Open source · MIT · Single binary

The self-hosted file manager
that embeds anywhere

One Go binary with a polished web UI, six storage drivers and a plugin API for the rest. Reachable as S3, SFTP, FTPS, NFS and WebDAV. Ships as a desktop app, a CLI, an embeddable component — and a built-in MCP server so AI agents can drive it natively.

$ docker run -p 5212:5212 -e FILEX_DEFAULT_STORAGE_DRIVER=local -e FILEX_DEFAULT_STORAGE_PATH=/srv/files -v filex-data:/data -v "$PWD:/srv/files" ghcr.io/brf-tech/filex:latest

Demo sign-in: [email protected] / demo — the files are yours to play with; the admin panel is read-only, and everything resets nightly.

Why filex

Not another directory listing

Most self-hosted file managers are either too small — a listing with an upload button — or part of a groupware suite you deploy for the file tab. filex aims at the gap.

Embeds in your product

The same UI ships as a Vue 3 component, a React adapter and a framework-agnostic <filex-explorer> web component. Confined API tokens keep each tenant locked to its own folder — enforced by the backend, not the widget. Presence avatars and live file updates arrive over WebSocket in embedded contexts too.

AI-agent native (MCP)

A built-in Model Context Protocol server at /api/ai/mcp, plus a token-scoped REST surface. Hand an agent a token confined to one folder: it can list, read, write, share and zip — nothing else. Every integration keeps its own audit trail.

Six storage drivers, plus yours

Local disk, S3, SFTP, FTP, WebDAV and SMB/NAS — mount many at once, each as a top-level folder, and cut a folder from one into another for a real move. For anything else, a storage plugin is a separate program, in any language, that teaches filex a backend it has never heard of. And filex will tell you what they cost: it reads the daily usage report your provider already writes and prices it with a table you can edit, free allowances shown beside the billable lines.

Apps: things to do with a file

A second kind of plugin — a sandboxed WebAssembly app that adds actions to the file menu, screens filex draws for it and public pages for people with no account, installed through a review of every permission it asks for and able to do exactly that and nothing else. Apps keep themselves up to date from where they came from; a new version that asks for more waits for your review. Two ship alongside filex as public repositories: e-Signature — a document sent round for signature, a PAdES signature from your own authority, the finished file sealed by filex itself — and Convert. Write your own in stock Go, against a test kit.

Your language, your colours

English and Turkish are built in; any other language is a language pack — a manifest of strings, no code and no release — which translates the explorer, the admin panel, the public pages and the text the server writes. Arabic, Hebrew, Persian and Urdu lay the whole interface out right to left. And it wears your colours, not ours: compose a theme on the Appearance screen and the sign-in page and every public link wear it too.

It finds things, and it keeps them

Search every mounted storage at once — by filename and by what is inside the file. Both are on by default, on an embedded index with nothing extra to run; add Tesseract and scanned pages join in. Behind that: trash with a retention window, version history, and optional ClamAV scanning of every file written — the built-in editor included, and files the storage sync finds on the backend rather than through filex — against a scanner on the box or a clamd container over the network.

RBAC, sharing & sign-in

Roles plus per-item grants with inheritance. Public links with a PIN, an expiry and a download cap; folder links stream as ZIP; file-request links take uploads into a folder without showing its contents. Sign in with a local password, OIDC, LDAP / Active Directory or a proxy header — set up on Admin → Identity providers, applied without a restart, with a Test now that really tests it.

Boringly deployable

One binary or one container. SQLite by default, PostgreSQL when you have a team. Multi-tenant mode serves independent realms from one install. Compose stacks, a Helm chart, and Umbrel, CasaOS, Runtipi, Portainer and Unraid listings included.

Both directions

Whatever it connects to, it can be reached as

Point rclone, restic, aws s3, WinSCP, a scanner that only ever learned FTP or a media player that only ever learned NFS straight at filex. They land in the same tree.

Connects to

Storage drivers — mount many at once.

local diskS3 SFTPFTP WebDAVSMB / NAS plugin://yours

Is reachable as

Protocol servers — each one a switch.

S3SFTP FTPSNFSv3 WebDAVHTTPS

Same tree, same permissions, same trash, same quota, same search index, same audit trail as the web UI — a file uploaded over FTPS is thumbnailed and indexed exactly like one dropped in the browser. Each protocol has a credential you can revoke on its own.

