¿Prefieres ver esta página en español?Ver en español →
Runs on Debian 13, amd64 and arm64

Run your hosting business on one server. Grow it into a cluster.

OPanel is the control panel that replaces WHM, cPanel and your billing system with a single product. Every site isolated, HTTPS by default, Stripe billing built in, and an API for everything.

Live cluster simulator
EdgeControllerMariaDB
web-1online
9 sites
web-2online
7 sites
Room for another server
Room for another server
Try it: add a server and watch the sites spread out.

Three products in one login

The operator console, the customer portal and the storefront share one account system, one API and one look.

panel.example.com/admin
OPanel
Cluster overview
Nodes
Sites
Customers
Subscriptions
Plans
Backups
IP blocking
Cluster overview
Nodes4online
Sites1,284in sync
Subscriptions932
Bandwidth · 24h318 GB
Requests · 24h
NodeRolesLoadStatus
edge-1edge, ssh0.21online
web-1web0.48online
web-2web0.36online
db-1db, cache0.29online

One server is a cluster of one

A single server runs exactly the same software as a fifty-node cluster. When you need more capacity you add a server, not a second island to manage.

  • Join a server with two commands. It gets its certificates, roles and configuration automatically.
  • Roles for control, edge, SSH, web, database and cache. Put them together or spread them out.
  • New sites are placed on the web server with the most room. Customers never see servers.
  • Move a site between servers with a resumable transfer, a cutover of seconds and a rollback window.
  • Drain a server for maintenance and its sites move away on their own.
  • The rebalancer scores every server every 15 minutes and proposes, or makes, the moves.
# on the first server
opanel cluster token create --roles web,edge
# on the new server
opanel join --controller 10.0.0.1:7444 \
  --token opj_… --ca-sha256 …

Every site in its own sandbox, on stock Debian

OPanel delivers what CloudLinux and CageFS sell, with no kernel patches and no extra licenses. The site, not the account, is the unit of isolation.

  • CPU, memory, processes and disk I/O limits per site or pooled per subscription
  • Other homes, processes and system paths are invisible from inside a site
  • Nothing internet-facing runs as root; the only root agent speaks a typed mTLS API

Typical hosting account

One user · one PHP pool · one quota

shop.com
blog.com
landing.com
3 of 3 sites infected

OPanel

own user · sandbox · limits

shop.com
blog.com
landing.com
1 site affected. The others never noticed.

Quiet sites sleep. Busy sites fly.

On a real server most sites are idle most of the time. OPanel stops their PHP after 15 idle minutes and wakes it on the next request, so a server holds far more sites.

WordPress cold start
574 ms
warm response
56 ms
memory an idle site uses
0 MB
awakeasleep
HTTP/3

A modern edge in Go

HTTP/1.1, HTTP/2, HTTP/3 and WebSockets, with certificates issued on demand and route changes applied without reloads.

1 OPcache

Per site, not per server

Each site has its own PHP-FPM master and OPcache: no cross-tenant cache poisoning, and accurate usage per site.

7.4–8.5

Every PHP version you need

Pick a version per site, tune php.ini within the plan’s limits and add a Valkey object cache with one click.

Every request passes four layers

Protection that other panels sell as add-ons sits in the path of every request, on every server.

  1. Incoming request
  2. Cluster-wide IP blocking

    Failed logins, WordPress attacks, WAF hits and floods add up across every server, with escalating blocks in seconds.

  3. Web application firewall

    Coraza with the OWASP Core Rule Set at the edge. Off, detect or block per domain.

  4. Per-site sandbox

    Even if code gets in, it runs as the site’s own user, with its own limits, unable to see anything else.

  5. Malware scanning

    Scheduled scans, WordPress checksums and PHP malware heuristics, with plain-language findings and quarantine.

And around it

Passkeys and 2FA

Passkeys, TOTP and recovery codes. Staff always sign in with a second factor.

Mutual TLS everywhere

Every server has a certificate from the cluster’s own CA, renewed automatically and revoked in seconds.

Complete audit log

Every change made by people, API tokens and the platform itself, with filters.

Signed releases

Packages from a signed APT repository, reproducible builds and a software bill of materials for every release.

Managed WordPress hosting, out of the box

Install, migrate, update and clean WordPress sites without plugins or add-ons to buy.

  • One-click install with a secure generated password
  • Migrate any site over SSH or with a small plugin
  • Malware scanning and one-click core reinstall

Safe updates with automatic rollback

  1. Snapshot

    A backup is taken before anything changes.

  2. Update

    Core, plugins and themes, on the plan’s schedule.

  3. Check

    Pages and error logs are checked for new fatal errors.

  4. Roll back

    A failing update is undone and held back until a newer version ships.

Your panel is your billing system

Stripe billing is built in. Card data never touches your servers, and the whole lifecycle runs on its own.

Choose a plan

A branded plans page with monthly and yearly prices in any currency.

Pay with Stripe

Stripe Checkout with trials, promotion codes and Stripe Tax.

Site ready

The account, subscription and first site are created automatically.

Hands-off lifecycle

Dunning, grace period, suspension and termination, plus a self-service billing portal.

Already on WHMCS, Blesta or HostBill? Use the provisioning modules, or drive OPanel through its API.

Sell hosting under many brands

Create reseller brands, each with its own panel address, look, staff, customers, plans and even its own Stripe account.

