[{"data":1,"prerenderedAt":207},["ShallowReactive",2],{"seo-verification":3,"blog-anythingllm-117-multi-user-on-vps-complete-guide-en":6},{"google":4,"bing":5},"EycwPY2XMyTkVzas3n1ygeNJFGAH513qrMjfDljzsMQ","",{"key":7,"data":8},"blog-anythingllm-117-multi-user-on-vps-complete-guide-en",{"id":9,"slug":10,"slugs":11,"title":15,"excerpt":16,"readTime":17,"views":18,"isPinned":19,"publishedAt":20,"updatedAt":21,"category":22,"categories":28,"featuredImage":30,"bgImage":31,"posterImage":32,"relatedSolution":33,"intro":36,"sections":37,"ctaTitle":151,"ctaBody":152,"ctaButton":153,"ctaUrl":154,"relatedPosts":155},417,"anythingllm-117-multi-user-on-vps-complete-guide",{"fr":12,"en":10,"ar":13,"es":14},"anythingllm-1-17-rag-multi-utilisateurs-vps-docker-guide","دليل-anythingllm-117-متعدد-المستخدمين-على-خادم-vps","anythingllm-117-multiusuario-en-vps-guia-completa","AnythingLLM 1.17 multi-user on VPS: complete guide","Set up AnythingLLM v1.17.0 in multi-user mode on a 4 GB RAM VPS: isolated workspaces per client, document RAG, Vertex AI, no SaaS subscription.",10,0,false,"2026-10-06T00:00:00+00:00","2026-10-07T23:07:24+00:00",{"id":23,"name":24,"slug":25,"color":26,"icon":27},1,"Artificial Intelligence","intelligence-artificielle","bg-purple-500\u002F10 text-purple-400","ia",[29],{"id":23,"name":24,"slug":25,"color":26,"icon":27},null,"\u002Fblog\u002Fcovers\u002Fbg.svg","\u002Fblog\u002Fcovers\u002Fanythingllm-1-17-rag-multi-utilisateurs-vps-docker-guide-poster.svg",{"categorySlug":34,"appSlug":35},"artificial-intelligence","anything-llm","AnythingLLM has supported multi-user mode for several versions. v1.17.0 (October 1, 2026) goes further with a dedicated Manager role, meeting diarization with Nemotron 3 and Parakeet Redux, building on the native Google Vertex AI support introduced in v1.16.2 (September 22, 2026). For an agency or developer paying for a ChatGPT Team or Claude for Teams subscription, this combination replicates that model as a self-hosted deployment: isolated workspaces per client, RAG over your own documents, and no data sent to a third party. This guide covers the working Docker Compose configuration, user creation via the Admin interface, and real errors encountered during setup.",[38,42,53,87,90,93,96,99,148],{"type":39,"title":40,"body":41},"h2","What version v1.17.0 changes for agency use","AnythingLLM has supported multi-user mode for several versions. v1.17.0 (October 1, 2026) refines this system by introducing a third role — Manager — who can create workspaces, invite users and manage documents without accessing system settings such as API keys or LLM configuration. For an agency, this role allows delegating the administration of a client to a project manager without exposing the entire infrastructure. Meeting diarization now relies on Nemotron 3 for speaker recognition and Parakeet Redux for transcription — two models that can run locally on a GPU-equipped VPS, or be delegated to an Nvidia API. Google Vertex AI was already available since v1.16.2 (September 22, 2026) as an LLM provider configurable directly from the interface, without manually patching the configuration file. These recent additions make the v1.16.2 + v1.17.0 combination the most complete configuration for structured multi-client use.",{"type":43,"title":44,"items":45},"ul","Prerequisites before starting",[46,47,48,49,50,51,52],"**VPS with at least 4 GB RAM** — 2 vCPU \u002F 4 GB for cloud APIs, 4 vCPU \u002F 8 GB if you embed a local embedding model or Parakeet Redux","**20 GB of SSD disk** — LanceDB vectors and the document cache grow with the corpus; leave room to expand","**Docker and Docker Compose v2** — verify with `docker compose version` (no hyphen); v1 (with hyphen) does not support all healthchecks","**A dedicated subdomain** — for example `chat.your-domain.com`; port 3001 must not be directly exposed publicly","**An active reverse proxy** — Nginx or Caddy for Let's Encrypt TLS and document upload size limits","**An LLM API key** — OpenAI, Anthropic, Vertex AI, or a local Ollama already running on the VPS","**Port 3001 free** — AnythingLLM uses it by default; verify with `ss -tlnp | grep 3001` before launching",{"type":54,"title":55,"steps":56},"steps","Deploy AnythingLLM v1.17.0 with Docker Compose",[57,60,63,66,69,72,75,78,81,84],{"title":58,"body":59},"Create the directory structure and set permissions","Connect via SSH and create the working directory with `mkdir -p \u002Fopt\u002Fanythingllm\u002Fstorage`. AnythingLLM runs as UID 1000 inside the container; without correcting permissions, the volume refuses writes on the first start. Apply `chown -R 1000:1000 \u002Fopt\u002Fanythingllm\u002Fstorage`. If you used `chmod -R 777`, it works but unnecessarily broadens access — prefer the targeted `chown`.",{"title":61,"body":62},"Write the docker-compose.yml file","Create `\u002Fopt\u002Fanythingllm\u002Fdocker-compose.yml` with the following content. The service is named `anythingllm`, image `mintplexlabs\u002Fanythingllm:latest`, `restart: unless-stopped`. Volumes: `.