ZefiraZEFIRA Docs Changelog Donate GitHub ↗

Users & Plans

Everything about selling and managing accounts.

Panel dashboard

The screen you land on after signing in. Counters first, then the machine, then the accounts you created last.

CardWhat it counts
Total usersEvery account on the panel, whatever state it is in
ActiveEnabled and not past its expiry date. The small line underneath adds the three groups that are not in that number: expiring within 7 days, not started yet, and out of volume
ExpiredStill enabled, but the date has passed. They serve a dashboard and no configs
DisabledSwitched off by you. Nothing resolves for them at all
Total sold volumeSum of every plan you sold, with the gigabytes consumed underneath

System status

CPU, memory and disk bars plus the uptime. The card disappears on hosts where the panel cannot read those numbers — that is the server saying no, not a bug to chase.

Latest users

The five newest accounts with their protocols, volume, expiry and status. View all jumps to the full list with the search box and CSV export.

Creating a user

  1. Open Users → New user.
  2. Pick a username (English letters, digits, _, 3–32 chars).
  3. Select one or more protocols — any mix of VLESS, REALITY, VMess, Trojan, Shadowsocks, Hysteria2, WireGuard, OpenVPN, L2TP/IPsec, Cisco AnyConnect, SOCKS5.
  4. Set volume (GB) and duration (days).
  5. Optional: note, device limit, start-on-first-use. Save.

The panel generates all secrets instantly (UUIDs, X25519 keys, OpenVPN certificates from its own CA, L2TP passwords + IPsec PSKs, Cisco/SOCKS5 passwords) and shows the subscription link + QR.

Plan mechanics

OptionWhat it does
Volume (GB)Traffic quota. At 100% the subscription stops working until you add volume or reset usage.
Duration (days)Expiry date counted from creation — unless start-on-first-use is on.
Start on first useExpiry countdown begins at the user's first subscription fetch. Ideal for pre-sold codes.
Device limitInformational cap shown in Clash configs (# zefira-device-limit); enforced by compatible clients.
Active toggleInstantly disables every protocol without deleting the account.

Managing users

AI assistant

The ? bubble (bottom-right of every panel page) chats with an assistant that knows this panel inside-out and answers panel questions only — great for beginners. Groq is the default provider (free and fast): sign up at console.groq.com → API Keys, create a key (gsk_…), then in Zefira go to Settings → AI Assistant, pick Groq, set model qwen/qwen3.8-27b (reliable default; openai/gpt-oss-20b also works for plain Q&A but insists on native tool-calls, which the panel deliberately disables in favor of its provider-agnostic text protocol), paste the key and leave the base URL empty — the panel already knows Groq lives at https://api.groq.com/openai/v1. Enable, save, open the bubble and ask. (Pasting api.groq.com or …/v1 by hand is auto-corrected; a bare wrong URL is what causes the classic provider 404.) OpenAI, Anthropic, Gemini, DeepSeek, OpenRouter and Ollama still work via OpenAI-compatible / native modes. The key is stored encrypted and never shown back; chats are rate-limited (30/hour); Groq's free tier is rate-limited too, so a 429 means wait a bit.

It can also act — just ask: create users, extend days, add volume, reset usage, pause/enable accounts, find users, show stats, hand over subscription links. Examples: “make user ali with 50 gig 30 days vless”, “extend sara 15 days”, “top up reza 20 gig”, “reset usage of omid”, “pause karim”, “link of mina?”, “how many users do I have?” Missing details are asked, never guessed (max 3 operations per turn). Every action runs through the same validation as the panel buttons and is audit-logged (AI_CREATE/AI_PATCH) with your name; new users trigger the usual Telegram notification.

Off-limits for the AI (it explains which button to press instead): deleting users, resetting tokens/keys, backup/restore, updates, settings changes, API tokens, password changes.

