{"id":51834145,"url":"https://github.com/liketrek/TREK","last_synced_at":"2026-07-30T04:00:50.264Z","repository":{"id":345400492,"uuid":"1186219527","full_name":"liketrek/TREK","owner":"liketrek","description":"A self-hosted travel/trip planner with real-time collaboration, interactive maps, PWA support, SSO, budgets, packing lists, and more.","archived":false,"fork":false,"pushed_at":"2026-07-26T16:22:46.000Z","size":139791,"stargazers_count":10639,"open_issues_count":19,"forks_count":901,"subscribers_count":32,"default_branch":"main","last_synced_at":"2026-07-26T18:16:37.822Z","etag":null,"topics":["budget-tracker","collaborative","open-source","opensource","packing-list","poi","real-time","routes","self-hosted","travel","travel-app","travel-planner","traveling","trip","trip-planner","tripit","wanderlog","wanderlust","webapplication"],"latest_commit_sha":null,"homepage":"https://demo.liketrek.com","language":"TypeScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"agpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/liketrek.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":".github/FUNDING.yml","license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":"NOTICE.md","maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null},"funding":{"ko_fi":"mauriceboe","buy_me_a_coffee":"mauriceboe"}},"created_at":"2026-03-19T11:51:54.000Z","updated_at":"2026-07-26T16:54:56.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/liketrek/TREK","commit_stats":null,"previous_names":["mauriceboe/nomad","mauriceboe/trek","liketrek/trek"],"tags_count":134,"template":false,"template_full_name":null,"purl":"pkg:github/liketrek/TREK","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/liketrek%2FTREK","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/liketrek%2FTREK/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/liketrek%2FTREK/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/liketrek%2FTREK/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/liketrek","download_url":"https://codeload.github.com/liketrek/TREK/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/liketrek%2FTREK/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":36059044,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-07-20T02:08:10.276Z","status":"online","status_checked_at":"2026-07-30T02:00:05.956Z","response_time":106,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["budget-tracker","collaborative","open-source","opensource","packing-list","poi","real-time","routes","self-hosted","travel","travel-app","travel-planner","traveling","trip","trip-planner","tripit","wanderlog","wanderlust","webapplication"],"created_at":"2026-07-22T19:00:25.900Z","updated_at":"2026-07-30T04:00:50.249Z","avatar_url":"https://github.com/liketrek.png","language":"TypeScript","funding_links":["https://ko-fi.com/mauriceboe","https://buymeacoffee.com/mauriceboe","https://www.buymeacoffee.com/mauriceboe"],"categories":["TypeScript"],"sub_categories":[],"readme":"\u003cdiv align=\"center\"\u003e\n\n\u003cpicture\u003e\n  \u003csource media=\"(prefers-color-scheme: dark)\" srcset=\"docs/logo-trek-light.gif\" /\u003e\n  \u003csource media=\"(prefers-color-scheme: light)\" srcset=\"docs/logo-trek-dark.gif\" /\u003e\n  \u003cimg src=\"docs/logo-trek-dark.gif\" alt=\"TREK\" height=\"96\" /\u003e\n\u003c/picture\u003e\n\n\u003cbr /\u003e\n\n\u003cpicture\u003e\n  \u003csource media=\"(prefers-color-scheme: dark)\" srcset=\"docs/subtitle-light.png\" /\u003e\n  \u003csource media=\"(prefers-color-scheme: light)\" srcset=\"docs/subtitle-dark.png\" /\u003e\n  \u003cimg src=\"docs/subtitle-dark.png\" alt=\"Your trips. Your plan. Your server.