Deployment guide

Penpot: the self-hosted Figma alternative for web agencies

Deploy on a VPS Cloud →

Tutorial

Penpot: the self-hosted Figma alternative for web agencies

Self-hosting9 min read8 steps

In early 2025, Figma revised its pricing upward — around 30% depending on the plan. For an agency managing ten clients with five designers, the annual bill quickly exceeds two thousand dollars. Penpot v2, an open-source collaborative design tool built on web standards (SVG, CSS), offers a serious alternative: self-hosted on your own VPS, it gives you full control over data, access, and costs. This guide is aimed at agencies managing five to fifteen clients who want to move away from Figma without sacrificing design quality or collaboration fluidity.

Contents· Why reconsider Figma in 20251/8
  1. 01Why reconsider Figma in 2025
  2. 02Penpot v2 vs Figma — parity and honest limits
  3. 03Technical prerequisites before installation
  4. 04Installing Penpot with Docker Compose
  5. 05Multi-client management: workspaces and permissions
  6. 06Troubleshooting common errors
  7. 07Migrating from Figma: SVG export and design tokens
  8. 08Self-hosted Penpot: sovereignty and cost control for your agency

Why reconsider Figma in 2025

The failed Adobe acquisition did not make Figma less ambitious on pricing. In 2025, the Professional plan rose to $15 per seat per month, and the Organization plan to $45 per seat. For a team of five designers, that means $900 and $2,700 per year respectively — before counting FigJam licenses or paid plugins. For an agency with tight margins that sometimes needs to give read access to dozens of clients, the per-workspace pricing model becomes a real obstacle. Penpot does not solve every Figma problem, but it solves exactly that one: the cost of multi-client collaboration.

  • Zero cost per seat: invite as many designers, developers, or read-only clients as you need, with no billing tiers.
  • Data hosted by you: your mockups and client assets do not pass through third-party servers — a strong argument in GDPR discussions.
  • Separate workspaces per client: each client project lives in its own space, with its own members and permissions.
  • Open standard: Penpot generates native SVG, making files readable and portable without relying on a proprietary format.
  • CSS and design token export: developers get style values directly without third-party plugins, speeding up handoff.
  • Full control over updates: you decide when to update, without forced migrations or interface changes overnight.
  • Sovereign compliance: for agencies working with public or sensitive clients, storing data on your own infrastructure simplifies compliance audits.

Penpot v2 vs Figma — parity and honest limits

Penpot covers the essentials of an agency's daily work: vector editing, components, prototyping, and developer handoff. Where honesty is required is on two points: the third-party plugin ecosystem is still modest compared to the Figma Community library, and .fig file import remains partial — complex constraints, certain advanced effects, and shared libraries do not always translate faithfully. If you have five years of Figma files, plan for a gradual migration.

Scroll the table

FeaturePenpot v2Figma Pro
Vector editing✓✓
Components and variants✓✓
Interactive prototyping✓✓
Dev handoff / Inspect✓✓
Real-time collaboration✓✓
.fig file importPartial✓
Third-party pluginsLimited✓ (large library)
SVG / CSS export✓✓
Design tokens✓✓ (via plugins)
Guest access at no extra cost✓Paid per seat
Self-hosting✓✗

Technical prerequisites before installation

Penpot v2 runs in Docker and requires a VPS with at least 2 vCPU, 4 GB RAM (8 GB recommended for teams of more than five), and 40 GB SSD storage for assets and the PostgreSQL database. You will need Docker Engine 24+ and Docker Compose v2, a domain name pointing to your VPS (e.g. your-domain.com), and root or sudo SSH access. A ServOrbit VPS starting at 99 DH/month meets these requirements: over a year, that is a fraction of the $900 to $2,700 that Figma would cost for the same team of five designers.

Installing Penpot with Docker Compose

Penpot v2 deploys via Docker Compose. The steps below set up the Penpot server, an Nginx reverse proxy with SSL, and SMTP for team invitations.

  1. Prepare the server

    Connect to your VPS via SSH, update the system, and install Docker and Docker Compose: apt update && apt upgrade -y && apt install -y docker.io docker-compose-plugin. Verify versions with docker --version and docker compose version to confirm Docker 24+ and Compose v2.

  2. Clone the official Penpot configuration

    Fetch the official Docker configuration from the Penpot repository: git clone https://github.com/penpot/penpot.git /opt/penpot && cd /opt/penpot. The docker/images/ folder contains the reference docker-compose.yaml file for production.

  3. Configure environment variables

    Copy the example file and edit it: cp docker/images/.env.example docker/images/.env. Set at minimum PENPOT_FLAGS (enable enable-smtp and enable-registration), PENPOT_PUBLIC_URI (your domain: https://penpot.your-domain.com), and generate a strong secret for PENPOT_SECRET_KEY with openssl rand -hex 32.

  4. Start the containers

    From the docker/images/ folder, run: docker compose -p penpot -f docker-compose.yaml up -d. Docker will pull the images (penpot-frontend, penpot-backend, penpot-exporter, penpot-pgsql, penpot-redis) and start the services. Verify all containers are in running state with docker compose -p penpot ps.

