Who 3x Ui is for#
Operators managing private proxy nodes
3X-UI handles client provisioning, traffic accounting, and config distribution for operators running one or more Xray-core servers. Per-client quotas, expiry dates, and QR-code share links remove the need to edit raw config files for each user change.
Skip if:
You need enterprise SLA support, multi-tenant billing, or a hosted control plane you do not administer yourself. Commercial VPN management services are a better fit for those requirements.
Developers testing multi-protocol proxy setups
The panel lets developers stand up inbounds for a wide range of protocols without writing Xray JSON by hand. REALITY, XTLS-Vision, and AmneziaWG configurations that require significant manual effort in raw Xray config are available through guided forms in the UI.
Skip if:
Your use case is a single-protocol VPN for personal connectivity with no per-client control needed. A simpler tool like wg-easy is easier to configure and operate for that scenario.
Network operators in regions with deep packet inspection
3X-UI's REALITY, XTLS, and AmneziaWG support directly targets environments where standard VPN protocols are identified and blocked. These circumvention configurations are available through the web UI without manual JSON editing.
Skip if:
DPI circumvention is not a requirement in your network environment. Standard WireGuard or a simpler VPN tool is easier to configure and audit when stealth is not needed.
The problem it solves#
Managing proxy and VPN infrastructure at the server level means living inside configuration files. Every new client requires a manual Xray config edit, a service reload, and careful tracking of who has what access. Traffic accounting, expiry enforcement, and IP limits all need external tooling or manual auditing. As client count grows, a single misconfiguration can expose credentials or drop existing sessions.
Coordinating multiple servers compounds this. Operators running nodes in different regions have to SSH into each one, sync config changes manually, and reconcile traffic stats by hand. Distributing connection links to end users means copy-pasting UUIDs or writing custom scripts to generate QR codes. Commercial VPN management panels solve some of this but lock operators into per-seat pricing and proprietary cloud backends.
How it solves it#
Multi-Protocol Inbound Support
VLESS, VMess, Trojan, Shadowsocks, WireGuard, AmneziaWG, TUIC v5, Hysteria2, MTProto, HTTP, SOCKS, and TUN are all managed from a single panel. Each inbound can be created, edited, or cloned to other nodes without editing Xray's raw JSON config directly.
Per-Client Traffic and Access Controls
Each client gets individual traffic quotas, expiry dates, IP limits with trusted-address exemptions, and HWID device limits. Live online status is visible per client. One-click share links and QR codes let operators distribute connection configs without manual UUID handling.
Multi-Node Coordination
Manage multiple servers from a single panel, clone inbounds across nodes, and aggregate traffic stats. External proxies and managed hosts are supported alongside direct node connections, making it practical for operators running distributed infrastructure.
Built-In Subscription Server
Generates VLESS, Clash, and JSON subscription output automatically, with format auto-selection based on the client's User-Agent. Custom page templates are supported for operators who want branded config delivery pages for their end users.
Telegram and Discord Bot Integration
Built-in bots send notifications for traffic cap hits, expiry warnings, and system load alerts. Bots also support admin actions, so operators can respond to alerts and manage clients without opening the web UI.
REALITY and XTLS-Vision Support
First-class support for VLESS with REALITY, including x25519 key generation, short IDs, and the xtls-rprx-vision flow. This combination targets stealth against deep packet inspection, with configuration available directly from the UI without manual JSON editing.
Strengths and trade-offs#
Strengths
- No client count limits or per-seat feesThe panel runs on your own server with no licensing calls to external services. Unlike OpenVPN Access Server, which requires paid licensing above 2 simultaneous connections, 3X-UI imposes no connection or user limits beyond what your server hardware can handle.
- AmneziaWG without kernel modulesAmneziaWG, the DPI-resistant WireGuard variant, runs on a userspace network stack inside the panel. No DKMS, no kernel patches, and no extra packages are required, which simplifies deployment on VPS providers that restrict kernel module installation.
- Active maintenance and large communityOver 47,780 GitHub stars and regular releases through October 2026 reflect sustained community activity. Security patches, protocol updates, and new platform support follow from this active maintainer and contributor base.
- PostgreSQL backend for high-scale deploymentsSingle-server setups use SQLite by default. Operators managing high client counts or multi-node infrastructure can migrate to PostgreSQL with a built-in migration command without reinstalling the panel or losing existing client data.
Trade-offs
- -Intended for personal use per project READMEThe README explicitly states the project is intended for personal use only and cautions against use in production environments. Operators considering it for team or commercial proxy infrastructure should read this caveat and assess the implications before committing.
- -GPL-3.0 copyleft applies to redistributionsGPL-3.0 requires distributing source changes if you redistribute 3X-UI as a modified version. For most self-hosting operators this has no practical impact. Integrators building commercial products on top of 3X-UI need to comply with the copyleft terms.
