mistgate Docs
Documentation

Mistgate documentation

Mistgate is a self-hosted panel for your own VPN fleet: one binary for the panel, one for the node agent, Hysteria2 and AmneziaWG in one subscription. This documentation describes what the code does today; features that are still being built are marked Planned.

On this page

What is where#

Section For
Getting started The concepts, what you need, and the path from an empty server to the first user with a working subscription.
Guide Day-to-day work in the admin: nodes, profiles, protocols, WARP, users, subscriptions, the user page, DNS.
Operations Keeping the fleet healthy, updated and safe, and what to do when something breaks.
Reference Exact commands, flags, environment variables, the API, the MCP server and how the parts fit together.

Reading order for a new admin#

  1. Overview and Requirements: what a panel, a node and a profile are, and what servers you need.
  2. Install the panel, then Add a node.
  3. First users: a profile on the node, a group, a user, a subscription link.
  4. Health and Security before you give links to other people.
  5. The Guide pages as you need them; the Reference when you script or automate.

All pages#

Getting started#

  • Overview: what Mistgate is and its concepts: panel, node, profile, server on a node, user, group, device, subscription, user page.
  • Requirements: what the panel and the nodes need, and what you need to build from source.
  • Install the panel: from a fresh Linux server to the owner account in the admin.
  • Add a node: enroll a server with the agent and see it come online.
  • First users: put a profile on a node, give it to a group, create a user and send the link.

Guide#

  • Nodes: node settings, status and what the agent does on the host.
  • Profiles: what a profile is and how it becomes a server on a node.
  • Hysteria2: Hysteria2 profile settings, certificates and obfuscation.
  • AmneziaWG: AmneziaWG 2.0 and 3.1 profiles, userspace or the kernel module, devices and keys.
  • WARP: sending a profile's traffic out through Cloudflare WARP.
  • Users and groups: users, groups, devices, traffic limits and terms.
  • Subscriptions: one link per person and which format each app gets.
  • User page: the person's own page with instructions, a QR code and traffic.
  • DNS: DNS presets for users and groups, and the DNS of the nodes.

Operations#

  • Health: client-eye checks, the node doctor and alerts.
  • Updates: node self-update, release keys, rollouts, and updating the panel.
  • Security: admin sign-in, roles, step-up, sessions, audit, the decoy site and the hidden admin, the data directory and backups, recovering access.
  • Troubleshooting: common problems and how to find their cause.

Reference#

  • CLI: every mistgate and mistgate-node command and flag.
  • Configuration: every serve and setup flag, every MISTGATE_* environment variable, and the data directory layout.
  • API: the Connect API, API tokens and their profiles.
  • MCP: the MCP server, the stdio proxy, the tools, plan / apply and approvals.
  • Architecture: how the panel, the agents and the clients talk to each other.
  • FAQ: short answers to common questions.