# linuxserver/Heimdall: a PHP application dashboard you host yourself

> Heimdall is a self-hosted launcher for web apps, built on Laravel 11 and installable from a git clone or the linuxserver Docker image. It is at its best when you already run a rack of services and want one page with icons and live stats instead of a bookmark folder.

**linuxserver/Heimdall** — An Application dashboard and launcher

- Repository: https://github.com/linuxserver/Heimdall
- Stars: 9,338 · Forks: 624
- Language: PHP
- License: MIT
- Published: 2026-09-21 · Updated: 2026-09-21 · Language: en
- Canonical page: https://hysenlabs.com/projects/linuxserver-heimdall

## The problem Heimdall solves for people running a home server

Anyone who runs a stack of self-hosted services ends up with the same problem: the URLs multiply. A media server, a download client, a request manager, a router admin page, a couple of dashboards, and each one lives in a browser bookmark folder that grows until nobody opens it. Heimdall is a single page that lists those services as tiles. The README frames it plainly: it is "a dashboard for all your web applications" and, importantly, it does not have to be limited to applications, since you can add links to anything.

The intended audience is the homelab and HTPC crowd. The repository topics name the usual suspects directly: plex, emby, sonarr, radarr, sabnzbd, nzbget, couchpotato. These are the services a Heimdall page is meant to gather. It also works as a browser start page, with an optional search bar that can be pointed at Google, Bing or DuckDuckGo. That is a narrower claim than a bookmark manager makes: Heimdall is not trying to sync your personal bookmarks across devices, it is trying to be the page you open when you sit down at a machine that talks to your server.

## Foundation and Enhanced apps: how tiles get icons and live data

Heimdall's tile system has two layers. The first is recognition by name. Supported applications are matched by the title you type into the title field when adding an application, so typing "p" and picking pfSense from the list is the documented flow. When a match is found, Heimdall fills in the icon and supplies a default colour for the tile. The README calls these Foundation apps.

The second layer is Enhanced apps. Here you supply details for an application's API, and the dashboard shows live stats on the tile. The README's own example is specific: the NZBGet and SABnzbd Enhanced apps display queue size and download speed while something is downloading. That is the real differentiator between Heimdall and a static links page, and it is also where most of the operational friction lives.

If Heimdall and the Enhanced app it polls both run in Docker, the README warns that you may need Docker networking addresses to reach them, using the form http(s)://docker_name:port in the config section rather than a public hostname. That is a container DNS detail, not a Heimdall bug, but it is the kind of thing that produces a tile that silently shows nothing until you fix the address.

## Installing Heimdall from a git clone and generating the app key

Heimdall is a Laravel 11 application. The README lists the runtime requirements as PHP >= 8.4 plus a long set of PHP extensions: Ctype, cURL, DOM, Fileinfo, Filter, Hash, Mbstring, OpenSSL, PCRE, PDO, Session, Tokenizer and XML. On top of the framework requirements it needs sqlite support and zip support (php-zip).

The documented manual install is a clone (or an extracted zip/tar) with the document root pointed at the /public folder, followed by creating the .env file and generating an encryption key. The README gives exactly these three commands:

```bash
cd /path/to/heimdall
cp .env.example .env
php artisan key:generate
```

The .env.example file confirms the defaults: DB_CONNECTION is sqlite and DB_DATABASE is app.sqlite, so a fresh install does not need a separate database server. For a quick look at the UI without configuring a web server, the README says you can go to the folder and run:

```bash
php artisan serve
```

The Docker route is the one most people will take. The README points to the linuxserver image on Docker Hub and notes it is multi-arch, covering x86-64, armhf and arm64. The Docker path handles the .env and key generation for you, per the README. After the first page loads you add an application, type its name, and pick it from the supported list to get the icon.

## Search providers are a YAML file, not a settings screen

Search customisation arrived in v2.3.0, and the implementation is worth knowing about because it tells you how the project thinks. The options are stored in a file, not in the database: /storage/app/searchproviders.yaml on a manual install, or /config/www/searchproviders.yaml on Docker. The README says you can rearrange the options, add new ones, or delete the ones you do not use, and points contributors at a GitHub Discussions category for search providers.

The top item in that list is Tiles, which searches apps on your own dashboard by name. If you have accumulated dozens of icons, that entry is the practical way to find one without scanning the grid. Treating search providers as an editable YAML file is a good fit for a self-hosted tool: you can keep it in version control alongside the rest of your configuration, and you do not need a UI to add a provider. The trade-off is that the list is not managed from the web interface, so anyone expecting a settings page will not find one.

## Where Heimdall breaks: uploads, fileinfo and the 2MB background limit

Two failure modes are documented in the README, and both are PHP configuration rather than Heimdall logic.

