Tokens are stateless JWTs, so changing a password left every session that the old one had opened working until its own expiry, up to a day later. That is the case the password change is meant to close: an administrator resetting a compromised account did not evict whoever was already in it. The auth row already records when the password last changed, so no migration is needed: `Access.init()` reads it alongside the user it already loads and refuses a token whose `iat` is older. Both sides are compared as whole seconds, which is all `iat` carries, so a token minted in the same second as the change is kept. Postgres stores that column to the microsecond, which is why the comparison is not done in milliseconds. It is reported as 401 rather than the usual 403 because that is what the frontend clears the session on, so the browser holding the dead token lands on the login page instead of a page full of errors, and `can()` lets that one error through unwrapped for the same reason. Only the password does this. A user row changing (a rename, an avatar, permissions) does not, and a user with no password auth row, which is what a login through an external provider looks like, is not affected.
This project comes as a pre-built Docker image that enables you to easily forward to your websites running at home or otherwise, including free SSL, without having to know too much about Nginx or Letsencrypt.
Project Goal
I created this project to fill a personal need to provide users with an easy way to accomplish reverse proxying hosts with SSL termination, and it had to be so easy that a monkey could do it. This goal hasn't changed. While there might be advanced options, they are optional, and the project should be as simple as possible so that the barrier to entry here is low.
Features
- Beautiful and Secure Admin Interface based on Tabler
- Easily create forwarding domains, redirections, streams, and 404 hosts without knowing anything about Nginx
- Free SSL using Let's Encrypt or provide your own custom SSL certificates
- Access Lists and basic HTTP Authentication for your hosts
- Advanced Nginx configuration available for super users
- User management, permissions, and audit log
::: warning
armv7 is no longer supported in version 2.14+. This is due to Nodejs dropping support for armhf. Please
use the 2.13.7 image tag if this applies to you.
:::
Hosting your home network
I won't go into too much detail here, but here are the basics for someone new to this self-hosted world.
- Your home router will have a Port Forwarding section somewhere. Log in and find it
- Add port forwarding for ports 80 and 443 to the server hosting this project
- Configure your domain name details to point to your home, either with a static ip or a service like
- DuckDNS
- Amazon Route53
- Cloudflare
- Use the Nginx Proxy Manager as your gateway to forward to your other web-based services
Quick Setup
- Install Docker
- Create a docker-compose.yml file similar to this:
services:
app:
image: 'docker.io/jc21/nginx-proxy-manager:latest'
restart: unless-stopped
ports:
- '80:80'
- '81:81'
- '443:443'
volumes:
- ./data:/data
- ./letsencrypt:/etc/letsencrypt
This is the bare minimum configuration required. See the documentation for more.
- Bring up your stack by running
docker compose up -d
- Log in to the Admin UI
When your docker container is running, connect to it on port 81 for the admin interface.
Sometimes this can take a little bit because of the entropy of keys.
Contributing
All are welcome to create pull requests for this project, against the develop branch. Official releases are created from the master branch.
CI is used in this project. All PR's must pass before being considered. After passing, docker builds for PR's are available on dockerhub for manual verifications.
Documentation within the develop branch is available for preview at
https://develop.nginxproxymanager.com
Contributors
Special thanks to all of our contributors.

