Documentation
Mistgate documentation
Mistgate is a self-hosted panel for your own VPN fleet: one binary for the panel, one for the node agent, Hysteria2 and AmneziaWG in one subscription. This documentation describes what the code does today; features that are still being built are marked Planned.
On this page
What is where#
| Section | For |
|---|---|
| Getting started | The concepts, what you need, and the path from an empty server to the first user with a working subscription. |
| Guide | Day-to-day work in the admin: nodes, profiles, protocols, WARP, users, subscriptions, the user page, DNS. |
| Operations | Keeping the fleet healthy, updated and safe, and what to do when something breaks. |
| Reference | Exact commands, flags, environment variables, the API, the MCP server and how the parts fit together. |
Reading order for a new admin#
- Overview and Requirements: what a panel, a node and a profile are, and what servers you need.
- Install the panel, then Add a node.
- First users: a profile on the node, a group, a user, a subscription link.
- Health and Security before you give links to other people.
- The Guide pages as you need them; the Reference when you script or automate.
All pages#
Getting started#
- Overview: what Mistgate is and its concepts: panel, node, profile, server on a node, user, group, device, subscription, user page.
- Requirements: what the panel and the nodes need, and what you need to build from source.
- Install the panel: from a fresh Linux server to the owner account in the admin.
- Add a node: enroll a server with the agent and see it come online.
- First users: put a profile on a node, give it to a group, create a user and send the link.
Guide#
- Nodes: node settings, status and what the agent does on the host.
- Profiles: what a profile is and how it becomes a server on a node.
- Hysteria2: Hysteria2 profile settings, certificates and obfuscation.
- AmneziaWG: AmneziaWG 2.0 and 3.1 profiles, userspace or the kernel module, devices and keys.
- WARP: sending a profile's traffic out through Cloudflare WARP.
- Users and groups: users, groups, devices, traffic limits and terms.
- Subscriptions: one link per person and which format each app gets.
- User page: the person's own page with instructions, a QR code and traffic.
- DNS: DNS presets for users and groups, and the DNS of the nodes.
Operations#
- Health: client-eye checks, the node doctor and alerts.
- Updates: node self-update, release keys, rollouts, and updating the panel.
- Security: admin sign-in, roles, step-up, sessions, audit, the decoy site and the hidden admin, the data directory and backups, recovering access.
- Troubleshooting: common problems and how to find their cause.
Reference#
- CLI: every
mistgateandmistgate-nodecommand and flag. - Configuration: every
serveandsetupflag, everyMISTGATE_*environment variable, and the data directory layout. - API: the Connect API, API tokens and their profiles.
- MCP: the MCP server, the stdio proxy, the tools, plan / apply and approvals.
- Architecture: how the panel, the agents and the clients talk to each other.
- FAQ: short answers to common questions.