\u002Fstorage:\u002Fapp\u002Fserver\u002Fstorage`. Ports: `3001:3001` (close at the firewall, only the reverse proxy accesses it). Environment variables in the `env_file: .env` section. Network: create a `proxy` network shared with your reverse proxy to avoid exposing port 3001 on the public interface.",{"title":64,"body":65},"Write the .env file","Create `\u002Fopt\u002Fanythingllm\u002F.env` with at least these three variables. `JWT_SECRET`: a random string of at least 32 characters, generated by `openssl rand -hex 32` — never change it after the first start, all session tokens are invalidated. `STORAGE_DIR`: `\u002Fapp\u002Fserver\u002Fstorage` (must match the volume target path). `SERVER_PORT`: `3001`. Then add the variables for your LLM provider, for example `LLM_PROVIDER=openai` and `OPEN_AI_KEY=sk-...` for OpenAI, or `LLM_PROVIDER=gemini` and `GEMINI_API_KEY=...` for Vertex AI via the Gemini adapter.",{"title":67,"body":68},"Start the container and check logs","From `\u002Fopt\u002Fanythingllm`, run `docker compose up -d`. Wait 30 seconds then verify the service is listening with `docker compose logs --tail=50`. You should see the line `Server started on port 3001`. If the log shows `EACCES: permission denied, mkdir '\u002Fapp\u002Fserver\u002Fstorage\u002F...'`, the `chown` from step 1 was not applied to the correct path — redo step 1 then `docker compose restart`.",{"title":70,"body":71},"Configure the reverse proxy and obtain a TLS certificate","With Nginx, create a vhost that proxies `https:\u002F\u002Fchat.your-domain.com` to `http:\u002F\u002F127.0.0.1:3001`. Add `client_max_body_size 100m` in the `server` block to allow uploading large PDFs. Request the certificate with `certbot --nginx -d chat.your-domain.com`. With Caddy, the directive `reverse_proxy localhost:3001` is sufficient, TLS is automatic.",{"title":73,"body":74},"Create the administrator account on first access","Open `https:\u002F\u002Fchat.your-domain.com` in a browser. The interface prompts you to create the first administrator account — this account is the only one that can modify API keys, the LLM provider and system settings. Choose a strong password; AnythingLLM does not offer email-based password reset in self-hosted mode without additional SMTP configuration.",{"title":76,"body":77},"Enable multi-user mode and invite a second user","In the Admin interface, go to Settings → Security → enable Multi-user mode. An Invite User button appears in the users menu. Enter the email address, choose the role (Default or Manager), and copy the generated invitation link. The Manager role can manage workspaces and documents; the Default role only accesses workspaces they are assigned to.",{"title":79,"body":80},"Create an isolated workspace and assign it to a user","From the dashboard, click New Workspace and name it (for example `Client Dupont`). Drag your PDFs into the workspace, then click Save & Embed to start vectorization. Once embedding is complete, go to the workspace settings → Manage Users and add only the authorized users. Users not assigned cannot see this workspace.",{"title":82,"body":83},"Configure Google Vertex AI as the LLM provider","In Settings → LLM Provider, select Google Gemini (which uses the Vertex AI API under the hood via the native adapter available since v1.16.2). Enter your Google API key (`GEMINI_API_KEY`) and choose the model. If you prefer GCP service account authentication, export `GOOGLE_APPLICATION_CREDENTIALS` to the JSON file path in your `.env` and restart the container with `docker compose restart`.",{"title":85,"body":86},"Update without data loss","To upgrade to a newer version, stop the container with `docker compose down`, update the image tag in `docker-compose.yml` (example: `mintplexlabs\u002Fanythingllm:v1.17.0`), then run `docker compose pull && docker compose up -d`. Your data is in `.