One Go binary with a polished web UI, six storage drivers and a plugin API for the rest. Reachable as S3, SFTP, FTPS, NFS and WebDAV. Ships as a desktop app, a CLI, an embeddable component — and a built-in MCP server so AI agents can drive it natively.
Demo sign-in: [email protected] / demo — the files are yours to play with; the admin panel is read-only, and everything resets nightly.
Most self-hosted file managers are either too small — a listing with an upload button — or part of a groupware suite you deploy for the file tab. filex aims at the gap.
The same UI ships as a Vue 3 component, a React adapter and a framework-agnostic
<filex-explorer> web component. Confined API tokens keep each
tenant locked to its own folder — enforced by the backend, not the widget. Presence
avatars and live file updates arrive over WebSocket in embedded contexts too.
A built-in Model Context Protocol server at
/api/ai/mcp, plus a token-scoped REST surface. Hand an agent a token
confined to one folder: it can list, read, write, share and zip — nothing else.
Every integration keeps its own audit trail.
Local disk, S3, SFTP, FTP, WebDAV and SMB/NAS — mount many at once, each as a top-level folder, and cut a folder from one into another for a real move. For anything else, a storage plugin is a separate program, in any language, that teaches filex a backend it has never heard of. And filex will tell you what they cost: it reads the daily usage report your provider already writes and prices it with a table you can edit, free allowances shown beside the billable lines.
A second kind of plugin — a sandboxed WebAssembly app that adds actions to the file menu, screens filex draws for it and public pages for people with no account, installed through a review of every permission it asks for and able to do exactly that and nothing else. Apps keep themselves up to date from where they came from; a new version that asks for more waits for your review. Two ship alongside filex as public repositories: e-Signature — a document sent round for signature, a PAdES signature from your own authority, the finished file sealed by filex itself — and Convert. Write your own in stock Go, against a test kit.
English and Turkish are built in; any other language is a language pack — a manifest of strings, no code and no release — which translates the explorer, the admin panel, the public pages and the text the server writes. Arabic, Hebrew, Persian and Urdu lay the whole interface out right to left. And it wears your colours, not ours: compose a theme on the Appearance screen and the sign-in page and every public link wear it too.
Search every mounted storage at once — by filename and by what is inside the file. Both are on by default, on an embedded index with nothing extra to run; add Tesseract and scanned pages join in. Behind that: trash with a retention window, version history, and optional ClamAV scanning of every file written — the built-in editor included, and files the storage sync finds on the backend rather than through filex — against a scanner on the box or a clamd container over the network.
Roles plus per-item grants with inheritance. Public links with a PIN, an expiry and a download cap; folder links stream as ZIP; file-request links take uploads into a folder without showing its contents. Sign in with a local password, OIDC, LDAP / Active Directory or a proxy header — set up on Admin → Identity providers, applied without a restart, with a Test now that really tests it.
One binary or one container. SQLite by default, PostgreSQL when you have a team. Multi-tenant mode serves independent realms from one install. Compose stacks, a Helm chart, and Umbrel, CasaOS, Runtipi, Portainer and Unraid listings included.
Point rclone, restic, aws s3,
WinSCP, a scanner that only ever learned FTP or a media player that only ever learned
NFS straight at filex. They land in the same tree.
Storage drivers — mount many at once.
Protocol servers — each one a switch.
Same tree, same permissions, same trash, same quota, same search index, same audit trail as the web UI — a file uploaded over FTPS is thumbnailed and indexed exactly like one dropped in the browser. Each protocol has a credential you can revoke on its own.
The same explorer, wherever you happen to be working.
Thumbnails that show the thing itself — a PDF's first page, a video's first frame that is not black, a text file's own first lines — and viewers and editors for images, video, audio, PDF, Markdown, CSV, source code (Monaco), notebooks, draw.io and Mermaid diagrams and glTF/USDZ 3D models, with Office documents editable through a self-hosted ONLYOFFICE. + New also creates them: Markdown, text, CSV and code straight away, and Word, Excel, PowerPoint or OpenDocument once an ONLYOFFICE server is connected — the templates are compiled into the binary, so no LibreOffice is involved and a type this install could not then open is never offered. Light and dark, and any language: English and Turkish are built in, and a language pack adds more — Spanish, German and French ship as examples — right-to-left languages laid out right to left.
The same explorer in its own window: several accounts side by side, folders kept
in step with the server from the tray, drag-out to any folder on your disk — and on
Windows and Linux the installed copy updates itself quietly. Not allowed to install
anything? Every platform also has a build that just runs: a portable Windows
.exe, an AppImage, a macOS .zip. The portable one keeps
everything it has in one folder beside itself, so deleting that folder leaves
nothing of yours on a machine that is not yours.
Keep a folder on your disk and a folder on the server in step — live:
an edit on either side arrives in about a second, not on the next 30-second lap.
Work offline and catch up on reconnect, with a bandwidth limit and a sync window when
you want them, and a first run that holds back a big re-upload and asks first. Same
engine in the desktop app and in filex sync, so a pair made in one is
visible to the other.
filex mountAttach a remote server over ordinary HTTPS: a folder on Linux, a drive letter on Windows. Nothing is downloaded but a bounded read cache, so one file opens out of a hundred thousand without pulling the rest.
winget install BRFTech.filex-app
Or take the installer, the portable .exe, the AppImage, the
.deb, the .rpm or the .dmg from the
latest release. The command
line alone: brew install brf-tech/filex/filex.
Microsoft and the Microsoft Store badge are trademarks of the Microsoft group of companies. The Snap Store badge is © Canonical Ltd., licensed CC BY-ND 2.0 UK.
Run it, open the admin UI, add a storage. That is the whole setup.
# serves the folder you are standing in docker run -p 5212:5212 \ -e FILEX_DEFAULT_STORAGE_DRIVER=local \ -e FILEX_DEFAULT_STORAGE_PATH=/srv/files \ -v filex-data:/data \ -v "$PWD:/srv/files" \ ghcr.io/brf-tech/filex:latest # the first run prints the admin credentials open http://localhost:5212/admin
services:
filex:
image: ghcr.io/brf-tech/filex:latest
ports: ["5212:5212"]
volumes:
- filex-data:/data
- ./files:/srv/files
environment:
FILEX_PUBLIC_URL: https://files.example.com
FILEX_DEFAULT_STORAGE_DRIVER: local
FILEX_DEFAULT_STORAGE_PATH: /srv/files
volumes: { filex-data: }
<!-- one script tag, any framework --> <script type="module" src="https://cdn.jsdelivr.net/npm/@brftech/filex/dist/filex.js"></script> <filex-explorer api-base="https://files.example.com"></filex-explorer>
claude mcp add filex --transport http \
https://files.example.com/api/ai/mcp \
--header "Authorization: Bearer <token>"
# the server as a folder filex mount ~/filex # or point a tool that never heard of filex rclone copy ./photos filex-s3:demo/Photos
Click any of them to see the whole thing.
Built and run in production at BRF Tech — powering multi-tenant platforms with per-project isolation.