Skip to content
  • MangoFly

    A self-hosted WireGuard mesh. Devices connect straight to each other; the coordination server is one binary and a SQLite file, and never sees their traffic.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol
  • MangoDock

    Docker management with nothing on the hosts. Reaches each daemon over an ordinary SSH session — no agent to install, no port to open.

    The MangoDock dashboard showing three host cards with container state counts, CPU and memory gauges, a usage history and recent events
  • MangoWiFi

    A Wi-Fi 6/7/8 test bench. One binary runs as Console or Agent either side of the access point under test, measuring latency under real load.

    AP under testWi-Fi 6 / 6E / 7Agentstation side · real radioLAN receiveriperf3 -sConsoleUI · orchestrates · probes
  • Blog
  • Nothing phones home

    No telemetry, no analytics, no crash reporter, no account login. Check it with a packet capture on your own network.

    Download MangoSSH
  • Project
  • Download
  • Access

    SSO, LDAP and two-factor

    Three ways to stop maintaining a separate list of passwords, each optional and each configured by an admin.

    Single sign-on (OIDC)

    FieldWhat it is
    issuer_urlYour identity provider's issuer URL.
    client_idThe client MangoDock is registered as.
    client_secretStored encrypted; the API only ever reports whether one is set.
    external_urlThe URL users reach MangoDock on, which is what the redirect comes back to. Behind a proxy this is the proxy's address, not the container's.
    default_roleThe role a person gets the first time they sign in this way.
    button_labelWhat the sign-in button says. Defaults to “Single sign-on”.

    LDAP and Active Directory

    FieldWhat it is
    urlThe directory server.
    bind_dnThe account MangoDock binds as to search.
    bind_passwordStored encrypted, like every other credential.
    base_dnWhere to search from.
    user_filterWhich entries count as users.
    default_roleThe role a directory user gets on first sign-in.
    button_labelWhat the sign-in button says.

    Two-factor

    Per-user TOTP, enrolled by the user from their own account rather than imposed centrally. Enrolment issues recovery codes; each is single-use and MangoDock tracks how many remain unused, so you find out you are running low before you are locked out.

    A TOTP step is claimed once — the same code cannot be replayed within its window. An admin can disable two-factor on another user's account, which is the way back in when someone loses their phone and their recovery codes.

    Recovery codes are hashed, not stored

    They are kept as SHA-256 rather than in the clear. That is deliberately a fast hash, not a slow one: a recovery code already has enough entropy that the hash only needs to resist lookup from a stolen database, which is a different job from the deliberate slowness of a password hash.

    Air-gapped

    • Both integrations talk only to the server you name. An internal identity provider or directory works exactly as an external one would.