\u002Fstorage` mounted as a volume: it survives the update. Check the logs after restarting to ensure no schema migration failed.",{"type":88,"body":89},"tip","Pin a specific version tag in your `docker-compose.yml` rather than using the `latest` tag. The command `docker image ls mintplexlabs\u002Fanythingllm` shows you the currently downloaded version. This way, an update is only applied when you decide, and you can roll back by changing only the tag and running `docker compose up -d` again.",{"type":39,"title":91,"body":92},"Managing workspaces and roles in practice","Once multi-user mode is enabled, the Admin interface exposes three distinct views: Users (list of accounts, roles, active status), Workspaces (global list with document and conversation counts) and Invites (pending invitation links). For an agency managing ten clients, the recommended approach is to create one workspace per client, attach one Manager user per client, and keep collaborators in the Default role with access limited to only the workspaces that concern them. The Manager role cannot view API keys or change the LLM provider: this isolation prevents one client from observing another's configuration. Conversations remain in the workspace — they do not migrate if you move a document between workspaces. Name your workspaces explicitly from the start: renaming a workspace does not change the internal storage paths, but can cause confusion in logs.",{"type":39,"title":94,"body":95},"Backing up and restoring the instance","The entire state of AnythingLLM fits in the `.\u002Fstorage` volume: the LanceDB vector database, document metadata, instance configuration and conversation history. A backup consists of archiving this folder while the container is stopped, or using `rsync` to a remote storage while the container is running — LanceDB tolerates concurrent reads. For a programmatic backup, add a `cron` service in your compose that runs `tar -czf \u002Fbackup\u002Fanythingllm-$(date +%Y%m%d).tar.gz \u002Fopt\u002Fanythingllm\u002Fstorage`. Restoration follows the reverse path: copy the archive into `.\u002Fstorage` respecting `1000:1000` permissions, then `docker compose up -d`. The `.env` contains the `JWT_SECRET`: back it up separately, encrypted, as losing it invalidates all active sessions and any API tokens.",{"type":39,"title":97,"body":98},"Troubleshooting: real errors encountered during setup","Here are the five most common documented errors when deploying AnythingLLM v1.17.0 on a VPS, with the exact message and the correction applied. First error: `EACCES: permission denied, mkdir '\u002Fapp\u002Fserver\u002Fstorage\u002Fvector-cache'` at container startup. Cause: the `storage` folder is owned by root but the container runs as UID 1000. Fix: `chown -R 1000:1000 \u002Fopt\u002Fanythingllm\u002Fstorage` then `docker compose restart`. Second error: `address already in use :::3001` in the logs. Cause: another service is using the port. Fix: `ss -tlnp | grep 3001` to identify the conflicting process, then stop it or change `SERVER_PORT` in `.env`. Third error: `Invalid JWT secret — all sessions invalidated` after a restart. Cause: the `JWT_SECRET` variable was changed. Fix: restore the original value of `JWT_SECRET` or ask all users to log back in. Fourth error: PDF uploads blocked at 1 MB despite configuration. Cause: `client_max_body_size` is defined in Nginx's `http` block but not in the vhost's `server` block — the most specific wins. Verify with `nginx -T | grep client_max_body_size`. Fifth error: workspace returns no sourced response after embedding. Cause: the embedding model selected at ingestion differs from the active model. Vectors are incompatible. Fix: remove the documents from the workspace, change the embedding model in the workspace settings, then re-ingest.",{"type":100,"title":101,"headers":102,"rows":108},"comparison","AnythingLLM vs self-hosted RAG alternatives",[103,104,105,106,107],"Criterion","AnythingLLM v1.17.0","Open WebUI","LibreChat","PrivateGPT",[109,115,121,127,133,136,141,144],[110,111,112,113,114],"Built-in document RAG","Yes — PDF, Word, URL, Notion, GitHub","Basic import without RAG pipeline","Via RAG plugin (manual config)","Yes — optimized for confidential documents",[116,117,118,119,120],"Multi-user mode","Admin \u002F Manager \u002F Default — natively supported, Manager role refined in v1.17.0","Basic user management","Yes with roles per conversation","No — single-user by default",[122,123,124,125,126],"Isolated workspaces per client","Yes — native cloisoning per workspace","No — shared conversations","Limited — per conversation