Skip to content

All settings screens ​

Ten screens, reached from Settings in the sidebar. This page is the full field reference — one section per screen.

ScreenRouteMinimum role
General /admin/settings/generalAdministrator
Appearance /admin/settings/appearanceAdministrator
Search /admin/settings/searchAdministrator
SEO /admin/settings/seoAdministrator
Email /admin/settings/mailAdministrator
SMS /admin/settings/smsAdministrator
Firebase /admin/settings/firebaseAdministrator
Social links /admin/settings/socialAdministrator
Shop /admin/settings/shopAdministrator
Advanced /admin/settings/advancedAdministrator

Administrator only

Settings screens are administrator-only. Editors stop at content.

Three of these screens belong to modules and disappear when the module is off: SMS, Firebase and Shop.

General ​

Site identity, contact details, branding and timezone.

The General settings screen with site name, tagline, contact fields, logo uploads, timezone and maintenance mode
FieldTypeDefaultNotes
Site nametextRadiusRequired. Used in titles and emails
TaglinetextA fast, modular CMS
Contact emailemail—Where contact form notifications go
Contact phonetext—
Addresstextarea—Appears on invoices
Logoimageshipped fileFor light backgrounds
Logo for dark backgroundsimagefalls back to LogoOnly needed if your logo vanishes on dark
Faviconimageshipped file
TimezoneselectUTCAffects every displayed date and scheduled post
Date formatselectd M Y
Languageselecten
Maintenance modebooleanoffHolding page for visitors; signed-in admins still browse
Maintenance messagetextareaa default sentence

Set the timezone before scheduling anything

A scheduled post's time is interpreted in this timezone. Changing it later does not move already-scheduled posts.

See Branding for how the two logo inks resolve.

Appearance ​

Theme selection, colour scheme, and the three injection points for custom code.

The Appearance settings screen with active theme, primary colour, colour scheme, items per page and the custom CSS and JS fields
FieldTypeDefaultNotes
Active themeselectdefaultSame list as Appearance → Themes
Primary colorcolor#2563ebThemes that read it use it as their accent
Color schemeselectsystemAlways light, always dark, or follow the visitor
Items per pagenumber12Pagination for posts and products. 1–100
Custom CSScode—Injected into the front-end <head>
Custom JScode—Injected before the closing </body>
Header scriptscode—Analytics, pixels and verification tags

Custom CSS is the right place for small visual tweaks. It survives theme updates, where edits to a theme's own files do not.

Header scripts and Custom JS run on every page

Anything pasted here executes for every visitor. Paste only what you understand and control — your own analytics snippet, not a "free widget" from a forum.

Custom CSS and header scripts arrive via @stack('head'), and Custom JS via @stack('scripts'). A theme omitting those directives silently ignores all three fields — see Building a theme.

How visitors search the site: which engine answers, whether results appear while typing, and what is searchable. Site search explains the choices in full.

FieldTypeDefaultNotes
Search engineselectDatabaseDatabase or Index. Choosing Index builds the index on save
Show results while typingbooleanonLive dropdown under search boxes
Start after this many charactersnumber21–10
Results per group while typingnumber51–20
Search blog postsbooleanonNo effect while the Blog module is off
Search productsbooleanonNo effect while the Shop module is off
Search pagesbooleanon
Site-wide results page at /searchbooleanonTurn off if you have your own page at /search
Live searches allowed per visitor per minutenumber60Rate limit on live results
Remember live results for (seconds)number60Database engine only. 0 turns it off

Below the form, the Search status card shows what the index holds for each kind of content, with a Rebuild index now button.

SEO ​

Site-wide defaults. Anything set per page overrides these.

The SEO settings screen with default meta title and description, social share image, schema type, sitemap toggle and robots.txt editor
FieldTypeDefaultNotes
Default meta titletextRadiusFallback when a page sets none
Title separatortext|Between page title and site name
Default meta descriptiontextarea—
Default meta keywordstext—Ignored by Google; harmless
Default social share imageimage—Used when a page has no featured image
Site schema typeselectOrganizationOr Person, etc.
Organization / person nametext—
Schema logoimage—
Twitter / X handletext—Without the @
Generate sitemap.xmlbooleanonServes /sitemap.xml
robots.txtcodedisallows admin, cart, checkoutServed dynamically
Discourage search enginesbooleanoffSite-wide noindex
Google Analytics IDtext—Format G-XXXXXXXXXX
Google site verificationtext—

Turn off "Discourage search engines" before launch

It is useful while building and catastrophic if forgotten. It adds a site-wide noindex, and no amount of good content outranks that.

