Run your hosting business on one server. Grow it into a cluster.
OPanel is the control panel that replaces WHM, cPanel and your billing system with a single product. Every site isolated, HTTPS by default, Stripe billing built in, and an API for everything.
Three products in one login
The operator console, the customer portal and the storefront share one account system, one API and one look.
ssh shop@ssh.example.com -p 2222One server is a cluster of one
A single server runs exactly the same software as a fifty-node cluster. When you need more capacity you add a server, not a second island to manage.
- Join a server with two commands. It gets its certificates, roles and configuration automatically.
- Roles for control, edge, SSH, web, database and cache. Put them together or spread them out.
- New sites are placed on the web server with the most room. Customers never see servers.
- Move a site between servers with a resumable transfer, a cutover of seconds and a rollback window.
- Drain a server for maintenance and its sites move away on their own.
- The rebalancer scores every server every 15 minutes and proposes, or makes, the moves.
# on the first server opanel cluster token create --roles web,edge # on the new server opanel join --controller 10.0.0.1:7444 \ --token opj_… --ca-sha256 …
Every site in its own sandbox, on stock Debian
OPanel delivers what CloudLinux and CageFS sell, with no kernel patches and no extra licenses. The site, not the account, is the unit of isolation.
- CPU, memory, processes and disk I/O limits per site or pooled per subscription
- Other homes, processes and system paths are invisible from inside a site
- Nothing internet-facing runs as root; the only root agent speaks a typed mTLS API
Typical hosting account
One user · one PHP pool · one quota
OPanel
own user · sandbox · limits
Quiet sites sleep. Busy sites fly.
On a real server most sites are idle most of the time. OPanel stops their PHP after 15 idle minutes and wakes it on the next request, so a server holds far more sites.
- WordPress cold start
- 574 ms
- warm response
- 56 ms
- memory an idle site uses
- 0 MB
A modern edge in Go
HTTP/1.1, HTTP/2, HTTP/3 and WebSockets, with certificates issued on demand and route changes applied without reloads.
Per site, not per server
Each site has its own PHP-FPM master and OPcache: no cross-tenant cache poisoning, and accurate usage per site.
Every PHP version you need
Pick a version per site, tune php.ini within the plan’s limits and add a Valkey object cache with one click.
Every request passes four layers
Protection that other panels sell as add-ons sits in the path of every request, on every server.
- Incoming request
Cluster-wide IP blocking
Failed logins, WordPress attacks, WAF hits and floods add up across every server, with escalating blocks in seconds.
Web application firewall
Coraza with the OWASP Core Rule Set at the edge. Off, detect or block per domain.
Per-site sandbox
Even if code gets in, it runs as the site’s own user, with its own limits, unable to see anything else.
Malware scanning
Scheduled scans, WordPress checksums and PHP malware heuristics, with plain-language findings and quarantine.
And around it
Passkeys and 2FA
Passkeys, TOTP and recovery codes. Staff always sign in with a second factor.
Mutual TLS everywhere
Every server has a certificate from the cluster’s own CA, renewed automatically and revoked in seconds.
Complete audit log
Every change made by people, API tokens and the platform itself, with filters.
Signed releases
Packages from a signed APT repository, reproducible builds and a software bill of materials for every release.
Managed WordPress hosting, out of the box
Install, migrate, update and clean WordPress sites without plugins or add-ons to buy.
- One-click install with a secure generated password
- Migrate any site over SSH or with a small plugin
- Malware scanning and one-click core reinstall
Safe updates with automatic rollback
Snapshot
A backup is taken before anything changes.
Update
Core, plugins and themes, on the plan’s schedule.
Check
Pages and error logs are checked for new fatal errors.
Roll back
A failing update is undone and held back until a newer version ships.
Your panel is your billing system
Stripe billing is built in. Card data never touches your servers, and the whole lifecycle runs on its own.
Choose a plan
A branded plans page with monthly and yearly prices in any currency.
Pay with Stripe
Stripe Checkout with trials, promotion codes and Stripe Tax.
Site ready
The account, subscription and first site are created automatically.
Hands-off lifecycle
Dunning, grace period, suspension and termination, plus a self-service billing portal.
Already on WHMCS, Blesta or HostBill? Use the provisioning modules, or drive OPanel through its API.
Sell hosting under many brands
Create reseller brands, each with its own panel address, look, staff, customers, plans and even its own Stripe account.
- Own panel hostname and SSH hostname
- Name, colors, logos and favicon, checked for contrast in light and dark mode
- Branded emails, suspension and maintenance pages
- Brand staff with admin and support roles, and limits you set
Pick a brand to see its panel
Tools your customers will actually use
SSH and SFTP gateway
One hostname for the whole cluster. Keys belong to people, so removing a team member revokes access everywhere at once.
