Every ISP operator I spoke to during research mentioned the same daily frustration: enabling and disabling MikroTik accounts manually. A customer pays at 9pm. Staff are off. The customer calls the owner's personal number to ask why the internet is still cut. The owner logs into WinBox from his phone to re-enable the PPPoE user. This happens 10–20 times a month.
The fix is obvious in theory: connect the billing system to MikroTik's API so that when a payment is received, the router is updated automatically. In practice, it requires careful engineering.
The MikroTik RouterOS API
MikroTik exposes a TCP API on port 8728 (or 8729 for SSL). You send encoded binary commands and receive responses. It's low-level, but powerful. With the routeros-api PHP library, we can send commands like:
$client->query('/ppp/secret/set', [
'.id' => $secretId,
'disabled' => 'no',
]);The entire PPPoE user lifecycle — create, suspend, reactivate, update speed, delete — maps to a set of API commands against /ppp/secret and /queue/simple.
The event-driven architecture
We built the MikroTik layer as a set of queued jobs triggered by Laravel events:
CustomerActivated→CreateMikrotikUserJob(creates PPPoE secret + queue)InvoicePaid→ReactivateMikrotikUserJob(enables PPPoE + queue)CustomerAutoSuspended→SuspendMikrotikUserJob(disables PPPoE + queue)PackageChanged→UpdateMikrotikQueueJob(updates queue max-limit)CustomerTerminated→DeleteMikrotikUserJob(removes PPPoE + queue)
Each job runs through Laravel Horizon on a dedicated Redis queue. If the MikroTik device is unreachable, the job retries 3 times with exponential backoff. After 3 failures, a NOC alert is fired and the failed job is logged for manual retry.
Multi-device support
ISPs often have 3–5 MikroTik routers serving different zones. We store each device in the mikrotik_devices table with encrypted credentials. Customers are assigned to a device based on their network zone. When a job fires, it opens a TCP connection to the correct device, executes the command, and closes the connection.
A "sync" tool lets ISP admins compare the system state against the actual MikroTik state — showing discrepancies between what's in the database and what's configured on the router.
The result: payment received → connection reactivated in under 30 seconds, 24 hours a day, without any human involved.
---
