Skip to content

Self-hosted app builder

Self-hosted low-code platform for internal tools

Run ToolJet on your own infrastructure: Docker, Kubernetes, your VPC or on-premise. Build internal tools with AI, a coding agent or the visual builder, connect the databases behind your firewall, and keep every app under your SSO, permissions and audit logs.

  • Docker and Kubernetes
  • VPC or on-premise
  • Air-gapped on Enterprise
Example Self-hosted app · illustrative data
Change requestsProduction · platform teamSSOAudit onProduction
Open requests236 need a second approver
Approved this week41median 3 h
Rolled back2linked incidents
ChangeTeamEnvironmentStatus
CHG-2291PaymentsProductionApproved
CHG-2294Data platformProductionSecond approval
CHG-2297IdentityStagingApproved
CHG-2301PaymentsProductionBlocked

Production changes need two approvers from the platform group; log both names and link the ticket

Approval rule, platform role and ticket query added · awaiting your review

40,000+stars on the open-source core
AICPA SOCISO 27001
SOC 2 Type IIISO 27001 and GDPR · Visit the trust centre
Your infrastructureCloud, VPC, on-premise or air-gapped
100+ connectorsplus any REST or gRPC endpoint

Self-hosted app builder

What a self-hosted low-code platform gives you

A self-hosted app builder runs on infrastructure you operate instead of a vendor's cloud. The builder, the apps it produces and the connections to your databases and APIs all live inside your network, so internal tools can reach private systems without exposing them to the internet.

ToolJet is an open-source low-code platform you can self-host from the free plan. The Community Edition is licensed under AGPL-3.0, and the whole platform runs in your environment: the editor, the apps, ToolJet Database and every data-source connection. Build with ToolJet AI, with a coding agent through the ToolJet MCP server, or visually on the canvas.

Teams self-host for data residency, private networks, regulated workloads or control over upgrades. Teams that would rather not run infrastructure can start on ToolJet Cloud instead.

  • Control where AI runs and what it receives

    Your deployment initiates a key-authenticated outbound connection to the AI gateway. Requests can include prompts, app context, schemas and data read through connected credentials. Restrict data-source permissions. Fully local AI requires the Self-hosted Enterprise AI gateway add-on and a supported local model.

  • Open source, free to start

    The Community Edition is AGPL-3.0. The Self-hosted Free plan covers 2 builders, 50 end users and 10 apps; Team adds SSO, audit logs and Git sync, and Enterprise adds SCIM and multiple instances, with air-gapped deployment available as an add-on.

  • More on Self-hosted, not less

    Workflows, Agent Builder and private connectors are available on Self-hosted deployments and not on ToolJet Cloud.

No engineering ticket needed

Describe the tool you need. ToolJet builds it.

Type what you want in plain language. ToolJet generates the pages, queries and logic as a working app. Connect your data, set who can see what, and review the generated logic before publishing. Edit the app on the canvas afterwards.

  • Working app, not a mockup
  • Review access rules before publishing
  • Free to start, per-builder pricing
Enter to build · Shift+Enter for a new line

Connect the databases and APIs inside your network

  • PostgreSQL
  • MySQL
  • Oracle
  • SAP HANA
  • MongoDB
  • Snowflake
  • BigQuery
  • REST API
Browse all integrations

Have developers? They can build the same apps fromClaude CodeCodexCursorGitHub CopilotGrok Buildthrough the ToolJet plugin

What teams run on self-hosted ToolJet

The internal tools that need to sit next to private data, built by the teams that use them.

Admin panels on private databases

CRUD over production tables in PostgreSQL, MySQL, Oracle or SQL Server, with row-level rules on who can edit what.

Operations dashboards

Live views over your warehouse and internal services, filtered by team, with actions wired to queries.

Approval workflows

Multi-step approvals with thresholds, role-gated actions and a decision record in your own database.

Customer and partner portals

Scoped views for external users through SSO or invited access, served from your domain.

Workflows

Webhook, scheduled or app-triggered workflows with JavaScript logic, data-source nodes and run logs. Self-hosted only.

AI agents

Add an AI Agent node to a workflow, connect the model you prefer and your business data, and debug the agent visually. Self-hosted only.

From docker run to production in four steps

  1. 01

    Evaluate with Docker

    Run the single-container image, which includes PostgreSQL, and build a first app against a test database.

  2. 02

    Choose your production target

    Kubernetes with Helm, OpenShift, AWS ECS or EKS, Azure AKS or Container Apps, Google GKE or Cloud Run, or a VM, in your VPC or on-premise.

  3. 03

    Connect identity and data

    Configure SSO with SAML, OpenID Connect or LDAP on Team and above, then connect the databases and APIs your tools need through 100+ connectors.

  4. 04

    Promote through environments

    Move apps from development to staging to production with Git sync. Enterprise supports multiple instances, so AI can stay on in development and off in production.

Deployment

Run ToolJet where your infrastructure already is

Evaluate with a single Docker container, then move to Kubernetes, Helm or a managed container service for production. Every target has a setup guide.

Try ToolJet locally with Docker
docker run \
  --name tooljet \
  --restart unless-stopped \
  -p 80:80 \
  --platform linux/amd64 \
  -v tooljet_data:/var/lib/postgresql/16/main \
  tooljet/try:ee-lts-latest

ToolJet runs on x86-64 Linux (arm64 is not supported). A VM deployment needs at least 1 vCPU, 4 GB RAM and 8 GiB of storage for ToolJet itself; production deployments also need PostgreSQL (16.x recommended) and Redis 7. Check the system requirements before sizing production.

