{"id":13432538,"url":"https://github.com/muety/wakapi","last_synced_at":"2026-03-01T10:03:22.160Z","repository":{"id":37393333,"uuid":"187916430","full_name":"muety/wakapi","owner":"muety","description":"📊 A minimalist, self-hosted WakaTime-compatible backend for coding statistics","archived":false,"fork":false,"pushed_at":"2026-02-22T14:53:32.000Z","size":9452,"stargazers_count":4164,"open_issues_count":35,"forks_count":267,"subscribers_count":18,"default_branch":"master","last_synced_at":"2026-02-22T18:56:12.378Z","etag":null,"topics":["coding-statistics","developer-tools","productivity","self-hosted","time-tracker","wakatime","wakatime-api"],"latest_commit_sha":null,"homepage":"https://wakapi.dev","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/muety.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":".github/FUNDING.yml","license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null},"funding":{"github":"muety","liberapay":"muety","custom":["https://paypal.me/ferdinandmuetsch","https://www.buymeacoffee.com/n1try"]}},"created_at":"2019-05-21T21:31:57.000Z","updated_at":"2026-02-22T14:53:36.000Z","dependencies_parsed_at":"2026-02-14T12:21:54.228Z","dependency_job_id":null,"html_url":"https://github.com/muety/wakapi","commit_stats":{"total_commits":1106,"total_committers":50,"mean_commits":22.12,"dds":"0.34267631103074137","last_synced_commit":"d1b940f84ae291dd7c10fdd240650940bbf27971"},"previous_names":["n1try/wakapi"],"tags_count":133,"template":false,"template_full_name":null,"purl":"pkg:github/muety/wakapi","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/muety%2Fwakapi","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/muety%2Fwakapi/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/muety%2Fwakapi/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/muety%2Fwakapi/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/muety","download_url":"https://codeload.github.com/muety/wakapi/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/muety%2Fwakapi/sbom","scorecard":{"id":667317,"data":{"date":"2025-08-11","repo":{"name":"github.com/muety/wakapi","commit":"1c47ebf636db9967b458b21ec80ad65b827c3144"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":4.6,"checks":[{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Code-Review","score":1,"reason":"Found 4/21 approved changesets -- score normalized to 1","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Maintained","score":10,"reason":"30 commit(s) and 22 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:12","Info: jobLevel 'contents' permission set to 'read': .github/workflows/ci.yml:41","Warn: no topLevel permission defined: .github/workflows/ci.yml:1","Warn: no topLevel permission defined: .github/workflows/docker.yml:1","Warn: no topLevel permission defined: .github/workflows/release.yml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: MIT License: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/muety/wakapi/ci.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/muety/wakapi/ci.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/muety/wakapi/ci.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/muety/wakapi/ci.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docker.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/muety/wakapi/docker.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/muety/wakapi/docker.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/muety/wakapi/docker.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/muety/wakapi/docker.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/muety/wakapi/docker.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/muety/wakapi/docker.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:56: update your workflow using https://app.stepsecurity.io/secureworkflow/muety/wakapi/docker.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/muety/wakapi/release.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/muety/wakapi/release.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:76: update your workflow using https://app.stepsecurity.io/secureworkflow/muety/wakapi/release.yml/master?enable=pin","Warn: containerImage not pinned by hash: Dockerfile:1","Warn: containerImage not pinned by hash: Dockerfile:30: pin your Docker image by updating alpine:3 to alpine:3@sha256:4bcff63911fcb4448bd4fdacec207030997caf25e9bea4045fa6c8c44de311d1","Warn: npmCommand not pinned by hash: .github/workflows/ci.yml:31","Warn: npmCommand not pinned by hash: .github/workflows/ci.yml:59","Info:   0 out of   7 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of   7 third-party GitHubAction dependencies pinned","Info:   0 out of   2 containerImage dependencies pinned","Info:   0 out of   2 npmCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Packaging","score":10,"reason":"packaging workflow detected","details":["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/docker.yml:9"],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact 2.14.1 not signed: https://api.github.com/repos/muety/wakapi/releases/233505867","Warn: release artifact 2.14.0 not signed: https://api.github.com/repos/muety/wakapi/releases/225086494","Warn: release artifact 2.13.4 not signed: https://api.github.com/repos/muety/wakapi/releases/214930765","Warn: release artifact 2.13.3 not signed: https://api.github.com/repos/muety/wakapi/releases/211826255","Warn: release artifact 2.13.2 not signed: https://api.github.com/repos/muety/wakapi/releases/210602895","Warn: release artifact 2.14.1 does not have provenance: https://api.github.com/repos/muety/wakapi/releases/233505867","Warn: release artifact 2.14.0 does not have provenance: https://api.github.com/repos/muety/wakapi/releases/225086494","Warn: release artifact 2.13.4 does not have provenance: https://api.github.com/repos/muety/wakapi/releases/214930765","Warn: release artifact 2.13.3 does not have provenance: https://api.github.com/repos/muety/wakapi/releases/211826255","Warn: release artifact 2.13.2 does not have provenance: https://api.github.com/repos/muety/wakapi/releases/210602895"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"SAST","score":10,"reason":"SAST tool is run on all commits","details":["Info: all commits (13) are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Vulnerabilities","score":6,"reason":"4 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GHSA-grv7-fg5c-xmjg","Warn: Project is vulnerable to: GHSA-952p-6rrq-rcjv","Warn: Project is vulnerable to: GHSA-mwcw-c2x4-8c55","Warn: Project is vulnerable to: GHSA-7fh5-64p2-3v2j"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-21T18:31:55.788Z","repository_id":37393333,"created_at":"2025-08-21T18:31:55.788Z","updated_at":"2025-08-21T18:31:55.788Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":29966684,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-03-01T09:33:09.965Z","status":"ssl_error","status_checked_at":"2026-03-01T09:25:48.915Z","response_time":124,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.5:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["coding-statistics","developer-tools","productivity","self-hosted","time-tracker","wakatime","wakatime-api"],"created_at":"2024-07-31T02:01:13.078Z","updated_at":"2026-03-01T10:03:22.142Z","avatar_url":"https://github.com/muety.png","language":"Go","readme":"\u003cp align=\"center\"\u003e\n  \u003cimg src=\"static/assets/images/logo-gh.svg\" width=\"350\"\u003e\n\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003cimg src=\"https://badges.fw-web.space/github/license/muety/wakapi\"\u003e\n  \u003ca href=\"https://liberapay.com/muety/\"\u003e\u003cimg src=\"https://badges.fw-web.space/liberapay/receives/muety.svg?logo=liberapay\"\u003e\u003c/a\u003e\n  \u003cimg src=\"https://wakapi.dev/api/badge/n1try/interval:any/project:wakapi?label=wakapi\"\u003e\n  \u003cimg src=\"https://badges.fw-web.space/github/languages/code-size/muety/wakapi\"\u003e\n  \u003ca href=\"https://goreportcard.com/report/github.com/muety/wakapi\"\u003e\u003cimg src=\"https://goreportcard.com/badge/github.com/muety/wakapi\"\u003e\u003c/a\u003e\n  \u003ca href=\"https://sonarcloud.io/dashboard?id=muety_wakapi\"\u003e\u003cimg src=\"https://sonarcloud.io/api/project_badges/measure?project=muety_wakapi\u0026metric=ncloc\"\u003e\u003c/a\u003e\n\u003c/p\u003e\n\n\u003ch3 align=\"center\"\u003eA minimalist, self-hosted WakaTime-compatible backend for coding statistics.