  • Own panel hostname and SSH hostname
  • Name, colors, logos and favicon, checked for contrast in light and dark mode
  • Branded emails, suspension and maintenance pages
  • Brand staff with admin and support roles, and limits you set

Pick a brand to see its panel

OPanelpanel.example.com
Welcome backNew site
Your sites
shop.example.comPHP 8.4
blog.example.comWordPress
docs.example.comStatic

Tools your customers will actually use

SSH and SFTP gateway

One hostname for the whole cluster. Keys belong to people, so removing a team member revokes access everywhere at once.

$ ssh shop@ssh.example.com -p 2222
shop@web-2:~$ wp plugin list --status=active
woocommerce     9.8.2   active
wordfence       8.0.5   active

Private database access

MariaDB is never public. Connect TablePlus or DBeaver through an SSH tunnel.

Command palette

Press Ctrl+K or ⌘K to jump to any site, customer or action.

CtrlK

File manager and editor

Drag-and-drop uploads and a code editor with syntax highlighting and conflict warnings.

Web terminal

A real shell in the browser, running inside the site’s sandbox.

Database studio

Browse tables, edit rows, run SQL and import or export dumps in the browser.

SELECT ID, user_login FROM wp_users LIMIT 3;
1maria
2editor
3shopmanager

Self-service backups

Encrypted, incremental backups. Restore a site, some folders or a database yourself.

Teams and roles

Owner, admin, developer, billing and viewer roles, optionally limited to certain sites. One login for many customers.

Staging and Git

Create staging copies, deploy from Git and import static sites from a repository or an archive.

Everything the panel does, the API does

The web interface is just another client of the same versioned API that your scripts, billing system and resellers use.

  • OpenAPI 3.1 with interactive docs on every install
  • API tokens scoped by permission and by customer
  • Idempotency keys, cursor pagination and standard error documents
  • A capabilities endpoint so integrations adapt to each plan
curl -X POST https://panel.example.com/api/v1/sites \
  -H "Authorization: Bearer $OPANEL_TOKEN" \
  -H "Idempotency-Key: 5f0c2a4e-new-shop" \
  -H "Content-Type: application/json" \
  -d '{
    "subscriptionId": "1b9d6bcd-bbfd-4b2d-9b5d-ab8dfbbd4bed",
    "domain": "shop.example.com",
    "preset": "wordpress",
    "phpVersion": "8.4"
  }'

# 201 Created
{ "id": "…", "state": "provisioning", "node": "web-2" }

Built for the whole hosting business

Hosting companies

Start on a single server with Stripe billing, and add servers as you grow without migrating customers by hand.

Resellers

Offer hosting under your own brand, with your own plans, staff and Stripe account.

Agencies

Manage every client from one login, give each team access only to its sites, and keep WordPress updated safely.

Developers and sysadmins

Stock Debian, apt, systemd and nftables. No kernel patches, no black boxes, and an API for everything.

How OPanel compares

Built from scratch for today’s hosting, not layered on top of a panel from the nineties.

OPanelcPanel & WHMPleskDirectAdmin
Native multi-server clusterIncludedNot availableNot availableNot available
Per-site isolation includedIncludedPaid add-onPartialPartial
Built-in billingIncludedPaid add-onPaid add-onPaid add-on
Cluster-wide IP blockingIncludedPer server onlyPer server onlyPer server only
Malware scanning includedIncludedPaid add-onPaid add-onPartial
WordPress updates with automatic rollbackIncludedPaid add-onPaid add-onNot available
Runs on DebianIncludedNot availableIncludedIncluded

From a fresh server to your first customer in minutes

Install the package

Copy the OPanel package to a clean Debian 13 server and install it with apt.

Run the installer

It sets up the controller, edge, SSH gateway, nginx, PHP, MariaDB and Valkey, then prints a one-time setup link.

Create your first plan

Connect SMTP and Stripe, create a plan and start taking signups.

# Debian 13, as root
apt install ./opanel_*_amd64.deb
opanel install \
  --panel-hostname panel.example.com \
  --acme-email ops@example.com

# open the one-time setup link it prints, then
opanel doctor

Requirements

  • Debian 13 "trixie" on amd64 or arm64
  • 2 GB RAM recommended
  • XFS volume with project quotas recommended

Frequently asked questions

Which operating systems does OPanel support?

Debian 13 "trixie" on amd64 or arm64. Supporting one distribution well lets OPanel use stock systemd, cgroup v2 and nftables features instead of kernel patches.

Do I need several servers?

No. One server is enough to run a hosting company. It is already a cluster of one, so adding servers later needs no migration.

Can I move my customers from cPanel or Plesk?

Yes. OPanel imports cPanel and Plesk accounts, migrates WordPress sites over SSH or with a small plugin, and imports static sites from Git or an archive.

Does it support FTP or .htaccess?

Files are transferred over SFTP, which is secure and works with every modern client. Sites are served by nginx, and an optional Apache backend is available for sites that depend on .htaccess.

Can I keep my current billing system?

Yes. Use the built-in Stripe billing, or connect WHMCS, Blesta or HostBill through their modules or the API.

Can I sell it under my own brand?

Yes. Every brand has its own panel hostname, colors, logos, emails, staff and plans, and optionally its own Stripe account.

Your first server is one command away

#opanel install --panel-hostname panel.example.com --acme-email ops@example.com