windows service keeps it in a protected file instead of a log, because every local user can read the Windows Application log and whoever saw the code first could create the administrator. The file is deleted the moment the first administrator exists, and a restart before then replaces it with a fresh code.

What you see first

An empty home page with two big starting points (Flowchart and Architecture), shortcuts for ER, UML class, BPMN, swimlane and org-chart starting points, importers for SQL and Mermaid, and a small link, Add four sample diagrams. Samples are offered, never forced: nothing creates them until you press that link, and it appears only on an empty list. It adds a flowchart, an architecture, a sequence and an ER diagram, each titled "Sample: …". They are ordinary documents. Edit or delete them freely.

The empty home page: a Documents heading, buttons for Bin, Import SQL, Import Mermaid and New diagram, a heading No documents yet, two cards for Flowchart and Architecture, links to start from an ER diagram, UML class diagram, BPMN process, swimlane diagram or org chart, and an Add four sample diagrams link with a note under it.
A fresh instance, signed in as the new administrator. A note under the top bar says the copy is an unlicensed evaluation: everything works, nothing is limited.
The Documents list after pressing Add four sample diagrams: Sample: Shop schema, Sample: Checkout, Sample: Order service and Sample: Order approval, newest first.
After pressing Add four sample diagrams.

Help, About and the Status page

  • Help menu. In the editor, the menu (the three-line button at the top left) ends with a Help group: the command palette (Cmd/Ctrl+K), Keyboard shortcuts (press ?), Documentation and About. The shortcut sheet is built from the same list of commands as the palette, so it cannot drift from what the keys do.
  • About (top bar) is the same for every signed-in person: version, build date, licence state in one word, the support contact and documentation address from draughtsman.yaml, and a link to the third-party notices. It never shows the data folder or anything about the host.
  • Admin, Status (administrators only) says what this server is running and what is not: the layout service, PDF export, the AI provider, storage, the data folder and where the log goes, and the version. It is read-only and carries the reasons, including the exact advice when PDF export is switched on but cannot print.
The editor menu scrolled to its end: Tidy layout and Align commands, then Command palette Cmd+K, Keyboard shortcuts ?, Documentation and About.
The end of the editor menu: the Help entries.
The About Draughtsman page: version 0.1.0, build date 1 October 2026, licence Unlicensed evaluation, the support contact, the documentation address and a link to the third-party licences.
About. The same for everyone who is signed in.
The System status page: layout service OK, PDF export OK using Google Chrome, AI provider off, storage SQLite, the data folder and version 0.1.0 built 2026-10-01, with a Refresh button.
Admin, Status. Here PDF export is on (through an installed Chrome) and the AI provider is off, and each line says what it needs.

If you lose the only administrator

A reset link needs an administrator to create it, and Forgot password? needs email, so neither helps when the only administrator is locked out. On purpose there is no way to recover an administrator account over the network. (For everyone else, see Password recovery and email.) On the server itself, as a user who can write the data folder:

draughtsman reset-admin admin@example.com --generate

Run against a scratch data folder, it printed:

Password reset for fixture-admin@example.invalid. Their sessions and API tokens were revoked.
New password (shown once): 4yN3hrFUfnS3RwQPjdVhrYBK                                  (exit 0)

It reactivates the account if it was deactivated, revokes its sessions and API tokens, and ends any reset link that account held, records an admin.recovered event in the security log naming the operating-system user who ran it. An Editor's address is refused unless you add --promote; an unknown address is refused too:

fixture-editor@example.invalid is not an administrator. Re-run with --promote to make them one.     (exit 1)
No account with the email 'nobody@example.invalid'.                                                  (exit 1)

The trust model is that anyone with shell access to the host could already edit the database; the command makes recovery supported and logged. In Docker use docker exec <container> draughtsman reset-admin <email> --generate.

Next