\u003c/h3\u003e\n\n\u003cdiv align=\"center\"\u003e\n  \u003ch3\u003e\n    \u003ca href=\"https://wakapi.dev\"\u003eWebsite\u003c/a\u003e\n    \u003cspan\u003e | \u003c/span\u003e\n    \u003ca href=\"#-features\"\u003eFeatures\u003c/a\u003e\n    \u003cspan\u003e | \u003c/span\u003e\n    \u003ca href=\"#%EF%B8%8F-how-to-use\"\u003eHow to use\u003c/a\u003e\n    \u003cspan\u003e | \u003c/span\u003e\n    \u003ca href=\"https://github.com/muety/wakapi/issues\"\u003eIssues\u003c/a\u003e\n    \u003cspan\u003e | \u003c/span\u003e\n    \u003ca href=\"https://github.com/muety\"\u003eContact\u003c/a\u003e\n  \u003c/h3\u003e\n\u003c/div\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003cimg src=\"static/assets/images/screenshot.webp\" width=\"500px\"\u003e\n\u003c/p\u003e\n\n\u003e [!IMPORTANT]\n\u003e Upvote Wakapi on [AlternativeTo](https://alternativeto.net/software/wakapi/about/) and [ProductHunt](https://www.producthunt.com/posts/wakapi-coding-statistics) to support the project 🌈.\n\n## 🚀 Features\n\n* ✅ Free and open-source\n* ✅ Built by developers for developers\n* ✅ Statistics for projects, languages, editors, hosts and operating systems\n* ✅ Badges\n* ✅ Weekly E-Mail reports\n* ✅ REST API\n* ✅ Partially compatible with WakaTime\n* ✅ WakaTime integration\n* ✅ Support for Prometheus exports\n* ✅ Lightning fast\n* ✅ Self-hosted\n\n## ⌨️ How to use?\n\nThere are different options for how to use Wakapi, ranging from our hosted cloud service to self-hosting it. Regardless of which option choose, you will always have to do the [client setup](#-client-setup) in addition.\n\n### ☁️ Option 1: Use [wakapi.dev](https://wakapi.dev)\n\nIf you want to try out a free, hosted cloud service, all you need to do is create an account and then set up your client-side tooling (see below).\n\n### 📦 Option 2: Quick-run a release\n\n```bash\n$ curl -L https://wakapi.dev/get | bash\n```\n\n### 🐳 Option 3: Use Docker\n\n```bash\n# Create a persistent volume\n$ docker volume create wakapi-data\n\n$ SALT=\"$(cat /dev/urandom | LC_ALL=C tr -dc 'a-zA-Z0-9' | fold -w ${1:-32} | head -n 1)\"\n\n# Run the container\n$ docker run -d \\\n  --init \\\n  -p 3000:3000 \\\n  -e \"WAKAPI_PASSWORD_SALT=$SALT\" \\\n  -v wakapi-data:/data \\\n  --name wakapi \\\n  --restart unless-stopped \\\n  ghcr.io/muety/wakapi:latest\n```\n\n**Note:** By default, SQLite is used as a database. To run Wakapi in Docker with MySQL or Postgres, see [Dockerfile](https://github.com/muety/wakapi/blob/master/Dockerfile) and [config.default.yml](https://github.com/muety/wakapi/blob/master/config.default.yml) for further options.\n\nIf you want to run Wakapi on **Kubernetes**, there is [wakapi-helm-chart](https://github.com/ricristian/wakapi-helm-chart) for quick and easy deployment.\n\n#### Docker Compose\n\nAlternatively, you can use Docker Compose for an even more straightforward deployment. See [compose.yml](https://github.com/muety/wakapi/blob/master/compose.yml) for configuration details.\n\nWakapi supports [Docker Secrets](https://docs.docker.com/compose/how-tos/use-secrets/) for the following variables: `WAKAPI_PASSWORD_SALT`, `WAKAPI_DB_PASSWORD`, `WAKAPI_MAIL_SMTP_PASS`. You can set these either by having them mounted as a secret file, or directly pass them as environment variables.\n\n##### Example\n\n```bash\nexport WAKAPI_PASSWORD_SALT=changeme\nexport WAKAPI_DB_PASSWORD=changeme\nexport WAKAPI_MAIL_SMTP_PASS=changeme\n\ndocker compose up -d\n```\n\nIf you prefer to persist data in a local directory while using SQLite as the database, make sure to set the correct `user` option in the Docker Compose configuration to avoid permission issues.\n\n### 🧑‍💻 Option 4: Compile and run from source\n\n```bash\n# Build and install\n# Alternatively: go build -o wakapi\n$ go install github.com/muety/wakapi@latest\n\n# Get default config and customize\n$ curl -o wakapi.yml https://raw.githubusercontent.com/muety/wakapi/master/config.default.yml\n$ vi wakapi.yml\n\n# Run it\n$ ./wakapi -config wakapi.yml\n```\n\n**Note:** Check the comments in `config.yml` for best practices regarding security configuration and more.\n\n💡 When running Wakapi standalone (without Docker), it is recommended to run it as a [SystemD service](etc/wakapi.service).\n\n### 💻 Client setup\n\nWakapi relies on the open-source [WakaTime](https://github.com/wakatime/wakatime-cli) client tools. In order to collect statistics for Wakapi, you need to set them up.\n\n1. **Set up WakaTime** for your specific IDE or editor. Please refer to the respective [plugin guide](https://wakatime.com/plugins)\n2. **Edit your local `~/.wakatime.cfg`** file as follows.\n\n```ini\n[settings]\n\n# Your Wakapi server URL or 'https://wakapi.dev/api' when using the cloud server\napi_url = http://localhost:3000/api\n\n# Your Wakapi API key (get it from the web interface after having created an account)\napi_key = 406fe41f-6d69-4183-a4cc-121e0c524c2b\n```\n\nOptionally, you can set up a [client-side proxy](https://github.com/muety/wakapi/wiki/Advanced-Setup:-Client-side-proxy) in addition.\n\n#### WakaTime integration\nYou can use WakaTime and Wakapi in parallel, that is, have your coding activity tracked in both systems. \nThis can be configured either on the **client-side (preferred)** on a system-wide- or per-project basis or using Wakapi's **relay** functionality (__Settings → Integrations__) to forward heartbeats to WakaTime.\n\n**Example:**\n```ini\n[settings]\napi_key = defaults-to-this-api-key-when-not-defined-below\n[api_urls]\n.* = https://wakapi.dev/api|wakapi-api-key\n.* = https://api.wakatime.com/api/v1|waka-api-key\n```\n\nSee [wakatime-cli usage](https://github.com/wakatime/wakatime-cli/blob/develop/USAGE.md#api-urls-section) for details.\n\n## 🔧 Configuration options\n\nYou can specify configuration options either via a config file (default: `config.yml`, customizable through the `-c` argument) or via environment variables. Here is an overview of all options.\n\n| YAML key / Env. variable                                                                    | Default                                          | Description                                                                                                                                                                     |\n|---------------------------------------------------------------------------------------------|--------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|\n| `env` /\u003cbr\u003e`ENVIRONMENT`                                                                    | `dev`                                            | Whether to use development- or production settings                                                                                                                              |\n| `app.leaderboard_enabled` /\u003cbr\u003e`WAKAPI_LEADERBOARD_ENABLED`                                 | `true`                                           | Whether to enable the public leaderboard                                                                                                                                        |\n| `app.leaderboard_scope` /\u003cbr\u003e`WAKAPI_LEADERBOARD_SCOPE`                                     | `7_days`                                         | Aggregation interval for public leaderboard (see [here](https://github.com/muety/wakapi/blob/7d156cd3edeb93af2997bd95f12933b0aabef0c9/config/config.go#L71) for allowed values) |\n| `app.leaderboard_generation_time` /\u003cbr\u003e`WAKAPI_LEADERBOARD_GENERATION_TIME`                 | `0 0 6 * * *,0 0 18 * * *`                       | One or multiple times of day at which to re-calculate the leaderboard                                                                                                           |\n| `app.leaderboard_require_auth` /\u003cbr\u003e`WAKAPI_LEADERBOARD_REQUIRE_AUTH`                       | `false`                                          | Restrict leaderboard access to logged in users only                                                                                                                             |\n| `app.aggregation_time` /\u003cbr\u003e`WAKAPI_AGGREGATION_TIME`                                       | `0 15 2 * * *`                                   | Time of day at which to periodically run summary generation for all users                                                                                                       |\n| `app.report_time_weekly` /\u003cbr\u003e`WAKAPI_REPORT_TIME_WEEKLY`                                   | `0 0 18 * * 5`                                   | Week day and time at which to send e-mail reports                                                                                                                               |\n| `app.data_cleanup_time` /\u003cbr\u003e`WAKAPI_DATA_CLEANUP_TIME`                                     | `0 0 6 * * 0`                                    | When to perform data cleanup operations (see `app.data_retention_months`)                                                                                                       |\n| `app.optimize_database_time` /\u003cbr\u003e`WAKAPI_OPTIMIZE_DATABASE_TIME`                           | `0 0 8 1 * *`                                    | When to perform database vacuuming (SQLite, Postgres) or table optimization (MySQL)                                                                                             |\n| `app.import_enabled` /\u003cbr\u003e`WAKAPI_IMPORT_ENABLED`                                           | `true`                                           | Whether data imports from WakaTime or other Wakapi instances are permitted                                                                                                      |\n| `app.import_batch_size` /\u003cbr\u003e`WAKAPI_IMPORT_BATCH_SIZE`                                     | `50`                                             | Size of batches of heartbeats to insert to the database during importing from external services                                                                                 |\n| `app.import_backoff_min` /\u003cbr\u003e`WAKAPI_IMPORT_BACKOFF_MIN`                                   | `5`                                              | \"Cooldown\" period in minutes before user may attempt another data import                                                                                                        |\n| `app.import_max_rate` /\u003cbr\u003e`WAKAPI_IMPORT_MAX_RATE`                                         | `24`                                             | Minimum number of hours to wait after a successful data import before user may attempt another one                                                                              |\n| `app.inactive_days` /\u003cbr\u003e`WAKAPI_INACTIVE_DAYS`                                             | `7`                                              | Number of days after which to consider a user inactive (only for metrics)                                                                                                       |\n| `app.heartbeat_max_age /`\u003cbr\u003e`WAKAPI_HEARTBEAT_MAX_AGE`                                     | `4320h`                                          | Maximum acceptable age of a heartbeat (see [`ParseDuration`](https://pkg.go.dev/time#ParseDuration))                                                                            |\n| `app.warm_caches /`\u003cbr\u003e`WAKAPI_WARM_CACHES`                                                 | `true`                                           | Whether to perform some initial cache warming upon startup                                                                                                                      |\n| `app.custom_languages`                                                                      | -                                                | Map from file endings to language names                                                                                                                                         |\n| `app.avatar_url_template` /\u003cbr\u003e`WAKAPI_AVATAR_URL_TEMPLATE`                                 | (see [`config.default.yml`](config.default.yml)) | URL template for external user avatar images (e.g. from [Dicebear](https://dicebear.com) or [Gravatar](https://gravatar.com))                                                   |\n| `app.date_format` /\u003cbr\u003e`WAKAPI_DATE_FORMAT`                                                 | `Mon, 02 Jan 2006`                               | Go time format strings to format human-readable date (see [`Time.Format`](https://pkg.go.dev/time#Time.Format))                                                                 |\n| `app.datetime_format` /\u003cbr\u003e`WAKAPI_DATETIME_FORMAT`                                         | `Mon, 02 Jan 2006 15:04`                         | Go time format strings to format human-readable datetime (see [`Time.Format`](https://pkg.go.dev/time#Time.Format))                                                             |\n| `app.support_contact` /\u003cbr\u003e`WAKAPI_SUPPORT_CONTACT`                                         | `hostmaster@wakapi.dev`                          | E-Mail address to display as a support contact on the page                                                                                                                      |\n| `app.data_retention_months` /\u003cbr\u003e`WAKAPI_DATA_RETENTION_MONTHS`                             | `-1`                                             | Maximum retention period in months for user data (heartbeats) (-1 for unlimited)                                                                                                |\n| `app.max_inactive_months` /\u003cbr\u003e`WAKAPI_MAX_INACTIVE_MONTHS`                                 | `12`                                             | Maximum number of inactive months after which to delete user accounts without data (-1 for unlimited)                                                                           |\n| `server.port` /\u003cbr\u003e `WAKAPI_PORT`                                                           | `3000`                                           | Port to listen on                                                                                                                                                               |\n| `server.listen_ipv4` /\u003cbr\u003e `WAKAPI_LISTEN_IPV4`                                             | `127.0.0.1`                                      | IPv4 network address to listen on (set to `'-'` to disable IPv4)                                                                                                                |\n| `server.listen_ipv6` /\u003cbr\u003e `WAKAPI_LISTEN_IPV6`                                             | `::1`                                            | IPv6 network address to listen on (set to `'-'` to disable