# Vikunja: a self-hosted task manager you can install with Docker

> Vikunja is an AGPL-3.0 Go and Vue task manager that you run yourself. It installs from a container image or a built binary, and its API is the real product. The trade-off is operational work you do not do with a hosted to-do app.

**go-vikunja/vikunja** — The task manager you actually own.

- Repository: https://github.com/go-vikunja/vikunja
- Website: https://vikunja.io
- Stars: 5,573 · Forks: 719
- Language: Go
- License: AGPL-3.0
- Published: 2026-09-10 · Updated: 2026-09-10 · Language: en
- Canonical page: https://hysenlabs.com/projects/go-vikunja-vikunja

## What Vikunja solves, and who it is for

Task data lives in someone else's account. Vikunja's answer is to move the whole application onto hardware you control. The README states the positioning in one line: "The task manager you actually own." The repository is a Go backend (module code.vikunja.io/api, go 1.27.0) with a Vue frontend under frontend/, packaged as a single binary or a container image.

The audience is narrower than a general to-do app. It fits engineers, small teams and privacy-conscious users who already run a server, a reverse proxy and a database, and who treat a task list as infrastructure rather than a subscription. The topics on the repository (self-hosted, api, golang, project-management, todo) describe that audience accurately.

It does not fit someone who wants a task app and nothing else. Every capability that a hosted product bundles, from backups to upgrades, becomes yours.

## How the Go API and the Vue frontend fit together

The architecture is a conventional split. The API is the product; the web interface is one client of it. The README links an OpenAPI specification at try.vikunja.io/api/v2/docs, which means the HTTP surface is documented independently of the UI. Anything the frontend does, an external client can do through the same endpoints.

The dependency list in go.mod shows what the backend carries: huma/v2 for the HTTP API layer, watermill for event handling, arran4/golang-ical for calendar data, adlio/trello for importing from Trello, coreos/go-oidc/v3 for OpenID Connect, and the AWS SDK v2 S3 packages for object storage. That combination suggests a server that expects to be integrated with, not just clicked through.

The repository also ships a desktop/ directory with its own LICENSE file, and the README notes that contents of desktop/ are licensed under GPL-3.0-or-later rather than the AGPL-3.0-or-later that covers most of the repository. If you plan to redistribute a build that includes the desktop client, that distinction matters.

One README note is worth quoting for what it says about the codebase itself: the project states that LLM-assisted coding tools are used in various parts of the codebase, and that most contributions made by tink-bot are built that way. Read that as transparency about provenance, not as a quality claim in either direction.

## Installing Vikunja with Docker and making a first task

The README points to vikunja.io/docs/installing as the install path and links the container image on Docker Hub as vikunja/vikunja. The Dockerfile builds a scratch image whose entrypoint is the Vikunja binary, so the container has no shell to debug inside; logs and configuration are your interface.

The README gives this example for the container image. The image name comes from the README badge and the Docker Hub link; the README itself does not spell out a run command, so treat the installing docs on vikunja.io as the source for the exact flags, ports and configuration keys rather than guessing them here.

```bash
docker pull vikunja/vikunja
```

After the container starts, the web interface answers on the published port. The documentation on vikunja.io covers the database and configuration options; the README does not reproduce a full environment variable list, so use the installing docs for those keys.

The API is where a first real integration happens. The README links the OpenAPI docs at try.vikunja.io/api/v2/docs, and a public demo instance runs at try.vikunja.io. Reading that specification before writing a client is the difference between using the documented endpoints and reverse-engineering the frontend's requests.

If you would rather not run anything, the README offers two hosted options: vikunja.cloud for a managed instance, and Vikunja Pro for teams that need an admin panel, audit logs or time tracking. Those are the paths the project itself names.

## Where self-hosting Vikunja costs you

The scratch base image is the clearest limitation. There is no package manager and no shell in the runtime container, so a misconfigured instance cannot be repaired from inside it. You debug from logs and from the configuration you mounted, and the fix is a new container.

The README does not document rollback. Upgrades are described on the website's installing page, not in the repository README, and nothing in the README describes what happens to your data if a new version changes the schema. Anyone running this in production should confirm the database migration and backup story from the docs before upgrading, because the README is silent on it.

