Skip to content
KANAP
EN
Start free trial
Self-hosting · first-class citizen

Run KANAP yourself. Own every layer.

Open source under AGPL v3. Deploy to your infrastructure, own your data, update on your cadence. The full platform, unlimited users, every feature, on your terms.

Why self-host

Control, compliance, and no strings attached.

Self-hosting KANAP is not a stripped-down tier. It's the full platform, with the full feature set, free of charge. These are the reasons teams pick it first.

Your data stays put

Budget figures, supplier contracts, IT landscape, everything. On your servers, in your network. No third-party data processor to trust with your governance data, except the services you choose to connect, such as an AI model provider or an email relay. The agent runtime and its actions run there too, which matters when an auditor asks.

No per-seat tax

Unlimited users, unlimited workspaces, Plaid and agents with your own LLM key. Roll it out to the entire department without a pricing page spreadsheet.

Compliance-ready

Row-level security isolates tenants. Argon2 password hashing. HTTPS with certificates you control. Your VPC, your backups, your SOC.

Audit the source

AGPL v3 means the code is open. Your security team reads it, your architects extend it, your CISO sleeps better.

Air-gap friendly

Docker Compose deployment runs in restricted networks. You build the images from the public source, and once built they make no mandatory outbound calls for core functions.

Your cadence

Pin the version you run, test an update, migrate on your change-window schedule. No forced updates, no surprise downtime.

AGPL v3: openness without compromise

KANAP is released under the GNU Affero General Public License v3. You get every classic open source freedom: use it, read it, modify it, distribute it. The copyleft provision means anyone who runs a modified version as a service must share their changes, which is how the project stays genuinely open.

  • Use it commercially, internally, or externally, no royalty, no seat count
  • Read and audit the full source, nothing hidden
  • Modify and extend, the code is yours to shape
  • Contribute back, your improvements benefit the whole community
Read the AGPL v3 license →
Install in minutes

One prompt. Fifteen minutes.

A coding AI agent reads our documentation, installs every dependency, and configures the whole stack (Docker, PostgreSQL 16, MinIO, nginx, Let's Encrypt) on a clean Ubuntu server. You paste one prompt, confirm the steps, and log in.

  1. 01

    Prepare a clean server

    A freshly provisioned Ubuntu 24.04 LTS host with sudo access, a DNS A record pointing your hostname at it, and outbound internet for packages and Let's Encrypt. Install your AI coding agent on the server (Claude Code, Codex, anything similar).

  2. 02

    Grant temporary passwordless sudo

    So the agent isn't prompted for your password on every step. You'll revert this at the end.

    echo "$USER ALL=(ALL) NOPASSWD:ALL" | sudo tee /etc/sudoers.d/90-install-nopasswd
  3. 03

    Paste the install prompt

    Open your agent and paste the prompt template from our docs, then fill in your hostname, admin email and (optionally) your email transport (Resend or SMTP). The agent reads the linked install pages, installs Docker, PostgreSQL 16 with the required extensions, MinIO, nginx and certbot, clones KANAP into /opt/kanap, generates strong credentials, builds the images and starts the containers. It also wires up TLS and auto-renewal. The agent asks for confirmation before running each command.

  4. 04

    Sign in and harden

    Log in at your hostname with the generated admin credentials, change the password, then remove the temporary passwordless sudo entry. Done. The full install log is saved at ~/kanap-install.md.

What you'll need

Modest requirements for a platform that runs the whole IT department.

OS
Any Linux with Docker (Ubuntu 22+, Debian 12+, RHEL 9+ recommended)
CPU
2 vCPU minimum · 4+ recommended for 50+ users
RAM
4 GB minimum · 8 GB recommended
Storage
20 GB for the platform + whatever your data grows to, plus S3-compatible object storage
Database
PostgreSQL 16+ with citext, pgcrypto and uuid-ossp (you provide it)
Network
HTTPS terminator (your choice, nginx, Traefik, cloud LB)
Outbound (optional)
FX rate APIs (World Bank, exchangerate-api.com) · LLM provider for Plaid and agents · Microsoft Entra for SSO · Resend or your SMTP relay for email · Web search provider, if enabled

Operating KANAP

Built to run like any other internal service.

Updates on your schedule

Pin the version you run, test an update in pre-prod, apply it in your change window. Migrations run on boot, idempotent by design.

Backups with your own tools

Standard PostgreSQL and file storage. Back them up with the pipeline you already run.

Observability you already have

Containers write logs to stdout and expose a health endpoint. Point your existing stack at them (Prometheus, Loki, Datadog, whatever you already run).

Branding included

Upload your logo, set your primary color. The admin branding page works the same in self-hosted as in cloud.

SSO via Entra ID

Enterprise SSO is part of the core platform. Add your Entra app registration to the configuration, then connect it from the admin console.

Plaid and agents, your way

Bring your own LLM key for both Plaid and your agents, OpenAI, Anthropic, Ollama, or any OpenAI-compatible endpoint. The agent runtime and its actions run inside your own deployment. The only content that leaves is what you send to the provider you chose, plus short web search queries if you turn web search on.

Ready to self-host?

Clone the repo and bring up the stack in under ten minutes. No account required, no trial countdown, just open source.