IPv6)                                                                                                                |\n| `server.listen_socket` /\u003cbr\u003e `WAKAPI_LISTEN_SOCKET`                                         | -                                                | UNIX socket to listen on (set to `'-'` to disable UNIX socket)                                                                                                                  |\n| `server.listen_socket_mode` /\u003cbr\u003e `WAKAPI_LISTEN_SOCKET_MODE`                               | `0666`                                           | Permission mode to create UNIX socket with                                                                                                                                      |\n| `server.timeout_sec` /\u003cbr\u003e `WAKAPI_TIMEOUT_SEC`                                             | `30`                                             | Request timeout in seconds                                                                                                                                                      |\n| `server.tls_cert_path` /\u003cbr\u003e `WAKAPI_TLS_CERT_PATH`                                         | -                                                | Path of SSL server certificate (leave blank to not use HTTPS)                                                                                                                   |\n| `server.tls_key_path` /\u003cbr\u003e `WAKAPI_TLS_KEY_PATH`                                           | -                                                | Path of SSL server private key (leave blank to not use HTTPS)                                                                                                                   |\n| `server.base_path` /\u003cbr\u003e `WAKAPI_BASE_PATH`                                                 | `/`                                              | Web base path (change when running behind a proxy under a sub-path)                                                                                                             |\n| `server.public_url` /\u003cbr\u003e `WAKAPI_PUBLIC_URL`                                               | `http://localhost:3000`                          | URL at which your Wakapi instance can be found publicly                                                                                                                         |\n| `security.disable_local_auth` /\u003cbr\u003e `WAKAPI_DISABLE_LOCAL_AUTH`                             | `false`                                          | Disables login via local credentials (username and password) to enforce OIDC provider login                                                                                     |\n| `security.disable_webauthn` /\u003cbr\u003e `WAKAPI_DISABLE_WEBAUTHN`                                 | `true`                                           | Disables login via WebAuthn (security keys, biometrics, etc.)                                                                                                                   |\n| `security.password_salt` /\u003cbr\u003e `WAKAPI_PASSWORD_SALT`                                       | -                                                | Pepper to use for password hashing                                                                                                                                              |\n| `security.insecure_cookies` /\u003cbr\u003e `WAKAPI_INSECURE_COOKIES`                                 | `true`                                           | Whether or not to allow cookies over HTTP. For production, it is **highly recommended** to serve Wakapi via HTTPS and set this to `false`.                                      |\n| `security.cookie_max_age` /\u003cbr\u003e `WAKAPI_COOKIE_MAX_AGE`                                     | `172800`                                         | Lifetime of authentication cookies in seconds or `0` to use [Session](https://developer.mozilla.org/en-US/docs/Web/HTTP/Cookies#Define_the_lifetime_of_a_cookie) cookies        |\n| `security.allow_signup` /\u003cbr\u003e `WAKAPI_ALLOW_SIGNUP`                                         | `true`                                           | Whether to enable local user registration                                                                                                                                       |\n| `security.oidc_allow_signup` /\u003cbr\u003e `WAKAPI_OIDC_ALLOW_SIGNUP`                               | `true`                                           | Whether to enable user registration via OIDC                                                                                                                                    |\n| `security.signup_captcha` /\u003cbr\u003e `WAKAPI_SIGNUP_CAPTCHA`                                     | `false`                                          | Whether the registration form requires solving a CAPTCHA                                                                                                                        |\n| `security.invite_codes` /\u003cbr\u003e `WAKAPI_INVITE_CODES`                                         | `true`                                           | Whether to enable registration by invite codes. Primarily useful if registration is disabled (invite-only server).                                                              |\n| `security.disable_frontpage` /\u003cbr\u003e `WAKAPI_DISABLE_FRONTPAGE`                               | `false`                                          | Whether to disable landing page (useful for personal instances)                                                                                                                 |\n| `security.expose_metrics` /\u003cbr\u003e `WAKAPI_EXPOSE_METRICS`                                     | `false`                                          | Whether to expose Prometheus metrics under `/api/metrics`                                                                                                                       |\n| `security.trusted_header_auth` /\u003cbr\u003e `WAKAPI_TRUSTED_HEADER_AUTH`                           | `false`                                          | Whether to enable trusted header authentication for reverse proxies (see [#534](https://github.com/muety/wakapi/issues/534)). **Use with caution!**                             |\n| `security.trusted_header_auth_key` /\u003cbr\u003e `WAKAPI_TRUSTED_HEADER_AUTH_KEY`                   | `Remote-User`                                    | Header field for trusted header authentication. **Caution:** proxy must be configured to strip this header from client requests!                                                |\n| `security.trusted_header_auth_allow_signup` /\u003cbr\u003e `WAKAPI_TRUSTED_HEADER_AUTH_ALLOW_SIGNUP` | `false`                                          | Whether to allow creation of new users based on upstream trusted header authentication (see [#808](https://github.com/muety/wakapi/issues/808))                                 |\n| `security.trust_reverse_proxy_ips` /\u003cbr\u003e `WAKAPI_TRUST_REVERSE_PROXY_IPS`                   | -                                                | Comma-separated list of IPv4 or IPv6 addresses or CIDRs of reverse proxies to trust to handle authentication (e.g. `172.17.0.1`, `192.168.0.0/24`, `[::1]`).                    |\n| `security.signup_max_rate` /\u003cbr\u003e `WAKAPI_SIGNUP_MAX_RATE`                                   | `5/1h`                                           | Rate limiting config for signup endpoint in format `\u003cmax_req\u003e/\u003cmultiplier\u003e\u003cunit\u003e`, where `unit` is one of `s`, `m` or `h`.                                                      |\n| `security.login_max_rate` /\u003cbr\u003e `WAKAPI_LOGIN_MAX_RATE`                                     | `10/1m`                                          | Rate limiting config for login endpoint in format `\u003cmax_req\u003e/\u003cmultiplier\u003e\u003cunit\u003e`, where `unit` is one of `s`, `m` or `h`.                                                       |\n| `security.password_reset_max_rate` /\u003cbr\u003e `WAKAPI_PASSWORD_RESET_MAX_RATE`                   | `5/1h`                                           | Rate limiting config for password reset endpoint in format `\u003cmax_req\u003e/\u003cmultiplier\u003e\u003cunit\u003e`, where `unit` is one of `s`, `m` or `h`.                                              |\n| `security.oidc`                                                                             | `[]`                                             | List of OpenID Connect provider configurations (for details, see [wiki](https://github.com/muety/wakapi/wiki/OpenID-Connect-login-(SSO)))                                       |\n| `security.oidc[0].name` /\u003cbr\u003e `WAKAPI_OIDC_PROVIDERS_0_NAME`                                | -                                                | Name / identifier for the OpenID Connect provider (e.g. `gitlab`)                                                                                                               |\n| `security.oidc[0].display_name` /\u003cbr\u003e `WAKAPI_OIDC_PROVIDERS_0_DISPLAY_NAME`                | -                                                | Optional \"human-readable\" display name for the provider presented to the user                                                                                                   |\n| `security.oidc[0].client_id` /\u003cbr\u003e `WAKAPI_OIDC_PROVIDERS_0_CLIENT_ID`                      | -                                                | OAuth client name with this provider                                                                                                                                            |\n| `security.oidc[0].client_secret` /\u003cbr\u003e `WAKAPI_OIDC_PROVIDERS_0_CLIENT_SECRET`              | -                                                | OAuth client secret with this provider                                                                                                                                          |\n| `security.oidc[0].endpoint` /\u003cbr\u003e `WAKAPI_OIDC_PROVIDERS_0_ENDPOINT`                        | -                                                | OpenID Connect provider API entrypoint (for [discovery](https://openid.net/specs/openid-connect-discovery-1_0.html))                                                            |\n| `security.oidc[0].username_claim` /\u003cbr\u003e `WAKAPI_OIDC_PROVIDERS_0_USERNAME_CLAIM`            | -                                                | Optionally spcified custom OIDC ID token claim to read username from (by `preferred_username`, `nickname` and `sub` are checked)                                                |\n| `security.oidc[0].scopes` /\u003cbr\u003e `WAKAPI_OIDC_PROVIDERS_0_SCOPES`                            | -                                                | Additional OAuth scopes to request beyond `openid`, `profile` and `email` (to be used in custom username claim)                                                                 |\n| `db.host` /\u003cbr\u003e `WAKAPI_DB_HOST`                                                            | -                                                | Database host                                                                                                                                                                   |\n| `db.port` /\u003cbr\u003e `WAKAPI_DB_PORT`                                                            | -                                                | Database port                                                                                                                                                                   |\n| `db.socket` /\u003cbr\u003e `WAKAPI_DB_SOCKET`                                                        | -                                                | Database UNIX socket (alternative to `host`) (for MySQL only)                                                                                                                   |\n| `db.user` /\u003cbr\u003e `WAKAPI_DB_USER`                                                            | -                                                | Database user                                                                                                                                                                   |\n| `db.password` /\u003cbr\u003e `WAKAPI_DB_PASSWORD`                                                    | -                                                | Database password                                                                                                                                                               |\n| `db.name` /\u003cbr\u003e `WAKAPI_DB_NAME`                                                            | `wakapi_db.db`                                   | Database name                                                                                                                                                                   |\n| `db.dialect` /\u003cbr\u003e `WAKAPI_DB_TYPE`                                                         | `sqlite3`                                        | Database type (one of `sqlite3`, `mysql`, `postgres`)                                                                                                                           |\n| `db.charset` /\u003cbr\u003e `WAKAPI_DB_CHARSET`                                                      | `utf8mb4`                                        | Database connection charset (for MySQL only)                                                                                                                                    |\n| `db.max_conn` /\u003cbr\u003e `WAKAPI_DB_MAX_CONNECTIONS`                                             | `2`                                              | Maximum number of database connections                                                                                                                                          |\n| `db.ssl` /\u003cbr\u003e `WAKAPI_DB_SSL`                                                              | `false`                                          | Whether to use TLS encryption for database connection (Postgres only)                                                                                                           |\n| `db.compress` /\u003cbr\u003e `WAKAPI_DB_COMPRESS`                                                    | `false`                                          | Whether to enable compression for database connection (MySQL only)                                                                                                              |\n| `db.automgirate_fail_silently` /\u003cbr\u003e `WAKAPI_DB_AUTOMIGRATE_FAIL_SILENTLY`                  | `false`                                          | Whether to ignore schema auto-migration failures when starting up                                                                                                               |\n| `mail.enabled` /\u003cbr\u003e `WAKAPI_MAIL_ENABLED`                                                  | `false`                                          | Whether to allow Wakapi to send e-mail (e.g. for password resets)                                                                                                               |\n| `mail.sender` /\u003cbr\u003e `WAKAPI_MAIL_SENDER`                                                    | -                                                | Default sender address for outgoing mails                                                                                                                                       |\n| `mail.skip_verify_mx_record` /\u003cbr\u003e `WAKAPI_MAIL_SKIP_VERIFY_MX_RECORD`                      | `false`                                          | Whether to skip validating MX DNS record for user email addresses                                                                                                               |\n| `mail.provider` /\u003cbr\u003e `WAKAPI_MAIL_PROVIDER`                                                | `smtp`                                           | Implementation to use for sending mails (one of [`smtp`])                                                                                                                       |\n| `mail.smtp.host` /\u003cbr\u003e `WAKAPI_MAIL_SMTP_HOST`                                              | -                                                | SMTP server address for sending mail (if using `smtp` mail provider)                                                                                                            |\n| `mail.smtp.port` /\u003cbr\u003e `WAKAPI_MAIL_SMTP_PORT`                                              | -                                                | SMTP server port (usually 465)                                                                                                                                                  |\n| `mail.smtp.username` /\u003cbr\u003e `WAKAPI_MAIL_SMTP_USER`                                          | -                                                | SMTP server authentication username                                                                                                                                             |\n| `mail.smtp.password` /\u003cbr\u003e `WAKAPI_MAIL_SMTP_PASS`                                          | -                                                | SMTP server authentication password                                                                                                                                             |\n| `mail.smtp.tls` /\u003cbr\u003e `WAKAPI_MAIL_SMTP_TLS`                                                | `false`                                          | Whether the SMTP server requires TLS encryption (`false` for STARTTLS or no encryption)                                                                                         |\n| `mail.smtp.skip_verify` /\u003cbr\u003e `WAKAPI_MAIL_SMTP_SKIP_VERIFY`                                | `false`                                          | Whether to allow invalid or self-signed certificates for TLS-encrypted SMTP                                                                                                     |\n| `sentry.dsn` /\u003cbr\u003e `WAKAPI_SENTRY_DSN`                                                      | –                                                | DSN for to integrate [Sentry](https://sentry.io) for error logging and tracing (leave empty to disable)                                                                         |\n| `sentry.environment` /\u003cbr\u003e `WAKAPI_SENTRY_ENVIRONMENT`                                      | (`env`)                                          | Sentry [environment](https://docs.sentry.io/concepts/key-terms/environments/) tag (defaults to `env` / `ENV`)                                                                   |\n| `sentry.enable_tracing` /\u003cbr\u003e `WAKAPI_SENTRY_TRACING`                                       | `false`                                          | Whether to enable Sentry request tracing                                                                                                                                        |\n| `sentry.sample_rate` /\u003cbr\u003e `WAKAPI_SENTRY_SAMPLE_RATE`                                      | `0.75`                                           | Probability of tracing a request in Sentry                                                                                                                                      |\n| `sentry.sample_rate_heartbeats` /\u003cbr\u003e `WAKAPI_SENTRY_SAMPLE_RATE_HEARTBEATS`                | `0.1`                                            | Probability of tracing a heartbeat request in Sentry                                                                                                                            |\n| `quick_start` /\u003cbr\u003e `WAKAPI_QUICK_START`                                                    | `false`                                          | Whether to skip initial boot tasks. Use only for development purposes!                                                                                                          |\n| `enable_pprof` /\u003cbr\u003e `WAKAPI_ENABLE_PPROF`                                                  | `false`                                          | Whether to expose [pprof](https://pkg.go.dev/runtime/pprof) profiling data as an endpoint for debugging                                                                         |\n\n### Supported databases\n\nWakapi uses [GORM](https://gorm.io) as an ORM. As a consequence, a set of different relational databases is supported.\n\n* [SQLite](https://sqlite.org/) (\u003e= 3.31) (_default, easy setup_)\n* [MySQL](https://hub.docker.com/_/mysql) (_recommended, because most extensively tested_)\n* [MariaDB](https://hub.docker.com/_/mariadb) (_open-source MySQL alternative_)\n* [Postgres](https://hub.docker.com/_/postgres) (_open-source as well_)\n\n## 🔐 Authentication\n\nWakapi supports different types of user authentication.\n\n* **Cookie:** This method is used in the browser. Users authenticate by sending along an encrypted, secure, HTTP-only cookie (`wakapi_auth`) that was set in the server's response upon login.\n* **API key:**\n    * **Via header:** This method is inspired by [WakaTime's auth. mechanism](https://wakatime.com/developers/#authentication) and is the common way to authenticate against API endpoints. Users set the `Authorization` header to `Basic \u003cBASE64_TOKEN\u003e`, where the latter part corresponds to your base64-hashed API key.\n    * **Vis query param:** Alternatively, users can also pass their plain API key as a query parameter (e.g. `?api_key=86648d74-19c5-452b-ba01-fb3ec70d4c2f`) in the URL with every request.\n* **Trusted header:** This mechanism allows to delegate authentication to a **reverse proxy** (e.g. for SSO), that Wakapi will then trust blindly. See [#534](https://github.com/muety/wakapi/issues/534) for details.\n    * Must be enabled via `trusted_header_auth` and configuring `trust_reverse_proxy_ip` in the config\n    * Warning: This type of authentication is quite prone to misconfiguration. Make sure that your reverse proxy properly strips relevant headers from client requests.\n\n### Single Sign-On / OpenID Connect\n\nWakapi supports login via external identity providers via OpenID Connect. See [our wiki](https://github.com/muety/wakapi/wiki/OpenID-Connect-login-(SSO)) for details.\n\nYou can also disable local authentication (username and password) entirely by setting `security.disable_local_auth` to `true`.\nThis enforces login exclusively via your configured OIDC providers.\n\n## 🔧 API endpoints\n\nSee our [Swagger API Documentation](https://wakapi.dev/swagger-ui).\n\n### Generating Swagger docs\n\n```bash\n$ go install github.com/swaggo/swag/cmd/swag@latest\n$ swag init -o static/docs\n```\n\n## 🤝 Integrations\n\n### Prometheus export\n\nYou can export your Wakapi statistics to Prometheus to view them in a Grafana dashboard or so. Here is how.