Feature gaps are explicit rather than hidden. Admin panel, audit logs and time tracking are named in the README as Vikunja Pro features. If your requirement list includes audit trails for compliance, the open source build is the wrong tool and the README says so directly.

The search data around this project includes phrases like "vikunja is loading" and questions about how secure it is. Neither the README nor the linked pages reproduced here contain a threat model or a hardening guide, so security posture depends on your deployment: TLS termination, network exposure, database credentials and the OpenID Connect configuration you choose. The project's security reporting route is a contact page on vikunja.io, not a document in the repository.

## Vikunja compared with Todoist and Super Productivity

The alternative people search for most often is Todoist, and the difference is not features, it is custody. Todoist hosts your tasks; you pay a subscription and someone else runs the database, the backups and the uptime. Vikunja gives you the same category of object, a task list with projects, but the server is yours. You gain control over the data and lose the operational safety net. That is the entire trade, and it is why the README's own line is about ownership rather than capability.

Super Productivity sits in a different place again. It is the comparison the search data raises alongside Todoist. Where Vikunja is a server with clients, a local-first desktop tool keeps the working copy on your machine and treats sync as an add-on concern. If your real requirement is a task list that works offline on one computer, a server you have to keep running is overhead you did not ask for.

The honest framing is that Vikunja competes with hosted services on custody and with local tools on collaboration. It is weakest when you need neither: a single user who never shares a list and never calls an API gets little from running a database.

## Maintenance, upgrades and the AGPL-3.0 licence

The repository is not archived, and its last push was on 2026-09-10. Recent releases are close together: v2.6.0 on 2026-08-31, v2.5.0 on 2026-08-04 and v2.4.0 on 2026-07-19. That cadence means upgrade work arrives regularly rather than once a year, and with a scratch image and an undocumented rollback path, each release is a decision rather than a routine pull.

Upgrade cost has three parts. You track releases, you read the changelog (CHANGELOG.md is in the repository root and cliff.toml suggests it is generated), and you test the migration against a copy of your data before touching production. The repository provides vikunja.service and vikunja.initd for running it as a system service outside containers, which is the path to take if you want the host's package tooling to manage the binary.

On licensing: most of the repository is AGPL-3.0-or-later, and desktop/ is GPL-3.0-or-later. The AGPL is the part to think about. It is a copyleft licence with a network clause, which is the reason a self-hosted product can be offered commercially at all: if you modify the software and let users interact with it over a network, the licence's obligations attach to that modified version. Whether your specific use triggers them is a question for your own counsel, not for this article. The README also notes that Unsplash background images ship under the Unsplash License and require credit to the photographer and to Unsplash.

## Conclusion

Adopt Vikunja if you want your task data on infrastructure you control and you are willing to run a database, a container and an upgrade path. Do not adopt it if you want zero operations or if your team needs an admin panel, audit logs or time tracking, which the README places in Vikunja Pro. Before committing, verify the install path for your platform against the installing docs, confirm which database you will run, and read the AGPL-3.0-or-later terms against how you intend to expose the service.

## FAQ

### What is Vikunja used for?

Vikunja is a task manager you host yourself. The README describes it as "The task manager you actually own," and the repository topics list project management, to-do lists and self-hosting.

### Is Vikunja free to use?

The repository is licensed AGPL-3.0-or-later, so you can run it yourself at no licence cost. The README also points to a hosted version at vikunja.cloud and to Vikunja Pro for admin panel, audit logs and time tracking.

### How do I install Vikunja?

The README links vikunja.io/docs/installing as the install guide and points to the vikunja/vikunja image on Docker Hub. The repository also ships a Dockerfile that builds a scratch image whose entrypoint is the Vikunja binary.

### Is Vikunja open source?

Yes. Most of the repository is AGPL-3.0-or-later, and the README states that the contents of desktop/ are licensed under GPL-3.0-or-later instead.

## Sources

- [go-vikunja/vikunja on GitHub](https://github.com/go-vikunja/vikunja)
- [License: AGPL-3.0](https://github.com/go-vikunja/vikunja/blob/main/LICENSE)
- [Project website](https://vikunja.io)
- [README](https://github.com/go-vikunja/vikunja/blob/main/README.md)
- [Releases](https://github.com/go-vikunja/vikunja/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/go-vikunja-vikunja