\" height=\"28\" /\u003e\n\u003c/picture\u003e\n\nA self-hosted, real-time collaborative travel planner — with maps, budgets, packing lists, a journal, and AI built in.\n\n\u003cbr /\u003e\n\n\u003ca href=\"https://demo.liketrek.com\"\u003e\u003cimg alt=\"Demo\" src=\"https://img.shields.io/badge/Demo-try-111827?style=for-the-badge\" /\u003e\u003c/a\u003e\n\u0026nbsp;\n\u003ca href=\"https://hub.docker.com/r/mauriceboe/trek\"\u003e\u003cimg alt=\"Docker\" src=\"https://img.shields.io/badge/Docker-ready-2496ED?style=for-the-badge\" /\u003e\u003c/a\u003e\n\u0026nbsp;\n\u003ca href=\"https://discord.gg/NhZBDSd4qW\"\u003e\u003cimg alt=\"Discord\" src=\"https://img.shields.io/badge/Discord-join-5865F2?style=for-the-badge\" /\u003e\u003c/a\u003e\n\u0026nbsp;\n\u003ca href=\"https://kanban.pakulat.org/shared/I4wxF6inOOMB0C6hH6kQm3efyNxFjwyI\"\u003e\u003cimg alt=\"Roadmap\" src=\"https://img.shields.io/badge/Roadmap-view-0EA5E9?style=for-the-badge\" /\u003e\u003c/a\u003e\n\u003cbr /\u003e\n\u003ca href=\"https://ko-fi.com/mauriceboe\"\u003e\u003cimg alt=\"Ko-fi\" src=\"https://img.shields.io/badge/Ko--fi-support-FF5E5B?style=for-the-badge\" /\u003e\u003c/a\u003e\n\u0026nbsp;\n\u003ca href=\"https://www.buymeacoffee.com/mauriceboe\"\u003e\u003cimg alt=\"BMAC\" src=\"https://img.shields.io/badge/BMAC-support-FFDD00?style=for-the-badge\" /\u003e\u003c/a\u003e\n\u003cbr /\u003e\n\u003ca href=\"LICENSE\"\u003e\u003cimg alt=\"License\" src=\"https://img.shields.io/badge/license-AGPL_v3-6B7280?style=flat-square\" /\u003e\u003c/a\u003e\n\u003ca href=\"https://github.com/liketrek/TREK/releases\"\u003e\u003cimg alt=\"Latest Release\" src=\"https://img.shields.io/github/v/release/liketrek/trek?include_prereleases\u0026style=flat-square\u0026color=6B7280\" /\u003e\u003c/a\u003e\n\u003ca href=\"https://hub.docker.com/r/mauriceboe/trek\"\u003e\u003cimg alt=\"Docker Pulls\" src=\"https://img.shields.io/docker/pulls/mauriceboe/trek?style=flat-square\u0026color=6B7280\" /\u003e\u003c/a\u003e\n\u003ca href=\"https://github.com/liketrek/TREK\"\u003e\u003cimg alt=\"Stars\" src=\"https://img.shields.io/github/stars/liketrek/trek?style=flat-square\u0026color=6B7280\" /\u003e\u003c/a\u003e\n\n\u003c/div\u003e\n\n---\n\n\u003cdiv align=\"center\"\u003e\n\n\u003cimg src=\"https://github.com/liketrek/TREK-media/releases/download/readme-assets/TREK1.gif\" alt=\"TREK — 60-second tour\" width=\"100%\" /\u003e\n\n\u003c/div\u003e\n\n\u003cbr /\u003e\n\n\u003cdiv align=\"center\"\u003e\n  \u003ca href=\"docs/screenshots/dashboard.png\"\u003e\u003cimg src=\"docs/screenshots/dashboard.png\" alt=\"Dashboard\" width=\"49%\" /\u003e\u003c/a\u003e\n  \u003ca href=\"docs/screenshots/trip-planner.png\"\u003e\u003cimg src=\"docs/screenshots/trip-planner.png\" alt=\"Trip planner · day plan \u0026 route\" width=\"49%\" /\u003e\u003c/a\u003e\n  \u003ca href=\"docs/screenshots/journey.png\"\u003e\u003cimg src=\"docs/screenshots/journey.png\" alt=\"Journey journal\" width=\"49%\" /\u003e\u003c/a\u003e\n  \u003ca href=\"docs/screenshots/budget.png\"\u003e\u003cimg src=\"docs/screenshots/budget.png\" alt=\"Costs · expense splitting\" width=\"49%\" /\u003e\u003c/a\u003e\n  \u003ca href=\"docs/screenshots/atlas.png\"\u003e\u003cimg src=\"docs/screenshots/atlas.png\" alt=\"Atlas · visited countries\" width=\"49%\" /\u003e\u003c/a\u003e\n  \u003ca