\n\n```bash\n# 1. Start Wakapi with the feature enabled\n$ export WAKAPI_EXPOSE_METRICS=true\n$ ./wakapi\n\n# 2. Get your API key and hash it\n$ echo \"\u003cYOUR_API_KEY\u003e\" | base64\n\n# 3. Add a Prometheus scrape config to your prometheus.yml (see below)\n```\n\n#### Scrape config example\n\n```yml\n# prometheus.yml\n# (assuming your Wakapi instance listens at localhost, port 3000)\n\nscrape_configs:\n  - job_name: 'wakapi'\n    scrape_interval: 1m\n    metrics_path: '/api/metrics'\n    bearer_token: '\u003cYOUR_BASE64_HASHED_TOKEN\u003e'\n    static_configs:\n      - targets: [ 'localhost:3000' ]\n```\n\n#### Grafana\n\nThere is also a [nice Grafana dashboard](https://grafana.com/grafana/dashboards/12790), provided by the author of [wakatime_exporter](https://github.com/MacroPower/wakatime_exporter).\n\n![](https://grafana.com/api/dashboards/12790/images/8741/image)\n\n### WakaTime integration\n\nWakapi plays well together with [WakaTime](https://wakatime.com). For one thing, you can **forward heartbeats** from Wakapi to WakaTime to effectively use both services simultaneously. In addition, there is the option to **import historic data** from WakaTime for consistency between both services. Both features can be enabled in the _Integrations_ section of your Wakapi instance's settings page.\n\n### GitHub Readme Stats integrations\n\nWakapi also integrates with [GitHub Readme Stats](https://github.com/anuraghazra/github-readme-stats#wakatime-week-stats) to generate fancy cards for you. Here is an example. To use this, don't forget to **enable public data** under [Settings -\u003e Permissions](https://wakapi.dev/settings#permissions).\n\n\u003cdetails\u003e\n\u003csummary\u003eClick to view code\u003c/summary\u003e\n\n```markdown\n![](https://github-readme-stats.vercel.app/api/wakatime?username={yourusername}\u0026api_domain=wakapi.dev\u0026bg_color=2D3748\u0026title_color=2F855A\u0026icon_color=2F855A\u0026text_color=ffffff\u0026custom_title=Wakapi%20Week%20Stats\u0026layout=compact)\n```\n\n\u003c/details\u003e\n\u003cbr\u003e\n\n### GitHub Readme Metrics integration\n\nThere is a [WakaTime plugin](https://github.com/lowlighter/metrics/tree/master/source/plugins/wakatime) for GitHub [Metrics](https://github.com/lowlighter/metrics/) that is also compatible with Wakapi. To use this, don't forget to **enable public data** under [Settings -\u003e Permissions](https://wakapi.dev/settings#permissions).\n\nPreview:\n\n![](https://raw.githubusercontent.com/lowlighter/metrics/examples/metrics.plugin.wakatime.svg)\n\n\u003cdetails\u003e\n\u003csummary\u003eClick to view code\u003c/summary\u003e\n\n```yml\n- uses: lowlighter/metrics@latest\n  with:\n    # ... other options\n    plugin_wakatime: yes\n    plugin_wakatime_token: ${{ secrets.WAKATIME_TOKEN }}      # Required\n    plugin_wakatime_days: 7                                   # Display last week stats\n    plugin_wakatime_sections: time, projects, projects-graphs # Display time and projects sections, along with projects graphs\n    plugin_wakatime_limit: 4                                  # Show 4 entries per graph\n    plugin_wakatime_url: http://wakapi.dev                    # Wakatime url endpoint\n    plugin_wakatime_user: .user.login                         # User\n\n```\n\n\u003c/details\u003e\n\u003cbr\u003e\n\n### Browser Plugin (Chrome \u0026 Firefox)\n\nThe [browser-wakatime](https://github.com/wakatime/browser-wakatime) plugin enables you to track your web surfing in WakaTime (and Wakapi, of course). Visited websites will appear as \"files\" in the summary. Follow these instructions to get started:\n\n1. Install the browser extension from the official store ([Firefox](https://addons.mozilla.org/en-US/firefox/addon/wakatimes), [Chrome](https://chrome.google.com/webstore/detail/wakatime/jnbbnacmeggbgdjgaoojpmhdlkkpblgi?hl=de))\n2. Open the extension settings dialog\n3. Configure it like so (see screenshot below):\n    * API Key: Your personal API key (get it at [wakapi.dev](https://wakapi.dev))\n    * Logging Type: _Only the domain_\n    * API URL: `https://wakapi.dev/api/compat/wakatime/v1` (alternatively, replace _wakapi.dev_ with your self-hosted instance hostname)\n4. Save\n5. Start browsing!\n\n![](.github/assets/screenshot_browser_plugin.png)\n\nNote: the plugin will only sync heartbeats once in a while, so it might take some time for them to appear on Wakapi. To \"force\" it to sync, simply bring up the plugin main dialog.\n\n### Gnome Extension\n\nIf you're using the GNOME desktop, there is a quick way to display your today's coding statistics in the status bar.\n\n![](.github/assets/screenshot_gnome.png)\n\nSimply install the [Executor](https://extensions.gnome.org/extension/2932/executor/) extension and add the following command as a status bar indicator:\n\n```bash\n~/.wakatime/wakatime-cli-linux-amd64 --today\n```\n\n## 📦 Data Export\n\nYou can export your coding activity from Wakapi to CSV in the form of raw heartbeats. While there is no way to achieve this directly through the web UI, we provide an easy-to-use Python [script](scripts/download_heartbeats.py)\ninstead.\n\n```bash\n$ pip install requests tqdm\n$ python scripts/download_heartbeats.py --api_key API_KEY [--url URL] [--from FROM] [--to TO] [--output OUTPUT]\n```\n\n\u003cdetails\u003e\n\n\u003csummary\u003eExample\u003c/summary\u003e\n\n```bash\npython scripts/download_heartbeats.py --api_key 04648d14-15c9-432b-b901-dbeec70d4eaf \\\n  --url https://wakapi.dev/api \\\n  --from 2023-01-01 \\\n  --to 2023-01-31 \\\n  --output wakapi_export.csv\n```\n\n\u003c/details\u003e\n\n## 👍 Best practices\n\nIt is recommended to use wakapi behind a **reverse proxy**, like [Caddy](https://caddyserver.com) or [nginx](https://www.nginx.com/), to enable **TLS encryption** (HTTPS).\n\nHowever, if you want to expose your wakapi instance to the public anyway, you need to set `server.listen_ipv4` to `0.0.0.0` in `config.yml`.\n\n## 🧪 Tests\n\n### Unit tests\n\nUnit tests are supposed to test business logic on a fine-grained level. They are implemented as part of the application, using Go's [testing](https://pkg.go.dev/testing?utm_source=godoc) package alongside [stretchr/testify](https://pkg.go.dev/github.com/stretchr/testify).\n\n#### How to run\n\n```bash\n$ go install github.com/mfridman/tparse@latest  # optional\n$ CGO_ENABLED=0 go test -json -coverprofile=coverage/coverage.out ./... -run ./... | tparse -all\n```\n\n### API tests\n\nAPI tests are implemented as black box tests, which interact with a fully-fledged, standalone Wakapi through HTTP requests. They are supposed to check Wakapi's web stack and endpoints, including response codes, headers and data on a syntactical level, rather than checking the actual content that is returned.\n\nOur API (or end-to-end, in some way) tests are implemented as a [Bruno](https://www.usebruno.com/) collection and can be run either from inside Bruno, or using [Bruno CLI](https://www.npmjs.com/package/@usebruno/cli) as a command-line runner.\n\nTo get a predictable environment, tests are run against a fresh and clean Wakapi instance with a SQLite database that is populated with nothing but some seed data (see [data.sql](testing/data.sql)). It is usually recommended for software tests to be [safe](https://www.restapitutorial.com/lessons/idempotency.html), stateless and without side effects. In contrary to that paradigm, our API tests strictly require a fixed execution order (which Bruno assures) and their assertions may rely on specific previous tests having succeeded.