Tools / Monban

Monban

One panel for every site behind your proxy: maintenance, coming soon, password or login — per host, no redeploy.

Monban is a self-hosted gate that sits in front of your sites through your reverse proxy's forward-auth. For each host you pick a mode from one admin panel: open, maintenance (a styled 503), coming soon (with an optional notify-me email list), a shared password, or a login. Changes take effect on the next request — no container restarts, no config edits, no redeploys. Login is passwordless: allow-listed users get a one-time code by email, and one sign-in covers every protected host. Behind Traefik, hosts appear automatically from a single Docker label. It runs on your infrastructure and never phones home.

In the workshop. It ships when it's ready.

One email when it's released. Nothing else, nothing to pay.

monban
Screenshots coming soon.

What it does.

Maintenance mode in one click

Flip any host to a styled maintenance page (a proper 503, so search engines know it's temporary) and back again. Optionally show a start and end time. No redeploy, no static container, no proxy config edits.

Coming-soon pages that collect emails

Put a host on a coming-soon page while it waits to launch, and optionally collect notify-me addresses. Filter signups by site and download them as CSV. The list survives launch.

Password-protect staging for clients

Give a host a shared password. Browsers get a form; API clients and scripts send the same password as a header, so automated checks still get through.

Passwordless login, single sign-on

Turn on Protect and only allow-listed people get in, with a one-time code sent by email. One sign-in covers every protected host. Codes are hashed, single-use, expire in 10 minutes, and burn after 5 wrong guesses.

Hosts enrol themselves

Behind Traefik, add one middleware label to a service and its hosts appear in Monban automatically, ready to configure. Sites behind other proxies are added by hand and authenticate with their own per-site key.

Five themes, your choice per host

Glass, editorial, terminal, aurora and brutalist. Each gate page is self-contained and styled per host, or set it to random for a different one on every load.

Keeps gating when the database blips

Monban remembers the last good policy for every host and keeps serving it if its database is briefly unreachable, so a database failover doesn't take every site offline.

Questions

Which reverse proxies does Monban work with?

Monban answers the standard forward-auth request. Traefik is first-class: hosts are discovered automatically from a Docker label. Other proxies are supported as manually added sites with a per-site key. Step-by-step guides for Caddy and nginx are in the workshop.

Do I need to redeploy anything to change a site's mode?

No. You enrol a site once. After that, switching between open, maintenance, coming soon, password and login happens in Monban's admin panel and applies on the next request.

Is it a replacement for Authelia or Authentik?

Not as an identity provider. Monban's job is per-site state: which sites are in maintenance, which are coming soon, which need a password or a login. If you need SAML, LDAP or social login, use a full identity provider.

What does Monban need to run?

A Docker host, a Postgres database, and an SMTP account to send login codes. Docker socket access is only needed for automatic discovery behind Traefik.

How will Monban be licensed?

A one-off purchase per major version, per instance, perpetual, with a 14-day full-function trial. One licence covers every site that instance protects; there are no per-user or per-site fees.

What happens to my sites if a licence lapses?

Your gates keep enforcing exactly as configured. A lapsed licence only locks changes in the admin panel. It never opens a protected site and never takes a site offline.

Does Monban send anything back to you?

No. The licence is verified offline and Monban never phones home. The only outbound traffic is the login-code email, through the SMTP server you configure.