Log inJoin the waitlist

Search the help center, features, guides and more.

Self-host

Your server. Your rules.

Run the same server that runs Vallkey Cloud, on your own hardware. Your devices still encrypt everything, so even your own server sees only ciphertext.

What you run

The same server as Vallkey Cloud.

Not a cut-down version: everything the hosted service does, on hardware you choose, and with no plans to buy.

  • Sync, sharing, families and legacy contacts
  • The web vault, served on the server's own address
  • Files kept with items, end-to-end encrypted
  • The key transparency log your devices check
  • Organizations, with single sign-on, SCIM and audit logs
  • Instant sync over WebSockets, and request limits before sign-in

Running it

One binary, one file, one address.

  1. Start the server

    One program, told where to listen and where to keep its data. It sets itself up, and brings itself up to date at every start.

  2. Put https in front

    A reverse proxy such as Caddy gets the certificate by itself and passes requests on. The apps refuse plain http for anything but the same computer.

  3. Type its address in the apps

    The browser extension, the web vault, the desktop app, and the iPhone, iPad, Mac and Android apps all connect to the address you give them.

Included

What it does.

  • Email over SMTP

    Recovery codes, invitations and legacy contacts' notices go through your own mail service, with its certificate checked.

  • Backups while it runs

    One command writes a whole, consistent copy of the database, readable by its owner only.

  • Upgrades that carry on

    Start the new version, and it brings the database up to date. Devices keep working offline meanwhile.

  • Aliases on your own domain

    Email aliases work with the relay and a mail server of your own.

  • Single sign-on and a key connector

    Your identity provider vouches for your people, and a key connector on your servers can stand in for master passwords.

  • Nothing to trust it with

    Everything in the database is encrypted by keys only the devices have. The server's own setup file is its one secret to guard.

Later

Packaged for bigger deployments.

For larger installs.

  • Signed releases and an image

    Downloads, a Docker image, and updates.

  • A database server

    For companies, with several servers behind one address.

  • S3-compatible storage

    Files kept with items, on any S3-compatible store. Today they're in the database, up to 1 GB an account.

  • Helm chart

    For Kubernetes.

  • An admin page

    To make and remove accounts. Today people make their own, and remove them.

  • Enterprise license

    Enterprise features unlock with a signed license file, checked offline.

Questions

Is the self-hosted server different from Vallkey Cloud?

No. It's the same server binary. Self-hosting doesn't mean a cut-down version.

Does it need a database server?

No. It keeps everything in one file, which it makes and brings up to date by itself. A database server and outside file storage, for bigger installs, come later.

Will the official apps work with my server?

Yes. Every app asks which server to use when you create an account or log in: type your server's address. It has to be https, through a reverse proxy such as Caddy or nginx.

Can my server read my vault?

No, any more than ours can. Everything is encrypted on your devices; the server stores only ciphertext.

Who can make an account on it?

Anyone who can reach it. To keep it to your household or team, put it where only they reach it: a VPN, or your proxy's own access rules.

Is self-hosting free?

Yes. Running the server for yourself is free, and a self-hosted server sells no plans: every account on it has everything.

Your passwords. Your keys. Your price.

Vallkey opens soon. Join the waitlist to hear first.