\n\n#### Prerequisites (Linux only)\n\n```bash\n# 1. sqlite (cli)\n$ sudo apt install sqlite  # Fedora: sudo dnf install sqlite\n\n# 2. bruno cli\n$ npm install -g @usebruno/cli\n```\n\n#### How to run (Linux only)\n\n```bash\n$ ./testing/run_api_tests.sh\n```\n\n## 🤓 Developer notes\n\n### Building web assets\n\nTo keep things minimal, all JS and CSS assets are included as static files and checked in to Git. [TailwindCSS](https://tailwindcss.com/docs/installation#building-for-production) and [Iconify](https://iconify.design/docs/icon-bundles/) require an additional build step. To only require this at the time of development, the compiled assets are checked in to Git as well.\n\n```bash\n$ yarn\n$ yarn build  # or: yarn watch\n```\n\nNew icons can be added by editing the `icons` array in [scripts/bundle_icons.js](scripts/bundle_icons.js).\n\n#### Precompression\n\nAs explained in [#284](https://github.com/muety/wakapi/issues/284), precompressed (using Brotli) versions of some of the assets are delivered to save additional bandwidth. This was inspired by Caddy's [`precompressed`](https://caddyserver.com/docs/caddyfile/directives/file_server) directive. [`gzipped.FileServer`](https://github.com/muety/wakapi/blob/07a367ce0a97c7738ba8e255e9c72df273fd43a3/main.go#L249) checks for every static file's `.br` or `.gz` equivalents and, if present, delivers those instead of the actual file, alongside `Content-Encoding: br`. Currently, compressed assets are simply checked in to Git. Later we might want to have this be part of a new build step.\n\nTo pre-compress files, run this:\n\n```bash\n# Install brotli first\n$ sudo apt install brotli  # or: sudo dnf install brotli\n\n# Watch, build and compress\n$ yarn watch:compress\n\n# Alternatively: build and compress only\n$ yarn build:all:compress\n\n# Alternatively: compress only\n$ yarn compress\n```\n\n## ❔ FAQs\n\nSince Wakapi heavily relies on the concepts provided by WakaTime, [their FAQs](https://wakatime.com/faq) largely apply to Wakapi as well. You might find answers there.\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cb\u003eWhat data are sent to Wakapi?\u003c/b\u003e\u003c/summary\u003e\n\n\u003cul\u003e\n  \u003cli\u003eFile names\u003c/li\u003e\n  \u003cli\u003eProject names\u003c/li\u003e\n  \u003cli\u003eEditor names\u003c/li\u003e\n  \u003cli\u003eYour computer's host name\u003c/li\u003e\n  \u003cli\u003eTimestamps for every action you take in your editor\u003c/li\u003e\n  \u003cli\u003e...\u003c/li\u003e\n\u003c/ul\u003e\n\nSee the related [WakaTime FAQ section](https://wakatime.com/faq#data-collected) for details.\n\nIf you host Wakapi yourself, you have control over all your data. However, if you use our webservice and are concerned about privacy, you can also [exclude or obfuscate](https://wakatime.com/faq#exclude-paths) certain file- or project names.\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cb\u003eWhat happens if I'm offline?\u003c/b\u003e\u003c/summary\u003e\n\nAll data are cached locally on your machine and sent in batches once you're online again.\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cb\u003eHow did Wakapi come about?\u003c/b\u003e\u003c/summary\u003e\n\nWakapi was started when I was a student, who wanted to track detailed statistics about my coding time. Although I'm a big fan of WakaTime I didn't want to pay \u003ca href=\"https://wakatime.com/pricing\"\u003e$9 a month\u003c/a\u003e back then. Luckily, most parts of WakaTime are open source!\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cb\u003eHow does Wakapi compare to WakaTime?\u003c/b\u003e\u003c/summary\u003e\n\nWakapi is a small subset of WakaTime and has a lot less features. Cool WakaTime features, that are missing Wakapi, include:\n\n\u003cul\u003e\n  \u003cli\u003eLeaderboards\u003c/li\u003e\n  \u003cli\u003e\u003ca href=\"https://wakatime.com/share/embed\"\u003eEmbeddable Charts\u003c/a\u003e\u003c/li\u003e\n  \u003cli\u003ePersonal Goals\u003c/li\u003e\n  \u003cli\u003eTeam- / Organization Support\u003c/li\u003e\n  \u003cli\u003eAdditional Integrations (with GitLab, etc.)\u003c/li\u003e\n  \u003cli\u003eRicher API\u003c/li\u003e\n\u003c/ul\u003e\n\nWakaTime is worth the price. However, if you only need basic statistics and like to keep sovereignty over your data, you might want to go with Wakapi.\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cb\u003eHow are durations calculated?\u003c/b\u003e\u003c/summary\u003e\n\nInferring a measure for your coding time from heartbeats works similar to WakaTime, see their [docs](https://wakatime.com/faq#timeout). Traditionally, Wakapi used to _pad_ every heartbeat before a `\u003ctimeout\u003e`-long break with a padding of 2 minutes by default. Now, after the refactoring addressed in [#675](https://github.com/muety/wakapi/issues/675), Wakapi's logic is prtty much the same as WakaTime's, including a manually configurable timeout (default is 10 minutes).\n\nHere is an example (circles are heartbeats):\n\n```text\n|---o---o--------------o---o---|\n|   |10s|      3m      |10s|   |\n\n```\n\nIt is unclear how to handle the three minutes in between. Did the developer do a 3-minute break, or were just no heartbeats being sent, e.g. because the developer was staring at the screen trying to find a solution, but not actually typing code?\n\n\u003cul\u003e\n  \u003cli\u003e\u003cb\u003eWith 10 min timeout:\u003c/b\u003e: 3 min 20 sec\n  \u003cli\u003e\u003cb\u003eWith 2 min timeout:\u003c/b\u003e 20 sec\n  \u003cli\u003e\u003cb\u003ePreviously (with 2 min timeout + padding):\u003c/b\u003e 10 sec + 2 min + 10 sec = 2 min 20 sec\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\nSee [this comment](https://github.com/muety/wakapi/issues/716#issuecomment-2668887035) for another example.\n\n## 👥 Community contributions\n\n* 💻 [Code] Image generator from Wakapi stats – [LacazeThomas/wakapi-stats](https://github.com/LacazeThomas/wakapi-stats) (`Go`)\n* 💻 [Code] Discord integration for Wakapi - [LLoneDev6/Wakapi-Discord](https://github.com/LoneDev6/Wakapi-Discord) (`JavaScript`)\n* 💻 [Code] Alternative heartbeats export script - [wakapiexporter.nim](https://github.com/theAkito/mini-tools-nim/tree/master/generic/web/wakapiexporter) (`Nim`)\n* 💻 [Code] Wakapi Helm chart for K8s deployments - [andreymaznyak/wakapi-helm-chart](https://github.com/andreymaznyak/wakapi-helm-chart) (`YAML`)\n* 🗒 [Article] [Wakamonth: hours reporting tool](https://bitstillery.com/2024/01/09/wakamonth-hours-reporting-tool/)\n\n## 👏 Support\n\nCoding in open source is my passion, and I would love to do it on a full-time basis and make a living from it one day. So if you like this project, please consider supporting it 🙂. You can donate either through [buying me a coffee](https://buymeacoff.ee/n1try) or becoming a GitHub sponsor. Every little donation is highly appreciated and boosts my motivation to keep improving Wakapi!\n\n## 🙏 Thanks\n\nI highly appreciate the efforts of **[@alanhamlett](https://github.com/alanhamlett)** and the WakaTime team and am thankful for their software being open source.\n\nMoreover, thanks to **[server.camp](https://server.camp)** for donating server infrastructure for Wakapi.dev and [Tuta](https://tuta.com) to support us with their open-source sponsorship program.\n\n\u003cdiv\u003e\n  \u003cimg src=\".github/assets/servercamp_logo.png\" width=\"200px\" /\u003e\n  \u003cimg src=\".github/assets/tuta_logo.svg\" width=\"200px\"/\u003e\n\u003c/div\u003e\n\n## 📓 License\n\nMIT @ [Ferdinand Mütsch](https://muetsch.io)\n","funding_links":["https://github.com/sponsors/muety","https://liberapay.com/muety","https://paypal.me/ferdinandmuetsch","https://www.buymeacoffee.com/n1try","https://liberapay.com/muety/"],"categories":["Go","Time Tracking","时间跟踪","Apps","置顶"],"sub_categories":["Packages","Development","1、AI应用生态","AWS Amplify"],"project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmuety%2Fwakapi","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fmuety%2Fwakapi","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmuety%2Fwakapi/lists"}