Features

Every feature, by edition

The Community edition is free, with no limits on hosts, nodes or users, and everything marked Community stays free. Paid editions add features for teams, compliance and scale. A license only controls setting up or changing a paid feature: nothing on the request path ever checks it.

"Homelab and up" means Homelab, Business, Enterprise and MSP; "Business and up" means Business, Enterprise and MSP. MSP includes everything in Business plus its own features. Compare editions in one table.

Proxy and certificates

Everything Caddy serves, configured from one place.

  • Proxy hosts

    Several upstreams per host, eight load-balancing policies, active and passive health checks, retries, custom headers and an on/off switch. Documentation

    • Community
  • Location rules, redirects and rewrites

    Path-based routing to other upstreams (for example /api/* to one backend), redirect rules (301, 302, 307, 308) and path prefix rewrites. Documentation

    • Community
  • L4 TCP and UDP proxying

    Stream proxying with TLS SNI matching, the PROXY protocol (v1 and v2), load balancing, health checks and geo blocking. A sidecar manages the Docker Compose ports.

    • Community
  • Automatic HTTPS

    Certificates from Let's Encrypt or your own ACME directory for every host, DNS-01 through 22 DNS providers with credentials encrypted at rest, and imported certificates with expiry monitoring. Documentation

    • Community
  • Internal CA and mTLS

    Issue and revoke client certificates from a built-in CA, require them per host, and give certificate roles access to chosen paths. Documentation

    • Community
  • Default response and DNS controls

    What unknown hosts and direct-IP requests get, custom resolvers per host and upstream DNS pinning.

    • Community
  • Host tags

    Free-form tags on proxy and L4 hosts, shown in the lists and matched by their search; a custom role can be limited to hosts with one of its tags. Documentation

    • Community

Security

What stands in front of each host, and what it stopped.

  • Web application firewall

    Coraza with the OWASP Core Rule Set 4.25: paranoia levels, anomaly thresholds, detection only or blocking per host, rule exclusions scoped to a host, path or variable, and custom SecLang rules. Documentation

    • Community
  • Security events

    What the WAF, geo rules, access lists, sign-in and rate limits stopped, with the reason, the top rules and sources, and one-click blocking of an address. Documentation

    • Community
  • Access lists and geo blocking

    Ordered allow and deny rules by address, CIDR range, country, continent or AS number, HTTP basic auth, and a global list of blocked sources with expiring entries. Documentation

    • Community
  • Rate limiting

    Per host and global, by path and method, counted per client address, request header or signed-in user, answering 429 with Retry-After. Documentation

    • Community
    • New

Sign-in and identity

Who may use the dashboard, and who may reach your apps.

  • Forward auth portal

    A built-in sign-in page in front of any proxy host, with access by user or group and paths that skip it; or an external forward-auth server: Authentik, Authelia or another. Documentation

    • Community
  • OpenID Connect sign-in

    Dashboard sign-in through any OIDC provider (Authentik, Keycloak, Auth0 and others), with account linking. Documentation

    • Community
  • Multi-factor authentication and passkeys

    Authenticator apps, backup codes and passkeys for dashboard sign-in, and a policy that requires them. Documentation

    • Community
    • New
  • Users, groups and built-in roles

    Viewer, user and admin, groups for forward-auth access, and a view of how each account signs in and when it last did. Documentation

    • Community
  • SAML single sign-on

    Sign in to the dashboard through a SAML 2.0 identity provider, with group-to-role mapping. Documentation

    • Business and up
  • Enforced SSO

    Turn off password sign-in for everyone except named break-glass accounts. Documentation

    • Business and up
  • LDAP / Active Directory

    Dashboard sign-in with LDAP or Active Directory accounts, with group-to-role mapping. Documentation

    • Enterprise
  • SCIM provisioning

    Create, update and disable users and groups from your identity provider (Microsoft Entra ID, Okta and other SCIM 2.0 clients). Documentation

    • Enterprise
The Users page: each account with its role, where it signs in from (local, OIDC, SAML, LDAP or SCIM), its second factor and last sign-in.
Users and groups: role, sign-in source, second factor and last sign-in for every account.

Roles, audit and change control

Who changed what, and who may.

  • Audit log

    Every change, sign-in and check, linked into a tamper-evident hash chain, with the before and after of each change. Documentation

    • Community
  • Configuration export and import

    Hosts, access lists, certificates and settings in one file, with every secret encrypted by a passphrase, to load on the same or another install. Users, sessions, API tokens, the audit log and the license stay out of it. Documentation

    • Community
  • Custom roles

    Roles with fine-grained permissions, scoped to tagged hosts so teams can share one install. Documentation

    • Business and up
  • Audit streaming and export

    Stream the audit log to a SIEM (syslog, webhook, Splunk HEC), export it, set retention and verify its hash chain. Documentation

    • Business and up
  • Configuration history and rollback

    A snapshot of the configuration on every change, with diffs and one-click rollback. Documentation

    • Homelab and up
  • Scheduled backups

    Encrypted configuration backups to your own S3-compatible storage on a schedule. The secrets in them are encrypted with a passphrase; host names and settings stay readable, so keep the bucket private. Documentation

    • Business and up
  • Change approvals

    Four-eyes approval for changes to protected hosts, and change windows. Documentation

    • Enterprise

Analytics and alerts

What happened, and who needs to know.

