The middleware platform for your edge
One place to terminate, authenticate, fan-out and route everything that crosses your perimeter — HTTP, webhooks and SIP/RTP. Built on Bun, self-hosted, audit-logged.
HTTP proxy & gateway
Profile-based reverse proxy with credential injection, per-route IP allowlists, blocked extensions and streamed forwarding with zero buffering.
Identity & access
Built-in user login (JWT + TOTP), static access keys, OAuth 2.0 / OIDC provider, LDAP directory adoption and per-profile consent pages.
Webhook distribution
Fan-out incoming payloads to multiple destinations with body templating, retry policies, persistent retry queue, DLQ and silence alerts. Native Meta verification.
SIP & RTP relay
TCP / UDP / TLS listeners, Via & Record-Route rewriting, multi-threaded RTP media relay so your PBX can stay on a private network.
Certificate store
Central PEM/ACME cert store with Let's Encrypt issuance and renewal. Optional read-only integration with an Nginx Proxy Manager Let's Encrypt volume.
Observability & audit
Per-profile request logs, SIP message logs, OpenTelemetry traces & metrics, and a full audit trail of every admin action.
Nginx Proxy Manager bridge
Manage NPM proxy hosts and certificates from the dashboard. Adopt existing hosts into Midleman profiles or webhooks — bulk import in one click.
Operator essentials
SMTP, invite-based onboarding, encrypted credentials at rest, sandboxed config in JSON files, single Docker image.