href=\"docs/screenshots/vacay.png\"\u003e\u003cimg src=\"docs/screenshots/vacay.png\" alt=\"Vacay planner\" width=\"49%\" /\u003e\u003c/a\u003e\n  \u003ca href=\"docs/screenshots/collections.png\"\u003e\u003cimg src=\"docs/screenshots/collections.png\" alt=\"Collections · saved place lists\" width=\"49%\" /\u003e\u003c/a\u003e\n  \u003ca href=\"docs/screenshots/admin.png\"\u003e\u003cimg src=\"docs/screenshots/admin.png\" alt=\"Admin panel\" width=\"49%\" /\u003e\u003c/a\u003e\n\u003c/div\u003e\n\n---\n\n## What you get\n\n\u003cpicture\u003e\n  \u003csource media=\"(max-width: 700px)\" srcset=\"docs/tiles/grid-mobile.svg\" /\u003e\n  \u003cimg src=\"docs/tiles/grid-desktop.svg\" alt=\"TREK feature tiles\" width=\"100%\" /\u003e\n\u003c/picture\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cb\u003eSee all features\u003c/b\u003e\u003c/summary\u003e\n\n\u003ctable\u003e\n\u003ctr\u003e\n\u003ctd width=\"50%\" valign=\"top\"\u003e\n\n#### 🧭 Trip planning\n\n- **Drag \u0026 drop planner** — organise places into day plans with reordering and cross-day moves\n- **Interactive map** — Leaflet or Mapbox GL with 3D buildings, terrain, photo markers, clustering, route visualization\n- **Place search** — Google Places (photos, ratings, hours) or OpenStreetMap (free, no API key)\n- **Place import** — shared Google Maps / Naver Maps lists, plus GPX and KML/KMZ/GeoJSON map files\n- **Day notes** — timestamped, icon-tagged notes with drag-and-drop reordering\n- **Route optimisation** — auto-sort places and export to Google Maps\n- **Weather forecasts** — 16-day via Open-Meteo (no key) + historical climate fallback\n- **Category filter** — show only matching pins on the map\n\n\u003c/td\u003e\n\u003ctd width=\"50%\" valign=\"top\"\u003e\n\n#### 🧳 Travel management\n\n- **Reservations** — flights, accommodations, restaurants with status, confirmation numbers, files; import from booking confirmation emails and PDFs ([KDE Itinerary](https://invent.kde.org/pim/kitinerary))\n- **Costs** — track and split trip expenses (Splitwise-style): per-person / per-day breakdowns, settle-up, multi-currency\n- **Packing lists** — categories, templates, user assignment, progress tracking\n- **Bag tracking** — optional weight tracking with iOS-style distribution\n- **Document manager** — attach docs, tickets, PDFs to trips / places / reservations (≤ 50 MB each)\n- **PDF export** — full trip plan as PDF with cover page, images, notes\n\n\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd width=\"50%\" valign=\"top\"\u003e\n\n#### 👥 Collaboration\n\n- **Real-time sync** — WebSocket. Changes appear instantly across all connected users\n- **Multi-user trips** — invite members with role-based access\n- **Invite links** — one-time or reusable links with expiry\n- **SSO (OIDC)** — Google, Apple, Authentik, Keycloak, or any OIDC provider\n- **2FA** — TOTP + backup codes\n- **Passkeys** — passwordless WebAuthn login (fingerprint / face / PIN / security key), admin-toggleable\n- **Collab suite** — group chat, shared notes, polls, day check-ins\n\n\u003c/td\u003e\n\u003ctd width=\"50%\" valign=\"top\"\u003e\n\n#### 📱 Mobile \u0026 PWA\n\n- **Installable** — iOS and Android, straight from the browser, no App Store needed\n- **Offline support** — Service Worker caches tiles, API, uploads via Workbox\n- **Native feel** — fullscreen standalone, themed status bar, splash screen\n- **Touch optimised** — mobile-specific layouts with safe-area handling\n\n\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd