Files
3x-ui/docs
ilyusha af3e6c11b6 docs(api): document WireGuard and mtproto secret generation on clients/add (#6282)
* docs(api): document WireGuard and mtproto secret generation on clients/add

The POST /panel/api/clients/add summary enumerated the protocols whose
secrets the server fills in, and that list stopped being complete when
WireGuard gained per-client keys and mtproto gained a FakeTLS secret.
Read literally it says the endpoint is unusable for WireGuard without a
hand-made keypair and address, while defaultWireguardClients in fact
generates the keypair, derives the public key from a supplied private
one, and allocates a free /32.

Rather than extend an enumeration that goes stale on every new protocol,
the summary now states the rule alone and the per-protocol detail moves
into the operation description - a field Endpoint already declares and
build-openapi.mjs already maps, but that no endpoint used until now.
Swagger UI in the panel and the docs site both render it.

The attach operation gets the rule added for #5785 that nothing
documented: a client already carrying allowedIPs brings them into the
new inbound instead of being given a fresh address, and is rejected when
another client of that inbound holds it.

Closes #6276

* docs(api): correct the clients/add generation rules flagged in review

Three claims in the new description did not hold:

Shadowsocks does not keep every supplied password. fillProtocolDefaults
regenerates it when validShadowsocksClientKey rejects it, which on a
2022-blake3-* inbound means any password that does not base64-decode to
16 or 32 bytes - the call still returns success, so the caller has to
read the client back to notice. Split off from Trojan and spelled out.

The UUID is not always fresh: re-adding an email that already exists,
with the stored subId, reuses the stored id, password, auth and secret
so the identity stays in sync across its inbounds. That branch was
documented nowhere.

The mtproto secret falls back to www.cloudflare.com when the inbound
carries no fakeTlsDomain.
2026-08-22 20:37:39 +02:00
..
2026-07-09 00:45:35 +02:00

3x-ui

3x-ui Documentation

The official documentation and product site for 3x-ui — an advanced web panel for managing Xray-core servers.

Live site CI License: GPL-3.0 Next.js 16 Fumadocs 16

Read the docs →


Overview

This directory (docs/ in the 3x-ui monorepo) contains the source for docs.sanaei.dev — a static-first documentation and marketing site built with Fumadocs on Next.js. It has no backend, no database, and no auth: every page is prerendered and every tool runs entirely in the browser.

What's inside

The documentation walks you through 3x-ui from first install to day-to-day operation:

  • Getting Started — installation, first login, and updating or uninstalling the panel.
  • Configuration — the panel, inbounds, REALITY, transports, clients, subscriptions, and share links.
  • Operations — reverse proxy, multi-node setups, outbounds & routing, backup/restore, the Telegram bot, and security.
  • Reference — environment variables, the database, ports & firewall, and the HTTP API.
  • Help — troubleshooting, FAQ, migration, and how to contribute.

Interactive tools

The site ships with in-browser helpers that generate configuration for you — no data ever leaves your browser:

Tool What it does
REALITY Config Generator Build a valid REALITY inbound configuration.
Share Link Inspector Decode and inspect vless:// / vmess:// share links.
Install Command Builder Assemble the right install command for your setup.
Reverse Proxy Generator Generate reverse-proxy configs (Nginx / Caddy).
Protocol Wizard Pick and configure the right protocol for your needs.
Firewall Rules Generator Produce firewall rules for your ports.

Tech stack

Layer Technology
Framework Next.js 16 (App Router) · React 19
Docs Fumadocs (-ui / -core / -mdx)
Styling Tailwind CSS v4
Search Orama static index
Language TypeScript (strict)
Tests Vitest for the pure lib/xray logic
Tooling pnpm · oxlint · oxfmt

Quick start

This project uses pnpm (npm lockfiles are gitignored). Run everything from the docs/ directory:

cd docs
pnpm install
pnpm dev        # http://localhost:3000

Useful scripts:

Script Description
pnpm dev Start the dev server
pnpm build Production build (also typechecks)
pnpm typecheck Generate MDX/route types and tsc --noEmit
pnpm lint Run oxlint (.oxlintrc.json)
pnpm test Run unit tests (Vitest)

See CONTRIBUTING.md for the full list and project conventions.

Project structure

app/             # Next.js App Router — layouts, home, docs, OG images, search, llms.txt
components/      # React components — interactive tools, home sections, MDX bindings
content/docs/    # MDX documentation, one folder per locale (en · fa · ru · zh)
lib/             # source config, i18n, GitHub stats, and the unit-tested lib/xray logic
public/          # static assets — logos, favicon, openapi.json, CNAME
scripts/         # build-time scripts (API reference generation)
source.config.ts # Fumadocs MDX schema & collection config
next.config.mjs  # Next.js config (static-export gating)
proxy.ts         # i18n middleware

Internationalization

Documentation is authored in English. Persian (fa, RTL), Russian (ru), and Chinese (zh) locales are wired up; untranslated pages fall back to English so they never 404. English URLs are unprefixed; other locales live under /fa, /ru, /zh.

Deployment

The site builds for two targets:

  • Vercel / Nodepnpm build (static search index + prerendered OG images).
  • GitHub Pages (static export)DEPLOY_TARGET=static pnpm buildout/.

Contributing

Contributions are welcome! Setup, scripts, and project conventions live in CONTRIBUTING.md.

License

Licensed under GPL-3.0.