Compared

Self-hosting ToolJet vs Retool, Appsmith and Superblocks

Which plan each platform lets you self-host on, what runs on your infrastructure, and under which license.

FeatureToolJetRetoolAppsmithSuperblocks
Self-hosting available onFree, Team and EnterpriseEnterprise for new deploymentsFree and aboveEnterprise only (Hybrid or Cloud-Prem)
Air-gapped deploymentEnterprise add-onEnterpriseEnterprise add-onNot documented
LicenseAGPL-3.0 Community EditionProprietaryApache-2.0Proprietary
Build from a coding agentMIT-licensed MCP server, cloud or self-hostedProprietary MCP server in public beta; self-hosted 4.0+No MCP serverBuilder MCP that relays to Clark

Competitor details were verified on 7 September 2026 against each vendor's public pricing and documentation. Superblocks Hybrid runs the data plane in your VPC; Cloud-Prem runs the full platform in your AWS environment, managed by Superblocks. Deployment wording was checked on 30 September 2026. Sources are listed on each comparison page.

Governance

Enterprise controls that run inside your perimeter

Identity, permissions and audit apply to every app, whether a person built it on the canvas or an agent built it from a prompt. SOC 2 Type II, ISO 27001 and GDPR.

Single sign-on and SCIM

SAML, OpenID Connect and LDAP on Team and above, with SCIM provisioning on Enterprise.

Permissions down to the query

Workspace, app, page, component and query-level access, with row-level security where the data needs it.

Audit logs and SIEM export

Platform events with actor, resource and timestamp; configurable retention; export to your SIEM.

Encrypted, quiet by default

Data-source credentials are encrypted with AES-256-GCM, and administrators can turn off telemetry and update checks.

Security and governance features vary by plan. Workflows and Agent Builder are available on Self-hosted only; BYOK is a Self-hosted Enterprise add-on. Compare plan availability.

Two ways to get there

Build it yourself, or bring our engineers in

Self-serve

Your team, your pace

Start free. Describe the tool, refine it on the canvas, and ship it under your own access rules. Start with one app, then test it with your team before rolling it out.

Start free

Professional services

Forward-deployed engineers, embedded with your team

When the timeline is fixed or the process is tangled, our engineers build alongside you: scoped delivery, production-ready apps, and knowledge transfer so your team owns the result.

Talk about a project

Questions platform teams ask before they start

What is a self-hosted low-code platform?

A self-hosted low-code platform is an app builder you run on your own infrastructure instead of a vendor's cloud. You keep the builder, the apps and the data connections inside your network, and your team controls upgrades, backups and access. ToolJet is an open-source, self-hosted low-code platform for internal tools.

Can I self-host ToolJet for free?

Yes. The Community Edition is open source under AGPL-3.0, and the Self-hosted Free plan includes 2 builders, up to 50 end users and up to 10 apps. Team adds SSO, audit logs and Git sync; Enterprise adds unlimited end users, SCIM and multiple instances, with air-gapped deployment available as an add-on.

What do I need to self-host ToolJet?

An x86-64 Linux host or a Kubernetes cluster (arm64 is not supported), PostgreSQL (16.x recommended) and Redis 7. A VM deployment needs at least 1 vCPU, 4 GB RAM and 8 GiB of storage for ToolJet itself. The system requirements page in the docs covers database and cache sizing.

Which platforms can I deploy ToolJet on?

Docker, Kubernetes with or without Helm, OpenShift, AWS (AMI, ECS and EKS), Azure (AKS and Container Apps), Google Cloud (GKE and Cloud Run) and DigitalOcean, in your VPC or on-premise. ToolJet is also available from the AWS and Azure marketplaces.

Can self-hosted ToolJet connect to databases and APIs inside a private network?

Yes. ToolJet runs inside your network, so its 100+ connectors reach databases and internal APIs directly, without exposing them to the internet. Data-source credentials are encrypted with AES-256-GCM and stay in your deployment.

Who manages upgrades and backups on a self-hosted deployment?

Your team does. You run the ToolJet containers, PostgreSQL and Redis, and you decide when to upgrade. ToolJet publishes LTS releases and upgrade guides in the docs. If you would rather not operate the platform, ToolJet Cloud is the managed option.

Does ToolJet support air-gapped deployment?

Yes, on Enterprise. Fully air-gapped operation, including offline licensing, requires the Enterprise air-gapped add-on.

Can I use ToolJet AI on a self-hosted deployment?

Yes. By default your deployment opens an outbound connection to ToolJet's managed AI server. Requests can include prompts, app context, schemas and data read through connected credentials. Outbound-only connectivity does not limit request contents to schemas. Running the AI gateway inside your infrastructure and bringing your own model keys are Self-hosted Enterprise add-ons. Fully local AI also requires a supported local model; an external model provider still receives requests.

What is available on Self-hosted but not on ToolJet Cloud?

Workflows, Agent Builder and private connectors are available on Self-hosted deployments and not on ToolJet Cloud. Builder bring-your-own-key and a customer-hosted AI server are Self-hosted Enterprise add-ons.

How does self-hosting ToolJet compare with Retool, Appsmith and Superblocks?

As verified on 7 September 2026, ToolJet self-hosts on Free, Team and Enterprise; Retool lists self-hosting on Enterprise for new deployments; Appsmith self-hosts from its free plan; and Superblocks offers Enterprise Hybrid (data plane in your VPC) or Cloud-Prem (the full platform in your AWS environment, managed by Superblocks).

Self-host your first internal tool this week

Run the Docker image to evaluate, or talk to an engineer about Kubernetes, SSO and an air-gapped rollout.

Page updated