width=\"50%\" valign=\"top\"\u003e\n\n#### 🧩 Addons (admin-toggleable)\n\n- **Lists** — packing lists + to-dos with templates, member assignments, optional bag tracking\n- **Costs** — expense tracker with splits and settle-up (who owes whom), multi-currency\n- **Documents** — file attachments on trips, places, and reservations\n- **Collab** — chat, notes, polls, day-by-day attendance\n- **Vacay** — personal vacation planner with calendar, 100+ country holidays, carry-over tracking\n- **Atlas** — world map of visited countries, bucket list, travel stats, streak tracking, liquid-glass UI\n- **Journey** — magazine-style travel journal with entries, photos (Immich/Synology), maps, moods\n- **AirTrail** — connect a self-hosted AirTrail instance to import and sync flights into reservations\n- **MCP** — expose TREK to AI assistants via OAuth 2.1\n\n\u003c/td\u003e\n\u003ctd width=\"50%\" valign=\"top\"\u003e\n\n#### 🤖 AI / MCP\n\n- **Built-in MCP server** — OAuth 2.1 authenticated. 150+ tools, 30 resources\n- **Granular scopes** — 27 OAuth scopes across 13 permission groups\n- **Full automation** — AI can create trips, plan days, build packing lists, manage budgets, mark countries visited\n- **Pre-built prompts** — `trip-summary`, `packing-list`, `budget-overview`\n- **Addon-aware** — exposes Atlas, Collab, Vacay when those addons are on\n\n\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd colspan=\"2\" valign=\"top\"\u003e\n\n#### ⚙️ Admin \u0026 customisation\n\n- **Dashboard views** — card grid or compact list · **Dark mode** — full theme with matching status bar\n- **20 languages** — EN, DE, ES, FR, IT, NL, HU, RU, ZH, ZH-TW, PL, CS, AR (RTL), BR, ID, TR, JA, KO, UK, GR\n- **Admin panel** — users, invites, packing templates, categories, addons, API keys, backups, GitHub history\n- **Notifications** — per-user preferences across email (SMTP), webhook, ntfy, and an in-app notification center\n- **Auto-backups** — scheduled with configurable retention · **Units** — °C/°F, 12h/24h, map tile sources, default coordinates\n\n\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/table\u003e\n\n\u003c/details\u003e\n\n\u003cbr /\u003e\n\n## Get started in 30 seconds\n\n```bash\nENCRYPTION_KEY=$(openssl rand -hex 32) docker run -d -p 3000:3000 \\\n  -e ENCRYPTION_KEY=$ENCRYPTION_KEY \\\n  -v ./data:/app/data -v ./uploads:/app/uploads mauriceboe/trek\n```\n\nOpen `http://localhost:3000`. On first boot TREK seeds an admin account — if you set `ADMIN_EMAIL`/`ADMIN_PASSWORD` those are used, otherwise the credentials are printed to the container log (`docker logs trek`).\n\n\u003cdiv align=\"center\"\u003e\n\n\u0026nbsp;\u0026nbsp;·\u0026nbsp;\u0026nbsp;\u003ca href=\"#docker-compose-production\"\u003eDocker Compose\u003c/a\u003e\u0026nbsp;\u0026nbsp;·\u0026nbsp;\u0026nbsp;\u003ca href=\"#helm-kubernetes\"\u003eHelm / Kubernetes\u003c/a\u003e\u0026nbsp;\u0026nbsp;·\u0026nbsp;\u0026nbsp;\u003ca href=\"#install-as-app-pwa\"\u003eInstall as PWA\u003c/a\u003e\u0026nbsp;\u0026nbsp;·\u0026nbsp;\u0026nbsp;\u003ca href=\"#reverse-proxy\"\u003eReverse Proxy\u003c/a\u003e\u0026nbsp;\u0026nbsp;·\u0026nbsp;\u0026nbsp;\n\n\u003c/div\u003e\n\n\u003cbr /\u003e\n\n## Tech stack\n\n\u003cdiv