m-uising-box panel
sing-box panel by Maoyangui

An embedded sing-box control plane, in one binary

m-ui runs sing-box inside the panel process instead of babysitting an external one. You manage lines (protocol + port → exit) rather than inbound, outbound and route objects; users and upstreams hot-reload without dropping anyone; every apply is dry-run first and rolled back if it fails; and one master keeps any number of servers in sync.

bash <(curl -fsSL https://raw.githubusercontent.com/Maoyangui/m-ui/main/deploy/install.sh)

One static binaryNo Docker, no external databaseHot user & upstream reloadOne master, any number of nodesGPL-3.0

m-ui dashboard with traffic chart, data-plane status, online users and top talkers

Why m-ui

Not another Xray wrapper. These are the parts that are actually different.

Embedded sing-box

The core runs inside the panel binary. No separate service to install, version-match or restart by hand — the panel talks to it in-process.

A line is one thing

Inbound protocol + port → where it exits. No inbound / outbound / routing tables to keep in sync. Hysteria2, AnyTLS, TUIC, VLESS Reality, Trojan, VMess, Shadowsocks 2022.

Hot user and upstream updates

Adding, disabling or re-keying a user swaps the inbound user table in place. Changing an exit swaps the outbound. Nobody else gets disconnected.

Validated before it ships

Every save is parsed by sing-box first. A bad config never reaches the database, and if a new config still fails to start, m-ui rolls back to the last working one.

One master, many nodes

Lines, users and credentials are pushed to every node every 5 seconds. Traffic and online IPs flow back, quota and device limits are enforced centrally.

Ops without a terminal

Let's Encrypt, Cloudflare WARP, kernel tuning, backup and restore, a migration wizard, Telegram alerts, two-factor login and a one-click updater — all in the panel.

From empty server to first subscription

A domain is recommended, not required — an IP with a self-signed certificate is a fully supported path.

  1. InstallOne command on Debian / Ubuntu. Log in at :2053/app/.
  2. CertificateIssue one for your domain, or self-sign with one click.
  3. LinePick a protocol from the quick-add menu; a free port is filled in for you.
  4. UserCreate the first user — the detail drawer opens with the subscription link and QR code.
  5. SubscriptionClash, sing-box or universal links, plus a landing page with usage and one-tap import.

Read the full getting-started guide →

Multi-server without the spreadsheet

Install m-ui on each server, flip one to node mode, paste its pairing info into the master. Every line is listed once per server in the subscription, so clients pick the lowest-latency entry themselves.

Servers page: one master and two nodes, both online and synced

How master/node sync works →

What your users get

A subscription link that works in Clash, sing-box, Shadowrocket, Stash and Hiddify, and a landing page that explains itself: usage, expiry, one-tap import, QR code, client downloads. When a subscription runs out, the browser shows why and who to contact — not a blank 404.

User detail drawer with subscription URLs, QR code, usage and traffic chart
Subscription landing page on a phone: usage, expiry, one-tap import

Free, GPL-3.0, one binary

Linux amd64 / arm64. SQLite for state, vanilla JS for the UI, no build chain, no external database.

Star or fork on GitHub Community showcases

Quick answers

Do I need a domain?

No. Self-sign a certificate with one click and use the server IP; clients are told to allow the insecure certificate automatically. A domain lets you issue a real certificate and drop that warning.

Is this a fork of an existing panel?

m-ui has its own data model (lines instead of inbound/outbound/routing tables), its own embedded data plane and its own sync protocol. It can import a legacy panel database so existing clients keep working after a switch.

Does it phone home?

No telemetry. The only outbound calls are the ones you configure: certificate issuance, WARP, Telegram, and a version check against GitHub Releases every 6 hours.

What does it run on?

Linux, amd64 or arm64, with systemd. A 1 vCPU / 1 GB VPS is plenty for the panel itself.

More questions →