The first is the background image. If you use the Docker image or a default PHP install, the README states that images over 2MB will not be set as the background. The fix is to raise upload_max_filesize in php.ini. On the linuxserver image the README gives a concrete instruction: edit /path/to/config/php/php-local.ini and append upload_max_filesize = 30M. That is a file edit plus a container restart, not a toggle in the dashboard.

The second is php_fileinfo. If you cannot change the background at all, the README says to make sure php_fileinfo is enabled, and notes that one user hit this on a Windows system. That is a real limitation of the manual install path: the requirement list is long, and a missing extension shows up as a broken feature rather than a clear error.

There is a third consideration that is not a bug. Heimdall is a dashboard, not a monitoring system. It shows what an Enhanced app's API returns. If a service is down, the tile is the wrong place to learn about it, and nothing in the README suggests alerting, history or health checks. If you need to know when something fails, Heimdall is the wrong tool.

## Heimdall, Organizr and the plain bookmark folder

The closest thing to a direct alternative in the repository's own topic list is Organizr, which appears alongside muximux and heimdall in the topics. The difference in approach is structural. Organizr is built around tabbed iframes that embed your services inside one page, so you stay in a single browser tab and the services render in frames. Heimdall does not embed anything: it is a launcher, and clicking a tile takes you to the application's own page. That makes Heimdall lighter and less likely to fight with services that set X-Frame-Options, but it also means the dashboard is a starting point rather than a workspace.

The other alternative is the browser itself. A bookmarks folder costs nothing and syncs across devices for free. Heimdall's answer is that you "won't lose your links in a sea of bookmarks", plus icons, a search bar and Enhanced-app stats. If you do not care about live queue sizes or a start page, the bookmark folder wins on maintenance.

## Maintenance, upgrades and what the MIT licence means here

The repository is not archived, and the last push was on 2026-09-09. Releases are frequent: v2.8.3 on 2026-09-05, v2.8.2 on 2026-08-12, v2.8.1 on 2026-07-09. The documented upgrade path is deliberately blunt. To update, you clone the repository or download the zip/tar of the new version and copy it over the old installation. The README does not document a database migration step or a rollback procedure, and it does not describe what happens to your data if you copy a new version over an old one. Back up your database and .env before you do it. On Docker, upgrading means pulling a new image, which is the path most users will take.

The project is MIT licensed. In practice that means you can run, modify and redistribute it, including inside a company, provided the copyright notice and permission notice are kept with copies or substantial portions. This is not legal advice, and the LICENSE file in the repository is the authoritative text.

One security-relevant detail is visible in .env.example rather than the README. It documents TRUSTED_PROXIES and TRUSTED_HOSTS under a comment about CVE-2025-50578, host header injection and open redirect hardening. TRUSTED_PROXIES defaults to the private ranges 192.168.0.0/16, 172.16.0.0/12, 10.0.0.0/8 and 127.0.0.1 when unset, and "*" trusts all proxies. TRUSTED_HOSTS is unset by default, which the file describes as no restriction and backward compatible. If you expose Heimdall through a reverse proxy, setting TRUSTED_HOSTS to your own domain is the documented way to close that gap.

## Conclusion

Adopt Heimdall if you run several self-hosted services behind a reverse proxy and want a single landing page with icons, a search bar and optional live stats from Enhanced apps; the README's own examples are NZBGet and SABnzbd queue size and download speed. Skip it if you want a hosted bookmark service with sync and mobile apps, or if you cannot give it a PHP 8.4 runtime with sqlite and zip support. Before committing, verify that php_fileinfo is enabled (background uploads depend on it), that upload_max_filesize is raised if you use large background images, and set TRUSTED_HOSTS and TRUSTED_PROXIES in .env if Heimdall sits behind a reverse proxy.

## FAQ

### How do I install Heimdall on Linux?

Clone the repository or extract the zip/tar, point your web server document root at the /public folder, then run cp .env.example .env and php artisan key:generate. The runtime needs PHP 8.4 or newer with the Laravel extensions listed in the README, plus sqlite and zip support.

### How do I use the Heimdall dashboard?

Add an application by typing its name in the title field and selecting it from the list of supported applications, which fills in the icon and a default colour. Clicking a tile opens that application, and the Tiles entry in the search providers list lets you search your own dashboard by name.

### How do I use Heimdall on Windows?

The README does not give a Windows-specific procedure. It mentions Windows only in the context of php_fileinfo, which one user found disabled on a Windows system, and which must be enabled if you cannot change the background image.

## Sources

- [Issues](https://github.com/linuxserver/Heimdall/issues)
- [License: MIT](https://github.com/linuxserver/Heimdall/blob/2.x/LICENSE)
- [linuxserver/Heimdall on GitHub](https://github.com/linuxserver/Heimdall)
- [README](https://github.com/linuxserver/Heimdall/blob/2.x/README.md)
- [Releases](https://github.com/linuxserver/Heimdall/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/linuxserver-heimdall
