# CryptPad: a self-hostable, end-to-end encrypted office suite

> CryptPad bundles documents, sheets, presentations, forms, kanban and whiteboards behind browser-side encryption. Here is how the ChainPad sync model works, how to bring up an instance with Docker, and where the design stops protecting you.

**cryptpad/cryptpad** — Collaborative office suite, end-to-end encrypted and open-source.

- Repository: https://github.com/cryptpad/cryptpad
- Website: https://cryptpad.org
- Stars: 7,966 · Forks: 855
- Language: JavaScript
- License: AGPL-3.0
- Published: 2026-09-22 · Updated: 2026-09-22 · Language: en
- Canonical page: https://hysenlabs.com/projects/cryptpad-cryptpad

## What CryptPad actually solves

Most collaborative editors ask you to trust the operator. The document lives on their disk in a form they can read, and the encryption, if any, is a transport detail. CryptPad inverts that: the README states that data is encrypted in the browser before it is sent to the server and to collaborators, so a compromised database holds content that is, in the project's phrasing, "not of much value to attackers."

The audience follows from that. It is for organisations that want the editing surface of a Google Workspace or Office 365 style suite (the repository ships Document, Sheet, Presentation, Form, Kanban, Code, Rich Text and Whiteboard applications) but cannot accept a provider holding plaintext. It is also for individuals who want a shared drive and chat without running their own server, which is what the hosted cryptpad.fr instance exists for.

The README is unusually direct about the boundary. The encryption code is still served by the host, so a malicious or compromised administrator could ship code that leaks keys. The project calls this an active attack and notes that an expert can download the served code and check it. That is a real caveat, not a footnote, and it means CryptPad protects you from a stolen database far better than from a hostile operator.

## ChainPad, Netflux and the shape of a CryptPad instance

The dependency list is the architecture. chainpad, chainpad-crypto, chainpad-listmap, chainpad-netflux and chainpad-server form the synchronisation core; netflux-websocket carries the transport. ChainPad is a replicated data structure that orders operations across peers, and the crypto package wraps the encryption around those operations. In practice the browser holds the plaintext, encrypts changes, and pushes them through a websocket to the server, which stores and relays ciphertext without the ability to interpret it.

Around that core sit the application pieces: CKEditor 4 for rich text, CodeMirror for the code editor, drawio for diagrams, MathJax for formulas, and jszip, pako and file-saver for archive and compression work on the client. The server itself is Express, with body-parser, cookie-parser and connect-gzip-static, plus @node-saml and openid-client for enterprise single sign-on. That last pair matters: the README says registration and account access are based on cryptographic keys derived from username and password, so the server never sees either. SAML and OpenID Connect integration therefore has to be reconciled with that model rather than replacing it.

Storage is split across directories you will see in the compose file: blob, block, data, datastore, and a customize directory for instance-specific assets. The Dockerfile declares each as a volume and creates them at build time, which tells you the intended deployment shape before you read a single line of config.

## Installing CryptPad with Docker Compose

The README points developers at a setup guide for a local instance without HTTPS, and administrators at a production installation guide. It also notes that Dockerfile, docker-compose.yml and docker-entrypoint.sh live at the repository root, and that every release is published to Docker Hub as AMD64 and ARM64 images. The community-maintained image era ended with v5.4.0 in July 2023, so the image under cryptpad/cryptpad is the official one.

The compose file expects two domains to be set. Both are passed as environment variables, and the container reads its configuration from /cryptpad/config/config.js inside the mounted customize volume.

```yaml
services:
  cryptpad:
    image: "cryptpad/cryptpad:latest"
    hostname: cryptpad
    environment:
      - CPAD_MAIN_DOMAIN=https://your-main-domain.com
      - CPAD_SANDBOX_DOMAIN=https://your-sandbox-domain.com
      - CPAD_CONF=/cryptpad/config/config.js
```

The two ports published by the compose file are 3000 and 3003, and the Dockerfile exposes the same pair. 3000 serves the application; the sandbox domain is a separate origin used to isolate user content, which is why the project asks for a second hostname rather than a path. The Dockerfile runs npm install --production followed by npm run install:components during a build stage, then copies the result into a node:lts-alpine image that runs as a non-root cryptpad user with uid 4001.

A healthcheck is baked in, polling http://localhost:3000/ every minute, so a container that starts but never answers will be marked unhealthy rather than silently idle. The compose file also raises the nofile soft and hard limit to 1000000, which is a hint about how many concurrent connections a busy instance holds open.

The entrypoint is /bin/bash /cryptpad/docker-entrypoint.sh, and the container command is npm start. There is an optional OnlyOffice integration: the compose file carries a commented CPAD_INSTALL_ONLYOFFICE=yes line, and the comment above it tells you to read and accept the OnlyOffice licence before uncommenting. The image also installs git, rdfind and unzip specifically to support install-onlyoffice.sh. If you do not need Office-format fidelity, leave that line alone.

## Where CryptPad stops protecting you

The honest limitation is the one the README volunteers: the code that performs encryption is delivered by the server on every page load. End-to-end encryption here means the server cannot read stored content, not that a hostile server cannot attack you. Anyone who controls the instance and chooses to serve modified JavaScript can attempt to exfiltrate keys. Verifying otherwise requires downloading and auditing the served code, which the README frames as the expert's option.

