# CVAT Community: self-hosted image, video and 3D annotation under the MIT licence

> CVAT Community is the free, self-hosted edition of the CVAT annotation platform. It runs as a Docker Compose stack on your own hardware, and the trade-off is that several of the features shown in the paid editions are not in this repository.

**cvat-ai/cvat** — Computer Vision Annotation Tool (CVAT) is a leading platform for building high-quality visual datasets for vision AI. It offers open-source, cloud, and enterprise products, as well as labeling services, for image, video, and 3D annotation with AI-assisted labeling, quality assurance, team collaboration, analytics, and developer APIs.

- Repository: https://github.com/cvat-ai/cvat
- Website: https://www.cvat.ai
- Stars: 16,827 · Forks: 3,889
- Language: Python
- License: MIT
- Published: 2026-09-10 · Updated: 2026-09-10 · Language: en
- Canonical page: https://hysenlabs.com/projects/cvat-ai-cvat

## The problem CVAT Community solves, and who it is actually for

Vision teams accumulate raw images, video and point clouds faster than they can label them. What they need is not a drawing program but a system that holds a dataset, splits it into tasks and jobs, assigns those jobs to people, and then exports the result in a format a training pipeline already understands. CVAT Community is that system, packaged so it runs inside your own network.

The README frames the audience directly: teams that need full control over their data and annotation infrastructure. That phrasing matters. If your data is under a contractual or regulatory constraint that forbids uploading it to a third-party service, a self-hosted stack is the only option, and this is the free edition of a platform that has been on GitHub since 2018. If you have no such constraint, the hosted CVAT Online free plan is the faster path, and the README says so before it says anything about installing anything.

The repository is not a single application. The top-level entries include cvat-core, cvat-canvas, cvat-canvas3d, cvat-data, cvat-ui, cvat-sdk and cvat-cli, alongside a Django backend under cvat/ and a serverless/ directory. You are adopting a platform with a browser client, a server, a task queue and a storage layer, not a library you import.

## How the Docker Compose stack is wired together

The mechanism is visible in docker-compose.yml. The file opens with a shared environment anchor that names the backing services: CVAT_POSTGRES_HOST points at cvat_db, CVAT_REDIS_INMEM_HOST at cvat_redis_inmem on port 6379, and CVAT_REDIS_ONDISK_HOST at cvat_redis_ondisk on port 6666. A separate ClickHouse anchor sets CLICKHOUSE_PORT to 8123 and CLICKHOUSE_DB to cvat.

Those are not incidental dependencies. PostgreSQL holds the relational data. The in-memory Redis instance is the broker for background work, and the on-disk instance, which the compose file runs from the apache/kvrocks:2.15.0 image, keeps job state that must survive a restart. ClickHouse is the analytics store. The backend depends on all of them: the x-backend-deps anchor declares cvat_redis_inmem, cvat_redis_ondisk, cvat_db and cvat_clickhouse with condition: service_started, so the server waits for each before it comes up.

Two more details are worth noticing before you deploy. The backend environment sets CVAT_ALLOW_STATIC_CACHE from a variable defaulting to no, and CVAT_NUM_PROXIES defaulting to 1. The first controls whether static assets are cached, and the second tells the application how many proxy hops sit in front of it. If you terminate TLS at your own reverse proxy and leave CVAT_NUM_PROXIES at 1, the server's view of client addresses will be wrong. The README does not document what breaks when that value is misconfigured, so treat it as something to verify against the Deployment Guides rather than guess at.

## Installing CVAT Community and labeling your first task

The README lists three prerequisites: Docker Engine, Docker Compose and Git. It also states that CVAT is primarily tested with Chromium-based browsers, that Firefox may work with some caveats, and that Safari and WebKit are not supported. Check that last point before you plan a rollout, because it is a hard boundary rather than a preference.

Start by cloning the repository and bringing up the default stack. The commented export line is optional and only needed if you are serving CVAT on an address other than localhost.

```bash
git clone https://github.com/cvat-ai/cvat
cd cvat

# Optional: set your IP or domain
# export CVAT_HOST=your-ip-or-domain

docker compose up -d
```

Once the containers are running, create the first administrator account. The README gives this as a one-liner against the cvat_server container.

```bash
docker exec -it cvat_server bash -ic 'python3 ~/manage.py createsuperuser'
```

Open http://localhost:8080 in a Chromium-based browser, or your CVAT_HOST value if you set one, and sign in with the account you just created. From there the README's workflow is: create a project or task, upload images, video or point clouds, define the labels, and start annotating. For scripted work, the Python SDK installs with pip install cvat-sdk and the command line tool with pip install cvat-cli. Both are documented separately from the web UI, and neither is required for a first manual pass.