  5. Configure Nginx as a reverse proxy with SSL

    Install Nginx and Certbot: apt install -y nginx certbot python3-certbot-nginx. Create a vhost in /etc/nginx/sites-available/penpot pointing to localhost:3449 (the default Penpot frontend port), then obtain a Let's Encrypt certificate: certbot --nginx -d penpot.your-domain.com. Certbot automatically modifies the configuration to redirect HTTP to HTTPS.

  6. Create the first administrator account

    Navigate to https://penpot.your-domain.com in your browser. The registration page is accessible if enable-registration is active in your flags. Create your administrator account, then disable public registration in .env (disable-registration) and restart the containers if you do not want anyone to be able to create an account.

  7. Configure SMTP for invitations (optional)

    To invite collaborators by email, set PENPOT_SMTP_HOST, PENPOT_SMTP_PORT, PENPOT_SMTP_USER, PENPOT_SMTP_PASSWORD, and PENPOT_SMTP_FROM in your .env file. Restart the containers after any changes: docker compose -p penpot restart.

  8. Verify the installation

    Open a test project, invite a second account, and verify that real-time collaboration works (cursors visible, changes synchronized). Check logs for anomalies: docker compose -p penpot logs backend --tail=50.

Multi-client management: workspaces and permissions

Penpot organizes work into teams, which map exactly to an agency's multi-client needs. Each client has their own team, with their own projects, members, and library space. The "Acme Corp" team never sees the mockups of the "Smith Industries" team. As an instance administrator, you can be a member of all teams simultaneously, allowing you to switch between clients without changing accounts.

Permission levels are granular: a client can be invited as read-only on their own projects (they view and comment, but cannot edit), while your designers have full edit access. Integration developers can access Inspect mode without touching source files. This architecture directly addresses Figma's limitation, where each edit access costs an additional seat.

Security and maintenance: enable two-factor authentication (2FA) for all administrator accounts. Set up automatic PostgreSQL backups with pg_dump to remote storage (e.g. an S3 bucket or another VPS) — once a day is sufficient for most agencies. Follow Penpot releases on GitHub and update by running docker compose -p penpot pull && docker compose -p penpot up -d from the installation folder. Before each update, perform a full database dump: docker exec penpot-pgsql pg_dump -U penpot penpot > backup_$(date +%F).sql.

Troubleshooting common errors

Here are the four most common errors during a Penpot installation and their remedies.

  • Error "502 Bad Gateway" in Nginx: the frontend container is not yet ready or is not listening on the right port. Verify that port 3449 is the one Nginx is proxying, and that the container is in running state (docker compose -p penpot ps). If the container is restarting in a loop, check docker compose -p penpot logs frontend.
  • Error "PENPOT_SECRET_KEY is not set" on backend startup: the PENPOT_SECRET_KEY variable is missing or empty in your .env file. Generate a value with openssl rand -hex 32 and restart the containers.
  • Invitation emails are not received: verify that enable-smtp appears in PENPOT_FLAGS and that your SMTP credentials are correct. Test sending from the backend container: docker exec -it penpot-backend ./manage.sh send-test-email [email protected].
  • SVG or PDF export fails silently: the penpot-exporter container (headless Chromium service) needs sufficient resources. Increase the memory allocated to Docker, and verify that the exporter container is started and reachable from the backend via the Docker internal network.

Migrating from Figma: SVG export and design tokens

Migration from Figma happens in three phases. First, export your Figma files as SVG (by page or by component) from Figma Desktop — this is the format Penpot imports best. The .fig import is available in Penpot v2 but remains partial: advanced constraints, complex blending modes, and shared libraries are not always faithfully preserved. For active projects, prefer a component-by-component migration over a mass import.

Next, extract your design tokens from Figma using a tool like Token Studio or Style Dictionary, then reimport them into Penpot via its token management interface. This preserves your color system, typography, and spacing without manual re-entry. Finally, inform your developers that Penpot's Inspect mode gives them CSS values, pixel spacing, and component specifications directly — without a third-party plugin. The transition is smoother because Penpot natively speaks the same standards as the browser.

Self-hosted Penpot: sovereignty and cost control for your agency

Penpot v2 is not a Figma clone and does not claim to be. The plugin ecosystem is still more modest, and migrating complex files takes patience. But for an agency managing multiple clients, the combination of a sovereign collaborative design space, access with no per-seat billing, and fixed-cost infrastructure represents a real structural advantage. Deploying Penpot on a ServOrbit VPS starting at 99 DH/month means taking back control of your design chain — without depending on a pricing decision you did not make.

Deploy Penpot on your VPS today

ServOrbit offers Penpot v2 as a one-click deployment from the marketplace. Configured VPS, Docker ready, SSL certificate included — your collaborative design space is up and running in minutes.

Need help?

Browse our help center and FAQ, or reach our team — callback, WhatsApp or email. Support in French, English and Arabic.

Message us on WhatsAppopens in a new tab