Deployment guide

AppFlowy AGPL archived: Docmost, the only Notion alternative left

Deploy on a VPS Cloud →

AppFlowy AGPL archived: Docmost, the only Notion alternative left

Comparison10 min read5 steps

In September 2026, AppFlowy-IO archived its AppFlowy-Cloud repository under AGPL. The multi-user server is no longer distributed as open source — it has moved to a proprietary commercial codebase. For teams that self-hosted AppFlowy to keep control of their data, this is a structural shift. One tool remains — Docmost — whose core is published under AGPL-3.0 and is actively maintained. This article explains what changed, what it means in practice, and how to move to a solid foundation.

Contents· What AppFlowy's AGPL repository archiving actually changes1/14
  1. 01What AppFlowy's AGPL repository archiving actually changes
  2. 02What stays the same — and what actually changes
  3. 03Docmost: what AGPL still covers in 2026
  4. 04AppFlowy-Cloud AGPL vs Docmost — status as of October 9, 2026
  5. 05Why an active client repository does not offset server archiving
  6. 06What the AGPL license says about this case
  7. 07Migrating from AppFlowy to Docmost: what to plan for
  8. 08Prerequisites for hosting Docmost on a VPS
  9. 09Deploy Docmost on a VPS in 5 steps
  10. 10Notion / Docmost / AppFlowy — what you actually pay
  11. 11What AppFlowy's archiving says about the open-core model
  12. 12Checking the health of an open source project before migrating
  13. 13Docmost in production: things to know
  14. 14Why host Docmost on a dedicated VPS rather than shared hosting

What AppFlowy's AGPL repository archiving actually changes

AppFlowy had two distinct parts: the client application (Flutter + Rust, still active) and AppFlowy-Cloud, the multi-user collaboration server. It is this second repository — AppFlowy-IO/AppFlowy-Cloud — that was archived on September 11, 2026 by the organization.

The organization now directs users to AppFlowy-SelfHost-Commercial: a repository whose codebase is proprietary. You can still deploy AppFlowy as a server, but no longer under a free license. This is not a license change on the same code: it is a closed commercial fork that replaces the public repository.

For teams that cited the AGPL license as a deployment condition — compliance requirements, IT policy, client contracts — that argument disappears overnight. And for those who chose AppFlowy specifically because an organization shutting down would not leave users stranded, the irony is real: the piece that manages team collaboration is no longer auditable.

What stays the same — and what actually changes

  • The AppFlowy client application remains open source (AGPL-3.0) and receives regular updates — v0.14.8 released October 8, 2026.
  • In solo or local mode, AppFlowy still works: archiving does not disable anything on the client side.
  • The multi-user server is no longer under a free license: no third-party security audit can cover the commercial codebase.
  • Security patches for the server side will not be released as open source. A CVE on the server can no longer be independently verified.
  • The community that maintained forks and plugins around AppFlowy-Cloud has lost its base: a fork of the last AGPL commit exists, but receives no downstream patches.
  • The forced migration to the commercial server introduces a vendor dependency that AGPL was precisely designed to avoid.

Docmost: what AGPL still covers in 2026

Docmost is a collaborative knowledge base published under AGPL-3.0 on github.com/docmost/docmost. Its distribution model resembles what AppFlowy once promised: a fully free core, with opt-in commercial extensions for large organizations.

The Open Source edition covers the essentials: hierarchical spaces and pages, real-time collaborative editing, comments, version history, granular space permissions, and RTL support (added in v0.96.0 — September 2026). No member caps, no features locked behind a paywall in the base edition.

Business and Enterprise editions add audit, DOCX export, and governance features for teams that need them — but they layer on top of an Open Source base that remains complete. The AGPL-3.0 license on the core requires any network service operator who modifies the code to publish those modifications: this is the guarantee that the server code handling your documents remains auditable.