Clients

Not just a browser tab

The same explorer, wherever you happen to be working.

Web

The app itself

Thumbnails that show the thing itself — a PDF's first page, a video's first frame that is not black, a text file's own first lines — and viewers and editors for images, video, audio, PDF, Markdown, CSV, source code (Monaco), notebooks, draw.io and Mermaid diagrams and glTF/USDZ 3D models, with Office documents editable through a self-hosted ONLYOFFICE. + New also creates them: Markdown, text, CSV and code straight away, and Word, Excel, PowerPoint or OpenDocument once an ONLYOFFICE server is connected — the templates are compiled into the binary, so no LibreOffice is involved and a type this install could not then open is never offered. Light and dark, and any language: English and Turkish are built in, and a language pack adds more — Spanish, German and French ship as examples — right-to-left languages laid out right to left.

Desktop

Windows, Linux, macOS

The same explorer in its own window: several accounts side by side, folders kept in step with the server from the tray, drag-out to any folder on your disk — and on Windows and Linux the installed copy updates itself quietly. Not allowed to install anything? Every platform also has a build that just runs: a portable Windows .exe, an AppImage, a macOS .zip. The portable one keeps everything it has in one folder beside itself, so deleting that folder leaves nothing of yours on a machine that is not yours.

Sync

Folders, both ways

Keep a folder on your disk and a folder on the server in step — live: an edit on either side arrives in about a second, not on the next 30-second lap. Work offline and catch up on reconnect, with a bandwidth limit and a sync window when you want them, and a first run that holds back a big re-upload and asks first. Same engine in the desktop app and in filex sync, so a pair made in one is visible to the other.

CLI

filex mount

Attach a remote server over ordinary HTTPS: a folder on Linux, a drive letter on Windows. Nothing is downloaded but a bounded read cache, so one file opens out of a hundred thousand without pulling the rest.

Install the desktop app

Download from the Microsoft Store Get it from the Snap Store
Homebrew · macOS 13+ brew install brf-tech/filex/filex-app
winget · Windows 10/11 · in review winget install BRFTech.filex-app

Or take the installer, the portable .exe, the AppImage, the .deb, the .rpm or the .dmg from the latest release. The command line alone: brew install brf-tech/filex/filex.

Quickstart

Up and running in a minute

Run it, open the admin UI, add a storage. That is the whole setup.

Docker

# serves the folder you are standing in
docker run -p 5212:5212 \
  -e FILEX_DEFAULT_STORAGE_DRIVER=local \
  -e FILEX_DEFAULT_STORAGE_PATH=/srv/files \
  -v filex-data:/data \
  -v "$PWD:/srv/files" \
  ghcr.io/brf-tech/filex:latest

# the first run prints the admin credentials
open http://localhost:5212/admin

Docker Compose

services:
  filex:
    image: ghcr.io/brf-tech/filex:latest
    ports: ["5212:5212"]
    volumes:
      - filex-data:/data
      - ./files:/srv/files
    environment:
      FILEX_PUBLIC_URL: https://files.example.com
      FILEX_DEFAULT_STORAGE_DRIVER: local
      FILEX_DEFAULT_STORAGE_PATH: /srv/files
volumes: { filex-data: }

Embed the component

<!-- one script tag, any framework -->
<script type="module" src="https://cdn.jsdelivr.net/npm/@brftech/filex/dist/filex.js"></script>

<filex-explorer api-base="https://files.example.com"></filex-explorer>

Connect an AI agent

claude mcp add filex --transport http \
  https://files.example.com/api/ai/mcp \
  --header "Authorization: Bearer <token>"

Reach it from anywhere else

# the server as a folder
filex mount ~/filex

# or point a tool that never heard of filex
rclone copy ./photos filex-s3:demo/Photos
Screenshots

A real UI, not an afterthought

Click any of them to see the whole thing.

Share links — PIN, expiry, download caps
Viewers for Markdown, code, Office, 3D
Admin — storages, users, queue, audit
Plugins — teach it a backend it never had
MIT licensed

Open source, all of it

Built and run in production at BRF Tech — powering multi-tenant platforms with per-project isolation.