Self-hosted workspace
Your services, notes, maps and keys. On your own server.
Manifold keeps the links to the services you run, your notes, notes pinned to places on a map and your passwords behind a single owner account, and lets your scripts and AI agents work with them through a REST API and an MCP server.
- Modules 04 in one place Services, Notes, Map Notes and Vault
- Integrations REST + MCP one set of scoped keys for scripts and agents
- Security review ASVS 5.0 every level 1 and 2 requirement checked
- Accounts 01 owner no sign-up, two-factor sign-in
01 / Modules
Four modules, one sidebar
Each module has its own page, its own place in the sidebar and in the search, and its own scopes in the API. Together they cover what you keep for yourself.
-
Services
Links to everything you run: the router, the NAS, the dashboards. Each service keeps an icon and a place in an order you choose, and opens in a new tab.
- They fill the sidebar, the Services page and the command palette.
- Icons in PNG, JPEG, WebP, GIF or SVG, checked by their content, never by their name.
- The first page you see after signing in.
-
Notes
A rich text editor with headings, lists, task lists, quotes, code blocks, links, tables and images. Notes save themselves while you type.
- A revision history with restore, and a trash that empties itself after 30 days.
- Changes from another tab or device are noticed instead of overwritten.
- Images are uploaded straight into the note.
-
Map Notes
Pins, lines and polygons on an OpenLayers map, each linked to a note, with the note editor right next to the map.
- OpenStreetMap by default, or any raster tile server over https.
- Stored in PostGIS and served as GeoJSON through the API.
- Agents can place a pin and write its note in one call.
-
Vault
Passwords and keys encrypted with AES-256-GCM. A value is revealed or copied only after you confirm your identity again.
- Names, addresses and descriptions are searchable; values are not.
- No API route and no MCP tool ever returns a value.
- Rotate the encryption key from the command line.
02 / Workspace
Everything is one keystroke away
One search covers your notes, your services and the names of your vault entries. The command palette moves you between pages and runs common actions without leaving the keyboard.
Ctrl+KorCmd+Kopens the palette on every page: go to a page, run an action or open a result.- A search page of its own lists every hit with a short passage.
- A history keeps a version for about every five minutes of editing and for every change through the API; restore any of them in one step.
- Layouts for phones and desktops, light and dark themes.
- An interface in English and Turkish.
- Download an export of your data under Settings → Data.
03 / API & MCP
Let your scripts and AI agents in, on your terms
The REST API and the MCP server share the same keys, scopes, rate limits and audit log. A key sees only the modules you allow, and you can revoke it at any moment.
REST API
JSON under /api/v1 with cursor paging, per-key rate limits and an OpenAPI 3.1 description.
curl -H "Authorization: Bearer $MANIFOLD_API_KEY" \
"https://manifold.example.com/api/v1/notes?limit=1"
{
"data": [
{
"id": "3f2504e0-4f89-41d3-9a0c-0305e82c3301",
"title": "North pier",
"excerpt": "Ferries to the island leave every hour.",
"version": 4,
"updated_at": "2026-09-29T17:42:10.512Z",
"deleted_at": null
}
],
"next_cursor": "eyJ1IjoiMjAyNi0wOS0yOVQxNzo0Mj…"
}
MCP server
Streamable HTTP at /mcp. Agents such as Claude Code search, read and write notes, keep services current and place notes on the map.
claude mcp add --transport http manifold \
https://manifold.example.com/mcp \
--header "Authorization: Bearer mfd_your_key"
# read
search list_notes get_note
list_note_revisions list_map_features
# write
create_note update_note trash_note
restore_note create_map_feature
update_map_feature delete_map_feature
vault:read shows names, addresses and descriptions only. There is no scope that reads or writes a vault value.
04 / Security
Built to hold what you would not put anywhere else
Manifold was checked against every level 1 and 2 requirement of OWASP ASVS 5.0 before its first release, and the protections below are on from the first start.
-
One owner, no sign-up
The only account is created from your configuration on the first start. Nobody can register.
-
Two-factor sign-in
Authenticator codes that work once, backup codes of 120 bits and optional sign-in codes by email.
-
Confirmation before it matters
Revealing a secret, changing the password or ending sessions asks for your identity again.
-
Careful password handling
8 to 128 characters, checked against common passwords from SecLists and hashed with scrypt.
-
Scoped, hashed API keys
Stored as SHA-256 hashes, limited to the modules you choose, with an expiry date and a rate limit each.
-
Strict browser policies
A nonce-based Content Security Policy and security headers on every response, and a clean slate on sign-out.
-
Append-only audit log
Sign-ins, changes and every write through a key are recorded in a log the database refuses to rewrite.
-
Limits everywhere
Five sign-in attempts per minute, a rate limit per API key, sessions that end after 30 days and bounds on every input.
-
Hardened container
An unprivileged user, a read-only root filesystem and no capabilities. Each image carries a software bill of materials and a signed build attestation.