AppFlowy-Cloud AGPL vs Docmost — status as of October 9, 2026

Scroll the table

CriterionAppFlowy-Cloud (AGPL)Docmost
Server licenseAGPL-3.0 → archived Sept. 2026AGPL-3.0 active
Server repositoryArchived (read-only)Active, v0.96.0 (Sept. 2026)
Server security patchesNo more public patchesPublished on GitHub
Real-time collaborationYes (client)Yes (server + client)
Browser-based editingYesYes
Space permissionsLimited in AGPLIncluded in free edition
Version historyYesYes
RTL support (Arabic)PartialFull since v0.96.0
Docker self-hostingAppFlowy-SelfHost-Commercial (proprietary)Official Docker Compose

Why an active client repository does not offset server archiving

A common argument in discussion threads: the main AppFlowy-IO/AppFlowy repository — the desktop and mobile application — is still active. That is true. But this argument conflates the client layer and the server layer.

In a team deployment, the server handles authentication, data synchronization, permissions, and page storage. It is the component that receives your documents. It is the component that enforces access rules. The client application, however open source, does not change the nature of the component it communicates with.

Staying on the last AGPL commit of AppFlowy-Cloud means: no future security fixes, progressive incompatibilities with the client (which keeps evolving), and an unmaintained codebase. This is the definition of short-horizon technical debt.

What the AGPL license says about this case

AGPL-3.0 requires that a network service that modifies the source code distribute its modifications. It does not require a publisher to continue developing an open source project. A publisher can archive a repository and move to a commercial model: that is legal. What AGPL guarantees is that already-distributed code remains redistributable. What it does not guarantee is that this code will receive security patches. Hence the long-term importance of an active community around the repository — or a project whose publisher has a commercial interest in maintaining the open source core.

Migrating from AppFlowy to Docmost: what to plan for

AppFlowy and Docmost do not share a native common export format. The cleanest migration goes through Markdown export from AppFlowy (available from the client interface) and import into Docmost. Images and file attachments require separate handling.

Docmost handles Markdown file imports and hierarchical page structures. For large volumes, bulk import via the API is the most reliable path.

Four things to check before switching: the structure of your AppFlowy spaces (one space = one Docmost space), third-party integrations connected to AppFlowy-Cloud (webhooks, automation scripts), group-based permissions, and users without a verified email who will not pass Docmost's standard invitation flow.

Prerequisites for hosting Docmost on a VPS

  • Minimum 2 vCPU and 4 GB RAM — sufficient for a team of 20 to 50 members.
  • Docker and Docker Compose installed on the server.
  • A domain name with a valid TLS certificate — Docmost does not serve plain HTTP traffic.
  • A reverse proxy (nginx or Caddy) to terminate TLS and route to the Docmost container.
  • A persistent volume for the PostgreSQL database and attached file storage.
  • An SMTP server or transactional email relay for team invitations.

Deploy Docmost on a VPS in 5 steps

  1. Prepare the server

    Connect to your VPS via SSH. Install Docker and Docker Compose:

    curl -fsSL https://get.docker.com | sh
    apt install -y docker-compose-plugin

    Verify that ports 80 and 443 are open in your firewall.

  2. Fetch the official configuration

    Clone the repository or download the docker-compose.yml directly from the docmost/docmost repository:

    mkdir -p /opt/docmost && cd /opt/docmost
    curl -O https://raw.githubusercontent.com/docmost/docmost/main/docker-compose.yml
    curl -O https://raw.githubusercontent.com/docmost/docmost/main/.env.example
    cp .env.example .env
  3. Configure environment variables

    Edit .env and set at minimum:

    - APP_URL: your domain (https://wiki.your-domain.com)
    - APP_SECRET: a long random string (generate with openssl rand -hex 32)
    - DATABASE_URL: keep the default value if using the Compose PostgreSQL
    - SMTP_HOST, SMTP_PORT, SMTP_USERNAME, SMTP_PASSWORD: your email relay

  4. Start the containers

    docker compose up -d

    Docmost starts with PostgreSQL and Redis. Verify all three containers are Up:

    docker compose ps

    The first access through your domain triggers the admin account creation wizard.