Do not add a static public/robots.txt

public/robots.txt is deliberately absent. A static file there would shadow the dynamic route this module serves, and your edits in this screen would stop having any effect.

The SEO section ​

Beyond this settings screen there is a SEO section in the sidebar with per-route meta overrides and redirect management:

The SEO section listing site routes with their resolved meta title and description, each editable
The redirect manager, listing source path, destination and redirect type

Add a redirect whenever you change a published slug. That is what keeps an existing ranking and any inbound links working.

The Ping sitemap button notifies search engines that your sitemap changed.

Email ​

Order confirmations, password resets and contact notifications all depend on this screen.

The Email settings screen with provider selection, from address, SMTP fields and the API-key provider notice
FieldTypeDefaultNotes
Mail providerselectsmtpSMTP, Resend, Amazon SES, Postmark, or log only
From addressemail—
From nametextRadius
SMTP hosttext—SMTP only
SMTP portnumber587SMTP only
SMTP usernametext—SMTP only
SMTP passwordsecret—SMTP only. Encrypted at rest
EncryptionselecttlsTLS, SSL or none

API-key providers read from .env ​

Resend, SES and Postmark take their keys from .env, not from this screen. API keys are deliberately kept out of the database, because a database backup travels more casually than a server does.

Provider.env keysPackage to install
ResendRESEND_KEYcomposer require resend/resend-laravel
Amazon SESAWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_DEFAULT_REGIONcomposer require aws/aws-sdk-php
PostmarkPOSTMARK_TOKENcomposer require symfony/postmark-mailer

The screen shows which keys are present and which package is missing. If a provider is not installed, mail falls back to the log rather than failing silently — so check the screen rather than assuming a quiet send worked.

Always press Send test email

It is on this screen. A misconfigured mail setup is invisible until a customer cannot reset their password.

SMS ​

Transactional SMS and OTP login. Needs the SMS module.

The SMS settings screen with provider selection and the MSG91 and Twilio credential fields
FieldTypeDefaultNotes
Enable SMSbooleanoff
Providerselectmsg91MSG91, Twilio, or log only
MSG91 auth keysecret—
MSG91 sender IDtext—
MSG91 routetext4
MSG91 DLT template IDtext—Required for Indian numbers
Twilio account SIDtext—
Twilio auth tokensecret—
Twilio from numbertext—
Allow OTP loginbooleanoffCustomers sign in with a texted code instead of a password

With Allow OTP login on and SMS working, the sign-in page gets a Sign in with a code sent to your phone button. It works only for customer accounts, never staff. The number typed in must match the phone on exactly one active account. The code always goes to the number saved on the account. It expires after 10 minutes and stops working after 5 wrong tries. An account with two-factor authentication still has to pass that step as well.

Indian numbers need DLT registration

MSG91 messages to Indian numbers require a DLT-registered template ID. Without it, delivery fails at the carrier rather than at the API, so the send looks successful.

Firebase ​

Web push notifications. Needs the Firebase module.

The Firebase settings screen with the web app config fields and the service-account credentials notice
FieldTypeNotes
Enable Firebaseboolean
Web API keytextFrom your Firebase web app config
Auth domaintext
Project IDtext
Storage buckettext
Messaging sender IDtext
App IDtext
Measurement IDtext
Web push VAPID keytextCloud Messaging → Web Push certificates

Server credentials go on disk, not in this screen. Upload your service-account JSON to:

storage/app/firebase/service-account.json

or point FIREBASE_CREDENTIALS in .env at its path.

The service worker is served from the site root at /firebase-messaging-sw.js, because a service worker can only control pages at or below its own path.

The Social links settings screen with URL fields for each network
FieldType
Facebookurl
Instagramurl
Twitter / Xurl
LinkedInurl
YouTubeurl
WhatsApp numbertext

Empty fields are skipped rather than rendered as dead icons. These feed both the theme footer and the builder's Social icons widget.

Enter the WhatsApp number in international format, for example +91 98765 43210. It becomes a click-to-chat wa.me link. You can also paste a full https://wa.me/... link.

