cPanel for Mac: the hosting page as an app of its own

A search for cPanel for Mac returns two kinds of page, and neither one is usually what was wanted. Most of the results are step by step guides for adding a cPanel mailbox to Apple Mail. The rest are catalogue listings that promise a desktop app. The actual question behind the search is normally simpler than either: the hosting panel is reached by typing an IP address and a port number into a browser, that tab keeps getting lost, and something better than a bookmark would be welcome.

Two different questions wear the same search

It is worth separating them, because one of the two has an answer that most of the ranking tutorials skip.

The first question is about mail. Someone has a mailbox on a cPanel server and wants it in Apple Mail. The long route is what the tutorials describe: find the incoming and outgoing server names, the ports, the authentication settings, and enter them by hand. The short route is documented but rarely mentioned. cPanel's Webmail interface has a section called Set up email on your device, which sends setup instructions and configuration scripts to an address, with a device chosen from a menu and checkboxes for email, calendar and contacts. The documentation adds one warning worth reading before relying on it: a downloaded script configures email only, and calendars and contacts have to be set up through the emailed version with those boxes ticked. For anyone who prefers to type the values, the Mail Client Manual Settings interface is where they come from.

The second question is about the panel itself. That one is about where a web interface lives on a Mac, and it has nothing to do with mail. The rest of this article is about the second question, because it is the one with no tutorial.

There is no cPanel client to install

cPanel is server software. A hosting company licenses it, installs it on the server, and the interface is served from that machine over HTTPS. There is no consumer download, and cpanel.net's own navigation reflects that: product, solutions, pricing, partners, documentation. Nothing for a Mac.

Access is by address and port, and the documentation is explicit about it.

To access cPanel, enter your server's IP address or your domain name and the 2083 port in your preferred browser. Source: docs.cpanel.net

There are three interfaces, on three ports, and they are genuinely separate destinations rather than tabs of one thing. The cPanel account interface is on 2083. WHM, which requires the root user or a reseller account, is on 2087. Webmail is on 2096. Each one has its own login screen, and a person with a reseller account plus a mailbox on the same server has three different things to sign into.

That is the shape of the problem. What a browser tab holds badly is not one site but several near identical sites with numeric addresses. Three panels on one server, multiplied by however many servers are involved, produces a set of tabs that cannot be told apart from their titles.

Why an address with a port number is the worst kind of bookmark

The URL visible in the address bar after signing in is not the URL to save, and the documentation explains why.

Security tokens help to prevent unauthorized use of a website through Cross-Site Request Forgery (XSRF). Security tokens contain the string cpsess and a 10-digit number. Source: docs.cpanel.net

The server appends that token to the session's URL. Copy the address bar contents into a bookmark and the bookmark carries a token belonging to a session that has since ended. The result is the classic cPanel annoyance: a saved link that worked yesterday and today lands on a login screen or an error.

The URL that is stable is the short one, protocol plus address plus port, with no path after it. That is the value worth putting somewhere permanent. It is also the value nobody remembers, because it contains an octet sequence or an unfamiliar hostname and a four digit number.

This is precisely the case a standalone window handles well, and for reasons that have nothing to do with speed. A window has a name chosen by the person who made it, so it can be called after the client rather than after the software. It has an icon, so three servers can be distinguished at a glance instead of by reading truncated tab titles. It has a fixed Dock position, a Cmd+Tab entry and a Spotlight name. And it has one fixed opening URL, set once, so the stable short address is never typed again.

A web app functions independently of Safari. It shares no browsing history, cookies, website data, or settings with Safari. Source: support.apple.com

Safari's route is File then Add to Dock, and the window's settings panel exposes Application Name, Application URL and Icon, which are exactly the three fields this problem needs. What a purpose built window covers is set out on the Features page.

The session rules that decide whether it stays signed in

A hosting panel is not an ordinary website, and three documented behaviours decide whether a permanently open window is realistic. All three are worth knowing before building one.

The first is cookie IP validation, a WHM setting with a documented default of strict.

This setting validates IP addresses for cookie-based logins. This denies attackers the ability to capture cPanel session cookies in order to gain access to your server's cPanel and WHM interfaces. Source: docs.cpanel.net

Strict requires the access address and the cookie address to match exactly. Loose only requires the same class C subnet. Disabled turns the check off. The consequence for daily use is direct: turning a VPN on or off, moving from an office network to a phone hotspot, or holding a dynamic address that rotates will end the session. That is the setting behind most of the mysterious logouts, and it is the host's to configure, not the user's.

The second is the pair of referrer safety checks. One requires any request to carry a referral URL, the other requires that URL to match the destination exactly. Both are documented as off by default and both carry a caution that enabling them can break integrations with other systems and login applications. If a host has enabled them, an unusual client can be refused where a plain browser is accepted.

The third is the one that catches multi window setups.