  • Traffic analytics

    Every request in ClickHouse for 30 days by default, nothing sampled: outcomes, countries and networks, top lists, a request log, CSV export and saved views. Documentation

    • Community
  • Overview and needs attention

    The first page after sign-in: what needs attention, most severe first, traffic, the busiest hosts, the nodes and the latest changes. Documentation

    • Community
  • Certificate expiry e-mails

    An e-mail before a certificate expires, without a license. Documentation

    • Community
  • Prometheus metrics

    Caddy's metrics for your own monitoring.

    • Community
  • Alerting

    Alerts for certificates, upstreams, WAF spikes and sync failures to e-mail, Slack, Teams, PagerDuty, ntfy or a webhook. Documentation

    • Homelab and up
  • AI analyst

    Plain-language alert explanations, a daily security digest and WAF tuning suggestions, using your own model. It also answers questions about your traffic asked in plain language on the Analytics page, with the numbers, a chart or a table and the query the question was read as. Documentation · Analytics questions

    • Homelab and up

Compliance

Evidence for audits, from what Ingressi already records.

  • Compliance reports

    Access reviews, change logs, certificate inventory and WAF/MFA coverage mapped to NIS2 and ISO 27001, and NIS2 incident notification drafts. Documentation

    • Enterprise
  • Access reviews

    Periodic access recertification: reviewers keep or revoke each user's roles, groups and API tokens, with a downloadable record. Documentation

    • Enterprise

Fleet and scale

More than one node.

  • Instance sync

    A master pushes proxy hosts, certificates, access lists and settings to its replicas on every change, with secrets sealed to each replica's own key. Documentation

    • Community
  • PostgreSQL

    Keep the dashboard's data in PostgreSQL 16 or later instead of SQLite: your own server, or the one the bundled compose file runs next to the stack. A copy tool moves an existing install from SQLite and compares every table before it commits. Documentation

    • Community
    • New
  • Fleet management

    Manage many nodes: environments, promotion, drift detection and canary rollout. Documentation

    • Enterprise
  • High availability

    Shared certificate storage for Caddy nodes (Redis or Valkey): each certificate is ordered once and every node serves it. A dashboard cluster: one leader and warm standbys, SQLite streamed to object storage with Litestream, automatic failover. Shared state: forward-auth sessions and API balances in the same Redis or Valkey, so every web node serves them alike. PostgreSQL replicas: several dashboard containers on one PostgreSQL database, each serving every request, one running the background jobs. Documentation

    • Enterprise
  • Air-gapped installs

    Offline install bundle for hosts without Internet access. Long-term-support releases are planned, not announced yet. Documentation

    • Enterprise

Service providers

One install, many clients.

  • Multi-tenancy

    Isolated organizations with their own admins, hosts and usage reports. Documentation

    • MSP
  • White-label

    Your own product name, logos, favicon, colours, sign-in texts and e-mail sender name, for your clients to see. Documentation

    • MSP

API and integrations

Automate everything the dashboard does.

  • REST API

    Every resource under /api/v1 with Bearer tokens, which can be limited to chosen permissions, and interactive OpenAPI 3.1 docs at /api-docs. Documentation

    • Community
  • Command palette

    Ctrl+K searches hosts, certificates, users, pages, settings and documentation, and runs common actions. Documentation

    • Community
  • API monetization

    Charge your API's consumers per request through your Stripe account, enforced at the edge: prepaid, postpaid with a hard cap, or x402 through Stripe machine payments. Prepaid consumers top up a balance; postpaid ones pay afterwards with a saved card; x402 takes USDC on Base, paid to your Stripe account (a Stripe preview). Documentation

    • Enterprise

On the roadmap

Planned, not shipped. We do not sell what is not built.

  • Upgrades without stopping every replica

    The next phase of high availability: today, upgrading dashboard replicas on PostgreSQL stops every replica first. Next phases

    • Enterprise
  • Virtual patching

    Coming soon. WAF rules for newly published CVEs from a signed feed, fetched daily or imported offline, each in detection or blocking mode. New patches will start in detection unless you choose to block new critical ones automatically, and a feed that fails its signature or any other check will be refused whole. How it will work

    • Enterprise
  • Long-term-support release lines

    The policy is drafted: one release a year becomes an LTS line with 24 months of security and critical fixes. The first LTS line has not been announced yet. LTS policy

    • Enterprise

Missing something? Open an issue on GitHub.