Getting started · Chapter 1
Setting up nexpaper
nexpaper runs as a single Docker container on your own server, a NAS for instance or a small computer at home. This chapter takes you as far as the first account. Putting nexpaper behind a reverse proxy, the environment variables and how updates work are covered in full under Self-hosting.
What you need
- A machine with Docker and Docker Compose. The image is built for Intel and AMD processors (amd64) and for ARM (arm64).
- A folder on a local disk for the data. nexpaper's database is a SQLite file, and it cannot live on an SMB or NFS share, because its locks do not work reliably over a network drive. The documents themselves may sit on a share later.
- An authenticator app on your phone, for the second factor. Any app that shows six-digit codes is fine. If you would rather not use an app, you can add a passkey later.
Starting the server
- Create the compose file
In an empty folder, create a file called
docker-compose.yml. For a start, this is all it needs. The longer version with every option explained is on the Self-hosting page.docker-compose.ymlservices: nexpaper: image: ghcr.io/derkezorm/nexpaper:latest container_name: nexpaper restart: unless-stopped ports: - "127.0.0.1:8560:8000" volumes: - ./data:/data environment: PUID: 1000 PGID: 1000 TZ: Europe/Berlin - Start the container
In the folder of the file:
Shelldocker compose up -d - Fetch the setup code
When it starts, nexpaper writes a setup code to its log. A new one is made at every start until the first account exists. If you would rather choose the code yourself, set
NEXPAPER_SETUP_TOKEN.Shelldocker logs nexpaper - Open nexpaper
The file above opens port
8560on the machine itself only. There you reach nexpaper athttp://127.0.0.1:8560. To reach it from your home network, write8560:8000instead of127.0.0.1:8560:8000, but only for a network you trust. Without https, passwords and codes otherwise cross the network unencrypted. For everyday use a reverse proxy with https belongs in front of it, if only because the camera in the browser and passkeys both insist on an https address.
Creating the first account
The first page is called “Set up nexpaper”. The account you create here runs the server. It invites the others and may change every setting. It does not look into the personal vaults of the others. The setup code makes sure that nobody who happens to reach a fresh instance first can take it over.
- Enter the code, a name and a password
“Setup code” takes the code from the log. The “Name” is the one you sign in with: 2 to 64 characters made of letters without accents, digits, dot, hyphen or underscore. The “Password” has at least 12 characters. Then tap “Create account”.
- Set up the second factor
Right after that comes “Set up your second factor”. It is compulsory out of the box for every account that signs in with a password. Scan the QR code with your authenticator app, or type in the key under it, enter the six digits the app shows under “Code from the app” and press “Turn on”.
- Keep the recovery codes
Now nexpaper shows eight recovery codes, this once and never again. Each one signs you in once when your phone is not at hand. Take them with you with “Copy” or “Save as file”. Keep them apart from the phone, then tap “I have them, go on”.
After that you are signed in. On a computer you see the archive, still empty; on a phone you see the quick upload. A passkey, which means signing in with a fingerprint, your face or the PIN of the device, you add later under “My account”, tab “Security”. It counts as two factors by itself. Passkeys need an address with https, and for that the operator has to enter the public address first (see below). Only on localhost do they work without.
What is worth doing next
- Enter the public address. Under “Settings”, tab “Sign-in”, you find the field “Public address”. Invitations, Web Push and passkeys need it, and so does a sign-in provider. Enter the address you reach nexpaper under, the one with https.
- Know the backup. Out of the box nexpaper makes a backup every night and keeps seven of them, in the data folder on the same server. A backup holds the accounts, the settings, the filing of the documents and the server key, but not the documents themselves. Those are plain files in the folder
dokumenteand belong in the backup your server makes anyway. More in the chapter Running it. - Look before it goes on the internet. nexpaper is happiest inside your own network, reached by VPN when you are away. If you open it up anyway, “Settings”, tab “Sign-in”, has the card “Ready for the internet?”, which checks eight points by itself. More under Security.
- Invite the others. How that works is in the next chapter, Inviting people and sharing vaults.
Good to knowRecovery codes replace only the code from the app, not your password. If you forget it, nobody sets one for you. You get a link and choose a new one yourself. Another operator sends you that link, or you tap “Forgot your password?” when signing in, as soon as the server can send mail and your account has a mail address. If you are the only operator, enter a mail server early or make a second person an operator.