A fast, beautiful VPN panel on the mihomo core β one command to install, nothing to babysit.
English Β· Π ΡΡΡΠΊΠΈΠΉ
On a fresh Ubuntu 22.04+ or Debian 12+ server (amd64 or arm64):
curl -fsSL https://github.com/Miroshka000/mikan/releases/latest/download/install.sh | sudo bashThe installer asks for the panel language and an optional domain, checks that the domain points to the server, installs Docker if needed, picks REALITY camouflage sites next to your server and prints your admin link. Run mikan again at any time for the management menu.
A node for an existing panel: the panel's Nodes page (or mikan node add) gives the command with its key:
curl -fsSL https://github.com/Miroshka000/mikan/releases/latest/download/install.sh | sudo bash -s -- --join KEYWithout questions, for scripts: β¦ | sudo bash -s -- --yes --lang en --domain vpn.example.com --email you@example.com (all flags: mikan install --help).
|
mikan watches whether real clients still reach each protocol. When a port gets blocked on the way, it moves the protocol to a free HTTPS port; when a REALITY camouflage site stops working, it picks a new one next to your server. |
Subscriptions detect the app β Happ, v2RayTun, Koala Clash, Clash Verge, FlClash, Hiddify, Shadowrocket and more β and hand it only the protocols it actually supports. No more βit doesn't work for meβ. |
|
mihomo is embedded as a library, so traffic is counted per user on every connection β not sampled. Plans by time and gigabytes, billing days, device limits and device binding against key sharing. |
Subscribers check their plan, devices and connection guides in a bot you set up in the panel, open the subscription page as a Telegram Mini App and get notified before it expires. They can also buy and renew β Telegram Stars, cards and SBP through YooKassa, or crypto through CryptoBot β and the panel hands out the link by itself. Broadcasts respect Telegram's limits. |
|
Go and SQLite, two small containers. On a working server with clients: ~14 MB RAM for the panel, ~40 MB for the VPN core, <1% CPU. |
Secret admin link on a random port, HTTPS with Let's Encrypt (even for a bare IP), argon2id, TOTP 2FA, CSRF protection, strict CSP, audit log. Containers run non-root, read-only, with all capabilities dropped. |
|
Each node can have its own WARP β registered in one click or from your WireGuard config β and protocols can leave through another node of the panel (client β node A β node B β internet). Chosen protocols, domains and networks take those ways out, everything else goes direct. |
A REST API documented right in the panel, with read-only or full-access keys for bots, billing and monitoring. |
![]() |
![]() |
![]() |
![]() |
Fifteen protocols, each a preset with keys generated for you. The subscription gives every app only what it runs:
| Protocol | Clash apps mihomo core |
Xray apps Happ, v2RayTun |
sing-box apps Hiddify, Karing |
|---|---|---|---|
| VLESS Β· REALITY Β· Vision | β | β | β |
| VLESS Β· REALITY Β· XHTTP | β | β | β |
| VLESS Β· REALITY Β· gRPC | β | β | β |
| VLESS PQ (post-quantum encryption) | β | β | β |
| Trojan Β· REALITY | β | β | β |
| Hysteria2 | β | β | β |
| TUIC v5 | β | β | β |
| AnyTLS | β | β | β |
| TrustTunnel | β | β | β |
| ShadowQUIC | β | β | β |
| Mieru | β | β | β |
| Shadowsocks-2022 ΒΉ | β | β | β |
| Sudoku ΒΉ | β | β | β |
| Snell ΒΉ | β | β | β |
| VMess (custom config) | β | β | β |
ΒΉ One key for all users in mihomo: no per-user accounting or limits on these. Newer protocols are sent to Clash apps only when their core is new enough.
flowchart LR
A[Browser] -- HTTPS, secret link --> P[mikan panel<br>users Β· plans Β· subscriptions]
P -- unix socket / pinned TLS --> N1[mikan node<br>mihomo inside]
P -- pinned TLS --> N2[remote node]
C[VPN apps] -- REALITY Β· QUIC Β· β¦ --> N1
C --> N2
C -. subscription .-> P
The panel and the node are two processes from one image. Update or restart the panel β VPN keeps running. Add remote nodes with a join key from the Nodes page.
Run mikan for the menu, or use the commands directly:
| Command | What it does |
|---|---|
mikan status |
containers, versions, health, available update |
mikan logs [panel|node] |
live logs |
mikan url |
admin link |
mikan reset-password Β· reset-path Β· disable-2fa |
regain access |
mikan update |
update now (backup first, automatic rollback) |
mikan backup Β· restore FILE |
backups in /opt/mikan/backups |
mikan node β¦ Β· mikan inbound β¦ |
nodes and protocols |
mikan targets scan Β· apply |
REALITY camouflage sites next to the server |
mikan join KEY |
on a node: take a new key from the panel |
mikan restart |
restart the containers |
mikan uninstall |
stop and remove the command, keep the data |
The panel checks for a new release once a day and shows what changed. Turn on auto-update in settings, or press Update β the host updater pulls the image from GitHub Packages, backs up, restarts and rolls back if the new version does not come up healthy. Every release manifest is signed.
docker buildx build -t mikan:dev . # panel + node image
cd web && pnpm install && pnpm dev # admin UI with hot reload
go test ./... # Go 1.27
cd installer && cargo test # the installer (Rust)Development happens on the dev branch; pull requests into main are built and tested, releases are published from tags.
mikan is free software under the GNU GPL v3. It embeds mihomo (GPL-3.0). Fonts: Unbounded, Onest, JetBrains Mono (SIL OFL 1.1).





