Features
What the panel manages, grouped the way the sidebar is. All of it lives in one binary and one SQLite file.
Lines
A line is inbound protocol + port → exit. Protocols: Hysteria2 (with port hopping), AnyTLS, TUIC, Trojan, VLESS (Reality / Vision), VMess, Shadowsocks including the 2022 ciphers, plus SOCKS, HTTP and Mixed. Transports: WebSocket, gRPC, HTTPUpgrade, HTTP. Each line can be deployed to all servers or a chosen subset. Quick-add presets fill in a free port and sensible options; every save is dry-run through sing-box and port-checked against the panel, other lines and other processes on the box.
Upstreams
Where traffic exits when it should not go direct: VLESS, VMess, Trojan, TUIC, Hysteria2, Shadowsocks and SOCKS outbounds, importable from share links. One-click latency test, scheduled health checks with failure/recovery alerts, and Cloudflare WARP set up from inside the panel. Health is measured on the servers that actually use the upstream: each one checks only what its own lines need, the upstream row shows every server's latency side by side, and alerts name the server that cannot reach it. Changing an upstream hot-swaps the outbound without restarting the data plane.
Users
- Quota, expiry, periodic reset, simultaneous device limit (by source IP, unioned across servers), upload / download speed limits.
- Over-quota and expired users are disabled and kicked automatically; the subscription landing page tells them why.
- Bulk create, bulk enable / disable / extend / reset / delete, CSV export, legacy database import.
- Subscription addresses can be the user name or a random token (setting), and users can generate a temporary share link that you can revoke — revoking cuts the borrower off immediately.
- Adding, disabling or re-keying a user swaps the inbound user table in place: nobody else is disconnected.
Plans
Templates for quota, duration, devices, speed and line assignment. Apply on create, on renewal or when extending. Resellers get their own plans, separate from yours.
Rules
Temporary speed limits layered on top of a user's own. Schedule: chosen weekdays and a time window in the panel time zone, crossing midnight allowed. Burst: X GB within the last N minutes limits the user for M minutes, lifts automatically and applies again on the next burst; a user can be under several rules at once, each independent. Targets are all users, every user of a reseller, or individual users. The master evaluates rules and syncs them to every node; several hits resolve to the strictest, and the default "tighten only" never exceeds the user's own limit. Changes reach live connections immediately, no reconnect needed. The user list shows "Limited"; the landing page never does.
Resellers
Give a reseller a set of lines plus a traffic quota, a device pool, a bandwidth pool and an expiry. Per-user limits are up to the reseller; the pools cap what all of their users can do at the same time. They get their own panel (default port 2054, path /dl) where they create users and plans, set their own landing-page title, notice and contact, and optionally enable two-factor login. All usage rolls up to the reseller; when the reseller is over budget, expired or disabled, every user of theirs is cut off at once. Reseller users are never mixed into your own user list.
Subscriptions
- Three formats from one address: universal links, Clash / Mihomo YAML, full sing-box JSON — chosen by
?format=or the client's User-Agent. - Every line is listed once per server it is deployed on; assignment can be narrowed to one server's entry (users, plans and reseller grants alike); external nodes and external subscriptions can be merged in; expand an external subscription to see each node's full parameters, test them on every server and add the ones you pick as upstreams.
- Browser landing page: usage, expiry, notice, one-tap import for Clash, Shadowrocket, Nextin, sing-box, Hiddify and Stash, QR codes for Clash / universal / sing-box, client download page, temporary sharing.
- Optional traffic-notice node at the top of the list; self-signed certificates automatically add
insecurefor clients. - Dead subscriptions get a short explanation page with your contact details instead of a blank 404.
Servers
One master, any number of nodes. The master pushes lines, upstreams, users and credentials every 5 seconds and pulls back traffic deltas and online IPs; nodes only forward. Per-server traffic ratio, per-server deployment of lines, connection tracking across servers. See Multi-server.
Certificates
Let's Encrypt via HTTP-01 or Cloudflare DNS-01 with DNS and port pre-checks, automatic renewal and hot reload without a restart. No domain? Self-sign with one click. Bring your own certificate files too.
Operations
- Backup / restore: one zip with the database and certificates, scheduled daily backups, restore from the panel, a migration wizard for moving to a new machine.
- Kernel tuning, WARP installation and capping the system journal from the Ops page, with logs streamed to the browser.
- Telegram: alerts for data plane, upstream and node failures, users about to expire or run out, daily report in your time zone.
- Update: the panel checks GitHub Releases every 6 hours; one click verifies the checksum, replaces the binary and restarts. Data, certificates and settings are untouched. Nodes update themselves the same way.
- Logs and audit trail in the panel, each with its own auto-clean retention; the SSH menu (
m-ui) for port, path, password and emergency recovery.
Security
Two-factor login (TOTP), login rate limiting per IP, sessions scoped per role, reseller isolation enforced server-side, checksum-verified downloads for the installer and the updater, no telemetry. Config changes never bypass validation.
External API
A token-authenticated HTTP API for creating and updating users, reading usage and fetching subscription links — for shops, bots and automation. Documented in docs/API.md.