  5. Configure TLS reverse proxy

    Point your domain to the VPS IP. With nginx, add a vhost that proxies to Docmost's internal port (default 3000) and terminate TLS with Let's Encrypt:

    apt install -y certbot python3-certbot-nginx
    certbot --nginx -d wiki.your-domain.com

    Restart nginx. Docmost is now accessible over HTTPS.

Notion / Docmost / AppFlowy — what you actually pay

Scroll the table

ToolServer cost (team of 20)Server code licenseSecurity updates
Notion Business$400/month (AI included)Proprietary SaaSNotion's responsibility
AppFlowy + commercial serverInfrastructure + publisher licenseProprietary (since Sept. 2026)Publisher's responsibility
Docmost Open SourceVPS cost onlyAGPL-3.0Published on GitHub, auditable
Docmost BusinessVPS cost + Business licenseAGPL-3.0 (core)Published on GitHub, auditable

What AppFlowy's archiving says about the open-core model

AppFlowy is not the first project to take this step. The pattern is documented: a tool starts under a permissive or copyleft license, gains popularity, raises funding, and progressively reserves the server code. What this archiving illustrates is the limit of the open-core model when the commercial core is the server.

The distinction that matters for a technical lead: a project whose publisher draws revenue from the server license has a direct interest in making that server difficult to replace. A project whose publisher draws revenue from Enterprise editions — built on a stable open source core — has an interest in keeping that core in good shape. This is the tension AGPL attempts to reduce: by requiring publication of modifications, it makes the core harder to close.

Docmost follows the second model. Its AGPL core is the foundation on which teams choosing to self-host place their trust. Removing that foundation would destroy the value proposition the project sells to its Business and Enterprise customers.

Checking the health of an open source project before migrating

Before migrating a team knowledge base to a self-hosted tool, three signals to check: commit frequency on the server repository (not just the client), the CVE disclosure policy, and the publisher's business model. A project with no revenue or whose revenue comes exclusively from SaaS has little incentive to maintain the self-hosted version. A project whose paying customers self-host has a strong incentive.

Docmost in production: things to know

Docmost has been stable in production since late 2025. A few things to know before a team deployment.

Backups: data lives in PostgreSQL and in the file storage volume. An automated daily backup of both is sufficient. pg_dump scheduled via cron, and rsync or an S3 snapshot for attachments.

Updates: Docmost publishes regular releases — approximately one per month in 2026. The procedure is a docker compose pull followed by docker compose up -d. Schema migrations are applied at startup. Read release notes before updating: some versions introduce non-reversible migrations.

SSO authentication: Docmost supports SAML 2.0 and OIDC in Business and Enterprise editions. The Open Source edition handles email-based authentication and invitations. For teams with an LDAP/AD directory, the Business edition is required.

Performance: on 2 vCPU / 4 GB RAM, Docmost comfortably handles 20 to 50 simultaneously active members. Beyond 100 members with heavily used spaces, plan for 4 vCPU / 8 GB and a dedicated PostgreSQL node.

Why host Docmost on a dedicated VPS rather than shared hosting

  • Docmost requires Docker: shared hosting does not offer it.
  • PostgreSQL must be accessible from the container: most shared plans do not provide access to a local PostgreSQL instance.
  • Persistent volumes for attached files must survive restarts: a VPS with NVMe storage provides this guarantee.
  • Root access is required to configure the TLS reverse proxy and firewall rules.
  • Vertical scalability of a VPS — adding RAM or CPU without migration — covers team growth without infrastructure overhaul.

Your Docmost workspace on a ServOrbit VPS

Docmost runs on 2 vCPU / 4 GB RAM — a VPS Start is enough for a team of 20 to 50 members. Root access, pre-installed Docker, dedicated IPv4, European data centers.

Need help?

Browse our help center and FAQ, or reach our team — callback, WhatsApp or email. Support in French, English and Arabic.

Message us on WhatsAppopens in a new tab