Domains overview
miaomiaowuX can use up to three domains, one for each kind of visitor:
| Domain | Who uses it | Paths allowed | Where to set it | Required |
|---|---|---|---|---|
| Master domain | Browsers of admins and users (the panel); also serves subscriptions and Agents when the others are not set | Everything | System Settings → “System” → Master Server URL | Yes |
| Subscription domain | Proxy clients fetching subscriptions and reporting allowlist IPs | Subscription paths (/x/*, subscription endpoints, /api/fw/*) |
System Settings → “System” → Subscription URL | Optional |
| Report domain (Agent connection address) | The Agent on every server: long-lived connection, heartbeats, traffic reports, install script | /api/remote/* (including WebSocket) |
System Settings → “System” → Agent connection address | Optional |
The last two are optional: when they are not set, subscription links and Agents simply use the master domain.
Why split into three domains
Section titled “Why split into three domains”- Keep the panel hidden: subscription links get shared and imported into all kinds of clients; an Agent runs on every server. With a single domain, anyone holding a subscription link or logging into any server knows where the panel is. Once split, opening the panel on the subscription or report domain returns 404.
- Route them differently: the subscription domain can sit behind a CDN or Cloudflare Tunnel so users fetch subscriptions faster; the report domain resolves on its own, so changing the panel domain never touches the Agents.
- Isolate blocking risk: if one domain gets blocked or abused, only one kind of access is affected and you can replace it without touching the other two.
Recommended setups
Section titled “Recommended setups”| Scenario | Recommendation |
|---|---|
| Personal use, a few servers | Master domain only |
| Several users, subscription links are handed out | Master + subscription domain |
| Many servers, you do not want every Agent to know the panel domain | All three |
All three can be subdomains covered by one certificate (for example panel., sub. and agent. under a wildcard *.example.com).
Order of configuration
Section titled “Order of configuration”- Set up the master domain and HTTPS following the deployment tutorial and make sure the panel opens.
- Add the subscription domain when needed: after saving, every subscription URL copied or pushed from the panel, the TG Bot and the Mini App switches to it.
- Configure the report domain last: it is pushed to every Agent in three steps — check, single-server test, switch all. See Report domain.
Full example (three domains on one master)
Section titled “Full example (three domains on one master)”Say the panel panel.example.com, subscriptions sub.example.com and reports agent.example.com all resolve to the master, which listens on the default port 12889. With Caddy the whole /etc/caddy/Caddyfile is (Caddy issues the certificates):
# Master domain: everything allowedpanel.example.com { reverse_proxy 127.0.0.1:12889}
# Subscription domain: subscription paths onlysub.example.com { @subscriptions path /x/* /api/fw/* /api/clash/subscribe /api/user/package-subscribe /api/subscribe handle @subscriptions { reverse_proxy 127.0.0.1:12889 } handle { respond 404 }}
# Report domain: Agent communication onlyagent.example.com { @agent path /api/remote/* handle @agent { reverse_proxy 127.0.0.1:12889 } handle { respond 404 }}With Nginx, use one server block per domain plus a reject-unknown-domains catch-all; see:
After setting up the reverse proxy, remember to fill in the matching addresses in System Settings → “System”; otherwise links generated by the panel keep using the master domain.