# Self-hosting

Part of the Oya Browser docs. All of it: https://oyabrowser.com/docs.md

## Self-hosting

Run the whole stack in your own network, for HIPAA and SOC 2 workloads or anywhere data may not leave. It needs git, Docker and Node 20 or later.

```
curl -fsSL https://raw.githubusercontent.com/OyadotAI/oya-browser/main/install.sh | sh
```

A wizard asks six questions, writes the config, starts the stack, waits until it is ready, and prints an API key. Add `--dry-run` after `sh -s --` to see the plan without writing anything.

| Choice | Options |
| --- | --- |
| Control plane | Docker on one machine; Amazon ECS, Kubernetes or Google Cloud for production |
| Database | SQLite (default, one replica), Postgres (many replicas) or JSON files |
| Browsers | Docker workers, one container or pod per session, Oya Cloud, or your own Chrome over CDP |
| LLM | Anthropic, OpenAI, Gemini, any OpenAI-compatible endpoint, or a local model (Ollama, vLLM) |

### Point your code at it

```
oya login --url http://localhost:3100 --key <the key it printed>
oya ls                             # the browsers that enrolled
oya goto https://example.com
```

In code, set `OYA_BASE_URL` next to `OYA_API_KEY`; everything else in these docs works unchanged.

### Settings that matter

| Variable | What it does |
| --- | --- |
| `OYA_PROFILE_SECRET` | Encrypts cookies, passwords and TOTP seeds at rest. Generated into the data volume when unset, so keep that volume. |
| `API_KEYS` | Comma-separated tenant keys. The control plane needs nothing else. |
| `OYA_STORAGE` | sqlite, postgres or file: where every table lives. |
| `DATABASE_URL` | The Postgres connection string, with OYA_STORAGE=postgres. |
| `OPENAI_API_KEY` | The default model for agents. Each API key can set its own. |

Keep the `oya-data` volume, or set `OYA_PROFILE_SECRET` yourself. Lose the secret and every stored login becomes unreadable.

Databases, cloud browser runtimes, upgrades and every setting are in the [full self-hosting guide](https://github.com/OyadotAI/oya-browser/blob/main/docs/self-hosting.md).