Two further constraints are structural. First, the README states it is impossible to verify whether a server's operators log your IP or other activity, and recommends assuming they do and reaching your instance through Tor if that matters. Second, instance quality is hard to judge from outside. The project says it is working on a public directory of servers at cryptpad.org/instances that meet its criteria, which is an admission that the criteria are not currently checkable by a non-expert.

There is also a maintenance constraint that behaves like a limitation. The README ties safe operation to running the most recent version, on a three-month release cycle, because fixes for issues the safeguards miss tend to land quickly. A team that cannot upgrade on that cadence is running a configuration the project does not consider safe. The dependency list reinforces the point: CKEditor 4, CodeMirror 5, jQuery 3.6.0 and RequireJS 2.3.7 are all older-generation components, so the upgrade work is not trivial.

## CryptPad compared with Nextcloud and Collabora

The closest alternative in practice is Nextcloud with an online office backend such as Collabora Online or OnlyOffice. The difference is where encryption lives. Nextcloud encrypts files at rest on the server, and the server holds the keys in the standard configuration; the office backend decrypts a document in order to edit it. CryptPad never gives the server a plaintext document to begin with, because the editing model is a replicated sequence of encrypted operations rather than a file that gets opened and rewritten.

That choice buys the security property and costs format fidelity. CryptPad's editors are its own applications, so the native artefact is a CryptPad document, not a .docx. The optional OnlyOffice integration exists precisely to bridge that gap, and it requires accepting a separate licence and running an additional component. If your requirement is "edit the .docx files on our file share without Microsoft seeing them," Nextcloud plus an office backend is the more direct fit. If your requirement is "the server must never hold readable content," CryptPad is the one designed around that from the sync layer up.

A second comparison is with the hosted cryptpad.fr service. Same code, someone else's operational burden. The README's own reasoning applies: you still trust the administrator to keep the server secure and to send the right code, so self-hosting only changes who that administrator is.

## Licence, upgrade cadence and the cost of running it

CryptPad is AGPL-3.0-or-later. package.json declares "AGPL-3.0+", the LICENSE file is at the repository root, and the source files carry SPDX headers naming XWiki CryptPad Team. The practical implication of the Affero clause is that if you modify CryptPad and let users interact with it over a network, you are expected to offer them the corresponding source. The README states the software will always be available under the AGPL and points anyone who wants to use the technology in a proprietary product at sales@cryptpad.org. That is a licensing conversation to have with counsel, not something to infer from a README line.

Upgrade cost is real and predictable. Releases land roughly quarterly, with fix releases in between; the recent history shows 2026.5.0 in May, 2026.5.1 later the same month, and 2026.2.2 in April. Since the README advises running the most recent version, budget for a recurring upgrade task rather than a one-time install. The Docker path makes this a matter of pulling a new image and restarting, provided your customisations live in the mounted customize volume and not inside the image.

Funding comes from XWiki SAS, subscriptions to cryptpad.fr, NLnet PET, NGI TRUST, NGI DAPSI and Open Collective donations, per the README. That mix matters for anyone betting on the project: it is a company-backed codebase with grant and subscription revenue, not a single-maintainer side project. The last push to the default branch was on 2026-09-18.

## Conclusion

Adopt CryptPad if you need a collaborative document suite where the server operator cannot read stored content, and you are willing to run and patch your own instance or pay someone who does. Do not adopt it if your workflow depends on real-time co-editing with external parties who refuse to create accounts, or if you cannot commit to upgrading on the project's three-month release cycle, since the README ties safe operation to running the most recent version. Before deploying, verify three things: that your main and sandbox domains are both configured and reachable, that the blob, block, data and datastore volumes are on storage you back up, and that you have a plan for the config/config.js file that the Docker image generates on first start.

## FAQ

### What is CryptPad used for?

It is a collaboration suite for real-time work on documents, sheets, presentations, forms, kanban boards, code, rich text and whiteboards, with all user data encrypted in the browser before it reaches the server. The README frames it as a way to collaborate while keeping stored content unreadable to the operator.

### Is CryptPad free?

The software is released under AGPL-3.0-or-later and can be self-hosted at no licence cost. A hosted instance at cryptpad.fr also exists; the README does not describe its pricing, so check that service directly if you want the hosted option.

### How do I install CryptPad?

The README offers three routes: a developer guide for a local instance without HTTPS, an admin installation guide for production, and Docker. The repository root contains Dockerfile, docker-compose.yml and docker-entrypoint.sh, and releases are published to Docker Hub as AMD64 and ARM64 images.

### Is CryptPad safe?

The README states that data is encrypted in the browser and that a compromised database holds content of little value to attackers, but it also warns that the encryption code is loaded from the host server, so you still trust the administrator to serve correct code. It recommends using instances running the most recent version.

### What is cryptpad.fr?

It is a hosted CryptPad instance. The README lists subscriptions to cryptpad.fr among the project's funding sources, and its security reasoning about trusting the administrator applies to it the same way it applies to any other instance.

## Sources

- [cryptpad/cryptpad on GitHub](https://github.com/cryptpad/cryptpad)
- [License: AGPL-3.0](https://github.com/cryptpad/cryptpad/blob/main/LICENSE)
- [Project website](https://cryptpad.org)
- [README](https://github.com/cryptpad/cryptpad/blob/main/README.md)
- [Releases](https://github.com/cryptpad/cryptpad/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/cryptpad-cryptpad