- -Fail2ban requires elevated Docker capabilitiesIP limit enforcement via Fail2ban uses iptables, which requires NET_ADMIN and NET_RAW capabilities in Docker. The provided docker-compose file adds these automatically, but bare docker run commands that omit the capability flags will log ban events without applying them.
3x Ui vs alternatives#
3X-UI vs OpenVPN Access Server
Both tools provide a web panel for administering VPN or proxy servers with per-client access controls. The key differences are protocol depth, licensing cost, and DPI circumvention capability.
| Feature | 3X-UI | OpenVPN Access Server |
|---|---|---|
| License | GPL-3.0 | Proprietary |
| Free tier | Unlimited (self-hosted) | 2 simultaneous connections |
| Protocols | VLESS, VMess, Trojan, WireGuard, Hysteria2, and more | OpenVPN, WireGuard |
| Multi-node | Yes | Limited in standard tiers |
| DPI circumvention | Yes (REALITY, XTLS, AmneziaWG) | No |
| Subscription links | Yes (VLESS, Clash, JSON) | No |
| Vendor support | Community | Paid plans available |
3X-UI is the better choice when protocol flexibility or DPI circumvention matters. REALITY, XTLS-Vision, and AmneziaWG are specific to the Xray-core ecosystem and are not available in any commercial panel at any price tier. For operators who need to support many different client apps via subscription links, 3X-UI has no commercial equivalent in that feature set.
OpenVPN Access Server is worth choosing when your environment standardizes on OpenVPN clients, your organization requires enterprise SLA support, or you need a vendor to provide compliance documentation. Its paid tiers include official support contracts that 3X-UI, as a community-maintained project, does not offer.
3X-UI vs Pritunl
Pritunl is a self-hosted VPN server panel with a commercial cloud management tier. Like 3X-UI, the base install runs on your own infrastructure; unlike 3X-UI, its protocol support covers OpenVPN and WireGuard only.
| Feature | 3X-UI | Pritunl |
|---|---|---|
| License | GPL-3.0 | AGPL-3.0 (open), proprietary (cloud tier) |
| Protocols | 15+ via Xray-core | OpenVPN, WireGuard |
| Multi-node | Yes, built-in | Yes, via paid cloud tier |
| DPI circumvention | Yes | No |
| Subscription output | Yes (VLESS, Clash, JSON) | No |
| Vendor support | Community | Paid plans available |
Pritunl fits teams already running OpenVPN or WireGuard who want a polished server management interface and optional commercial support. 3X-UI fits operators who need the broader Xray-core protocol set or require circumvention capabilities that Pritunl cannot provide.
Quick start#
Deploy 3X-UI on any Linux server with the official install script.
```bash
curl -Ls https://raw.githubusercontent.com/mhsanaei/3x-ui/master/install.sh | sudo bash
```What it's built on#
- Languages
- GoTypeScript
- Frameworks
- Next.jsReact
FAQ#
Is 3X-UI free to use?
Yes. 3X-UI is GPL-3.0 licensed and free to run on your own server. There are no client count limits, no per-seat fees, and no licensing calls to external services. Your only recurring cost is the server you run it on.
What VPN and proxy protocols does 3X-UI support?
3X-UI supports VLESS, VMess, Trojan, Shadowsocks, WireGuard, AmneziaWG, TUIC v5, Hysteria2, MTProto, HTTP, SOCKS (Mixed), Dokodemo-door, Tunnel, and TUN through Xray-core. Multiple protocols can share a single port using Xray's fallback feature.
Can 3X-UI manage multiple servers from one panel?
Yes. The multi-node feature lets you manage and scale across multiple servers from a single panel, including cloning inbounds onto other nodes. PostgreSQL is recommended as the backend when running multi-node deployments with high client counts.
How do I install 3X-UI?
Run the one-line install script from the GitHub README on any supported Linux distribution. The installer generates random credentials and sets up a systemd service automatically. Docker is also supported via the official image at ghcr.io/mhsanaei/3x-ui. Full documentation is at docs.sanaei.dev.
Does 3X-UI work on ARM servers and cloud VMs?
Yes. 3X-UI supports amd64, arm64 (aarch64), armv7, armv6, armv5, and s390x architectures. It runs on Ubuntu, Debian, Fedora, CentOS, AlmaLinux, Rocky Linux, Alpine, Arch, and several other distributions. Most standard cloud provider VMs are supported out of the box.
Similar open-source tools#
Vela
OpenStreetMap and Google data, no account, no Play Services
Obtainium
Android app updates direct from GitHub and F-Droid
Cloudflare Os
Open source AI workspace with sandboxed apps and Gatekeeper security
FckSignups
Open-source tools that work instantly, no signup required
fmt
Fast, type-safe C++ formatting that replaces printf and iostreams
ultimate-file-manager-pro
Dual-pane file manager for Android, Android TV, and Windows

