MikroTik PPPoE billing with automatic expiry
Last updated: 2 October 2026
If you sell home or business internet over PPPoE on MikroTik, the daily work is not the router. It is knowing who has paid, cutting off those who have not, and renewing people quickly. This guide shows how to move PPPoE accounts from secrets on the router to packages that expire and renew by themselves.
The problem with PPP secrets
A PPP secret on the router has a name, a password and a profile. It has no end date. So an unpaid customer stays online until somebody remembers to disable the secret, and a renewal means logging in to the router again. Scripts can add expiry, but they must be written, kept in sync with a spreadsheet of who paid, and repaired after upgrades.
PPPoE accounts on RADIUS
With RADIUS the router asks a server at every PPPoE login. The server knows the customer's package and end date, so it answers with the right speed, or refuses the login when the package has ended. One setting turns this on:
/ppp aaa set use-radius=yes accounting=yes
RadiusNest sets this for you as part of its setup command.
Setting it up
- Create your account. Start the free trial; no payment details are asked for.
- Add the router. Give it a name and choose RouterOS v7 or v6.
- Paste one command. The dashboard shows a single command made for that router. Paste it into the router's terminal (Winbox → New Terminal). It sets up the secure link to RadiusNest and switches hotspot and PPPoE logins to RADIUS.
- Make a package. Name, speed, data limit, time limit, how many days it is valid, and your price.
- Add users or print vouchers. They can log in at once, and each limit is enforced by itself.
For PPPoE, create each customer as a user with the PPPoE service and a package. Their username and password go into their home router as usual.
Day to day
- Expiry: when a package ends, the customer is disconnected and cannot log in again until renewed. Nothing to do on the router.
- Renewal: press Renew on the user. The new period is added and the sale is recorded at your package price.
- Speed: each package carries its speed; changing a customer's package changes their speed.
- Fixed address: a customer who needs one can be given a static IP address.
- Who is online: live sessions with address, device and data used, per router.
- Takings: this month and last, by package and by seller.
Fewer calls from customers
Each customer gets a page of their own, and your Telegram bot if you set one up, where they see how many days and how much data they have left and can change their own password.
Start the free trial See pricing
Questions and answers
Will existing PPP secrets on the router stop working?
No. Secrets on the router keep working next to RADIUS users, so you can move customers one at a time.
How is an expired PPPoE customer cut off?
Automatically. When the package ends the session is disconnected and new logins are refused until you renew the user.
Can I run hotspot and PPPoE from the same dashboard?
Yes. A user or package can be for hotspot, for PPPoE or for both, and both appear in the same lists and reports.
Can my staff renew customers without router access?
Yes. Staff logins work in the dashboard only and never see the router password.
What happens to my customers if my own RadiusNest plan runs out?
They keep working for a few grace days while you renew. Adding new users is paused during that time.