On this page
Get started with Connexia
Install the app, turn on encrypted sync if you want your hosts on every device, and run your own sync server when you'd rather keep everything in-house.
Install
Grab the build for your platform from the download section or the latest GitHub release. The app works fully offline, too.
Windows
Run connexia-setup.exe and follow the installer.
If SmartScreen warns about an unrecognized app, choose More info → Run anyway.
macOS
Open the DMG and drag Connexia into Applications. The build targets Apple Silicon (M-series) Macs.
The macOS build isn't notarized yet, so Gatekeeper blocks the first launch. Right-click the app and choose Open, or clear the quarantine flag once with the command below.
xattr -dr com.apple.quarantine /Applications/connexia.app
Linux
Extract the archive and start the app from the bundle folder.
It needs GTK 3, which is already installed on most desktop distributions.
tar -xzf connexia-linux-x64.tar.gz
./bundle/connexia
Android
Download app-release.apk on your phone and open it.
Android asks you to allow installs from your browser or file manager the first time.
An iOS version is in development.
Accounts & sync
Sync keeps your hosts, groups, keys and snippets identical on every device. It's zero-knowledge: everything is encrypted on your device before it's uploaded, and the sync server only ever stores ciphertext.
- Open Settings → Sync in the app.
-
Keep the default server
https://sync.connexia.run, or choose Change server and enter the address of your own. - Create an account and confirm your email with the 6-digit code, then sign in with the same account on your other devices.
Your password is the encryption key. The server can't reset it for you without losing access to your synced data, so store it in a password manager.
How the data is protected:
- The snapshot is encrypted with AES-256-GCM using a key derived from your password with PBKDF2-SHA256 (100,000 iterations).
- The server stores only that ciphertext plus an scrypt hash used to verify sign-ins.
- Optional TOTP two-factor authentication can be turned on for your account.
- Sessions are bearer tokens valid for 30 days. Use HTTPS whenever the server is reachable from untrusted networks.
Self-hosting the sync server
The sync server is a single Go program that also serves this website, the web dashboard and the admin panel.
Storage is pluggable: PostgreSQL when DATABASE_URL is set,
otherwise a built-in SQLite file in DATA_DIR.
The first account created on a fresh server becomes the admin and is trusted immediately.
Open /admin right after starting the server to set it up.
Run the binary
Prebuilt binaries for Linux and Windows are attached to every release.
The server listens on port 8047 and keeps data in ./data.
curl -LO https://github.com/Theyka/Connexia/releases/latest/download/connexia-server-linux-x64
chmod +x connexia-server-linux-x64
PORT=8047 DATA_DIR=/var/lib/connexia ./connexia-server-linux-x64
Run with Docker
The repository includes a small multi-stage Dockerfile that runs as a non-root user
and exposes a health check on /api/health.
git clone https://github.com/Theyka/Connexia.git
cd Connexia
docker build -t connexia-sync ./server
docker run -d --name connexia-sync -p 8047:8047 \
-v connexia-data:/data \
-e SMTP_HOST=smtp.example.com -e SMTP_USER=... -e SMTP_PASS=... \
connexia-sync
Deploy on Coolify
- Create a new resource from the Connexia repository and choose the Dockerfile build pack with
server/Dockerfile. - Expose container port
8047. - Mount a volume at
/data, or add a PostgreSQL resource and setDATABASE_URL(a PgBouncer URL works too). - Add your SMTP variables so verification emails are delivered.
- Attach your domain; Coolify issues the Let's Encrypt certificate automatically.
HTTPS & backups
On a local network you can point the app straight at http://<server-ip>:8047.
Over the internet, put the server behind a reverse proxy with TLS, for example Caddy:
sync.example.com {
reverse_proxy 127.0.0.1:8047
}
For backups, copy the data directory (SQLite runs in WAL mode, so include the
-wal and -shm files), or use pg_dump when running on PostgreSQL.
API endpoints
All endpoints speak JSON. Authenticated calls send the session token as
Authorization: Bearer <token>.
| Method | Path | Purpose |
|---|---|---|
| POST | /api/register |
Create an account (the first account becomes admin) |
| POST | /api/login |
Get a session token (30 days) |
| POST | /api/login/2fa |
Complete sign-in with a TOTP code |
| POST | /api/verify-email |
Verify an email address with the 6-digit code |
| POST | /api/resend-verification |
Request a new verification code |
| GET | /api/sync |
Fetch your encrypted snapshot |
| POST | /api/sync |
Store the next revision (409 on conflict) |
| GET | /api/account |
Account status (email, verification, 2FA) |
| POST | /api/account/delete |
Permanently delete the account and its data |
| GET | /api/health |
Liveness check |
| GET | /api/setup/status |
{ "adminExists": bool }, used for first-run setup |
| GET | /api/public/stats |
Public server statistics |
| GET | /api/admin/users |
List accounts (admin only) |
| POST | /api/admin/users/delete |
Delete an account (admin only) |
| POST | /api/admin/users/role |
Promote or demote an admin (admin only) |
Configuration
The sync server is configured entirely with environment variables.
| Variable | Default | Purpose |
|---|---|---|
PORT |
8047 |
Listen port |
DATA_DIR |
./data |
Where the SQLite database lives |
DATABASE_URL |
unset | PostgreSQL connection string; unset means SQLite |
SERVER_NAME |
Connexia Sync Server |
Name shown on the website and dashboard |
SMTP_HOST |
unset | SMTP relay for verification emails |
SMTP_PORT |
587 |
SMTP port (465 when SMTP_SECURE=true) |
SMTP_SECURE |
false |
Use implicit TLS |
SMTP_USER / SMTP_PASS |
unset | SMTP AUTH PLAIN credentials |
SMTP_FROM |
Connexia <[email protected]> |
Sender address |
Without SMTP, verification codes are printed to the server log instead of emailed, which is fine for local testing and the first admin setup.