Self-hosted internal apps for private infrastructure

Self-hosted internal app builder for private infrastructure

Run UI Bakery in your own environment when internal apps need deployment control, private-network access, custom identity setup, and operational ownership. Deploy with Docker, connect databases and APIs, and keep governed app delivery close to your infrastructure.

curl -k -L -o install.sh https://raw.githubusercontent.com/uibakery/self-hosted/main/install.sh && bash ./install.sh

Copy CURL

Explore additional installation options and configuration settings.

Azure Container instanceKubernetesRedHat OpenshiftGoogle Sheet setupSSOSending emails

etc.

Protect

For environments with strict security requirements.

Use self-hosted UI Bakery when private infrastructure, controlled network access, auditability, and identity governance are part of the buying criteria. Validate final compliance scope, data flows, and deployment requirements with your security and legal teams.

SOC2 Certified
Advanced RBAC
Audit logs
Multi-Factor Authentication
SSO
Run

Run UI Bakery self-hosted in minutes.

Deploy UI Bakery locally, connect it to your databases or APIs, and start building internal tools. Invite your team and other users.

Docker support

Run UI Bakery as a set of Docker containers, making it easy to integrate into your existing infrastructure and manage across environments.

Built-in database

Use the built-in MySQL database for data storage, or configure a connection to an external database for greater flexibility.

Security

Set up SSO with oAuth2 or SAML providers.

Enhance security with single sign-on. Allow users to log in using a single set of credentials. Support for SAML-based identity providers such as Google, Azure AD, Okta, and others. Import user groups to manage access within UI Bakery.

SSO
Adjust

Deploy your apps on a custom domain.

Deploy and host your apps on your own domain. Retain full control over access, activity, and data, all within your infrastructure.

Domain identity

Use your corporate domain to provide a consistent and recognizable experience for your users.

Domain identity
Domain identity
Access control

Enforce access policies using domain restrictions and firewall configurations.

Self-hosted version core capabilities.

Premium support
Public and Private Apps
Unlimited public app users
More than 50 workspace view seats
Add more than 5 users
App Migration & Custom Development Services
Mobile Responsive Apps
App Export
AI Capabilities
Community Support
Custom SSO (SAML, OpenID, oAuth2)
Custom User Roles
Unlimited seats
App and data source Environments
White-labelling
Unlimited apps & data source connections
Unlimited seats
Dedicated VM
Modules & Actions Library
Custom themes
Hosted database
$40 of AI usage credits
Community support
Unlimited scheduled jobs/webhooks
Online chat/ email support
Custom SSO (SAML, OpenID)
Up to 5 users
Audit Logs
Monthly AI trial credits included
Unlimited apps, pages, client actions, data sources
App Migration & Custom Development Services
User Roles (admin, editor, user)
Dedicated support
Embedded Apps
Bring your own AI model provider key
Git version-control
Release history
App and data source Environments
Built-in roles
Release history
Role-based access control
Audit logs
Git version control
AI usage credits via Cloud workspace *
Self-hosted decision center

Choose self-hosted UI Bakery when deployment control matters

Self-hosted UI Bakery is for teams that need to build internal apps close to private data, inside an infrastructure model their security, procurement, and platform teams can approve.

Best fit

  • Private databases or APIs should stay off the public internet.
  • Security review requires private-cloud or on-premise deployment.
  • Your team wants direct control over hosting, updates, backups, and network policy.

Operating model

Self-hosting gives more deployment control, while your team owns the environment: infrastructure, monitoring, backup policy, upgrade timing, and incident response.

Common use cases

Admin panels, operations dashboards, approval workflows, CRUD tools, and internal portals connected to private systems.

Cloud vs self-hosted UI Bakery

Choose Cloud whenChoose self-hosted when
You want the fastest pilot and minimal infrastructure work.Apps must run inside your own infrastructure model.
Data sources can be connected safely from a hosted setup.Databases or APIs are reachable only from a private network.
The first rollout is for a small team or lower-risk workflow.Security, platform, or procurement teams require deployment control.
Your team wants UI Bakery to manage most platform operations.Your team is ready to own monitoring, backups, updates, and infrastructure policy.

What runs in a self-hosted UI Bakery installation?

Public UI Bakery setup materials describe a Docker/Docker Compose-based deployment and production recommendations such as HTTPS, a standalone database, backups, version control for upgrades, and secure secret storage.

Application builder and runtime

Teams build and run internal apps, dashboards, forms, and workflows inside the self-hosted UI Bakery environment.

Private data connections

Apps can connect to databases, REST APIs, and internal services according to the network routes and credentials your team configures.

Identity and access

Use UI Bakery access controls with your identity setup, including SAML or OAuth2 SSO where configured for the deployment.

Self-hosted responsibility matrix

AreaUI Bakery providesYour team controls
Application platformBuilder and runtime for internal appsWhich apps are built, published, maintained, and retired
Hosting environmentSelf-hosted deployment package and setup guidanceServer, cloud account, private network, firewall, DNS, and infrastructure policy
InstallationDocker/Docker Compose-based installation flow and docsOS access, resource allocation, deployment automation, and compatibility checks
Data accessConnectors and app-building tools for databases and APIsCredentials, network routes, least-privilege access, and data policy
OperationsProduct releases and update guidanceUpgrade timing, backups, monitoring, alerts, rollback, and incident process
Compliance processPlatform controls and documentation inputsFinal compliance scope, audits, policies, and legal review

Production readiness checklist

Validate before rollout

  • Target infrastructure and network access
  • Credential and secret management
  • SSO, groups, RBAC, and MFA requirements

Plan operations

  • Backups and monitoring
  • Update testing and rollback
  • Ownership for incidents and access reviews

Check requirements

Public setup docs list a Linux-based OS, minimum 2 vCPUs, 4 GiB memory, 20 GiB storage, sudo access, and network access to required resources during installation/update.

AI, MCP, and external model providers

If your self-hosted setup uses AI chat, MCP workflows, external APIs, or model-provider keys, validate the exact deployment, license, and data flow before making compliance, BYOK, or data-residency commitments. Self-hosting gives infrastructure control, but connected services can change where data is processed.

Proof from real internal app rollouts

Action Behavior Centers

Action Behavior Centers replaced disconnected spreadsheet workflows with centralized internal apps for clinical and recruiting operations across 400+ clinics and 5,000+ users.

Qualifirst

Qualifirst moved from fragmented spreadsheets and custom development bottlenecks to 100+ internal apps, with a self-hosted UI Bakery setup reinforcing governance and control.

Self-hosted UI Bakery FAQ

Is UI Bakery available as self-hosted software?

Yes. UI Bakery provides a self-hosted/on-premise option for teams that want to run the platform in their own infrastructure.

Is self-hosted the same as offline?

Not necessarily. Offline operation depends on the exact setup, licensing, update process, and network requirements, so validate it before committing.

Can it connect to private databases?

Yes. A common reason to choose self-hosted UI Bakery is to build internal apps on top of private databases, APIs, and services that are reachable from your private network.

Who manages updates and backups?

In a self-hosted deployment, your team typically controls infrastructure, backup process, monitoring, and update timing.