Bots & integrations

Settings → API Tokens issues zfp_… bearer tokens for Telegram bots, reseller dashboards and scripts. Send Authorization: Bearer … instead of cookies (then no CSRF header is needed either). Pick a scope at creation:

ScopeCanUse for
botList/search users, lookup by username, create users (incl. start-on-first-use), read stats & templates, own subscription links, QR, developer resets (usage + token renewal)Reseller bots — least privilege, safe to ship
full (default)Everything the creating admin can do (except password-gated actions, which still need the password)Your own dashboards & scripts only

Tokens are shown once, can be revoked instantly, are included in backups, and a bot token gets 403 on deletes, patches, backup/restore, settings, tokens and updates. Guard them like passwords.

Telegram reseller bot in 5 minutes: 1) message @BotFather → /newbot, copy the token; 2) in Zefira create a bot-scoped API token; 3) open examples/telegram-bot-python (or -node), set TELEGRAM_BOT_TOKEN, ZEFIRA_URL, ZEFIRA_API_TOKEN; 4) run it — customers get /buy plans keyboard, instant account + subscription link, /my quota view. Panel-side notifications (user create/delete, brute-force lockouts) are separate: Settings → Telegram Notifications with any bot token + chat ID (message the bot once first, then Send Test).

Panel updates

Update (left menu, above Settings) compares this server with GitHub: current vs latest commit, and the exact incoming changes. Update now asks for your password, then pulls the code, reinstalls dependencies and restarts the panel — watch it poll until it reports the new version. Updates are refused if you have local code changes, and every step is audit-logged.

Appearance & branding

The Personalize menu (left sidebar) holds everything visual: Appearance & Branding personalizes colors (a live /theme.css recolors the panel, login page and every user dashboard), the brand name shown in place of ZEFIRA, and a message pinned on top of all subscription pages — empty color resets to the default red-black. The Menu Layout card reorders the left menu and hides unused sections (Dashboard, Users, Inbounds, Personalize, Settings always stay); User Dashboard Layout reorders or hides the usage, link, configs and apps cards on every customer page. All of it is included in backups.

Account security

Templates

Save recurring plans (Templates) — name, protocols, volume, days, first-use and device limit — then create users from a template in one click. Template names allow letters, digits, spaces, _ and -.

Inbounds

Extra ports per protocol (Inbounds): give VLESS port 443 and One port, one listener: give VLESS port 443 and 8443, each with its own host. Two protocols cannot share a port on the same server — the panel refuses it, and so would your server. The same port IS allowed on a different node, because that is a different machine. An inbound pinned to a node with no host of its own links to that node's address. Subscription links and Clash configs include every enabled inbound automatically, labeled with the inbound name.

Server nodes

Nodes (left menu) registers your remote VPN servers: name, address, check port, note. The panel probes each server every 5 minutes (plus on-demand Check now) and shows live status, latency in ms and uptime %.

Pin any inbound to a node from the Inbounds section (per-row dropdown, or at creation). Links served from a node that goes offline (or is disabled) are automatically left out of subscriptions until it recovers — unchecked nodes keep serving. Deleting a node returns its inbounds to the local panel.

Tunnels (BackPack)

Register Iran ⇄ Kharej tunnels: transport, both IPs, tunnel port, forwarded ports, UDP flag. Zefira stores an encrypted token per tunnel, generates a step-by-step setup guide for both servers, and can probe the Iran endpoint (Check now) with automatic online/offline status.

Anti-censorship settings

SettingEffect
REALITY keysGenerate an X25519 keypair; private key stays encrypted, reveal is audit-logged.
REALITY SNI listComma-separated SNIs, rotated across the generated links.
Obfuscated hostReplaces the real domain inside configs with a decoy host.
Per-user subdomainPrefixes a per-user hash (a1b2c3d4.domain) so links are not correlatable.
CDN SNI spoofingUses a separate CDN domain for TLS SNI.
Block direct IPReturns 403 for panel/API access via raw IP — domain only.

Site blocker

Append blocked domains to every Clash config (DOMAIN-SUFFIX,…,REJECT), plus a one-click porn preset (15 major domains). Max 500 custom entries.

Backup & restore

Backups contain password hashes and encrypted secrets — store them like passwords, never in a public place.