Dashboard
Traffic
Top Sites
Bandwidth
Countries
Status Codes
Blocked Requests
Sites
Site Explorer
Analytics
Traffic
Top pages β select one for its details
Countries
Referrers
Browsers
Operating systems
Devices
Languages
When visits happen
Bots & scripts
Access codes
Recent Requests
| Time | Method | Path | Status | Browser | IP | Country | Speed |
|---|
Settings
Change Password
Two-Factor Authentication
Passkeys
Sign in with Touch ID, Windows Hello, or a security key β no password or authenticator code. A passkey only works on the hostname it was created on, so register one for each address you use to reach this panel. Your password stays active as a fallback.
Users
Administrators manage the whole platform: every site, these Settings, users, MCP/OAuth, and backups. There can be as many as you like; the last one can never be demoted or deleted. Site users sign in the same way but see only the sites assigned to them and can't create or delete sites. Every account manages its own password, 2FA, and passkeys under Account. Changes that touch an administrator account ask for your password again.
Add an account
After the account is created you'll get its sign-in details to copy and send however you like.
MCP Access Tokens
Static bearer tokens for CLI tools (Claude Code, Cursor) that don't need an interactive login. Tokens can be scoped to a single site and set to expire.
MCP Activity Log
Recent MCP tool calls across all tokens.
OAuth Connections
Chat clients (Claude.ai, ChatGPT, etc.) connect via OAuth. Each MCP-enabled site is a separate connector β paste its URL into your chat client's "Add MCP server" dialog and complete the consent flow.
Default Landing Page
Choose what visitors see when they open this Hoster's root address. By default the root redirects to the admin sign-in; you can send it to one of your hosted sites or to any URL instead. Custom domains (host aliases) are unaffected.
Country Restrictions
Only serve hosted sites to visitors from the countries you pick; everyone else (and any visitor whose country can't be determined) gets a 403. Leave the list empty to allow the whole world. Any site can override this list from its own Settings β Access tab. The admin panel, MCP, and OAuth endpoints are never geo-blocked.
Admin Hostname
Sites served at /<slug>/ share a browser origin with everything else on their hostname. While the admin panel lives there too, a script on any of those sites can act as a signed-in administrator. Give the admin panel its own hostname (for example admin.example.com) to close that off: the panel and the OAuth consent screen are then served only there, and that hostname serves no sites. MCP connectors and existing OAuth grants keep working unchanged.
Bot Protection
Stops vulnerability scanners that walk lists like /.env, /.git/config, and /wp-login.php. Everything runs in memory, applies to every hosted site, and never touches the admin panel, MCP, or OAuth. Blocked IPs appear in the list below with the reason.
IP Auto-Blocking
Automatically block IP addresses that accumulate too many requests refused by the country restrictions above. Uses the real client IP from Cloudflare headers.
Configuration Backup
Save your entire hoster configuration (settings, sites, versions) to a file for migration or backup. Optionally protect with a password.
Repair Sites
Walk every site in the database and recreate its _current symlink from the recorded active version. Use this if sites are returning 404s after a restore or manual file changes. Safe to run anytime β it's a no-op on healthy sites.
CMS Library
JavaScript and CSS served at /_cms/cms.js and /_cms/cms.css for every CMS-enabled site. The same lib serves every host β canonical, host-aliased, or path-prefixed. Edits take effect on the next request (clients revalidate via ETag).
System
Disk
Host
Database
Tables
Maintenance
Runs SQLite's quick check over every page. Read-only.
Folds the write-ahead log back into the database file and truncates it.
Deletes logged requests older than . Everything else is untouched.
Rewrites the database to give free pages back to the disk (VACUUM). Pauses all writes while it runs β seconds for a large log. Needs about twice the database's size free.
About
Lightweight Web Hosting Platform
Hoster is a self-hosted web hosting platform that turns any device into a web server. Upload a ZIP file and your site is live β with versioning, SPA support, analytics, and free HTTPS via Cloudflare Tunnel.
No cloud providers, no monthly fees, no vendor lock-in. Just your code, your device, your domain.