only","No",[128,129,130,131,132],"Supported LLM providers","20+ (Ollama, OpenAI, Vertex AI, Anthropic…)","Ollama + OpenAI-compatible","OpenAI, Azure, Anthropic, Ollama…","Ollama and OpenAI-compatible",[134,135,126,126,126],"Meeting diarization","Yes — Nemotron 3 + Parakeet Redux (v1.17.0)",[137,138,139,140,138],"Minimum RAM (cloud API)","~512 MB","~256 MB","~384 MB",[142,143,126,126,126],"No-code AI agent builder","Yes",[145,146,146,146,147],"License","MIT","Apache 2.0",{"type":39,"title":149,"body":150},"Going further with your AI infrastructure","AnythingLLM v1.17.0 covers the multi-client RAG use case on a single VPS. If your corpus exceeds several million vectors, consider offloading the vector database to Qdrant in a neighboring container — AnythingLLM supports it natively from the instance settings. For teams that want to compare interfaces before deciding, the article on Open WebUI, LibreChat and Dify details the selection criteria according to usage profile. If your documents are subject to strict confidentiality requirements (GDPR, medical data, sensitive contracts), the PrivateGPT article explains how to work in fully local mode without any outgoing network call. These three resources are complementary and cover the majority of self-hosted AI architectures encountered in production on a VPS.","Your AnythingLLM environment ready in minutes","The AnythingLLM VPS template in the ServOrbit catalogue pre-configures the Docker environment, volumes and permissions at startup — you arrive directly at the administrator account creation step.","Activate this solution","\u002Fmarketplace\u002Fartificial-intelligence\u002Fanything-llm",[156,173,189],{"id":157,"slug":158,"slugs":159,"title":163,"excerpt":164,"readTime":165,"views":18,"isPinned":19,"publishedAt":166,"updatedAt":167,"category":168,"categories":169,"featuredImage":30,"bgImage":31,"posterImage":171,"relatedSolution":172},9,"how-to-host-anythingllm-on-a-vps",{"fr":160,"en":158,"ar":161,"es":162},"heberger-anythingllm-vps","كيفية-استضافة-anythingllm-على-خادم-vps","como-alojar-anythingllm-en-un-vps","AnythingLLM on VPS: Full Guide with Pitfalls to Avoid","Host AnythingLLM on VPS: Docker, HTTPS, mandatory version pinning. :latest, Gemini v1.16 and Ollama Docker network pitfalls documented.",8,"2026-06-11T00:00:00+00:00","2026-09-07T11:26:10+00:00",{"id":23,"name":24,"slug":25,"color":26,"icon":27},[170],{"id":23,"name":24,"slug":25,"color":26,"icon":27},"\u002Fblog\u002Fcovers\u002Fheberger-anythingllm-vps-poster.svg",{"categorySlug":34,"appSlug":35},{"id":174,"slug":175,"slugs":176,"title":180,"excerpt":181,"readTime":17,"views":23,"isPinned":19,"publishedAt":182,"updatedAt":167,"category":183,"categories":184,"featuredImage":30,"bgImage":31,"posterImage":186,"relatedSolution":187},329,"open-webui-librechat-dify-which-one-to-choose-on-a-vps",{"fr":177,"en":175,"ar":178,"es":179},"open-webui-vs-librechat-vs-dify-choisir-interface-ia-vps","open-webui-أو-librechat-أو-dify-أيها-تختار-على-vps","open-webui-librechat-dify-cual-elegir-en-un-vps","Open WebUI, LibreChat, Dify: which one to choose on a VPS?","Open WebUI, LibreChat or Dify: three open-source AI interfaces, three usage profiles. Three questions to choose in under five minutes.","2026-09-04T00:00:00+00:00",{"id":23,"name":24,"slug":25,"color":26,"icon":27},[185],{"id":23,"name":24,"slug":25,"color":26,"icon":27},"\u002Fblog\u002Fcovers\u002Fopen-webui-vs-librechat-vs-dify-choisir-interface-ia-vps-poster.svg",{"categorySlug":34,"appSlug":188},"open-webui",{"id":190,"slug":191,"slugs":192,"title":196,"excerpt":197,"readTime":198,"views":18,"isPinned":19,"publishedAt":199,"updatedAt":200,"category":201,"categories":202,"featuredImage":30,"bgImage":31,"posterImage":204,"relatedSolution":205},281,"privategpt-on-a-vps-analyze-confidential-documents-locally",{"fr":193,"en":191,"ar":194,"es":195},"privategpt-documents-confidentiels-vps","تشغيل-privategpt-على-vps-تحليل-المستندات-السرية-محليا","privategpt-en-vps-documentos-confidenciales","PrivateGPT on a VPS: analyze confidential documents locally","Deploy PrivateGPT on a VPS to analyze contracts, financial reports and HR files with no data leaving your server. GDPR and AI Act article 50 compliant.",7,"2026-08-18T00:00:00+00:00","2026-09-23T15:23:17+00:00",{"id":23,"name":24,"slug":25,"color":26,"icon":27},[203],{"id":23,"name":24,"slug":25,"color":26,"icon":27},"\u002Fblog\u002Fcovers\u002Fprivategpt-documents-confidentiels-vps-poster.svg",{"categorySlug":34,"appSlug":206},"private-gpt",1791414789777]