align=\"center\"\u003e\n\n![Node.js](https://img.shields.io/badge/Node.js_22-339933?style=flat-square\u0026logo=node.js\u0026logoColor=white)\n![NestJS](https://img.shields.io/badge/NestJS_11-E0234E?style=flat-square\u0026logo=nestjs\u0026logoColor=white)\n![SQLite](https://img.shields.io/badge/SQLite-003B57?style=flat-square\u0026logo=sqlite\u0026logoColor=white)\n![React](https://img.shields.io/badge/React_19-61DAFB?style=flat-square\u0026logo=react\u0026logoColor=black)\n![Vite](https://img.shields.io/badge/Vite-646CFF?style=flat-square\u0026logo=vite\u0026logoColor=white)\n![TypeScript](https://img.shields.io/badge/TypeScript-3178C6?style=flat-square\u0026logo=typescript\u0026logoColor=white)\n![Tailwind](https://img.shields.io/badge/Tailwind-06B6D4?style=flat-square\u0026logo=tailwindcss\u0026logoColor=white)\n![Leaflet](https://img.shields.io/badge/Leaflet-199900?style=flat-square\u0026logo=leaflet\u0026logoColor=white)\n![Docker](https://img.shields.io/badge/Docker-2496ED?style=flat-square\u0026logo=docker\u0026logoColor=white)\n\n\u003c/div\u003e\n\nReal-time sync via WebSocket (`ws`). Backend on NestJS 11. State with Zustand. Auth via JWT + OAuth 2.1 + OIDC + Passkeys (WebAuthn) + TOTP MFA. Weather via Open-Meteo (no key required). Maps with Leaflet and Mapbox GL.\n\n\u003cbr /\u003e\n\n\u003ch2 id=\"docker-compose-production\"\u003eDocker Compose (production)\u003c/h2\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003eFull compose example with secure defaults\u003c/summary\u003e\n\n```yaml\nservices:\n  app:\n    image: mauriceboe/trek:latest\n    container_name: trek\n    read_only: true\n    security_opt:\n      - no-new-privileges:true\n    cap_drop:\n      - ALL\n    cap_add:\n      - CHOWN\n      - SETUID\n      - SETGID\n    tmpfs:\n      - /tmp:noexec,nosuid,size=64m\n    ports:\n      - \"3000:3000\"\n    environment:\n      - NODE_ENV=production\n      - PORT=3000\n      - ENCRYPTION_KEY=${ENCRYPTION_KEY:-}   # generate with: openssl rand -hex 32\n      - TZ=${TZ:-UTC}\n      - LOG_LEVEL=${LOG_LEVEL:-info}\n      - ALLOWED_ORIGINS=${ALLOWED_ORIGINS:-}\n      - APP_URL=${APP_URL:-}                 # required for OIDC + email links\n      # - FORCE_HTTPS=true                   # behind a TLS-terminating proxy\n      # - TRUST_PROXY=1\n      # - OIDC_ISSUER=https://auth.example.com\n      # - OIDC_CLIENT_ID=trek\n      # - OIDC_CLIENT_SECRET=supersecret\n      # - OIDC_DISPLAY_NAME=SSO\n      # - OIDC_ADMIN_CLAIM=groups\n      # - OIDC_ADMIN_VALUE=app-trek-admins\n    volumes:\n      - ./data:/app/data\n      - ./uploads:/app/uploads\n    restart: unless-stopped\n    healthcheck:\n      test: [\"CMD\", \"wget\", \"-qO-\", \"http://localhost:3000/api/health\"]\n      interval: 30s\n      timeout: 10s\n      retries: 3\n      start_period: 15s\n```\n\nThen:\n\n```bash\ndocker compose up -d\n```\n\n**HTTPS notes:** `FORCE_HTTPS=true` is optional — it adds a 301 redirect, HSTS, CSP upgrade-insecure-requests, and forces the `secure` cookie flag. Only use it behind a TLS-terminating reverse proxy. `TRUST_PROXY=1` tells the server how many proxies sit in front so real client IPs and `X-Forwarded-Proto` work.\n\n\u003c/details\u003e\n\n\u003cbr /\u003e\n\n\u003ch2 id=\"helm-kubernetes\"\u003eHelm (Kubernetes)\u003c/h2\u003e\n\n```bash\nhelm repo add trek https://chart.liketrek.com\nhelm repo update\nhelm install trek trek/trek\n```\n\nSee [`charts/README.md`](https://github.com/liketrek/TREK/blob/main/charts/README.md) for values.\n\n\u003ch2 id=\"install-as-app-pwa\"\u003eInstall as App (PWA)\u003c/h2\u003e\n\nTREK works as a Progressive Web App — no App Store needed.\n\n1. Open TREK in the browser (HTTPS required)\n2. **iOS**: Share ▸ *Add to Home Screen*\n3. **Android**: Menu ▸ *Install app* (or *Add to Home Screen*)\n\nTREK then launches fullscreen with its own icon, just like a native app.