Self-host
Your server. Your rules.
Run the same server that runs Vallkey Cloud, on your own hardware. Your devices still encrypt everything, so even your own server sees only ciphertext.
What you run
The same server as Vallkey Cloud.
Not a cut-down version: everything the hosted service does, on hardware you choose, and with no plans to buy.
- Sync, sharing, families and legacy contacts
- The web vault, served on the server's own address
- Files kept with items, end-to-end encrypted
- The key transparency log your devices check
- Organizations, with single sign-on, SCIM and audit logs
- Instant sync over WebSockets, and request limits before sign-in
Running it
One binary, one file, one address.
Start the server
One program, told where to listen and where to keep its data. It sets itself up, and brings itself up to date at every start.
Put https in front
A reverse proxy such as Caddy gets the certificate by itself and passes requests on. The apps refuse plain http for anything but the same computer.
Type its address in the apps
The browser extension, the web vault, the desktop app, and the iPhone, iPad, Mac and Android apps all connect to the address you give them.
Included
What it does.
Email over SMTP
Recovery codes, invitations and legacy contacts' notices go through your own mail service, with its certificate checked.
Backups while it runs
One command writes a whole, consistent copy of the database, readable by its owner only.
Upgrades that carry on
Start the new version, and it brings the database up to date. Devices keep working offline meanwhile.
Aliases on your own domain
Email aliases work with the relay and a mail server of your own.
Single sign-on and a key connector
Your identity provider vouches for your people, and a key connector on your servers can stand in for master passwords.
Nothing to trust it with
Everything in the database is encrypted by keys only the devices have. The server's own setup file is its one secret to guard.
Later
Packaged for bigger deployments.
For larger installs.
Signed releases and an image
Downloads, a Docker image, and updates.
A database server
For companies, with several servers behind one address.
S3-compatible storage
Files kept with items, on any S3-compatible store. Today they're in the database, up to 1 GB an account.
Helm chart
For Kubernetes.
An admin page
To make and remove accounts. Today people make their own, and remove them.
Enterprise license
Enterprise features unlock with a signed license file, checked offline.
Questions
Is the self-hosted server different from Vallkey Cloud?
No. It's the same server binary. Self-hosting doesn't mean a cut-down version.
Does it need a database server?
No. It keeps everything in one file, which it makes and brings up to date by itself. A database server and outside file storage, for bigger installs, come later.
Will the official apps work with my server?
Yes. Every app asks which server to use when you create an account or log in: type your server's address. It has to be https, through a reverse proxy such as Caddy or nginx.
Can my server read my vault?
No, any more than ours can. Everything is encrypted on your devices; the server stores only ciphertext.
Who can make an account on it?
Anyone who can reach it. To keep it to your household or team, put it where only they reach it: a VPN, or your proxy's own access rules.
Is self-hosting free?
Yes. Running the server for yourself is free, and a self-hosted server sells no plans: every account on it has everything.
Your passwords. Your keys. Your price.
Vallkey opens soon. Join the waitlist to hear first.