copyparty: one Python file, and every protocol you switch on yourself
Portable file server with accelerated resumable uploads, dedup, WebDAV, SFTP, FTP, TFTP, zeroconf, media indexer, thumbnails++ all in one file
At a glance
- What is it?
- A portable file server whose quickstart is a single downloaded script, with resumable uploads, browser uploads, dedup, indexing and six protocols layered on as individual flags. The feature surface is wide, and the project's own text marks the sharp edges: SMB is called unsafe, the SFTP path is called slower, and each extra service is another listening port.
- Who is it for?
- Pick copyparty when one box must serve browsers, WebDAV clients and phones from the same tree, and pick a single-purpose daemon when you only need one protocol on a locked-down host. Before exposing anything, read the SMB warning in the README and decide which of --ftp 3921 and --tftp 3969 your firewall needs open, then turn on file indexing deliberately, since dedup and upload undo both depend on it.
- Can I use it commercially?
- Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Yes. The repository last received commits 6 days ago.
- What is it written in?
- Mainly Python, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 25, 2026, and from our analysis. They are not legal advice.
Editorial analysis
The quickstart is one file fetched from the releases page
There is no install ritual. The quickstart points at a single script on the latest release and tells you to run it:
https://github.com/9001/copyparty/releases/latest/download/copyparty-sfx.pyThe stated requirement is a Python interpreter, with the README claiming Python 2 or 3 and every dependency optional. That claim and the packaging metadata disagree in a way worth knowing before you choose a route. pyproject.toml sets requires-python to >=3.3 and declares a single dependency, Jinja2, so a wheel install is not dependency free, and Python 2 is outside the declared range. setup.py adds its own warning that it probably still works but is no longer in use, with pyproject.toml and scripts/make-pypi-release.sh in charge of building wheels. Practical result: the single file route skips pip and Jinja2 entirely, the wheel route does not, and picking the wrong one costs you a feature at runtime rather than a message at install time.
SMB is labelled unsafe in the project's own protocol list
Six protocols are listed, and the project grades them itself in the table of contents. The smb server entry reads unsafe, slow, not recommended for wan. That is the author telling you not to publish one of its own services on the open internet, and it is the fastest way to misread the project as a general purpose NAS replacement. The sftp entry carries a number instead of a warning: roughly 700 MiB/s, described as slower than webdav and ftp. ftp and ftp(s) are both offered, so the encrypted variant exists alongside the plain one, and the read-only distinction is not something the summary resolves. WebDAV is the one described as having read-write support with a note about connecting from Windows, which is the path most file managers can speak. Take the warning literally when you decide which of these faces the internet and which stays on the LAN.
Every extra service is its own flag and its own listening port
The server config is described as arguments, config files, or a mix of both, and the protocols are enabled one at a time. Two examples are spelled out with their ports:
--ftp 3921
--tftp 3969Add either flag and a second service starts listening while the first keeps running. The consequence is that the attack surface of a copyparty install is the sum of the flags you typed, and there is no single switch in the visible documentation that turns everything on. Discovery follows the same pattern: zeroconf is split into mdns, described as a LAN domain-name and feature announcer, and ssdp, described as a windows-explorer announcer, so announcing yourself to the network is also a per-feature decision. A QR code section exists for handing out access quickly, which is convenient for a home server and one more reason to think about which flags are live before you expose the port.
Deduplication is symlink based, and indexing is what makes it work
The deduplication feature is described as symlink-based upload deduplication, which is the single most consequential design decision in the project and the one with the most reach outside the server. It means an upload that duplicates existing content does not occupy a second block of storage, and it means your filesystem ends up with symlinks where other tools expect regular files. Backup software, sync clients, archivers and anything that walks the tree without following links can all behave differently afterwards, and the documentation does not enumerate which of them are affected. Deduplication quality depends on the file indexing feature, which is what enables music search, upload undo and better dedup, and that in turn brings exclude-patterns to save scanning time, filesystem guards to avoid traversing into other filesystems, and a periodic rescan for monitoring. Turning dedup on without reading the indexing settings is how you get a slow first scan and a surprise disk usage figure.
Shadowing and permissions are two separate controls, and the text keeps them apart
Access control is split across a permissions model and a visibility model, and the documentation presents them as separate features. Accounts and volumes cover per-folder, per-user permissions, which decide what an account may do. Shadowing is described as hiding specific subfolders. Dotfiles are handled as unix-style hidden files and folders, another visibility rule rather than an access rule. The practical consequence is that a folder you cannot see in the browser is not the same statement as a folder you cannot reach, and the summary does not tell you which one a given setting gives you. Anyone building a share for another person should decide those two questions separately: whether the account can write, and whether the directory tree is even part of that account's view. The same split shows up in the file manager, where cut, paste, rename and delete are all marked as conditional on permission.
