Users & Plans
Everything about selling and managing accounts.
Panel dashboard
The screen you land on after signing in. Counters first, then the machine, then the accounts you created last.
| Card | What it counts |
|---|---|
| Total users | Every account on the panel, whatever state it is in |
| Active | Enabled and not past its expiry date. The small line underneath adds the three groups that are not in that number: expiring within 7 days, not started yet, and out of volume |
| Expired | Still enabled, but the date has passed. They serve a dashboard and no configs |
| Disabled | Switched off by you. Nothing resolves for them at all |
| Total sold volume | Sum of every plan you sold, with the gigabytes consumed underneath |
System status
CPU, memory and disk bars plus the uptime. The card disappears on hosts where the panel cannot read those numbers — that is the server saying no, not a bug to chase.
Latest users
The five newest accounts with their protocols, volume, expiry and status. View all jumps to the full list with the search box and CSV export.
Creating a user
- Open Users → New user.
- Pick a username (English letters, digits,
_, 3–32 chars). - Select one or more protocols — any mix of VLESS, REALITY, VMess, Trojan, Shadowsocks, Hysteria2, WireGuard, OpenVPN, L2TP/IPsec, Cisco AnyConnect, SOCKS5.
- Set volume (GB) and duration (days).
- Optional: note, device limit, start-on-first-use. Save.
The panel generates all secrets instantly (UUIDs, X25519 keys, OpenVPN certificates from its own CA, L2TP passwords + IPsec PSKs, Cisco/SOCKS5 passwords) and shows the subscription link + QR.
Plan mechanics
| Option | What it does |
|---|---|
| Volume (GB) | Traffic quota. At 100% the subscription stops working until you add volume or reset usage. |
| Duration (days) | Expiry date counted from creation — unless start-on-first-use is on. |
| Start on first use | Expiry countdown begins at the user's first subscription fetch. Ideal for pre-sold codes. |
| Device limit | Informational cap shown in Clash configs (# zefira-device-limit); enforced by compatible clients. |
| Active toggle | Instantly disables every protocol without deleting the account. |
Managing users
- Edit (pencil button): change note, total volume, exact expiry, device limit, or reset usage to zero.
- Extend / top-up: edit a user to add days, add volume, reset usage, change note or device limit, set an exact expiry. Extending an expired account counts from today.
- Reset token: rotates the subscription token and all protocol secrets — use when a link leaks.
- Search: the Users search box matches username and note (special characters are escaped safely).
- Dashboard: totals, expiring-soon (7 days), out-of-volume, disabled and pending-start counters.
AI assistant
The ? bubble (bottom-right of every panel page) chats with an assistant that knows this panel inside-out and answers panel questions only — great for beginners. Groq is the default provider (free and fast): sign up at console.groq.com → API Keys, create a key (gsk_…), then in Zefira go to Settings → AI Assistant, pick Groq, set model qwen/qwen3.8-27b (reliable default; openai/gpt-oss-20b also works for plain Q&A but insists on native tool-calls, which the panel deliberately disables in favor of its provider-agnostic text protocol), paste the key and leave the base URL empty — the panel already knows Groq lives at https://api.groq.com/openai/v1. Enable, save, open the bubble and ask. (Pasting api.groq.com or …/v1 by hand is auto-corrected; a bare wrong URL is what causes the classic provider 404.) OpenAI, Anthropic, Gemini, DeepSeek, OpenRouter and Ollama still work via OpenAI-compatible / native modes. The key is stored encrypted and never shown back; chats are rate-limited (30/hour); Groq's free tier is rate-limited too, so a 429 means wait a bit.
It can also act — just ask: create users, extend days, add volume, reset usage, pause/enable accounts, find users, show stats, hand over subscription links. Examples: “make user ali with 50 gig 30 days vless”, “extend sara 15 days”, “top up reza 20 gig”, “reset usage of omid”, “pause karim”, “link of mina?”, “how many users do I have?” Missing details are asked, never guessed (max 3 operations per turn). Every action runs through the same validation as the panel buttons and is audit-logged (AI_CREATE/AI_PATCH) with your name; new users trigger the usual Telegram notification.
Off-limits for the AI (it explains which button to press instead): deleting users, resetting tokens/keys, backup/restore, updates, settings changes, API tokens, password changes.
