Self-hosted service
Liafanx/MTProxyL avatar
Liafanx/MTProxyL

MTProxyL: running a Telegram MTProto proxy through telemt, Docker or binary

Telegram Proxy менеджер на базе Telemt

357 stars13 forksShellMIT

At a glance

What is it?
MTProxyL installs and manages a Telegram MTProto proxy from a single shell command, with an interactive setup wizard, a secrets CLI, a web panel and a Telegram bot. The Rust engine telemt can run as a Docker container or as a verified binary service, and a Reanimator mode exists to repair an existing proxy.
Who is it for?
Run MTProxyL if you operate your own Telegram MTProto proxy and want engine lifecycle, secrets, blocking countermeasures, a panel and a bot managed from one CLI, with the Docker-or-binary choice covering both container shops and minimal VPS installs. Pass if you need a non-root deployment or documentation in English, since the README, wizard and code comments are in Russian.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 1 day ago.
What is it written in?
Mainly Shell, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on October 1, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What MTProxyL takes off your hands

MTProxyL is a manager for Telegram MTProto proxies built on the telemt engine, which is written in Rust. It also handles what its README calls reanimating an existing proxy, meaning a second mode aimed at installs that already exist and are broken. The pitch is one-click installation with full control afterwards.

One design detail matters to anyone who has run mobile clients: a single port serves all clients, iOS, Android and Desktop, with no additional per-client setup. The README repeats it in the quick start, and it removes the usual fragmentation where each platform needs its own transport tweak.

Operationally, MTProxyL runs as root. If you log in as a regular user, the installer creates an alias so that typing mtproxyl runs sudo mtproxyl, writing it into /etc/profile.d/ and your ~/.bashrc so the sudo prefix is not needed. Under a root login the alias is not created because the command already works directly. Running a proxy stack as root is a real trade-off to accept before installing.

Install, wizard, and the proxy link

The documented install is one line:

bash
wget -qO /tmp/mtproxyl-install.sh https://raw.githubusercontent.com/Liafanx/MTProxyL/main/install.sh && sudo bash /tmp/mtproxyl-install.sh && source ~/.bashrc

It downloads install.sh from the repository's main branch, runs it under sudo, and then sources ~/.bashrc so the alias applies immediately without relogging. After installation the setup wizard starts on its own. To get back into the menu later:

bash
mtproxyl

The wizard asks whether you want MTProto only, WEB only, or MTProto plus WEB, then walks you through the transport you picked. When it finishes you get a proxy link in the output, or you can print one at any time:

bash
   mtproxyl secret link
   

Open that link in Telegram and the proxy is in use. Two installer-time behaviours deserve advance warning. On a server with 1 GB of memory and no swap, the installer offers to create a 1 GB swap file and defaults to yes, because without it the Docker engine and the panel build hit memory limits, the kernel kills the process, and the installation looks hung. On first install the script also offers the Zapret2 MTProto fix first, defaulting to yes; declining it offers NFT Smart By-MEKO instead, which the README calls the recommended mode with iOS and Android separation.

Docker image or binary engine

In Manager mode MTProxyL owns the engine, and it can hold it two ways, chosen in the wizard right after the mode selection. The default is a Docker image: a container named mtproxyl on the host network, configured at /opt/mtproxyl/mtproxy/config.toml, logged through docker logs mtproxyl. The alternative is the MTProxyL-Telemt binary at /opt/mtproxyl/engine/mtproxyl-telemt, run as the systemd service mtproxyl-telemt.service, configured through telemt.toml and logged with journalctl -u mtproxyl-telemt. With the binary backend, Docker is not installed at all.

The binary comes from the telemt releases, with architecture and libc detected automatically across x86_64, x86_64-v3 and aarch64, in gnu or musl flavours, and a sha256 checksum verified. The service is deliberately named mtproxyl-telemt rather than telemt so it never collides with an original telemt installation, which is the thing the Reanimator mode repairs. If the ready-made GHCR image is missing, MTProxyL builds one around the official musl binary instead of compiling, yielding a scratch image of roughly 7 MB with no shell or package manager; compiling from source is the last fallback, and on a 2 GB box its success depends on free memory and cgroup limits.