$ ssh shop@ssh.example.com -p 2222 shop@web-2:~$ wp plugin list --status=active woocommerce 9.8.2 active wordfence 8.0.5 active
Private database access
MariaDB is never public. Connect TablePlus or DBeaver through an SSH tunnel.
Command palette
Press Ctrl+K or ⌘K to jump to any site, customer or action.
File manager and editor
Drag-and-drop uploads and a code editor with syntax highlighting and conflict warnings.
Web terminal
A real shell in the browser, running inside the site’s sandbox.
Database studio
Browse tables, edit rows, run SQL and import or export dumps in the browser.
SELECT ID, user_login FROM wp_users LIMIT 3;| 1 | maria |
| 2 | editor |
| 3 | shopmanager |
Self-service backups
Encrypted, incremental backups. Restore a site, some folders or a database yourself.
Teams and roles
Owner, admin, developer, billing and viewer roles, optionally limited to certain sites. One login for many customers.
Staging and Git
Create staging copies, deploy from Git and import static sites from a repository or an archive.
Everything the panel does, the API does
The web interface is just another client of the same versioned API that your scripts, billing system and resellers use.
- OpenAPI 3.1 with interactive docs on every install
- API tokens scoped by permission and by customer
- Idempotency keys, cursor pagination and standard error documents
- A capabilities endpoint so integrations adapt to each plan
curl -X POST https://panel.example.com/api/v1/sites \ -H "Authorization: Bearer $OPANEL_TOKEN" \ -H "Idempotency-Key: 5f0c2a4e-new-shop" \ -H "Content-Type: application/json" \ -d '{ "subscriptionId": "1b9d6bcd-bbfd-4b2d-9b5d-ab8dfbbd4bed", "domain": "shop.example.com", "preset": "wordpress", "phpVersion": "8.4" }' # 201 Created { "id": "…", "state": "provisioning", "node": "web-2" }
Built for the whole hosting business
Hosting companies
Start on a single server with Stripe billing, and add servers as you grow without migrating customers by hand.
Resellers
Offer hosting under your own brand, with your own plans, staff and Stripe account.
Agencies
Manage every client from one login, give each team access only to its sites, and keep WordPress updated safely.
Developers and sysadmins
Stock Debian, apt, systemd and nftables. No kernel patches, no black boxes, and an API for everything.
How OPanel compares
Built from scratch for today’s hosting, not layered on top of a panel from the nineties.
| OPanel | cPanel & WHM | Plesk | DirectAdmin | |
|---|---|---|---|---|
| Native multi-server cluster | Included | Not available | Not available | Not available |
| Per-site isolation included | Included | Paid add-on | Partial | Partial |
| Built-in billing | Included | Paid add-on | Paid add-on | Paid add-on |
| Cluster-wide IP blocking | Included | Per server only | Per server only | Per server only |
| Malware scanning included | Included | Paid add-on | Paid add-on | Partial |
| WordPress updates with automatic rollback | Included | Paid add-on | Paid add-on | Not available |
| Runs on Debian | Included | Not available | Included | Included |
From a fresh server to your first customer in minutes
Install the package
Copy the OPanel package to a clean Debian 13 server and install it with apt.
Run the installer
It sets up the controller, edge, SSH gateway, nginx, PHP, MariaDB and Valkey, then prints a one-time setup link.
Create your first plan
Connect SMTP and Stripe, create a plan and start taking signups.
# Debian 13, as root apt install ./opanel_*_amd64.deb opanel install \ --panel-hostname panel.example.com \ --acme-email ops@example.com # open the one-time setup link it prints, then opanel doctor
Requirements
- Debian 13 "trixie" on amd64 or arm64
- 2 GB RAM recommended
- XFS volume with project quotas recommended
Frequently asked questions
Which operating systems does OPanel support?
Debian 13 "trixie" on amd64 or arm64. Supporting one distribution well lets OPanel use stock systemd, cgroup v2 and nftables features instead of kernel patches.
Do I need several servers?
No. One server is enough to run a hosting company. It is already a cluster of one, so adding servers later needs no migration.
Can I move my customers from cPanel or Plesk?
Yes. OPanel imports cPanel and Plesk accounts, migrates WordPress sites over SSH or with a small plugin, and imports static sites from Git or an archive.
Does it support FTP or .htaccess?
Files are transferred over SFTP, which is secure and works with every modern client. Sites are served by nginx, and an optional Apache backend is available for sites that depend on .htaccess.
Can I keep my current billing system?
Yes. Use the built-in Stripe billing, or connect WHMCS, Blesta or HostBill through their modules or the API.
Can I sell it under my own brand?
Yes. Every brand has its own panel hostname, colors, logos, emails, staff and plans, and optionally its own Stripe account.
Your first server is one command away
opanel install --panel-hostname panel.example.com --acme-email ops@example.com