Bots & integrations
Settings → API Tokens issues zfp_… bearer tokens for Telegram bots, reseller dashboards and scripts. Send Authorization: Bearer … instead of cookies (then no CSRF header is needed either). Pick a scope at creation:
| Scope | Can | Use for |
|---|---|---|
bot | List/search users, lookup by username, create users (incl. start-on-first-use), read stats & templates, own subscription links, QR, developer resets (usage + token renewal) | Reseller bots — least privilege, safe to ship |
full (default) | Everything the creating admin can do (except password-gated actions, which still need the password) | Your own dashboards & scripts only |
Tokens are shown once, can be revoked instantly, are included in backups, and a bot token gets 403 on deletes, patches, backup/restore, settings, tokens and updates. Guard them like passwords.
Telegram reseller bot in 5 minutes: 1) message @BotFather → /newbot, copy the token; 2) in Zefira create a bot-scoped API token; 3) open examples/telegram-bot-python (or -node), set TELEGRAM_BOT_TOKEN, ZEFIRA_URL, ZEFIRA_API_TOKEN; 4) run it — customers get /buy plans keyboard, instant account + subscription link, /my quota view. Panel-side notifications (user create/delete, brute-force lockouts) are separate: Settings → Telegram Notifications with any bot token + chat ID (message the bot once first, then Send Test).
Panel updates
Update (left menu, above Settings) compares this server with GitHub: current vs latest commit, and the exact incoming changes. Update now asks for your password, then pulls the code, reinstalls dependencies and restarts the panel — watch it poll until it reports the new version. Updates are refused if you have local code changes, and every step is audit-logged.
Appearance & branding
The Personalize menu (left sidebar) holds everything visual: Appearance & Branding personalizes colors (a live /theme.css recolors the panel, login page and every user dashboard), the brand name shown in place of ZEFIRA, and a message pinned on top of all subscription pages — empty color resets to the default red-black. The Menu Layout card reorders the left menu and hides unused sections (Dashboard, Users, Inbounds, Personalize, Settings always stay); User Dashboard Layout reorders or hides the usage, link, configs and apps cards on every customer page. All of it is included in backups.
Account security
- Change password (Settings) logs out every other session immediately.
- Backup download asks for your password; there is no password-less export.
Templates
Save recurring plans (Templates) — name, protocols, volume, days, first-use and device limit — then create users from a template in one click. Template names allow letters, digits, spaces, _ and -.
Inbounds
Extra ports per protocol (Inbounds): give VLESS port 443 and One port, one listener: give VLESS port 443 and 8443, each with its own host. Two protocols cannot share a port on the same server — the panel refuses it, and so would your server. The same port IS allowed on a different node, because that is a different machine. An inbound pinned to a node with no host of its own links to that node's address. Subscription links and Clash configs include every enabled inbound automatically, labeled with the inbound name.
Server nodes
Nodes (left menu) registers your remote VPN servers: name, address, check port, note. The panel probes each server every 5 minutes (plus on-demand Check now) and shows live status, latency in ms and uptime %.
Pin any inbound to a node from the Inbounds section (per-row dropdown, or at creation). Links served from a node that goes offline (or is disabled) are automatically left out of subscriptions until it recovers — unchecked nodes keep serving. Deleting a node returns its inbounds to the local panel.
Tunnels (BackPack)
Register Iran ⇄ Kharej tunnels: transport, both IPs, tunnel port, forwarded ports, UDP flag. Zefira stores an encrypted token per tunnel, generates a step-by-step setup guide for both servers, and can probe the Iran endpoint (Check now) with automatic online/offline status.
Anti-censorship settings
| Setting | Effect |
|---|---|
| REALITY keys | Generate an X25519 keypair; private key stays encrypted, reveal is audit-logged. |
| REALITY SNI list | Comma-separated SNIs, rotated across the generated links. |
| Obfuscated host | Replaces the real domain inside configs with a decoy host. |
| Per-user subdomain | Prefixes a per-user hash (a1b2c3d4.domain) so links are not correlatable. |
| CDN SNI spoofing | Uses a separate CDN domain for TLS SNI. |
| Block direct IP | Returns 403 for panel/API access via raw IP — domain only. |
Site blocker
Append blocked domains to every Clash config (DOMAIN-SUFFIX,…,REJECT), plus a one-click porn preset (15 major domains). Max 500 custom entries.
Backup & restore
- Download Backup exports users, admins (password hashes), settings, templates and blocklist as JSON — asks for your password first.
- Restore asks for your current password, wipes users, then re-imports — bad rows are skipped, good rows kept, and every setting is re-validated.
ZEF