What AppFlowy's AGPL repository archiving actually changes
AppFlowy had two distinct parts: the client application (Flutter + Rust, still active) and AppFlowy-Cloud, the multi-user collaboration server. It is this second repository — AppFlowy-IO/AppFlowy-Cloud — that was archived on September 11, 2026 by the organization.
The organization now directs users to AppFlowy-SelfHost-Commercial: a repository whose codebase is proprietary. You can still deploy AppFlowy as a server, but no longer under a free license. This is not a license change on the same code: it is a closed commercial fork that replaces the public repository.
For teams that cited the AGPL license as a deployment condition — compliance requirements, IT policy, client contracts — that argument disappears overnight. And for those who chose AppFlowy specifically because an organization shutting down would not leave users stranded, the irony is real: the piece that manages team collaboration is no longer auditable.
What stays the same — and what actually changes
- The AppFlowy client application remains open source (AGPL-3.0) and receives regular updates — v0.14.8 released October 8, 2026.
- In solo or local mode, AppFlowy still works: archiving does not disable anything on the client side.
- The multi-user server is no longer under a free license: no third-party security audit can cover the commercial codebase.
- Security patches for the server side will not be released as open source. A CVE on the server can no longer be independently verified.
- The community that maintained forks and plugins around AppFlowy-Cloud has lost its base: a fork of the last AGPL commit exists, but receives no downstream patches.
- The forced migration to the commercial server introduces a vendor dependency that AGPL was precisely designed to avoid.
Docmost: what AGPL still covers in 2026
Docmost is a collaborative knowledge base published under AGPL-3.0 on github.com/docmost/docmost. Its distribution model resembles what AppFlowy once promised: a fully free core, with opt-in commercial extensions for large organizations.
The Open Source edition covers the essentials: hierarchical spaces and pages, real-time collaborative editing, comments, version history, granular space permissions, and RTL support (added in v0.96.0 — September 2026). No member caps, no features locked behind a paywall in the base edition.
Business and Enterprise editions add audit, DOCX export, and governance features for teams that need them — but they layer on top of an Open Source base that remains complete. The AGPL-3.0 license on the core requires any network service operator who modifies the code to publish those modifications: this is the guarantee that the server code handling your documents remains auditable.
AppFlowy-Cloud AGPL vs Docmost — status as of October 9, 2026
Scroll the table
| Criterion | AppFlowy-Cloud (AGPL) | Docmost |
|---|---|---|
| Server license | AGPL-3.0 → archived Sept. 2026 | AGPL-3.0 active |
| Server repository | Archived (read-only) | Active, v0.96.0 (Sept. 2026) |
| Server security patches | No more public patches | Published on GitHub |
| Real-time collaboration | Yes (client) | Yes (server + client) |
| Browser-based editing | Yes | Yes |
| Space permissions | Limited in AGPL | Included in free edition |
| Version history | Yes | Yes |
| RTL support (Arabic) | Partial | Full since v0.96.0 |
| Docker self-hosting | AppFlowy-SelfHost-Commercial (proprietary) | Official Docker Compose |
Why an active client repository does not offset server archiving
A common argument in discussion threads: the main AppFlowy-IO/AppFlowy repository — the desktop and mobile application — is still active. That is true. But this argument conflates the client layer and the server layer.
In a team deployment, the server handles authentication, data synchronization, permissions, and page storage. It is the component that receives your documents. It is the component that enforces access rules. The client application, however open source, does not change the nature of the component it communicates with.
Staying on the last AGPL commit of AppFlowy-Cloud means: no future security fixes, progressive incompatibilities with the client (which keeps evolving), and an unmaintained codebase. This is the definition of short-horizon technical debt.
What the AGPL license says about this case
AGPL-3.0 requires that a network service that modifies the source code distribute its modifications. It does not require a publisher to continue developing an open source project. A publisher can archive a repository and move to a commercial model: that is legal. What AGPL guarantees is that already-distributed code remains redistributable. What it does not guarantee is that this code will receive security patches. Hence the long-term importance of an active community around the repository — or a project whose publisher has a commercial interest in maintaining the open source core.
Migrating from AppFlowy to Docmost: what to plan for
AppFlowy and Docmost do not share a native common export format. The cleanest migration goes through Markdown export from AppFlowy (available from the client interface) and import into Docmost. Images and file attachments require separate handling.
Docmost handles Markdown file imports and hierarchical page structures. For large volumes, bulk import via the API is the most reliable path.
Four things to check before switching: the structure of your AppFlowy spaces (one space = one Docmost space), third-party integrations connected to AppFlowy-Cloud (webhooks, automation scripts), group-based permissions, and users without a verified email who will not pass Docmost's standard invitation flow.
Prerequisites for hosting Docmost on a VPS
- Minimum 2 vCPU and 4 GB RAM — sufficient for a team of 20 to 50 members.
- Docker and Docker Compose installed on the server.
- A domain name with a valid TLS certificate — Docmost does not serve plain HTTP traffic.
