Skip to content

Domains overview

miaomiaowuX can use up to three domains, one for each kind of visitor:

Domain Who uses it Paths allowed Where to set it Required
Master domain Browsers of admins and users (the panel); also serves subscriptions and Agents when the others are not set Everything System Settings → “System” → Master Server URL Yes
Subscription domain Proxy clients fetching subscriptions and reporting allowlist IPs Subscription paths (/x/*, subscription endpoints, /api/fw/*) System Settings → “System” → Subscription URL Optional
Report domain (Agent connection address) The Agent on every server: long-lived connection, heartbeats, traffic reports, install script /api/remote/* (including WebSocket) System Settings → “System” → Agent connection address Optional

The last two are optional: when they are not set, subscription links and Agents simply use the master domain.

  • Keep the panel hidden: subscription links get shared and imported into all kinds of clients; an Agent runs on every server. With a single domain, anyone holding a subscription link or logging into any server knows where the panel is. Once split, opening the panel on the subscription or report domain returns 404.
  • Route them differently: the subscription domain can sit behind a CDN or Cloudflare Tunnel so users fetch subscriptions faster; the report domain resolves on its own, so changing the panel domain never touches the Agents.
  • Isolate blocking risk: if one domain gets blocked or abused, only one kind of access is affected and you can replace it without touching the other two.
Scenario Recommendation
Personal use, a few servers Master domain only
Several users, subscription links are handed out Master + subscription domain
Many servers, you do not want every Agent to know the panel domain All three

All three can be subdomains covered by one certificate (for example panel., sub. and agent. under a wildcard *.example.com).

  1. Set up the master domain and HTTPS following the deployment tutorial and make sure the panel opens.
  2. Add the subscription domain when needed: after saving, every subscription URL copied or pushed from the panel, the TG Bot and the Mini App switches to it.
  3. Configure the report domain last: it is pushed to every Agent in three steps — check, single-server test, switch all. See Report domain.

Full example (three domains on one master)

Section titled “Full example (three domains on one master)”

Say the panel panel.example.com, subscriptions sub.example.com and reports agent.example.com all resolve to the master, which listens on the default port 12889. With Caddy the whole /etc/caddy/Caddyfile is (Caddy issues the certificates):

# Master domain: everything allowed
panel.example.com {
reverse_proxy 127.0.0.1:12889
}
# Subscription domain: subscription paths only
sub.example.com {
@subscriptions path /x/* /api/fw/* /api/clash/subscribe /api/user/package-subscribe /api/subscribe
handle @subscriptions {
reverse_proxy 127.0.0.1:12889
}
handle {
respond 404
}
}
# Report domain: Agent communication only
agent.example.com {
@agent path /api/remote/*
handle @agent {
reverse_proxy 127.0.0.1:12889
}
handle {
respond 404
}
}

With Nginx, use one server block per domain plus a reject-unknown-domains catch-all; see:

After setting up the reverse proxy, remember to fill in the matching addresses in System Settings → “System”; otherwise links generated by the panel keep using the master domain.