What version v1.17.0 changes for agency use
AnythingLLM has supported multi-user mode for several versions. v1.17.0 (October 1, 2026) refines this system by introducing a third role — Manager — who can create workspaces, invite users and manage documents without accessing system settings such as API keys or LLM configuration. For an agency, this role allows delegating the administration of a client to a project manager without exposing the entire infrastructure. Meeting diarization now relies on Nemotron 3 for speaker recognition and Parakeet Redux for transcription — two models that can run locally on a GPU-equipped VPS, or be delegated to an Nvidia API. Google Vertex AI was already available since v1.16.2 (September 22, 2026) as an LLM provider configurable directly from the interface, without manually patching the configuration file. These recent additions make the v1.16.2 + v1.17.0 combination the most complete configuration for structured multi-client use.
Prerequisites before starting
- VPS with at least 4 GB RAM — 2 vCPU / 4 GB for cloud APIs, 4 vCPU / 8 GB if you embed a local embedding model or Parakeet Redux
- 20 GB of SSD disk — LanceDB vectors and the document cache grow with the corpus; leave room to expand
- Docker and Docker Compose v2 — verify with
docker compose version(no hyphen); v1 (with hyphen) does not support all healthchecks - A dedicated subdomain — for example
chat.your-domain.com; port 3001 must not be directly exposed publicly - An active reverse proxy — Nginx or Caddy for Let's Encrypt TLS and document upload size limits
- An LLM API key — OpenAI, Anthropic, Vertex AI, or a local Ollama already running on the VPS
- Port 3001 free — AnythingLLM uses it by default; verify with
ss -tlnp | grep 3001before launching
Deploy AnythingLLM v1.17.0 with Docker Compose
Create the directory structure and set permissions
Connect via SSH and create the working directory with
mkdir -p /opt/anythingllm/storage. AnythingLLM runs as UID 1000 inside the container; without correcting permissions, the volume refuses writes on the first start. Applychown -R 1000:1000 /opt/anythingllm/storage. If you usedchmod -R 777, it works but unnecessarily broadens access — prefer the targetedchown.Write the docker-compose.yml file
Create
/opt/anythingllm/docker-compose.ymlwith the following content. The service is namedanythingllm, imagemintplexlabs/anythingllm:latest,restart: unless-stopped. Volumes:./storage:/app/server/storage. Ports:3001:3001(close at the firewall, only the reverse proxy accesses it). Environment variables in theenv_file: .envsection. Network: create aproxynetwork shared with your reverse proxy to avoid exposing port 3001 on the public interface.Write the .env file
Create
/opt/anythingllm/.envwith at least these three variables.JWT_SECRET: a random string of at least 32 characters, generated byopenssl rand -hex 32— never change it after the first start, all session tokens are invalidated.STORAGE_DIR:/app/server/storage(must match the volume target path).SERVER_PORT:3001. Then add the variables for your LLM provider, for exampleLLM_PROVIDER=openaiandOPEN_AI_KEY=sk-...for OpenAI, orLLM_PROVIDER=geminiandGEMINI_API_KEY=...for Vertex AI via the Gemini adapter.Start the container and check logs
From
/opt/anythingllm, rundocker compose up -d. Wait 30 seconds then verify the service is listening withdocker compose logs --tail=50. You should see the lineServer started on port 3001. If the log showsEACCES: permission denied, mkdir '/app/server/storage/...', thechownfrom step 1 was not applied to the correct path — redo step 1 thendocker compose restart.Configure the reverse proxy and obtain a TLS certificate
With Nginx, create a vhost that proxies
https://chat.your-domain.comtohttp://127.0.0.1:3001. Addclient_max_body_size 100min theserverblock to allow uploading large PDFs. Request the certificate withcertbot --nginx -d chat.your-domain.com. With Caddy, the directivereverse_proxy localhost:3001is sufficient, TLS is automatic.Create the administrator account on first access
Open
https://chat.your-domain.comin a browser. The interface prompts you to create the first administrator account — this account is the only one that can modify API keys, the LLM provider and system settings. Choose a strong password; AnythingLLM does not offer email-based password reset in self-hosted mode without additional SMTP configuration.Enable multi-user mode and invite a second user
In the Admin interface, go to Settings → Security → enable Multi-user mode. An Invite User button appears in the users menu. Enter the email address, choose the role (Default or Manager), and copy the generated invitation link. The Manager role can manage workspaces and documents; the Default role only accesses workspaces they are assigned to.
Create an isolated workspace and assign it to a user
From the dashboard, click New Workspace and name it (for example
Client Dupont). Drag your PDFs into the workspace, then click Save & Embed to start vectorization. Once embedding is complete, go to the workspace settings → Manage Users and add only the authorized users. Users not assigned cannot see this workspace.Configure Google Vertex AI as the LLM provider
In Settings → LLM Provider, select Google Gemini (which uses the Vertex AI API under the hood via the native adapter available since v1.16.2). Enter your Google API key (
GEMINI_API_KEY) and choose the model. If you prefer GCP service account authentication, exportGOOGLE_APPLICATION_CREDENTIALSto the JSON file path in your.envand restart the container withdocker compose restart.Update without data loss
To upgrade to a newer version, stop the container with
docker compose down, update the image tag indocker-compose.yml(example:mintplexlabs/anythingllm:v1.17.0), then rundocker compose pull && docker compose up -d. Your data is in./storagemounted as a volume: it survives the update. Check the logs after restarting to ensure no schema migration failed.