05 / Install
Up and running with Docker Compose
All you need is a server with Docker and Docker Compose. Every release is published as a prebuilt image for amd64 and arm64 on the GitHub Container Registry, next to a PostgreSQL database with PostGIS.
-
STEP 01
Get the Compose file
Clone the repository and create your configuration from the example file.
Terminalgit clone https://github.com/Rua-Systems/manifold.git cd manifold cp .env.example .env -
STEP 02
Set the secrets and the owner
Generate
BETTER_AUTH_SECRETandENCRYPTION_KEYas two different outputs ofopenssl rand -base64 32, choose a URL-safe database password and fill in the owner. To try it locally, useORIGIN=http://localhost:3000and addADDRESS_HEADER=andXFF_DEPTH=with empty values..envMANIFOLD_VERSION=0.1 ORIGIN=https://manifold.example.com POSTGRES_PASSWORD=<output of openssl rand -hex 32> BETTER_AUTH_SECRET=<output of openssl rand -base64 32> ENCRYPTION_KEY=<another output of openssl rand -base64 32> OWNER_USERNAME=you OWNER_EMAIL=you@example.com OWNER_PASSWORD=<8 to 128 characters> -
STEP 03
Start the containers
Compose pulls the image in the version set by
MANIFOLD_VERSION, where0.1follows the newest 0.1.x release, and starts the app next to its database. Open/loginand sign in as the owner.Terminaldocker compose up -d
-
Migrations on start
The database schema is brought up to date before the app accepts requests.
-
Health check
/healthzreports whether the database answers, for Docker and your monitoring. -
Backup and restore
node cli.js backupandrestoreon the command line, and an export in the settings. -
Behind your proxy
Documented setups for Caddy, Nginx and Coolify, where a release can deploy itself.
Keep copies of ENCRYPTION_KEY and BETTER_AUTH_SECRET outside the server: backups contain neither, and without the key the vault cannot be read. Manifold runs as a single instance, so never start more than one app container on the same database.
Open source
Apache 2.0, built on proven tools
Read the code, run it on your own hardware and shape it to your needs. Bug reports and fixes are welcome.
- SvelteKit
- Svelte 5
- TypeScript
- SCSS
- TipTap
- OpenLayers
- Better Auth
- Drizzle ORM
- PostgreSQL 17
- PostGIS
- Paraglide
- MCP TypeScript SDK
- Vitest
- Playwright
- Node.js 24
06 / FAQ
Frequently asked questions
Is Manifold free to use?
Yes. Manifold is open source under the Apache License 2.0. You can use it, change it and run it on your own servers, as long as derivative works keep the license and the NOTICE file.
Who is Manifold for?
For one person. Every installation has exactly one account, the owner, created on the first start. There is no sign-up, no team and no sharing; for more people, run more installations.
What do I need to run it?
A server with Docker and Docker Compose. Manifold runs as two containers, the app and PostgreSQL 17 with PostGIS. In production, put it behind a reverse proxy such as Caddy, Nginx or Coolify for TLS.
Can AI agents read my passwords?
No. With the vault:read scope an agent sees the names, addresses and descriptions of vault entries, never their values. No API route and no MCP tool returns or accepts a value; values are revealed only in the app, after you confirm your identity.
Which AI agents can connect?
Any MCP client that supports the streamable HTTP transport and custom headers, such as Claude Code. Give it the address https://your-host/mcp and an API key in the Authorization header; it sees only the tools that the key's scopes allow.
Which map does Map Notes use?
OpenStreetMap's standard tiles by default. Set MAP_TILE_URL and MAP_TILE_ATTRIBUTION to use any raster tile server that answers over https, and MAP_DEFAULT_CENTER and MAP_DEFAULT_ZOOM for the starting view.
How do backups work?
node cli.js backup writes an archive with the database and the uploaded files, and node cli.js restore brings it back. Settings → Data offers an export download as well. Archives never contain ENCRYPTION_KEY or BETTER_AUTH_SECRET, so keep copies of both outside the server.
How do I update Manifold?
Take a backup, read the release notes, compare docker-compose.yml and .env.example with your copies, set MANIFOLD_VERSION and run docker compose pull and docker compose up -d. Migrations run on start, and with a minor line such as 0.1, docker compose pull alone picks up the newest patch release.
Can I verify the Docker image?
Yes. Published images carry a signed attestation of the workflow and commit they were built from. The GitHub CLI checks it with gh attestation verify oci://ghcr.io/rua-systems/manifold:0.1 --owner Rua-Systems.
Is Manifold ready for production?
Version 0.1.0 is the first release. Manifold follows semantic versioning: before 1.0.0, a minor version may change the configuration, the API or the data in incompatible ways, and its release notes say so.
Where is the documentation?
The documentation lives in the docs folder of the repository: installation, deployment, operations and backups, every module, the REST API, the MCP server and the security review.
Ready
Bring your workspace home
Install Manifold with Docker Compose, sign in as the owner and connect your first agent.