The iPhone app
mikr.app is a free iPhone app for your own MikroTik Manager server. It signs in to that server and shows what the server knows, live: which devices are down, what needs attention across the fleet, and one device in detail.
It is read-only. It cannot run commands, start upgrades or change configuration on a device. Those stay in the web interface, which works on a phone as well.
It talks to your server and nothing else. There is no account with us, no cloud relay and no analytics in the app.
What you need
- An iPhone on iOS 26 or newer.
- A running MikroTik Manager server that the phone can reach: on the same network, or over a VPN when you are away. The app does not open a way in from the internet, so the phone has to be able to reach the server on its own.
- A user account on that server. The app uses the same username, password and two-factor code as the web interface.
To look around without a server, tap Explore the Demo on the sign-in screen. It opens a sample fleet built into the app, connects to nothing, and every screen works. Leave Demo on the More tab takes you back.
Signing in
Type the server's address with the port, the same address you open in a browser, for example http://10.0.0.5:3000. Without http:// or https:// the app assumes http://. It never adds a port on its own: 3000 is the default, but a server behind a reverse proxy answers somewhere else.
The address is checked while you type. When the server answers, the app shows its version under the field, so you know the address is right before you enter a password.
The first time the app reaches an address on your local network, iOS asks for permission to use the local network. Allow it, or the app cannot reach a server on the LAN.
If your account has two-factor sign-in, the next screen asks for the six-digit code from your authenticator app. One of your backup codes works there too. Passkeys are not offered in the app, so keep an authenticator app or backup codes for your phone.
What the app shows follows your account's role and site access on the server, the same as the web interface. A viewer, for example, does not see backup coverage.
HTTPS and self-signed certificates
Plain HTTP on a local network works. Over HTTPS with a certificate no public authority has signed, which is what the manager generates for itself, the app shows the certificate's SHA-256 fingerprint and asks whether to trust it.
Compare that fingerprint with your server's certificate before you tap Trust and Continue. Once accepted, it is the only certificate the app accepts from that address. If the certificate changes later, the app refuses the connection and asks again.
Face ID and more than one server
The sign-in is kept in the iPhone Keychain on that phone. When the phone has Face ID or Touch ID, the app asks for it on start before it uses the stored sign-in. The switch for it is on the More tab. It locks the app on your phone. It does not change what your account can do on the server.
You can add several servers. Each keeps its own sign-in, and switching between them does not sign you out of the others. Removing a server from the app deletes its sign-in from the phone and changes nothing on the server.
What you see
- Fleet says first whether everything is answering, then lists only what is not: devices down, and one line for each kind of problem. It also shows your sites, backup coverage, and a device flooding the log when one is.
- Issues lists every problem across the fleet, worst first: devices down, readings over the thresholds set on your server, PoE budget, RouterOS and firmware behind the latest release.
- Devices is the whole list, grouped by site and searchable.
- A device shows CPU, memory, temperature, PoE and power with their history, the ports drawn as they sit on the box with live traffic, the clients behind it (DHCP leases and wireless registrations), VLANs, WireGuard and IPsec tunnels, neighbours and the device's log.
The fleet updates on its own while the app is open, over the same live connection the web interface uses. When the app goes to the background the connection closes, and it reads the fleet again when you come back.
What it does not do
- No commands, upgrades, backups or settings. Use the web interface for those.
- No push notifications. For alerts on your phone, send them from the server with webhooks, for example to ntfy or Discord.