A self-hosted web control panel for Mihomo
(Clash Meta core) — manage the service, routing rules, proxy servers and
proxy-groups from a browser, without hand-editing config.yaml or restarting
the service yourself.
Not affiliated with the Mihomo/Clash Meta project.
Those are excellent dashboards for Mihomo's own Clash-compatible API, but that
API is read/control-only - there's no way to add a rule or add a proxy
server through it. MCPOr edits config.yaml directly instead (safely - see
below), on top of everything the Clash API already gives you (live delay
tests, connection stats, group switching).
- Service control: start/stop/restart Mihomo, run
mihomo -tconfig validation, see live status. - Rule constructor: add/delete/reorder simple rules (domain, domain-suffix, domain-keyword, IP-CIDR, RULE-SET, ...) through a form - no YAML by hand.
- Rule-provider management: point a rule at any external auto-updating
domain list (ad-block lists, category lists, anything published in Clash's
rule-providersformat) - Mihomo refreshes it on its own schedule, no scripting needed on your end. - Proxy servers: add by pasting a share link (
hysteria2://,trojan://,vpn://for AmneziaWG in its classic WireGuard-config format), with a preview you must confirm before anything is written. Delete, force a delay test. - Proxy-groups: change type (
select/url-test/fallback/load-balance/relay) and parameters, manage membership and order, see live per-member connection stats. - Safe apply workflow: every change is backed up, written, validated with
mihomo -t, and only then applied via a debounced service restart (batches rapid edits into one restart instead of hammeringsystemctl) with an automatic revert-on-timeout watchdog if the new config doesn't come up healthy. - English/Russian UI, light/dark theme.
- Linux with systemd, Mihomo already installed and running as a systemd
service (tested against a root-owned
/root/.config/mihomoinstall - see Configuration below if yours differs). - Python 3.11+.
- Root (needed for
systemctland for writing Mihomo's config file). - Tested on Debian/Ubuntu. Other distros should work but
python3-venvmay have a different package name.
git clone https://github.com/<you>/mcpor /opt/mihomo-control
cd /opt/mihomo-control
sudo ./install.shThe installer asks a handful of questions (Mihomo's config directory, binary
path, service name, Clash API address, the port MCPOr itself should listen
on, and - if you're putting it behind a reverse proxy - that proxy's IP), then
sets up a venv, generates an admin password (printed once - save it, e.g. in
a password manager), and registers/starts the mihomo-control systemd unit.
Open http://<host>:8097 (or whatever port you chose) and log in.
Read install.sh before running it as root - it's short and worth
understanding, especially since it's about to manage your network's routing.
Settings live in /opt/mihomo-control/.env (or wherever install.sh was
pointed), read by app/settings.py. All are optional - defaults match a
standard root-owned Mihomo install:
| Variable | Default | Meaning |
|---|---|---|
MCPOR_MIHOMO_CONFIG_DIR |
/root/.config/mihomo |
Directory containing config.yaml |
MCPOR_MIHOMO_BINARY |
/usr/local/bin/mihomo |
Path to the mihomo binary (used for -t validation) |
MCPOR_MIHOMO_SERVICE |
mihomo.service |
systemd unit name for Mihomo itself |
MCPOR_CLASH_API_BASE |
http://127.0.0.1:9090 |
Mihomo's Clash-compatible API address |
MCPOR_APP_DIR |
/opt/mihomo-control |
Where MCPOr's own files (venv, secrets) live |
MCPOR_TRUSTED_PROXY_IPS |
(empty) | Comma-separated IP(s) of a reverse proxy in front of MCPOr, if any - see Security below |
To change a setting after install, edit the .env file and
systemctl restart mihomo-control.
- Single admin password (bcrypt-hashed, never stored in plaintext), session cookie, exponential-backoff rate limiting on login attempts.
- MCPOr is meant for a trusted network (your LAN) or behind your own
authentication layer. If you expose it beyond your LAN (e.g. via a reverse
proxy with TLS), also set
MCPOR_TRUSTED_PROXY_IPSto that proxy's IP - otherwise the rate limiter can be trivially bypassed by spoofingX-Forwarded-For(which uvicorn itself will also blindly trust from that same address unless you additionally restrict it -install.shhandles this for you when you answer the reverse-proxy question). - MCPOr runs as root and rewrites live routing config - review changes
before running an unattended upgrade, and keep an eye on the automatic
config backups it creates (
config.yaml.bak-<timestamp>, pruned to the most recent 30). - No telemetry, no calls to anything other than your own Mihomo instance and whatever rule-provider URLs you configure.
cd /opt/mihomo-control
git pull
sudo ./install.sh
systemctl restart mihomo-controlUpdates are never automatic - you decide when to pull.
MIT - see LICENSE.
See SECURITY.md - please don't open a public issue.
