i
iptunnel admin console
Dashboard
Users Redeem Codes Leaderboard
Support Broadcast
Servers Managed operations Tweaks
Publish Import History
Activity Ad Settings Settings
AD
Admin Signed in
Operations Live configuration
Admin plane
Control plane / overview

Network command

Live infrastructure, audience, release, and economy signals in one operating view.

Operator queue
0Servers
0Tweaks
0Users
0Open tickets
0Redeem codes
1.0Config version
01 / Reliability

Thirty-day network ledger

Loading…

02 / Audience

Active network pulse

Loading…

03 / Geography

Connection field

Loading map…

04 / Adoption

Revenue and client adoption

AdMob revenue

Loading…

Client versions

Loading…

05 / Operations

What needs an operator

Publish queueScheduled configuration releases

Loading…

Recent activityLatest administrative changes

Loading…

Coin economyCodes and distribution state

Loading…

Audience / accounts

Users

Coin accounts keyed by device — search, filter, grant, and ban

0
Backend API: checking…
Device ID Coin balance Last active Status Actions
Loading users…
0 selected
Suspicious activity auto-ban Rules

No scan yet.

Coin balance bands: 1000+ 100–999 50–99 10–49 <10 · click “Coin balance” to sort · banning resets coins to zero

Support / inbox

Support

Threaded user tickets — reply, set priority, and track status

Admin 0
User 0
Resolved 0
Closed 0
Shown 0
Ticket Subject Latest message Device Priority Status Actions
Loading tickets…

Ticket workspace

No ticket selected
Select a ticket from the table to inspect the thread.

Details

Ticket
-
Status
Priority
Subject
-
Category
-
Device
-
Protocol
-
Created
-
Updated
-
Handled by
-

Workflow

Conversation

Sending a reply moves the ticket to “Waiting user”.
Economy / redemption

Redeem Codes

Mint codes and run coin compensation

Code generator

Format: encrypted <expiryMillis@coins> — compatible with the current app redeem flow.

New users (automatic)

Onboarding bonus granted to every new install.

Loads current policy when opening this page.

Existing users (run once)

One-time compensation for users already registered.

Run a dry run to see affected users before applying.

Communications / push

Broadcast

Push notification to every user via the FCM topic

Compose

History

FCM topic sends do not return recipient totals — delivery shows only when a compatible app reports a confirmed receipt.

Economy / ranking

Leaderboard

Weekly rewarded-ad competition — Top 10 incl. ties win Premium Server

Current week

RankDevice IDNameValid adsReward
Loading…

Ties share a rank — two users at #10 are both #10 and the next is #12. All tied users at the cutoff receive the reward.

Completed weeks

WeekWindow (UTC)ClosedParticipantsRewardActions
Loading…

Export produces a winners CSV (device ID, rank, score, Premium expiry) for announcements.

Pro users

Device IDNameActivated (UTC)Expires (UTC)StatusPremium server
Loading…

Every activation is recorded in the coin ledger (APP_ACTIVATE_PRO, −200) and the Activity log.

Network / inventory

Servers

Endpoint registry — hosts, ports, credentials, protocol payloads

Health probes run every 30 s; the draft feeds backend validation and publish.
S/N Status Name Flag SSH host SSH SSL Proxy Latency Actions
No servers configured
Add your first endpoint — host, ports, and credentials.
Network / profiles

Tweaks

Connection payloads, SNI, DNS and proxy routes by type

S/N order controls app-side priority.
S/N Name Flag Type SNI / Host Proxy Actions
No tweaks configured
Add payloads and routes the app can combine with servers.
Configuration / ingest

Import

Load an existing config into the panel draft

Paste config

Only needed if your config was generated with a different key.
Revenue / inventory

Ad Settings

AdMob unit IDs and timer behavior shipped inside the config

Ad units

Changes are stored in the draft config — publish to ship them.

Configuration / release

Publish v1.0

Ship the draft config to every app user over OTA

Release state

Release

Must be higher than the live version for apps to update.

Publishing encrypts the draft, snapshots it into History, and replaces the live OTA config for all users.

JSON preview

{}

Scheduled publish

Queue the current draft to publish automatically at a future time.

Loading…

Pre-publish validation

TCP-checks every draft server's SSH, SSL, and proxy ports before you ship.

Coin OTA rewards

Targeted coin rewards for specific devices, delivered through the encrypted app endpoint.

Each reward remains valid for 24 hours in the app flow (based on the Date field).

System / policy

Settings

API endpoint, app policy, storage, and Firebase

API Update policy Security Storage Defaults Firebase
Admin credentials live server-side only — in api/v2/.env (ADMIN_USER / ADMIN_PASS_HASH). They are never stored in the browser.

API

Full URL to the backend API. Via file:// the default fallback is the production endpoint unless overridden here.

App update policy

0 disables the check.
Turn on only after all app users are on builds that send X-App-Session.

App security

If on, the import signing key must be configured and all .ipt/cloud imports must be signed.

Blocks legacy (v1) auth — only session_v2 clients accepted, and forces signed imports on.

Strict mode is on: legacy auth blocked, signed imports forced. Use Require app session separately for Play Integrity.

Emergency switch for app_coin_sync writes.

Protects against abnormal coin jumps from modified clients.

Caps old-style codes not generated in the server pool.

Keep off in production. Logs are masked and .log files are blocked via .htaccess.

These devices skip strict mode, signatures, and session checks entirely. Debug/test builds only — keep empty in production.

Storage backend

SQL migration is conflict-safe. Back up first — existing SQL rows are never overwritten automatically.

Storage status not loaded yet.

Backend
-
Driver
-
Requested driver
-
Available drivers
-
Driver available
-
DSN
-
Mirror
-
Error
-

Default server credentials

Returned to app clients via the signed app policy; used only when per-server fields are empty.

Admin credentials

Changing the panel login is a server-side edit:

  1. Edit api/v2/.env on the server.
  2. Set ADMIN_USER to the new username.
  3. Generate a hash: php -r "echo password_hash('NEWPASS', PASSWORD_DEFAULT);"
  4. Paste it into ADMIN_PASS_HASH.

Firebase Firestore

Firebase config from Console → Project Settings. Stored in browser localStorage — clearing browser data removes it.

Save applies to localStorage; “Apply now” re-initializes the SDK immediately.

Managed operations

Device assignments and protocol-specific monitoring.

System / audit

Activity

Coin ledger and authentication audit

-- entries
TimeActionDevice IDBeforeAfterDeltaSource
Loading…
Configuration / history

History

Config snapshots, diffs, and rollback — newest 50 kept

Config diff

i
iptunnelnetwork operations
Private control plane

Operate the network.
Ship with confidence.

Infrastructure health, app configuration, user economy, and releases share one authenticated workspace.

Health telemetry Signed publishing Audience control
Authorized access

Sign in to continue

Use your admin credentials for this control plane.

Encrypted admin session

Server profile
Identity & Ordering
Set target row number, else add at end.
Host IP & Ports
Proxy & Access Credentials
Name Server & Public Key
Certificates & Profiles
Hysteria
Tweak profile
Identity & Type
Set target row number, else add at end.
Network Flags (V2Ray only)
Routing & Payload