2FA supports only one concurrent session for any user. If you open several browser windows to cPanel and WHM and log out in one of them, the server logs out all the other windows. Source: docs.cpanel.net

For one account with two factor authentication enabled, two simultaneous windows are not a supported arrangement. Separate windows are for separate accounts, not for one account twice. Getting that distinction right at the start avoids building something that logs itself out.

What the panel is actually used for, and how often

The frequency pattern is what decides whether any of this is worth setting up, and it is unusual.

A hosting panel is not opened for an hour. It is opened for ninety seconds, several times a week, usually because something is wrong or something needs to go live. A DNS record needs editing in Zone Editor. A file needs replacing in File Manager. A mailbox needs creating in Email Accounts. A WordPress installation needs a plugin rolled back through WP Toolkit. A site needs restoring from Backup Wizard. Disk usage needs checking before an upload.

Short and frequent is the exact pattern a browser tab handles worst. The visit is too brief for the search to be worth it, and too infrequent for the tab to still be where it was left. So the tab either gets closed and reopened by typing the address again, or it survives for weeks as one of forty and gets closed by accident during a cleanup.

There is a second reason the timing matters. A good share of these visits happen while something is broken, which is the worst moment to be hunting for an address and a password. A window that opens on the right panel already signed in removes two steps from an incident, and those two steps are the ones that get fumbled under pressure.

Several clients, several panels

Agencies and freelancers are the group this actually bites, because they hold accounts on servers belonging to other people.

A browser stores one session per site per profile. Three clients on three different hosts are three different hostnames, so those coexist in one browser without trouble. The problem arrives when two accounts share a hostname, which happens constantly on shared hosting, where dozens of customers reach the same panel address with different usernames. In one browser profile that is one session, and switching between two of those accounts means signing out and back in.

Windows built as separate applications each carry their own profile, cookies and storage, so two accounts on the same host can both stay signed in with two differently named icons. The naming matters more here than anywhere else, because the addresses are identical and the only distinguishing information is whatever label was chosen.

External authentication is worth knowing about alongside this. cPanel's documentation describes signing in through an identity provider such as cPanelID, a Google account, or the hosting provider's own portal, and notes that one provider can be linked to several cPanel accounts, with the login interface then offering a choice between them. Whether it is offered is the host's decision, so it is a question to ask rather than a setting to look for.

Route Setup Dock and Cmd+Tab Session per window Own name and icon Suits
Typed address and port None No No No Rare visits
Bookmark One click No No Name only One server, if the short URL was saved
Pinned tab One click No No Favicon only One server, daily
Safari, Add to Dock Two clicks Yes Yes Yes One or two panels
Chrome, install page as app Three clicks Yes Follows the Chrome profile Yes Already on Chrome
Site to app tool Pick the URL once Yes Yes, per app Yes Several clients or servers

Chrome's equivalent is the three dot menu, then Cast, save, and share, then Install page as app.

A web app is an app built for the web that you can access on any device. Source: support.google.com

The caveat is that a window created from a Chrome profile keeps sharing that profile's session, so two accounts on the same hostname still need two Chrome profiles first. Other panels and dashboards that end up in the same situation are listed on the Supported services page.

What to change first

Take the short form of the address, protocol plus hostname plus 2083, and make that the fixed opening URL of a window named after the server or the client rather than after the panel. Never save a URL containing a cpsess token, because it belongs to a session that has already ended. If several accounts share one panel address, one permanently signed in Kagemusha window per account keeps them apart, with the caveat that two windows into the same account will fight over a single two factor session.

Frequently asked questions

Is there a cPanel app for Mac?

No. cPanel is software that a hosting company installs on a server, and its interface is served to a browser over HTTPS on port 2083. There is no client to download for macOS, which is why the practical answer is a window built from that address rather than an installer.

Why does a saved cPanel link stop working?

Because the address bar contains a session token. cPanel's documentation states that the server appends a security token containing the string cpsess and a ten digit number to the session URL to prevent cross site request forgery. A bookmark made from that address carries an expired token, so the stable thing to save is the short address with the port and nothing after it.

Why does the cPanel session keep logging out?

Most often because of cookie IP validation, a WHM setting whose documented default is strict, meaning the access address and the cookie address must match exactly. Switching a VPN on or off, moving to a phone hotspot, or holding a rotating address will invalidate the session. The setting belongs to the server administrator.

Can two cPanel windows be open at once?

For two different accounts, yes, provided each window keeps its own session. For one account with two factor authentication enabled, no: the documentation states that 2FA supports only one concurrent session per user, and logging out in one window logs out the others.

What is the fastest way to get a cPanel mailbox into Apple Mail?

Through Webmail rather than by typing server settings. The Set up email on your device section emails setup instructions and configuration scripts for a chosen device, and a downloadable script is also offered. Note that the downloaded script configures email only, so calendars and contacts need the emailed version with those boxes selected. The Mail Client Manual Settings interface holds the same values for anyone who prefers to enter them by hand.

Back to all posts