SMM Panel
Node.js + Express SMM panel with wallet integrity, manual deposits, provider API sync, order creation, status tracking, admin APIs, and a static frontend.
Quick Start
npm install
docker compose up -d db
cp .env.example .env
npm run migrate
npm start
Open:
http://127.0.0.1:3000
Docker App
For the full app stack:
docker compose up --build
The compose defaults are for local testing. Before production, set
NODE_ENV=production and replace JWT_SECRET, PROVIDER_API_URL,
PROVIDER_API_KEY, and CORS_ORIGIN through your deployment environment.
Apply migrations against the compose database:
DATABASE_URL=mysql://smm:smm_password@127.0.0.1:3306/smm npm run migrate
Migrations are intentionally run as an explicit command, not automatically when the container starts.
Environment
Important variables:
PORT=3000
DATABASE_URL=mysql://smm:smm_password@127.0.0.1:3306/smm
JWT_SECRET=replace_with_a_long_random_secret
PROVIDER_API_URL=https://provider.example/api/v2
PROVIDER_API_KEY=replace_with_provider_key
CORS_ORIGIN=https://panel.example.com
DEFAULT_MARKUP_PERCENT=25
ENABLE_JOBS=false
For production, replace all placeholder values. The server refuses weak or placeholder production settings, and requires CORS_ORIGIN so browsers can only call the API from your real site origin.
Create Admin
ADMIN_USERNAME=admin \
ADMIN_EMAIL=admin@example.com \
ADMIN_PASSWORD='StrongPass123' \
DATABASE_URL=mysql://smm:smm_password@127.0.0.1:3306/smm \
npm run admin:create
Then sign in from the web UI.
Scripts
npm run dev # watch mode
npm start # run server
npm run migrate # apply migrations
npm run reconcile # wallet reconciliation
npm run sync:order-status # manually sync provider order statuses
npm test # lint + all tests + reconciliation
Make Commands
make db-up
make migrate
make start APP_PORT=3000
make test
make backup
Create an admin through make:
ADMIN_USERNAME=admin \
ADMIN_EMAIL=admin@example.com \
ADMIN_PASSWORD='StrongPass123' \
make admin-create
Backups
Create a database dump:
make backup
Restore requires an explicit confirmation:
BACKUP_FILE=backups/smm-YYYYMMDD-HHMMSS.sql CONFIRM_RESTORE=yes make restore
Provider
The provider integration is Perfect Panel-compatible:
servicesaddstatusbalance
Configure the real provider using PROVIDER_API_URL and PROVIDER_API_KEY. Provider keys are never exposed to the frontend.
Notes
- All wallet balance changes go through
wallet.service.js. - Money is stored as SQL
DECIMALand calculated using fixed-scaleBigInthelpers. - Partial provider orders are recorded for admin review; no automatic partial refund is performed until provider semantics are confirmed.