\n\n\u003cbr /\u003e\n\n## Updating\n\n**Docker Compose:**\n\n```bash\ndocker compose pull \u0026\u0026 docker compose up -d\n```\n\n**Docker run** — reuse the original volume paths:\n\n```bash\ndocker pull mauriceboe/trek\ndocker rm -f trek\ndocker run -d --name trek -p 3000:3000 -v ./data:/app/data -v ./uploads:/app/uploads --restart unless-stopped mauriceboe/trek\n```\n\n\u003e Not sure which paths you used? `docker inspect trek --format '{{json .Mounts}}'` before removing the container.\n\nYour data stays in the mounted `data` and `uploads` volumes — updates never touch it.\n\n\u003e [!IMPORTANT]\n\u003e Mount **only** the data and uploads directories — `-v ./data:/app/data -v ./uploads:/app/uploads`. **Never mount a volume at `/app`.** Doing so hides the application code shipped in the image and the container fails to start with `Cannot find module 'tsconfig-paths/register'`. If you previously mounted `/app`, switch to the two mounts above; your data in `data/` and `uploads/` is preserved.\n\n\u003ch3\u003eRotating the Encryption Key\u003c/h3\u003e\n\nIf you need to rotate `ENCRYPTION_KEY` (e.g. upgrading from a version that derived encryption from `JWT_SECRET`):\n\n```bash\ndocker exec -it trek node --import tsx scripts/migrate-encryption.ts\n```\n\nThe script creates a timestamped DB backup before making changes and prompts for old + new keys (input is not echoed).\n\n\u003ch2 id=\"reverse-proxy\"\u003eReverse Proxy\u003c/h2\u003e\n\nFor production, put TREK behind a TLS-terminating reverse proxy. TREK uses WebSockets for real-time sync, so the proxy **must** support WebSocket upgrades on `/ws`.\n\nIf you use the MCP addon, the proxy must also pass the `Mcp-Session-Id` header through in both directions on `/mcp` — Nginx and Caddy do this by default, but a proxy that strips it makes every tool call open a new session instead of reusing one. See the [Reverse Proxy wiki page](https://github.com/liketrek/TREK/wiki/Reverse-Proxy) for details.\n\n\u003cdetails\u003e\n\u003csummary\u003eNginx\u003c/summary\u003e\n\n```nginx\nserver {\n    listen 80;\n    server_name trek.yourdomain.com;\n    return 301 https://$host$request_uri;\n}\n\nserver {\n    listen 443 ssl http2;\n    server_name trek.yourdomain.com;\n\n    ssl_certificate     /etc/ssl/fullchain.pem;\n    ssl_certificate_key /etc/ssl/privkey.pem;\n\n    # 500 MB covers backup-restore uploads (capped at 500 MB server-side).\n    client_max_body_size 500m;\n\n    location / {\n        proxy_pass http://localhost:3000;\n        proxy_http_version 1.1;\n        proxy_set_header Host $host;\n        proxy_set_header X-Real-IP $remote_addr;\n        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;\n        proxy_set_header X-Forwarded-Proto $scheme;\n    }\n\n    location /ws {\n        proxy_pass http://localhost:3000;\n        proxy_http_version 1.1;\n        proxy_set_header Upgrade $http_upgrade;\n        proxy_set_header Connection \"upgrade\";\n        proxy_set_header Host $host;\n        proxy_read_timeout 86400;\n    }\n\n    # Only needed if you use the MCP addon. Responses are Server-Sent Events,\n    # so buffering must be off or tool results arrive late.