- A reverse proxy (nginx or Caddy) to terminate TLS and route to the Docmost container.
- A persistent volume for the PostgreSQL database and attached file storage.
- An SMTP server or transactional email relay for team invitations.
Deploy Docmost on a VPS in 5 steps
Prepare the server
Connect to your VPS via SSH. Install Docker and Docker Compose:
curl -fsSL https://get.docker.com | sh apt install -y docker-compose-pluginVerify that ports 80 and 443 are open in your firewall.
Fetch the official configuration
Clone the repository or download the
docker-compose.ymldirectly from thedocmost/docmostrepository:mkdir -p /opt/docmost && cd /opt/docmost curl -O https://raw.githubusercontent.com/docmost/docmost/main/docker-compose.yml curl -O https://raw.githubusercontent.com/docmost/docmost/main/.env.example cp .env.example .envConfigure environment variables
Edit
.envand set at minimum:-
APP_URL: your domain (https://wiki.your-domain.com)
-APP_SECRET: a long random string (generate withopenssl rand -hex 32)
-DATABASE_URL: keep the default value if using the Compose PostgreSQL
-SMTP_HOST,SMTP_PORT,SMTP_USERNAME,SMTP_PASSWORD: your email relayStart the containers
docker compose up -dDocmost starts with PostgreSQL and Redis. Verify all three containers are
Up:docker compose psThe first access through your domain triggers the admin account creation wizard.
Configure TLS reverse proxy
Point your domain to the VPS IP. With nginx, add a vhost that proxies to Docmost's internal port (default
3000) and terminate TLS with Let's Encrypt:apt install -y certbot python3-certbot-nginx certbot --nginx -d wiki.your-domain.comRestart nginx. Docmost is now accessible over HTTPS.
Notion / Docmost / AppFlowy — what you actually pay
Scroll the table
| Tool | Server cost (team of 20) | Server code license | Security updates |
|---|---|---|---|
| Notion Business | $400/month (AI included) | Proprietary SaaS | Notion's responsibility |
| AppFlowy + commercial server | Infrastructure + publisher license | Proprietary (since Sept. 2026) | Publisher's responsibility |
| Docmost Open Source | VPS cost only | AGPL-3.0 | Published on GitHub, auditable |
| Docmost Business | VPS cost + Business license | AGPL-3.0 (core) | Published on GitHub, auditable |
What AppFlowy's archiving says about the open-core model
AppFlowy is not the first project to take this step. The pattern is documented: a tool starts under a permissive or copyleft license, gains popularity, raises funding, and progressively reserves the server code. What this archiving illustrates is the limit of the open-core model when the commercial core is the server.
The distinction that matters for a technical lead: a project whose publisher draws revenue from the server license has a direct interest in making that server difficult to replace. A project whose publisher draws revenue from Enterprise editions — built on a stable open source core — has an interest in keeping that core in good shape. This is the tension AGPL attempts to reduce: by requiring publication of modifications, it makes the core harder to close.
Docmost follows the second model. Its AGPL core is the foundation on which teams choosing to self-host place their trust. Removing that foundation would destroy the value proposition the project sells to its Business and Enterprise customers.
Checking the health of an open source project before migrating
Before migrating a team knowledge base to a self-hosted tool, three signals to check: commit frequency on the server repository (not just the client), the CVE disclosure policy, and the publisher's business model. A project with no revenue or whose revenue comes exclusively from SaaS has little incentive to maintain the self-hosted version. A project whose paying customers self-host has a strong incentive.
Docmost in production: things to know
Docmost has been stable in production since late 2025. A few things to know before a team deployment.
Backups: data lives in PostgreSQL and in the file storage volume. An automated daily backup of both is sufficient. pg_dump scheduled via cron, and rsync or an S3 snapshot for attachments.
Updates: Docmost publishes regular releases — approximately one per month in 2026. The procedure is a docker compose pull followed by docker compose up -d. Schema migrations are applied at startup. Read release notes before updating: some versions introduce non-reversible migrations.
SSO authentication: Docmost supports SAML 2.0 and OIDC in Business and Enterprise editions. The Open Source edition handles email-based authentication and invitations. For teams with an LDAP/AD directory, the Business edition is required.
Performance: on 2 vCPU / 4 GB RAM, Docmost comfortably handles 20 to 50 simultaneously active members. Beyond 100 members with heavily used spaces, plan for 4 vCPU / 8 GB and a dedicated PostgreSQL node.
Why host Docmost on a dedicated VPS rather than shared hosting
- Docmost requires Docker: shared hosting does not offer it.
- PostgreSQL must be accessible from the container: most shared plans do not provide access to a local PostgreSQL instance.
- Persistent volumes for attached files must survive restarts: a VPS with NVMe storage provides this guarantee.
- Root access is required to configure the TLS reverse proxy and firewall rules.
- Vertical scalability of a VPS — adding RAM or CPU without migration — covers team growth without infrastructure overhaul.