# AirBridge Universe admin and SMS setup

The browser admin page is `/ceri-admin.html`. The page itself contains no
secret. Every admin API request must present the token stored in a file outside
the public web root.

## Private admin token

Create this directory and file through cPanel File Manager, SFTP, or FTP access
to the account home directory:

```text
/home/airbridg/ceri-private/admin-token.txt
```

The file contains exactly one random token of at least 32 characters followed
by an optional newline. Recommended permissions are directory `700` and file
`600`. PHP must be able to read the file. The token must not be placed in
`public_html`, JavaScript, a URL, source control, or the database.

To change the admin token, replace the contents of that file. The next admin
request immediately requires the new value; no service restart is needed.

## SMS admission

Production registration fails closed until SMS is configured. The FTP-friendly
method is to create `/home/airbridg/ceri-private/universe-v3.php` from
`deploy/universe-v3-private.example.php` and fill in the real values. This file
must remain outside `public_html`, with permission `600` where supported.

Environment variables are also supported:

```text
CERI_SMS_PROVIDER=twilio
CERI_TWILIO_ACCOUNT_SID=...
CERI_TWILIO_AUTH_TOKEN=...
CERI_TWILIO_FROM_NUMBER=+1...
CERI_SMS_CODE_SECRET=<random value of at least 32 characters>
```

The Twilio number must be SMS-capable for the countries being admitted. The
verification code is hashed in MySQL, expires after ten minutes, permits no
more than six attempts, and requests are rate-limited by phone and source IP.

## Database migration

Apply `ceri-auth/database/003_phone_admin_tools_and_commerce.sql` once after
migration `002`. Back up the Ceri database first. Migration 003 adds profile,
blocking, SMS-verification, template-price, coupon, and subscription structures
and seeds the always-visible App Creator tool.