## Where the open-source edition stops

This is the section that decides most evaluations. The README lists advanced capabilities that are available in CVAT Online paid plans and CVAT Enterprise, not here: advanced project analytics, the quality control UI, built-in auto-labeling with SAM 2 and SAM 3, AI agents and SSO. The Community edition does support connecting your own ML models for detection, segmentation and tracking, and the README describes Ground Truth and Honeypot checks as running through the server API rather than through a dedicated interface.

Read that split carefully. Auto-labeling exists in Community, but you supply the model. The convenience of a bundled segmentation model is a paid feature. Quality control exists in Community, but the parts that live in the server API are not the same as the review interface in the commercial editions.

Licensing is the second boundary. The core is MIT, which the README describes as permissive and usable, modifiable and distributable. It adds a qualifier that is easy to skim past: some serverless assets and dependencies may have separate licenses. The repository keeps serverless functions in a top-level serverless/ directory, which is where those separate terms would apply. The README does not enumerate which functions carry which licence, and this article is not legal advice, so if you plan to redistribute the stack, read the licence files in that directory rather than relying on the MIT label alone.

## CVAT Community compared with Label Studio

The nearest alternative most teams consider is Label Studio, and the difference is in what the tool is built to annotate. Label Studio is a general-purpose labeling environment that spans text, audio, images and time series through configurable templates. CVAT is narrower and deeper: image, video and 3D point cloud annotation, with a canvas layer (cvat-canvas, cvat-canvas3d) built specifically for drawing bounding boxes, polygons, masks, keypoints and cuboids, and with video tracking as a first-class concern.

That focus shows up in the export list. The README states that CVAT Community imports and exports more than 20 formats, naming COCO, YOLO, Pascal VOC and KITTI. If your pipeline consumes detection or segmentation datasets, that is the relevant surface area. If your labeling work is mostly text classification with a little image work on the side, the narrower tool is the wrong trade: you would be running PostgreSQL, two Redis instances and ClickHouse to annotate content that a lighter stack handles.

A second comparison is against the hosted CVAT Online itself. Same interface, same task model, different operations burden. Self-hosting moves upgrades, backups and storage capacity onto your team, and the README points to separate Deployment Guides for AWS, Kubernetes, external PostgreSQL, backups and upgrades rather than covering them in the main file.

## Maintenance, releases and what an upgrade costs you

The repository is not archived and the last push was on 2026-09-10, so this is a live codebase rather than a frozen one. Releases arrive often: v2.73.0 on 2026-08-12, v2.74.0 on 2026-08-26, and v2.74.1 on 2026-09-01. Three releases in under a month is a fast cadence, and fast cadences have a cost for self-hosters.

That cost is that you own the upgrade path. The README does not document rollback or a version pinning strategy; it defers to the Deployment Guides for upgrades and backups. A CHANGELOG.md sits at the top level and a changelog.d/ directory holds pending entries, so release notes exist, but reading them is a step your team has to schedule rather than something the stack does for you.

The compose file gives you one lever: the image tags for the backing services are pinned (postgres:15-alpine, redis:7.2.11-alpine, apache/kvrocks:2.15.0), so a docker compose pull will not silently move your database underneath you. Whether the CVAT application images themselves are pinned the same way is not shown in the portion of the file available here, and that is the first thing to check in your own copy before you automate upgrades.

## Conclusion

Adopt CVAT Community if your annotation data cannot leave your infrastructure and you are comfortable running a multi-container Docker Compose stack with PostgreSQL, Redis and ClickHouse. Do not adopt it if you want built-in SAM 2 or SAM 3 auto-labeling, SSO or the quality control UI, because the README places those in CVAT Online paid plans and CVAT Enterprise. Before committing, check the Installation Guide for your OS, decide whether you need docker-compose.external_db.yml or the helm-chart directory, and confirm that your team's browsers are Chromium-based, since Safari and WebKit are not supported.

## FAQ

### What does CVAT stand for?

The README expands the name as Computer Vision Annotation Tool. The repository is cvat-ai/cvat and the project has been on GitHub since 2018.

### Can I use CVAT for free?

Yes. CVAT Community is described as the free, self-hosted open-source edition, licensed under MIT, and the README also points to a free plan on CVAT Online. Feature availability and usage limits differ between the plans.

### Is CVAT.ai legit?

The repository is the source code and deployment assets for CVAT Community, which the README describes as the foundation of CVAT Online and CVAT Enterprise. It has been public on GitHub since 2018 and the last push was on 2026-09-10.

### What is the difference between GPT and CVAT?

The README says nothing about GPT, so no comparison can be drawn from it. CVAT is a data annotation platform for images, video and 3D point clouds, with manual and model-assisted labeling, task management and dataset export.

## Sources

- [cvat-ai/cvat on GitHub](https://github.com/cvat-ai/cvat)
- [License: MIT](https://github.com/cvat-ai/cvat/blob/develop/LICENSE)
- [Project website](https://www.cvat.ai)
- [README](https://github.com/cvat-ai/cvat/blob/develop/README.md)
- [Releases](https://github.com/cvat-ai/cvat/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/cvat-ai-cvat
