For Managed Service Providers
Managed MikroTik for every client, from one console
mikroHUB is a hosted, multi-tenant platform built for MSPs running MikroTik across many clients. Each client gets its own isolated organization, enforced by Postgres row-level security — while you monitor, back up and report on every fleet from a single cloud console.
One console, many clients
Every client is a separate organization with hard tenant isolation, scoped roles, and a full audit trail — so you can manage dozens of fleets without leaking data between them.
Org-per-client isolation
Every device, backup, alert and report is scoped to one client's organization. Postgres row-level security enforces the boundary at the database, not just the UI.
Owner / admin / viewer roles
Assign technicians admin rights to operate, or give a client read-only viewer access to their own fleet. Roles are scoped per organization.
Full audit log
Every action is recorded with user, device, IP and timestamp. When a client asks who changed what, you have the answer on record.
API keys and MFA
Drive monitoring and provisioning from your own tooling with scoped API keys, and protect privileged accounts with multi-factor authentication.
Deliver the service
Monitoring, LTE intelligence, automated backups, alerts and SLA — the operational toolkit you need to run managed MikroTik as a billable service.
Fleet monitoring + LTE
Real-time CPU, memory, uptime and interface traffic across every client, plus LTE intelligence: RSRP, RSRQ, SINR, signal history, tower geolocation, data usage and multi-SIM.
Automated backups
Scheduled configuration backups pulled over each device's own SSH/SFTP, with restore. Recover a client's router without driving to site.
Alerts and anomaly detection
Offline detection, CPU thresholds and LTE signal degradation trigger alerts and email digests. Anomaly detection surfaces problems before the client calls you.
SLA monitoring
Daily uptime snapshots and per-device SLA tracking give you the numbers to report against the service levels you promised each client.
Security you can put in front of a client
Plaintext device passwords never touch our database. Credentials live in an encrypted vault (AES-256-GCM), and in zero-trust agent mode the router pushes metrics outbound over HTTPS — so no stored password is needed to monitor it at all. Every fleet stays isolated in its own organization by row-level security.
Combined with scoped roles, MFA on privileged accounts and a full audit log, this is an architecture you can defend in a security questionnaire — and one you can hand a security-conscious client without caveats.
MSP FAQ
How are my clients isolated from each other?
Each client is a separate organization, and every resource is scoped to an org_id. Postgres row-level security enforces the boundary at the database level, so one client can never see another's devices, backups or data.
Can I give a client read-only access?
Yes. Invite the client into their own organization with the viewer role, which grants read-only visibility into their fleet. Your technicians keep admin or owner rights to operate.
How are device passwords protected?
Plaintext passwords never touch our database; credentials are held in an encrypted vault (AES-256-GCM). With zero-trust agent mode, the router pushes metrics outbound over HTTPS and no device password is stored at all.
Can I reach devices behind CGNAT?
Yes. mikroHUB can establish WireGuard tunnels to reach routers behind CGNAT or without a public IP, and agent mode also works outbound-only — so LTE devices without port forwarding are still fully manageable.
Is there an audit trail?
Yes. Every action is logged with user, device, IP address and timestamp, scoped per organization. It gives you an accountable record for both your team and your clients.
Related
Run managed MikroTik like a platform
Bring your first client's fleet onto mikroHUB in minutes. The free plan covers 3 devices with full multi-tenant isolation, monitoring and backups — no credit card required.