\n    location /mcp {\n        proxy_pass http://localhost:3000;\n        proxy_http_version 1.1;\n        proxy_set_header Host $host;\n        proxy_set_header X-Real-IP $remote_addr;\n        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;\n        proxy_set_header X-Forwarded-Proto $scheme;\n        proxy_buffering off;\n        proxy_read_timeout 3600s;\n    }\n}\n```\n\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003eCaddy\u003c/summary\u003e\n\n```caddy\ntrek.yourdomain.com {\n    reverse_proxy localhost:3000\n}\n```\n\nCaddy handles TLS and WebSockets automatically.\n\n\u003c/details\u003e\n\n\u003cbr /\u003e\n\n## Environment variables\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cb\u003eFull reference\u003c/b\u003e\u003c/summary\u003e\n\n\u003cbr /\u003e\n\n| Variable | Description | Default |\n|----------|-------------|---------|\n| **Core** | | |\n| `PORT` | Server port | `3000` |\n| `NODE_ENV` | Environment (`production` / `development`) | `production` |\n| `ENCRYPTION_KEY` | At-rest encryption key for stored secrets (API keys, MFA, SMTP, OIDC). Recommended: generate with `openssl rand -hex 32`. If unset, falls back to `data/.jwt_secret` (existing installs) or auto-generates a key (fresh installs). | Auto |\n| `TZ` | Timezone for logs, reminders and cron jobs (e.g. `Europe/Berlin`) | `UTC` |\n| `LOG_LEVEL` | `info` = concise user actions, `debug` = verbose details | `info` |\n| `TREK_WIKI_DIR` | Where the in-app Help pages (`/help`) read their content from. TREK ships its wiki and serves it from disk, so Help always matches the version you are running — you should not need to set this. Point it at your own directory to serve custom docs. If the path does not exist, Help falls back to fetching the public GitHub wiki (needs outbound network, and tracks the latest release). | bundled `wiki/` |\n| `DEFAULT_LANGUAGE` | Default language on the login page for users with no saved preference. Browser/OS language is auto-detected first; this is the fallback. Supported: `de`, `en`, `es`, `fr`, `hu`, `nl`, `br`, `cs`, `pl`, `ru`, `zh`, `zh-TW`, `it`, `ar`, `id`, `tr`, `ja`, `ko`, `uk`, `gr` | `en` |\n| `ALLOWED_ORIGINS` | Comma-separated origins for CORS and email links | same-origin |\n| `FORCE_HTTPS` | Optional. When `true`: 301-redirects HTTP to HTTPS, sends HSTS, adds CSP `upgrade-insecure-requests`, forces the session cookie `secure` flag. Useful behind a TLS-terminating reverse proxy. Requires `TRUST_PROXY`. | `false` |\n| `HSTS_INCLUDE_SUBDOMAINS` | When `true`: adds the `includeSubDomains` directive to the HSTS header, extending HTTPS enforcement to all subdomains. Only effective when HSTS is active (`FORCE_HTTPS=true` or `NODE_ENV=production`). Leave `false` if you run other services on sibling subdomains over plain HTTP. | `false` |\n| `COOKIE_SECURE` | Controls the `secure` flag on the `trek_session` cookie. Auto-derived: on when `NODE_ENV=production` or `FORCE_HTTPS=true`. Escape hatch: set `false` to allow session cookies over plain HTTP. Not recommended in production. | auto |\n| `SESSION_DURATION` | How long a login session stays valid when **\"Remember me\" is unchecked** (the default): sets the `trek_session` JWT `exp` and issues a browser-session cookie (cleared when the browser closes). Accepts `ms`-style strings: `1h`, `12h`, `7d`, `30d`, `90d`. Invalid values warn at startup and fall back to the default. | `24h` |\n| `SESSION_DURATION_REMEMBER` | Session length when **\"Remember me\" is ticked** at login: a longer-lived JWT plus a persistent `trek_session` cookie that survives browser restarts. Same format and startup-fallback behaviour as `SESSION_DURATION`. | `30d` |\n| `TRUST_PROXY` | Number of trusted reverse proxies. Tells the server