On this page
Documentation

Get started with Connexia

Install the app, turn on encrypted sync if you want your hosts on every device, and run your own sync server when you'd rather keep everything in-house.

Install

Grab the build for your platform from the download section or the latest GitHub release. The app works fully offline, too.

Windows

Run connexia-setup.exe and follow the installer. If SmartScreen warns about an unrecognized app, choose More info → Run anyway.

macOS

Open the DMG and drag Connexia into Applications. The build targets Apple Silicon (M-series) Macs.

The macOS build isn't notarized yet, so Gatekeeper blocks the first launch. Right-click the app and choose Open, or clear the quarantine flag once with the command below.

xattr -dr com.apple.quarantine /Applications/connexia.app

Linux

Extract the archive and start the app from the bundle folder. It needs GTK 3, which is already installed on most desktop distributions.

tar -xzf connexia-linux-x64.tar.gz
./bundle/connexia

Android

Download app-release.apk on your phone and open it. Android asks you to allow installs from your browser or file manager the first time. An iOS version is in development.

Accounts & sync

Sync keeps your hosts, groups, keys and snippets identical on every device. It's zero-knowledge: everything is encrypted on your device before it's uploaded, and the sync server only ever stores ciphertext.

  1. Open Settings → Sync in the app.
  2. Keep the default server https://sync.connexia.run, or choose Change server and enter the address of your own.
  3. Create an account and confirm your email with the 6-digit code, then sign in with the same account on your other devices.

Your password is the encryption key. The server can't reset it for you without losing access to your synced data, so store it in a password manager.

How the data is protected:

  • The snapshot is encrypted with AES-256-GCM using a key derived from your password with PBKDF2-SHA256 (100,000 iterations).
  • The server stores only that ciphertext plus an scrypt hash used to verify sign-ins.
  • Optional TOTP two-factor authentication can be turned on for your account.
  • Sessions are bearer tokens valid for 30 days. Use HTTPS whenever the server is reachable from untrusted networks.

Self-hosting the sync server

The sync server is a single Go program that also serves this website, the web dashboard and the admin panel. Storage is pluggable: PostgreSQL when DATABASE_URL is set, otherwise a built-in SQLite file in DATA_DIR.

The first account created on a fresh server becomes the admin and is trusted immediately. Open /admin right after starting the server to set it up.

Run the binary

Prebuilt binaries for Linux and Windows are attached to every release. The server listens on port 8047 and keeps data in ./data.

curl -LO https://github.com/Theyka/Connexia/releases/latest/download/connexia-server-linux-x64
chmod +x connexia-server-linux-x64
PORT=8047 DATA_DIR=/var/lib/connexia ./connexia-server-linux-x64

Run with Docker

The repository includes a small multi-stage Dockerfile that runs as a non-root user and exposes a health check on /api/health.

git clone https://github.com/Theyka/Connexia.git
cd Connexia
docker build -t connexia-sync ./server
docker run -d --name connexia-sync -p 8047:8047 \
  -v connexia-data:/data \
  -e SMTP_HOST=smtp.example.com -e SMTP_USER=... -e SMTP_PASS=... \
  connexia-sync

Deploy on Coolify

  1. Create a new resource from the Connexia repository and choose the Dockerfile build pack with server/Dockerfile.
  2. Expose container port 8047.
  3. Mount a volume at /data, or add a PostgreSQL resource and set DATABASE_URL (a PgBouncer URL works too).
  4. Add your SMTP variables so verification emails are delivered.
  5. Attach your domain; Coolify issues the Let's Encrypt certificate automatically.

HTTPS & backups

On a local network you can point the app straight at http://<server-ip>:8047. Over the internet, put the server behind a reverse proxy with TLS, for example Caddy:

sync.example.com {
    reverse_proxy 127.0.0.1:8047
}

For backups, copy the data directory (SQLite runs in WAL mode, so include the -wal and -shm files), or use pg_dump when running on PostgreSQL.

API endpoints

All endpoints speak JSON. Authenticated calls send the session token as Authorization: Bearer <token>.

Method Path Purpose
POST /api/register Create an account (the first account becomes admin)
POST /api/login Get a session token (30 days)
POST /api/login/2fa Complete sign-in with a TOTP code
POST /api/verify-email Verify an email address with the 6-digit code
POST /api/resend-verification Request a new verification code
GET /api/sync Fetch your encrypted snapshot
POST /api/sync Store the next revision (409 on conflict)
GET /api/account Account status (email, verification, 2FA)
POST /api/account/delete Permanently delete the account and its data
GET /api/health Liveness check
GET /api/setup/status { "adminExists": bool }, used for first-run setup
GET /api/public/stats Public server statistics
GET /api/admin/users List accounts (admin only)
POST /api/admin/users/delete Delete an account (admin only)
POST /api/admin/users/role Promote or demote an admin (admin only)

Configuration

The sync server is configured entirely with environment variables.

Variable Default Purpose
PORT 8047 Listen port
DATA_DIR ./data Where the SQLite database lives
DATABASE_URL unset PostgreSQL connection string; unset means SQLite
SERVER_NAME Connexia Sync Server Name shown on the website and dashboard
SMTP_HOST unset SMTP relay for verification emails
SMTP_PORT 587 SMTP port (465 when SMTP_SECURE=true)
SMTP_SECURE false Use implicit TLS
SMTP_USER / SMTP_PASS unset SMTP AUTH PLAIN credentials
SMTP_FROM Connexia <[email protected]> Sender address

Without SMTP, verification codes are printed to the server log instead of emailed, which is fine for local testing and the first admin setup.