Shop ​

Needs the shop module. Set currency before adding products.

The Shop settings screen with currency, tax, shipping, checkout, stock and download options
FieldTypeDefaultNotes
CurrencyselectUSD
Currency symboltext$Filled in for you when you change the currency
Symbol positionselectbeforeBefore or after the amount
Charge taxbooleanoff
Tax rate (%)number00–100
Prices already include taxbooleanoff
Flat shipping feenumber0
Free shipping overnumber00 disables free shipping
Sell toselectThe whole worldSwitch to Only the countries I choose to limit where you take orders from
Countries you sell tomulti-selectnoneA searchable checkbox list. Only shown when Sell to is set to the chosen-countries option. Leaving every box unticked keeps the shop worldwide
Allow guest checkoutbooleanon
Remember customer addressesbooleanonFills checkout in from the address the customer used last time, and gives signed-in customers an address book
Track stock levelsbooleanon
Low stock thresholdnumber5Flags products on the list screen
Order number prefixtextORD-
Terms page slugtexttermsThe page linked from the terms checkbox at checkout and registration. Shown as plain text if no published page has this slug
Downloads per purchasenumber50 for unlimited
Download access expires after (days)number0From the paid date. 0 = forever

Changing currency does not convert prices

Prices are stored as integers in the currency's minor unit. Switching from INR to USD turns ₹499 into $499. See Payment gateways.

Checkout ​

Needs the shop module. Chooses what checkout asks the customer for. Each field is Required, Optional or Hidden. Email address and full name are always required. See Choosing the checkout fields.

FieldDefault
PhoneOptional
Street addressRequired
Apartment, suite, unitOptional
CityRequired
State / regionOptional
Postcode / ZIPOptional
CountryRequired. Always required while Sell to is limited to chosen countries
Order notesOptional

Advanced ​

Caching, reCAPTCHA, registration and two security switches.

The Advanced settings screen with page caching, reCAPTCHA, registration, HTTPS and 2FA enforcement options
FieldTypeDefaultNotes
Cache rendered pagesbooleanoffCaches public HTML for signed-out visitors
Cache lifetime (seconds)number600Minimum 10
Enable reCAPTCHA v3booleanoffApplies to contact, newsletter and registration
reCAPTCHA site keytext—
reCAPTCHA secret keysecret—
Allow public registrationbooleanon
Require email verificationbooleanoffNeeds working email
Force HTTPSbooleanoff
Require 2FA for admin accountsbooleanoffEvery admin must enrol
Delete activity log entries after (days)number450 keeps them forever. See Activity log

How page caching works ​

Only the public content pages are cached: the homepage, pages, blog and shop listings, posts, products and the contact page. A page is never cached for a signed-in visitor, a visitor with items in their cart, or right after a form submission. It is also skipped when the address has query parameters other than ?page=. Each visitor still gets their own security token, so forms on a cached page submit normally.

Saving any content or setting in the admin panel clears every cached page. Orders, carts, sign-ups and form submissions do not. Pages served from the cache do not add to post and product view counts. To check whether a page came from the cache, look for the X-Page-Cache: HIT response header.

reCAPTCHA ​

reCAPTCHA stays off until the switch is on and both keys are filled in. Register a v3 key for your domain at google.com/recaptcha/admin. The script loads only on pages that have a protected form, and it works with any theme. Submissions scoring below 0.5 are refused. If your server cannot reach Google, the check is skipped and a warning is logged, so forms keep working.

Leave page caching off while building

A cached page does not reflect your last edit. If a change is not showing on the public site, this is the first thing to check — then clear the cache under System health.

Two worth turning on for any real site:

  • Require 2FA for admin accounts — especially with more than one admin
  • Force HTTPS — once your certificate is actually working, not before

Do not force HTTPS before the certificate works

You will lock yourself out of a site that now redirects to an address the browser refuses. Fix it by setting force_https back to 0 in the database, or by removing the setting row.

Where settings are stored ​

In the database, not in .env. Two consequences:

  • They survive an update — an update's path allowlist never touches your data
  • They travel in a database backup, which is why API keys are deliberately kept in .env instead

Values marked secret above are encrypted at rest with your APP_KEY and are never sent back to the browser once saved.

Radius is open source under the MIT licence. Security issues go to the address in SECURITY.md, not the public issue tracker.