Uploads can carry a lifetime, and shares are temporary by design
Several features exist for material that should not sit around. Self-destruct gives uploads a lifetime. Unpost is an undo for accidental uploads, listed in the same block as dropping files into the browser to upload. Shares create a temporary link to a file or folder. Race the beam lets a client download a file while it is still uploading, and the control panel shows an ETA for every incoming file. That cluster makes copyparty a good fit for a transfer window, a screenshot drop, or a phone-to-LAN move, and it is also where a reader should look for the gap: the summary names a lifetime feature but states no default retention period for ordinary uploads, and no automatic cleanup policy is described. If you host it for other people, deleting on a schedule is your job, not the server's.
Search and viewers cover text, markdown and media, each with its own edge
The browser side is broader than a file listing. Search covers size, date, path and name, and mp3 tags, the last of which depends on the file indexer rather than on a scan at query time. A textfile viewer streams logfiles in realtime, and a markdown viewer comes with two editors plus markdown vars, described as dynamic docs with serverside variable expansion, which is a templating feature with the same permission implications as anything else you enable. Media playback is presented as covering almost every audio format, with m3u8 playlists, an equalizer and a dynamic range compressor, and there is a separate note on fixing unreliable playback on android caused by phone or app settings. Two smaller entries matter for anyone automating: rss feeds for monitoring a folder from a reader, and opds feeds for browsing from an e-book reader. Each is a small protocol surface of its own.
Release names are jokes, so the breaking changes section is the real changelog
Maintenance is not the weak point. The default branch is hovudstraum, the last push was on 2026-09-24, and the recent releases are v1.20.24 named redup on 2026-09-19, v1.20.23 named rcm once again on 2026-09-06, and v1.20.22 named hello fedora on 2026-09-06. The version numbers carry the signal and the release names carry the humour, so a diff needs the numbers. The project maintains a breaking changes section described as upgrade notes, which is where a real upgrade decision comes from, and a bugs section sorted roughly by chance of encounter with a separate not my bugs subsection, which tells you in advance that some of what you hit belongs to the browser, the network or the client. The repository also ships SECURITY.md, CODE_OF_CONDUCT.md and a flake.nix, so packaging and reporting have homes, but none of the release names tells you what changed.
Editorial conclusion
Pick copyparty when one box must serve browsers, WebDAV clients and phones from the same tree, and pick a single-purpose daemon when you only need one protocol on a locked-down host. Before exposing anything, read the SMB warning in the README and decide which of --ftp 3921 and --tftp 3969 your firewall needs open, then turn on file indexing deliberately, since dedup and upload undo both depend on it.
Frequently asked questions
What is a copyparty file server?
It is a portable file server that turns almost any device with Python into a file server with resumable uploads and downloads from a web browser. The server needs only Python and the project states all dependencies are optional, with WebDAV, SFTP, FTP, TFTP and SMB available as additional protocols.
How do I install copyparty?
The quickstart sends you to the single-file download copyparty-sfx.py on the latest release and tells you to run it. If you prefer a wheel, pyproject.toml declares requires-python >=3.3 and one dependency, Jinja2, and setup.py states it is no longer in use since pyproject.toml and scripts/make-pypi-release.sh build the wheels.
What does copyparty do besides serving files?
It adds resumable and self-destructing uploads, undo for accidental uploads, temporary share links, symlink-based deduplication, a file indexer that powers music search, thumbnails, a textfile viewer that streams logfiles, a markdown viewer with two editors, search by size, date, path, name and mp3 tags, and rss and opds feeds.
How do I configure a copyparty server?
Configuration comes from command arguments, config files, or a mix of both. The documented flags include u2sz for upload chunking, upload rules through volflags, per-volume chmod and chown, and a version checker; the file indexing feature adds exclude-patterns, filesystem guards and a periodic rescan.
How do I access copyparty from a browser?
You connect with any web browser to the server and use the file manager, where cut, paste, rename and delete are available when you have permission. Dragging files or folders into the page uploads them, pressing g or the grid icon toggles the thumbnail view, F2 opens batch rename, and shares create a temporary link to a file or folder.
Is copyparty safe to expose to the internet?
The project itself flags the smb server as unsafe, slow and not recommended for wan, so treat that protocol as LAN only. The configuration summary also keeps a separate section for making the server accessible over the internet, and marks smb as the one service it tells you not to publish.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/9001-copyparty)