Switching backend on a live installation keeps the port, secrets and settings, regenerating the config under the new name. The switch is a menu item or a command:

bash
mtproxyl engine backend binary    # из контейнера в бинарник
mtproxyl engine backend docker    # обратно

The comments are in Russian, as is the whole README: the first line moves from the container to the binary, the second moves back. Updates and rollbacks work the same either way, documented as mtproxyl engine update with a release tag and mtproxyl engine rollback, and the binary keeps the previous version beside it as mtproxyl-telemt.prev so rollback needs no network. Unused engine images are cleaned up through:

bash
mtproxyl engine cleanup --dry-run   # Показать теги к удалению
mtproxyl engine cleanup             # Показать список и запросить подтверждение

The dry-run line only lists the tags that would go; the second line shows the list and asks for confirmation before deleting.

Manager and Reanimator, two jobs

Manager mode is the full lifecycle owner: it installs the engine, manages secrets and settings, fronts the panel and the Telegram bot, and covers backups, updates and migration to another server. Everything described in the engine section above is Manager territory.

Reanimator mode targets a proxy that already exists. The README introduces it as revival of an existing proxy, and the service-naming detail confirms the scope: the binary backend never names its service telemt precisely so an original telemt installation, the kind Reanimator works on, stays untouched. The CLI navigation pairs the mode with detection, listing it as a mode and a detector together, which fits a tool that first notices a proxy is dead and then tries to bring it back.

The split is honest about a real situation: people already run MTProto proxies that predate this manager, and a manager that could only install from scratch would be useless to them.

The blocking-shaped extras

The README's own table of contents reads like a checklist of what actually kills Telegram proxies. There are standalone sections on blocking of IP addresses, on choosing a domain for FakeTLS, on a WEB proxy mode, on Selfmask, on an NFT SYN limiter and NFT Smart By-MEKO, on the Zapret2 MTProto fix (which also has its own zapret2.md file at the repository root), on routing Telegram through WARP, on GeoIP, and on availability from Russia.

The names alone describe the operating environment: proxies whose IPs get blocked and need recovery, TLS fronts that need a believable domain to answer on, SYN floods that need rate limiting at the firewall layer, and clients in networks where plain MTProto no longer connects. The first-install default pushing the Zapret2 fix, a server-side TCP-manipulation route, tells you which environment the author expects most users to be in.

This is circumvention tooling in the plain sense: it exists so that a self-hosted proxy keeps working when someone tries to make it stop working. Whether any given use is lawful depends on where the server and the user sit, and the README does not wade into that question.

Panel, bot, and the update rhythm

Beyond the core, the repository ships a mtproxyl-panel directory for the web panel and a mtproxyl-tgbot directory for the Telegram bot, and the CLI navigation covers secrets, settings, an expert mode and a super expert mode, a PQ check, security, monitoring, backups, migration and a tune command for quick tuning. The panel is released separately: alongside engine releases v1.6.17 and v1.6.16, both published on 2026-09-16, the release list carries mtproxyl-panel-v1.1.11 dated the same day. The last push was on 2026-09-17, so the project moved within the week before this snapshot. The licence is MIT.

The upgrade story is first-class rather than bolted on: engine update and rollback commands, the previous binary kept on disk, backups and a documented server-to-server migration path. For a proxy whose whole job is staying reachable, that is the part that decides long-term cost, and it is the part small proxy scripts usually skip.

Editorial conclusion

Run MTProxyL if you operate your own Telegram MTProto proxy and want engine lifecycle, secrets, blocking countermeasures, a panel and a bot managed from one CLI, with the Docker-or-binary choice covering both container shops and minimal VPS installs. Pass if you need a non-root deployment or documentation in English, since the README, wizard and code comments are in Russian. Verify first: that a 1 GB server accepts the swap file the installer offers, which engine backend the wizard selected for you, and what mtproxyl secret link prints before you share the link with anyone. The last push was on 2026-09-17.

Frequently asked questions

What is MTProto proxy in Telegram?

MTProto is the proxy protocol Telegram clients connect through, and MTProxyL runs such a proxy using the Rust engine telemt. One port serves iOS, Android and Desktop clients alike, and the proxy is consumed by opening a link that the tool prints.

How to get MTProto proxy?

Run the one-line installer on your server, follow the setup wizard to configure the transport, then run mtproxyl secret link to print the proxy link. Opening that link in Telegram adds the proxy on the client side.

Is Telegram proxy safe?

The README makes no blanket safety claim and instead documents operational hardening: FakeTLS domain selection, a Selfmask mode, IP-blocking detection and a security section. Note that the whole stack runs as root, which is worth weighing before installing.

Official sources

  1. Issues
  2. Liafanx/MTProxyL on GitHub
  3. License: MIT
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/liafanx-mtproxyl.svg)](https://hysenlabs.com/projects/liafanx-mtproxyl)