HOSTER

Create the first administrator account to get started.

HOSTER

Sign in to manage your sites.

or
HOSTER

Enter the 6-digit code from your authenticator app.

Lost your device? Enter a recovery code instead.

HOSTER

Your account was set up with a temporary password. Choose your own to continue.

HOSTER
  • Dashboard
  • Sites
  • Site Explorer
  • Analytics
  • Logs
  • System
  • Settings
  • About

Dashboard

Traffic

Top Sites

Bandwidth

Countries

Status Codes

Blocked Requests

Sites

Site Explorer

Select a site to view actions.
No site selected Open β†—
Preview appears here.

Create Blank Site

Creates an empty site with a placeholder page. Open Settings on the new site to enable MCP access so AI tools can populate it.

Create Repository

A document library with its own built-in interface: drag-and-drop uploads, folders, previews, per-file version history, and packaged downloads. Nothing to upload for the design β€” set a name, an optional banner, and you're done.

Create Collection

A single page that gathers some of your sites and repositories as cards. After creating it, open Settings to pick the cards, put them in order, and add a banner or background.

Deploy New Site

Deploying...

Analytics

Traffic

Top pages β€” select one for its details

Countries

Referrers

Browsers

Operating systems

Devices

Languages

When visits happen

Bots & scripts

Access codes

Recent Requests

Time Method Path Status Browser IP Country Speed

Settings

Change Password

Two-Factor Authentication

Passkeys

Sign in with Touch ID, Windows Hello, or a security key β€” no password or authenticator code. A passkey only works on the hostname it was created on, so register one for each address you use to reach this panel. Your password stays active as a fallback.

Users

Administrators manage the whole platform: every site, these Settings, users, MCP/OAuth, and backups. There can be as many as you like; the last one can never be demoted or deleted. Site users sign in the same way but see only the sites assigned to them and can't create or delete sites. Every account manages its own password, 2FA, and passkeys under Account. Changes that touch an administrator account ask for your password again.

Add an account

After the account is created you'll get its sign-in details to copy and send however you like.

Sites this user may manage:

MCP Access Tokens

Static bearer tokens for CLI tools (Claude Code, Cursor) that don't need an interactive login. Tokens can be scoped to a single site and set to expire.

MCP Activity Log

Recent MCP tool calls across all tokens.

OAuth Connections

Chat clients (Claude.ai, ChatGPT, etc.) connect via OAuth. Each MCP-enabled site is a separate connector β€” paste its URL into your chat client's "Add MCP server" dialog and complete the consent flow.

Default Landing Page

Choose what visitors see when they open this Hoster's root address. By default the root redirects to the admin sign-in; you can send it to one of your hosted sites or to any URL instead. Custom domains (host aliases) are unaffected.

Country Restrictions

Only serve hosted sites to visitors from the countries you pick; everyone else (and any visitor whose country can't be determined) gets a 403. Leave the list empty to allow the whole world. Any site can override this list from its own Settings β†’ Access tab. The admin panel, MCP, and OAuth endpoints are never geo-blocked.

All countries allowed

Admin Hostname

Sites served at /<slug>/ share a browser origin with everything else on their hostname. While the admin panel lives there too, a script on any of those sites can act as a signed-in administrator. Give the admin panel its own hostname (for example admin.example.com) to close that off: the panel and the OAuth consent screen are then served only there, and that hostname serves no sites. MCP connectors and existing OAuth grants keep working unchanged.

After switching you sign in again on the new hostname. Passkeys belong to the hostname they were made on, so sign in with your password (and 2FA) the first time, then register a passkey there. Locked out? From the server shell: hoster admin-host --clear, or reach the panel over an SSH tunnel to localhost.

Bot Protection

Stops vulnerability scanners that walk lists like /.env, /.git/config, and /wp-login.php. Everything runs in memory, applies to every hosted site, and never touches the admin panel, MCP, or OAuth. Blocked IPs appear in the list below with the reason.

Requests for secrets, version-control folders, WordPress/PHP/ASP endpoints and the like get an instant 404 and count as a strike β€” unless the site really has that file.

An IP collecting a burst of 404s is blocked for a while. Search and link-preview crawlers (Google, Bing, Facebook, Slack, LinkedIn, X, Discord, …) are exempt; missing scripts, styles, and fonts don't count.

Answers 429 past the limit (no block). Off by default: app-style sites load many files per page, and visitors on mobile networks often share one IP β€” keep this generous.

IP Auto-Blocking

Automatically block IP addresses that accumulate too many requests refused by the country restrictions above. Uses the real client IP from Cloudflare headers.

Configuration Backup

Save your entire hoster configuration (settings, sites, versions) to a file for migration or backup. Optionally protect with a password.

Preparing backup...
Loading backup...

Repair Sites

Walk every site in the database and recreate its _current symlink from the recorded active version. Use this if sites are returning 404s after a restore or manual file changes. Safe to run anytime β€” it's a no-op on healthy sites.

CMS Library

JavaScript and CSS served at /_cms/cms.js and /_cms/cms.css for every CMS-enabled site. The same lib serves every host β€” canonical, host-aliased, or path-prefixed. Edits take effect on the next request (clients revalidate via ETag).

Confirm Configuration Load

This will replace all current settings, sites, and data.

This action cannot be undone. You may want to save your current configuration first.

System

Disk

Host

Database

Tables

Maintenance

Integrity check

Runs SQLite's quick check over every page. Read-only.

Checkpoint

Folds the write-ahead log back into the database file and truncates it.

Prune analytics

Deletes logged requests older than . Everything else is untouched.

Compact

Rewrites the database to give free pages back to the disk (VACUUM). Pauses all writes while it runs β€” seconds for a large log. Needs about twice the database's size free.

About

HOSTER

Lightweight Web Hosting Platform

Hoster is a self-hosted web hosting platform that turns any device into a web server. Upload a ZIP file and your site is live β€” with versioning, SPA support, analytics, and free HTTPS via Cloudflare Tunnel.

No cloud providers, no monthly fees, no vendor lock-in. Just your code, your device, your domain.

Created by David Geller

github.com/davidgeller/hoster

MIT License