updated September 30, 2026
Self-hosted Enterprise
With an Enterprise license, Tokaware runs on your own servers: the same console, API and collection, in one container image, its data in your database. Nothing is sent to us: the license is checked on the server, offline.
What you need
- A Linux server with Docker, or a Kubernetes cluster, with 2 GB of memory for a few hundred people.
- Somewhere to keep the data: a volume for /data, where the database is a file, or a libSQL database (Turso, or sqld of your own).
- HTTPS in front of it: a reverse proxy or load balancer. Sign-ins only work over HTTPS.
- Your license, from sales@tokaware.com.
Run it
The image serves the website and its API on port 3000. Its database migrates itself when it starts, and the scheduled jobs (alerts every five minutes, the connectors and the weekly digest's turn every hour, retention every night) run inside it.
docker run -d --name tokaware -p 3000:3000 \ -v tokaware-data:/data \ -e APP_SECRET=<32 or more random characters> \ -e APP_ORIGIN=https://ai.example.com \ -e TOKAWARE_LICENSE=<your license> \ tokaware
Settings
| Variable | What it does |
|---|---|
| APP_SECRET | Required: 32 or more random characters. Encrypts what the database keeps; without it, what is kept cannot be read. To change it, set APP_SECRET_PREVIOUS to the old one and run the reencrypt job. |
| APP_ORIGIN | The server's https:// address, as people reach it. Every link it sends or hands out (emails, invites, sign-in) uses it. |
| TOKAWARE_LICENSE, TOKAWARE_LICENSE_FILE | The license, or a file that holds it. A file can be replaced while the server runs. |
| LIBSQL_URL, LIBSQL_AUTH_TOKEN | The database. By default, file:/data/tokaware.db. |
| RESEND_API_KEY, EMAIL_FROM | Email (invites, verification, alerts, the digest) through Resend. Without them, nothing is emailed. |
| GOOGLE_CLIENT_ID and _SECRET, MICROSOFT_CLIENT_ID and _SECRET | Google and Microsoft sign-in, each once both are set. |
| WORKOS_API_KEY, WORKOS_CLIENT_ID, WORKOS_WEBHOOK_SECRET | SAML single sign-on and SCIM directory sync, through WorkOS. |
| TOKAWARE_ADMIN_EMAILS | The people who see the server's admin console, by email, comma-separated. |
| CRON_SECRET | Lets you run a job by hand: GET /api/cron/<job> with Authorization: Bearer and this value. |
The license
A license says whom it is for, the plan, the billable seats each organization on the server may have, and its last day, signed with our key; the server checks it offline. Invites and joins stop at the seats; the billing and viewer roles take none.
After its last day, the paid features turn read-only and nothing is lost: with a new license, everything is back at once. Without a license, or with one that does not check out, the organizations are on Free, and their history is kept until a good license is in place. Settings, Billing shows the license and its state.
Computers
The desktop app reports to your server when its managed configuration names it as the accounts server, and Claude Code's and Codex's own telemetry goes to your server's /api/otel/v1 with an ingest token made there.
Monitoring
GET /api/health tells your uptime checks whether the server is ok, degraded or down. Down, a 503, is when its database does not answer; degraded, still a 200, is when a scheduled job failed, is late or has not run yet, and its problems say which in words. It names no one and repeats nothing the jobs said. The image's own health check uses it.
The server writes a line of JSON to its log for each job's run, each webhook it receives, each connector's sync and each alert it sends: docker logs shows them, and a log collector can read them by field. The admin console shows the same health, with how the server is set and what is failing.
curl https://ai.example.com/api/health
{"status":"ok","checkedAt":"2026-10-01T09:00:00.000Z","database":{"ok":true,"ms":3},
"jobs":{"retention":{"state":"ok","lastRun":"2026-10-01T02:41:00.000Z"},"alerts":{"state":"ok","lastRun":"2026-10-01T08:55:00.000Z"},…},
"problems":[]}Backups and updates
- Back up /data (or your libSQL database) as you back up any database, and APP_SECRET with it: a backup cannot be read without it.
- To update, run the new image with the same volume and settings: the database migrates itself as it starts.