Skip to Content
πŸ–₯️ Self-HostingSelf-Hosting Overview

Self-Hosting Overview

Sitepins is free and open source. You can run the entire platform on your own infrastructure with zero third-party dependencies on hosted SaaS services.

What You Get

Every feature unlocked. The self-hosted build contains no paywalls, plan gates, or billing modules. Everything documented as Pro or Team throughout these docs is immediately available:

  • Unlimited Scale: No limits on organizations, sites, repositories, collaborators, or storage.
  • Full Editor Capabilities: Plate rich-text visual editor, raw Markdown editor, and full Monaco code editor.
  • Real-Time Collaboration: Multi-user editing powered by Yjs CRDTs with live cursor overlays, awareness rosters, and commit notifications.
  • Interactive Live Preview: Isolated execution of static site generators (Astro, Next.js, Hugo, TanStack, etc.) inside sandbox VMs.
  • Git Integrations: Native GitHub and GitLab support for branches, pull/merge requests, and direct commits.
  • Built-in SEO Tools: Live search-result previews, readability analysis, and rule-based audit engines.
  • AI Integration (BYOK): Multi-provider AI writing and SEO assistance with personal keys stored securely in the browser.
  • White-Labeling: Fully customizable brand name, logo, legal links, and commit email domains via environment variables.

What You Need

Running Sitepins requires a small set of standard open-source dependencies:

ComponentMinimum RequirementRecommended Production Choice
Node.js22.0.0 or newerNode.js 22 or 24 LTS
Package Managerpnpm 11.0.0 or newerpnpm 11.15+
DatabaseMongoDB 6.0 or newerMongoDB 7.0 (Local, Docker, or MongoDB Atlas)
Media StorageS3-compatible object storageAWS S3, Cloudflare R2, MinIO, or DigitalOcean Spaces
Git ProviderGitHub or GitLab accountGitHub App (repo access) + OAuth Apps (user login)
Reverse ProxyOptional in dev, required in prodNginx or Caddy with WebSocket upgrade support

High-Level Architecture

The core Sitepins platform consists of two primary services:

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ Next.js 16 Web App (:3000) β”‚ β”‚ CMS Interface β€’ Monaco Code Editor β€’ Plate β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚ HTTP / Cookies β”‚ Octokit / REST β–Ό β–Ό β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ Express 5 API (:4000) β”‚ β”‚ GitHub / GitLab API β”‚ β”‚ Auth β€’ MongoDB β€’ WS / IO β”‚ β”‚ (Site Content in Git) β”‚ β””β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚ Mongoose β”‚ S3 API β–Ό β–Ό β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ MongoDB β”‚ β”‚ S3 Bucket β”‚ β”‚ (State/Auth) β”‚ β”‚ (App Assets) β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
  1. app/ (Next.js 16 App Router): Serves the browser interface, Plate rich-text visual editor, Monaco code editor, and communicates directly with Git providers (GitHub/GitLab) for content reads and commits.
  2. api/ (Express 5): Handles user sessions via Better Auth, organization/project management, Socket.IO presence gateways, and the Hocuspocus WebSocket collaboration server.

Git provider credentials (such as your GitHub App private key) belong exclusively to the web app, not the API backend. The API never holds your repository signing keys.

Where Your Data Lives

Data TypeDestinationDurability & Ownership
Website Content & MediaYour Git repositorySingle source of truth. Your content remains completely portable and versioned in Git.
Accounts & OrganizationsMongoDB databaseStores user accounts, organization memberships, permissions, project configurations, and activity logs.
Application UI AssetsS3-compatible bucketStores user profile pictures (avatars), organization thumbnails, and project cover images.
AI API KeysUser’s browser (localStorage)By default, AI keys are stored locally in the client browser (BYOK) and never saved to the database.

Licensing

Sitepins is released under the GNU Affero General Public License v3.0 (AGPLv3). You are free to run, inspect, fork, and modify the source code.

Network Use Under AGPLv3: If you modify Sitepins and make that modified version accessible to users over a network (including private SaaS or hosting for clients), you must make the corresponding modified source code available to those network users under the AGPLv3. Running the standard, unmodified open-source build incurs no such obligation.

Documentation Roadmap

Follow these dedicated guides to set up, deploy, and maintain your instance:

  1. Architecture & Stack β€” In-depth breakdown of runtime processes, data flows, and security models.
  2. Installation Guide β€” Step-by-step setup using Docker Compose or manual pnpm.
  3. Environment Variables β€” Comprehensive reference for all api/.env and app/.env settings.
  4. GitHub & GitLab Apps β€” How to configure OAuth and GitHub App credentials.
  5. Media Storage β€” S3, Cloudflare R2, MinIO, and DigitalOcean Spaces configuration.
  6. Reverse Proxy & SSL β€” Production Nginx and Caddy virtual host configurations with WebSockets.
  7. Real-Time Collaboration & Preview β€” Architecture of Hocuspocus CRDTs and Vercel Sandboxes.
  8. Project Configuration β€” .sitepins/config.json specification and sidebar arrangement.
  9. API Reference β€” Complete REST and route handler endpoint documentation.
  10. Extension Points & Hooks β€” Extending Sitepins without modifying core source code.
  11. Troubleshooting & Runbook β€” Common error resolution and MongoDB disaster recovery.
  12. Contributing to Core β€” Development workflows, Vitest testing, and quality guidelines.
Last updated on