Pin a specific version tag in your docker-compose.yml rather than using the latest tag. The command docker image ls mintplexlabs/anythingllm shows you the currently downloaded version. This way, an update is only applied when you decide, and you can roll back by changing only the tag and running docker compose up -d again.
Managing workspaces and roles in practice
Once multi-user mode is enabled, the Admin interface exposes three distinct views: Users (list of accounts, roles, active status), Workspaces (global list with document and conversation counts) and Invites (pending invitation links). For an agency managing ten clients, the recommended approach is to create one workspace per client, attach one Manager user per client, and keep collaborators in the Default role with access limited to only the workspaces that concern them. The Manager role cannot view API keys or change the LLM provider: this isolation prevents one client from observing another's configuration. Conversations remain in the workspace — they do not migrate if you move a document between workspaces. Name your workspaces explicitly from the start: renaming a workspace does not change the internal storage paths, but can cause confusion in logs.
Backing up and restoring the instance
The entire state of AnythingLLM fits in the ./storage volume: the LanceDB vector database, document metadata, instance configuration and conversation history. A backup consists of archiving this folder while the container is stopped, or using rsync to a remote storage while the container is running — LanceDB tolerates concurrent reads. For a programmatic backup, add a cron service in your compose that runs tar -czf /backup/anythingllm-$(date +%Y%m%d).tar.gz /opt/anythingllm/storage. Restoration follows the reverse path: copy the archive into ./storage respecting 1000:1000 permissions, then docker compose up -d. The .env contains the JWT_SECRET: back it up separately, encrypted, as losing it invalidates all active sessions and any API tokens.
Troubleshooting: real errors encountered during setup
Here are the five most common documented errors when deploying AnythingLLM v1.17.0 on a VPS, with the exact message and the correction applied. First error: EACCES: permission denied, mkdir '/app/server/storage/vector-cache' at container startup. Cause: the storage folder is owned by root but the container runs as UID 1000. Fix: chown -R 1000:1000 /opt/anythingllm/storage then docker compose restart. Second error: address already in use :::3001 in the logs. Cause: another service is using the port. Fix: ss -tlnp | grep 3001 to identify the conflicting process, then stop it or change SERVER_PORT in .env. Third error: Invalid JWT secret — all sessions invalidated after a restart. Cause: the JWT_SECRET variable was changed. Fix: restore the original value of JWT_SECRET or ask all users to log back in. Fourth error: PDF uploads blocked at 1 MB despite configuration. Cause: client_max_body_size is defined in Nginx's http block but not in the vhost's server block — the most specific wins. Verify with nginx -T | grep client_max_body_size. Fifth error: workspace returns no sourced response after embedding. Cause: the embedding model selected at ingestion differs from the active model. Vectors are incompatible. Fix: remove the documents from the workspace, change the embedding model in the workspace settings, then re-ingest.
AnythingLLM vs self-hosted RAG alternatives
Scroll the table
| Criterion | AnythingLLM v1.17.0 | Open WebUI | LibreChat | PrivateGPT |
|---|---|---|---|---|
| Built-in document RAG | Yes — PDF, Word, URL, Notion, GitHub | Basic import without RAG pipeline | Via RAG plugin (manual config) | Yes — optimized for confidential documents |
| Multi-user mode | Admin / Manager / Default — natively supported, Manager role refined in v1.17.0 | Basic user management | Yes with roles per conversation | No — single-user by default |
| Isolated workspaces per client | Yes — native cloisoning per workspace | No — shared conversations | Limited — per conversation only | No |
| Supported LLM providers | 20+ (Ollama, OpenAI, Vertex AI, Anthropic…) | Ollama + OpenAI-compatible | OpenAI, Azure, Anthropic, Ollama… | Ollama and OpenAI-compatible |
| Meeting diarization | Yes — Nemotron 3 + Parakeet Redux (v1.17.0) | No | No | No |
| Minimum RAM (cloud API) | ~512 MB | ~256 MB | ~384 MB | ~512 MB |
| No-code AI agent builder | Yes | No | No | No |
| License | MIT | MIT | MIT | Apache 2.0 |
Going further with your AI infrastructure
AnythingLLM v1.17.0 covers the multi-client RAG use case on a single VPS. If your corpus exceeds several million vectors, consider offloading the vector database to Qdrant in a neighboring container — AnythingLLM supports it natively from the instance settings. For teams that want to compare interfaces before deciding, the article on Open WebUI, LibreChat and Dify details the selection criteria according to usage profile. If your documents are subject to strict confidentiality requirements (GDPR, medical data, sensitive contracts), the PrivateGPT article explains how to work in fully local mode without any outgoing network call. These three resources are complementary and cover the majority of self-hosted AI architectures encountered in production on a VPS.