ZefiraZEFIRA Docs Changelog Donate GitHub ↗

Subscriptions & Clients

How users connect with one link.

Every user gets a unique URL:

https://vpn.example.com/sub/9f2c…a41b

User dashboard page

When the subscription link is opened in a browser, the user gets a personal dashboard instead of raw text: username and status, usage ring with used/total, days left and expiry, last active time and IP (every subscription fetch is recorded, so a shared link shows up as an unfamiliar IP), one-tap import buttons (v2RayNG, Clash, sing-box), copyable per-protocol links, WireGuard/OpenVPN configs, QR code and recommended apps per platform.

VPN clients (v2rayNG, Clash, Streisand…) always receive raw subscription bytes — detection is by User-Agent, and anything unknown defaults to raw so no client ever breaks. Expired, disabled or out-of-volume users get 404 in both modes.

Formats

RequestGets
/sub/TOKEN in v2rayNG, Streisand, FoXray…Base64 subscription with all VLESS / VMess / Trojan / SS / Hy2 links (plus WireGuard & OpenVPN sections when enabled)
/sub/TOKEN?format=clash or any Clash user-agentClash YAML: proxies, Zefira select group, block rules, MATCH
PlatformClients
Androidv2rayNG, NekoBox
iOSStreisand, FoXray, Shadowrocket
WindowsNekoRay, Clash Verge, Hiddify
macOS / LinuxClash Verge, Hiddify, Nekoray

QR & config bundles

Custom subscription path

During install (or via SUBSCRIPTION_PATH) you can rename /sub to anything, e.g. /s — links become https://domain/s/TOKEN. Obscurity is not security, but it cuts scanner noise.