Users & Plans
Everything about selling and managing accounts.
Creating a user
- Open Users → New user.
- Pick a username (English letters, digits,
_, 3–32 chars). - Select one or more protocols — any mix of VLESS, REALITY, VMess, Trojan, Shadowsocks, Hysteria2, WireGuard, OpenVPN.
- Set volume (GB) and duration (days).
- Optional: note, device limit, start-on-first-use. Save.
The panel generates all secrets instantly (UUIDs, X25519 keys, OpenVPN certificates from its own CA) and shows the subscription link + QR.
Plan mechanics
| Option | What it does |
|---|---|
| Volume (GB) | Traffic quota. At 100% the subscription stops working until you add volume or reset usage. |
| Duration (days) | Expiry date counted from creation — unless start-on-first-use is on. |
| Start on first use | Expiry countdown begins at the user's first subscription fetch. Ideal for pre-sold codes. |
| Device limit | Informational cap shown in Clash configs (# zefira-device-limit); enforced by compatible clients. |
| Active toggle | Instantly disables every protocol without deleting the account. |
Managing users
- Extend / top-up: edit a user to add days, add volume, reset usage, change note or device limit, set an exact expiry.
- Reset token: rotates the subscription token and all protocol secrets — use when a link leaks.
- Search: the Users search box matches username and note (special characters are escaped safely).
- Dashboard: totals, expiring-soon (7 days), out-of-volume, disabled and pending-start counters.
Templates
Save recurring plans (Templates) — name, protocols, volume, days, first-use and device limit — then create users from a template in one click. Template names allow letters, digits, spaces, _ and -.
Inbounds
Extra ports per protocol (Inbounds): give VLESS port 443 and 8443, each with its own host. Subscription links and Clash configs include every enabled inbound automatically, labeled with the inbound name.
Tunnels (BackPack)
Register Iran ⇄ Kharej tunnels: transport, both IPs, tunnel port, forwarded ports, UDP flag. Zefira stores an encrypted token per tunnel, generates a step-by-step setup guide for both servers, and can probe the Iran endpoint (Check now) with automatic online/offline status.
Anti-censorship settings
| Setting | Effect |
|---|---|
| REALITY keys | Generate an X25519 keypair; private key stays encrypted, reveal is audit-logged. |
| REALITY SNI list | Comma-separated SNIs, rotated across the generated links. |
| Obfuscated host | Replaces the real domain inside configs with a decoy host. |
| Per-user subdomain | Prefixes a per-user hash (a1b2c3d4.domain) so links are not correlatable. |
| CDN SNI spoofing | Uses a separate CDN domain for TLS SNI. |
| Block direct IP | Returns 403 for panel/API access via raw IP — domain only. |
Site blocker
Append blocked domains to every Clash config (DOMAIN-SUFFIX,…,REJECT), plus a one-click porn preset (15 major domains). Max 500 custom entries.
Backup & restore
- Download Backup exports users, admins (password hashes), settings, templates and blocklist as JSON — asks for your password first.
- Restore asks for your current password, wipes users, then re-imports — bad rows are skipped, good rows kept, and every setting is re-validated.
ZEF