to read client IP from `X-Forwarded-For` and protocol from `X-Forwarded-Proto`. Defaults to `1` in production; off in dev unless set. | `1` |\n| `ALLOW_INTERNAL_NETWORK` | Allow outbound requests to private/RFC-1918 IPs (e.g. Immich on your LAN). Loopback and link-local addresses remain blocked. | `false` |\n| `APP_URL` | Public base URL of this instance (e.g. `https://trek.example.com`). Required when OIDC is enabled; used as base for email notification links. | — |\n| **OIDC / SSO** | | |\n| `OIDC_ISSUER` | OpenID Connect provider URL | — |\n| `OIDC_CLIENT_ID` | OIDC client ID | — |\n| `OIDC_CLIENT_SECRET` | OIDC client secret | — |\n| `OIDC_DISPLAY_NAME` | Label shown on the SSO login button | `SSO` |\n| `OIDC_ONLY` | Force SSO-only mode: disables password login + registration, regardless of Admin \u003e Settings. The first SSO login becomes admin. | `false` |\n| `OIDC_ADMIN_CLAIM` | OIDC claim used to identify admin users | — |\n| `OIDC_ADMIN_VALUE` | Value of the OIDC claim that grants admin role | — |\n| `OIDC_SCOPE` | Space-separated OIDC scopes. **Fully replaces** the default — always include `openid email profile`. | `openid email profile` |\n| `OIDC_DISCOVERY_URL` | Override the auto-constructed OIDC discovery endpoint (e.g. Authentik: `.../application/o/trek/.well-known/openid-configuration`) | — |\n| **Initial setup** | | |\n| `ADMIN_EMAIL` | Email for the first admin on initial boot. Must be set together with `ADMIN_PASSWORD`. If either is omitted a random password is printed to the server log. No effect once a user exists. | `admin@trek.local` |\n| `ADMIN_PASSWORD` | Password for the first admin on initial boot. Pairs with `ADMIN_EMAIL`. | random |\n| **Other** | | |\n| `DEMO_MODE` | Enable demo mode (hourly data resets) | `false` |\n| `UNSPLASH_ACCESS_KEY` | Optional Unsplash Access Key for trip-cover and place-image search. Without one, TREK uses Unsplash's unauthenticated endpoint, which some datacenter/VPS IPs are blocked from. Get a free key at [unsplash.com/developers](https://unsplash.com/developers). Overrides any per-admin key set in Admin \u003e Settings (where it can also be configured instead). | — |\n| `MCP_RATE_LIMIT` | Max MCP API requests per user per minute | `300` |\n| `MCP_MAX_SESSION_PER_USER` | Max concurrent MCP sessions per user. At the cap, the least-recently-active session is closed to make room | `20` |\n\n\u003c/details\u003e\n\n\u003cbr /\u003e\n\n## Data \u0026 Backups\n\n- **Database** — SQLite, stored in `./data/travel.db`\n- **Uploads** — stored in `./uploads/`\n- **Logs** — `./data/logs/trek.log` (auto-rotated)\n- **Backups** — create and restore via Admin Panel\n- **Auto-Backups** — configurable schedule and retention in Admin Panel\n\n\u003cbr /\u003e\n\n## Data sources\n\nThe Atlas map's country and sub-national (province/county) boundaries come from\n[**geoBoundaries**](https://www.geoboundaries.org/) (Runfola et al., 2020), licensed\n[CC BY 4.0](https://creativecommons.org/licenses/by/4.0/). See [NOTICE.md](NOTICE.md)\nfor full third-party attributions.\n\n## License\n\nTREK is [AGPL v3](LICENSE). Self-host freely for personal or internal company use. If you modify and offer TREK as a network service to third parties, your modifications must be open-sourced under the same licence.\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fliketrek%2FTREK","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fliketrek%2FTREK","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fliketrek%2FTREK/lists"}