← Back
Miroshka000

Miroshka000/mikan

🍊 A fast, beautiful VPN panel on the mihomo core β€” one command to install, nothing to babysit.

View on GitHub β†—
anytlsclash-metahysteria2mihomosing-boxtrojanvlessvless-grpcvless-realityvless-reality-visionvless-xhttp-realityvpn-panel-managementxrayxray-app
Stars
29
Forks
6
Watchers
29
Open issues
8
Contributors
1
Language
Go
License
GNU General Public License v3.0
Default branch
main
Created Sep 28, 2026Updated Oct 1, 2026

Star growth

Todayβ€”
This weekβ€”
This monthβ€”

Star history will appear here once this repo has been tracked for a couple of days.

README

mikan β€” VPN panel on the mihomo core

A fast, beautiful VPN panel on the mihomo core β€” one command to install, nothing to babysit.

Release Image License mihomo

English Β· Русский


Install

On a fresh Ubuntu 22.04+ or Debian 12+ server (amd64 or arm64):

curl -fsSL https://github.com/Miroshka000/mikan/releases/latest/download/install.sh | sudo bash

The installer asks for the panel language and an optional domain, checks that the domain points to the server, installs Docker if needed, picks REALITY camouflage sites next to your server and prints your admin link. Run mikan again at any time for the management menu.

A node for an existing panel: the panel's Nodes page (or mikan node add) gives the command with its key:

curl -fsSL https://github.com/Miroshka000/mikan/releases/latest/download/install.sh | sudo bash -s -- --join KEY

Without questions, for scripts: … | sudo bash -s -- --yes --lang en --domain vpn.example.com --email you@example.com (all flags: mikan install --help).

Why mikan

πŸ›‘οΈ Survives blocking on its own

mikan watches whether real clients still reach each protocol. When a port gets blocked on the way, it moves the protocol to a free HTTPS port; when a REALITY camouflage site stops working, it picks a new one next to your server.

πŸ“± Every app gets what it can use

Subscriptions detect the app β€” Happ, v2RayTun, Koala Clash, Clash Verge, FlClash, Hiddify, Shadowrocket and more β€” and hand it only the protocols it actually supports. No more β€œit doesn't work for me”.

πŸ“Š Byte-exact accounting

mihomo is embedded as a library, so traffic is counted per user on every connection β€” not sampled. Plans by time and gigabytes, billing days, device limits and device binding against key sharing.

πŸ€– Telegram bot and Mini App built in

Subscribers check their plan, devices and connection guides in a bot you set up in the panel, open the subscription page as a Telegram Mini App and get notified before it expires. They can also buy and renew β€” Telegram Stars, cards and SBP through YooKassa, or crypto through CryptoBot β€” and the panel hands out the link by itself. Broadcasts respect Telegram's limits.

πŸͺΆ Light as a mandarin

Go and SQLite, two small containers. On a working server with clients: ~14 MB RAM for the panel, ~40 MB for the VPN core, <1% CPU.

πŸ”’ Locked down by default

Secret admin link on a random port, HTTPS with Let's Encrypt (even for a bare IP), argon2id, TOTP 2FA, CSRF protection, strict CSP, audit log. Containers run non-root, read-only, with all capabilities dropped.

🌐 WARP and server cascades

Each node can have its own WARP β€” registered in one click or from your WireGuard config β€” and protocols can leave through another node of the panel (client β†’ node A β†’ node B β†’ internet). Chosen protocols, domains and networks take those ways out, everything else goes direct.

🧩 API and keys for integrations

A REST API documented right in the panel, with read-only or full-access keys for bots, billing and monitoring.

Screenshots

Overview Users
Protocols Telegram bot

Subscription page Β Β  Overview on a phone

Protocols

Fifteen protocols, each a preset with keys generated for you. The subscription gives every app only what it runs:

Protocol Clash apps
mihomo core
Xray apps
Happ, v2RayTun
sing-box apps
Hiddify, Karing
VLESS Β· REALITY Β· Vision βœ… βœ… βœ…
VLESS Β· REALITY Β· XHTTP βœ… βœ… β€”
VLESS Β· REALITY Β· gRPC βœ… βœ… βœ…
VLESS PQ (post-quantum encryption) βœ… βœ… β€”
Trojan Β· REALITY βœ… βœ… βœ…
Hysteria2 βœ… βœ… βœ…
TUIC v5 βœ… β€” βœ…
AnyTLS βœ… β€” βœ…
TrustTunnel βœ… β€” β€”
ShadowQUIC βœ… β€” β€”
Mieru βœ… β€” β€”
Shadowsocks-2022 ΒΉ βœ… βœ… βœ…
Sudoku ΒΉ βœ… β€” β€”
Snell ΒΉ βœ… β€” β€”
VMess (custom config) βœ… βœ… βœ…

ΒΉ One key for all users in mihomo: no per-user accounting or limits on these. Newer protocols are sent to Clash apps only when their core is new enough.

How it works

flowchart LR
    A[Browser] -- HTTPS, secret link --> P[mikan panel<br>users Β· plans Β· subscriptions]
    P -- unix socket / pinned TLS --> N1[mikan node<br>mihomo inside]
    P -- pinned TLS --> N2[remote node]
    C[VPN apps] -- REALITY Β· QUIC Β· … --> N1
    C --> N2
    C -. subscription .-> P
Loading

The panel and the node are two processes from one image. Update or restart the panel β€” VPN keeps running. Add remote nodes with a join key from the Nodes page.

Managing the server

Run mikan for the menu, or use the commands directly:

Command What it does
mikan status containers, versions, health, available update
mikan logs [panel|node] live logs
mikan url admin link
mikan reset-password Β· reset-path Β· disable-2fa regain access
mikan update update now (backup first, automatic rollback)
mikan backup Β· restore FILE backups in /opt/mikan/backups
mikan node … Β· mikan inbound … nodes and protocols
mikan targets scan Β· apply REALITY camouflage sites next to the server
mikan join KEY on a node: take a new key from the panel
mikan restart restart the containers
mikan uninstall stop and remove the command, keep the data

Updates

The panel checks for a new release once a day and shows what changed. Turn on auto-update in settings, or press Update β€” the host updater pulls the image from GitHub Packages, backs up, restarts and rolls back if the new version does not come up healthy. Every release manifest is signed.

Building from source

docker buildx build -t mikan:dev .            # panel + node image
cd web && pnpm install && pnpm dev            # admin UI with hot reload
go test ./...                                 # Go 1.27
cd installer && cargo test                    # the installer (Rust)

Development happens on the dev branch; pull requests into main are built and tested, releases are published from tags.

License

mikan is free software under the GNU GPL v3. It embeds mihomo (GPL-3.0). Fonts: Unbounded, Onest, JetBrains Mono (SIL OFL 1.1).

Made with 🍊