Overview
OverviewWhat it means for youThe stack in numbersAll appsWhat it replacesArchitectureComplianceThe manifest standard
Wilhelm core 16
📦chatnc📦homenc📄HTML67spec📦imagegennc🧬MarketingMachinenc📦notifync🔍OCR Gatewayinfra📦pdfnc📦ragnc📦searchnc📦settingsnc📦swaggernc📦toolsnc📦websitenc🤖Wilhelm MCP Servernc🎨Wilhelm UInc
Adapters 1
🧩SAP Adapterinfra
AI 1
🧠Wilhelm Intelligenceinfra
Analytics 1
📊Analyticsext
Automation 2
🔗n8n Workflowsext🪢o14n - open n8nhosted
CAD 1
📐Tusch3Dext
Commerce 1
🎁Amazing Shopext
Core 1
TaskHQext
CRM 2
🤝CRMext🫂garyn.ainc
Dashboards 1
🧪ACIDext
Database 1
🗄️NocoDBext
Design 1
🎨Designext
Documents 1
✍️Signext
Finance 1
💰Financeext
Forms 1
📝Formsext
Infrastructure 2
🔧Integrationsinfra☁️Wilhelm Cloudinfra
Mail 1
📧Mailext
Medical 1
🏥Medicalinfra
Monitoring 2
📈Prometheusinfra💓Uptime Kumaext
Photos 1
📷Photosext
Projects 1
✈️Projectsext
Scheduling 1
📅Bookingext
Security 2
🗝️Data Brokerinfra🔐Vaultext
Services 4
📦llmext📦newsletterext📦storefrontext📦tellext
Storage 1
🪣Wilhelm S3integration
Tools 8
📰Blackwellembedded🏜️Blueduneembedded🪢Codeflowinfra⌨️Enterext🏢eviembedded💕Fabi AIembedded💘WilheLLMhosted🎬wMoviehosted
Website 1
💻Website Builderext
<!doctype wilhelm>

Wilhelm Techstack

Your company's software, in your own house.

57 apps, one docker compose up, no vendor lock-in. Cloud files, mail, CRM, projects, forms, signatures, shop, analytics, monitoring and AI - self-hosted open-source tools, wired together behind one login, described by one manifest standard. This page is generated from those manifests, the icons, previews and READMEs next to them: the stack as it is in the repository.

57apps with a manifest
31wrap an upstream open-source project
26Wilhelm-native
36embedded in Nextcloud
7licences
69proprietary tools replaced
14with screenshots

What it means for you

  • Your data stays with you. Every service runs in your own containers; the compliance notes of every app say plainly what is a certificate, what is a vendor claim and what simply follows from self-hosting.
  • One login, one place. Nextcloud is the kernel - single sign-on, files, calendar, contacts, dashboard. 36 apps plug into it as Nextcloud apps or embedded services; TaskHQ shows the whole stack as a desktop, Enter edits it as code.
  • Subscriptions become services. The replacement table lists which proprietary product each app stands in for - Google Workspace, Salesforce, Jira, DocuSign, Figma, Zapier and friends.
  • Open licences, honestly labelled. Each app carries three licences: the upstream service, the Wilhelm wrapper and the Wilhelm code. Fair-code licences (n8n, NocoDB) are marked as such.
  • A standard, not glue. Every app is one folder with one manifest.json; icons, favicons, OpenGraph cards, standalone compose files, desktop builds and this documentation are derived from it by tools, never hand-maintained.
  • Runs alone, too. Every service app ships a self-contained docker-compose.yml so it can be used outside the stack.

The stack in numbers

Apps by category

CategoryApps
Wilhelm core16
Adapters1
AI1
Analytics1
Automation2
CAD1
Commerce1
Core1
CRM2
Dashboards1
Database1
Design1
Documents1
Finance1
Forms1
Infrastructure2
Mail1
Medical1
Monitoring2
Photos1
Projects1
Scheduling1
Security2
Services4
Storage1
Tools8
Website1
as a table
CategoryApps
Wilhelm core16
Adapters1
AI1
Analytics1
Automation2
CAD1
Commerce1
Core1
CRM2
Dashboards1
Database1
Design1
Documents1
Finance1
Forms1
Infrastructure2
Mail1
Medical1
Monitoring2
Photos1
Projects1
Scheduling1
Security2
Services4
Storage1
Tools8
Website1

Service licences

LicenceApps
MIT10
AGPL-3.012
Apache-2.013
Proprietary18
MPL-2.01
GPL-3.01
Fair-Code-SUL2
as a table
LicenceApps
MIT10
AGPL-3.012
Apache-2.013
Proprietary18
MPL-2.01
GPL-3.01
Fair-Code-SUL2

How to read this page

The sidebar lists every app by category. Each app page has the same shape: at a glance (what it is based on, what it replaces, licence, image, public URL), preview (screenshots and contributed widgets), icon & assets (the derived asset set), configuration (service, embedding, Nextcloud app, Enter, desktop, TaskHQ, resources, dependencies, MCP, SSO, skin, secrets), compliance, the full manifest as a tree, the standalone compose file and the README.

Generated 2026-09-14 by node tools/stack-docs/index.mjs --standalone. Layout and elements: HTML67. Folders in apps/ without a manifest are not documented here: kernel, keycloak, loki, nextcloud, nginx, odoo, penpot, promtail, twenty, uptime-kuma, wilhelm-mcp, wormhole.

All apps

Every app that carries a manifest, with what it is based on, what it replaces and under which licence the service runs. Click a name for the full page.

AppBased onCategoryTypeService licenceReplaces
ACID
Documents in, formats out.
Wilhelm acidDashboardsExternal serviceMIT
Analytics
Web analytics without snooping.
Plausible AnalyticsAnalyticsExternal serviceAGPL-3.0Google Analytics, Hotjar
Blackwell
BlackwellToolsEmbedded appApache-2.0
Bluedune
Full-stack HTML, done.
BlueduneToolsEmbedded appApache-2.0
Booking
Appointments that book themselves.
Cal.comSchedulingExternal serviceAGPL-3.0Calendly, MS Bookings
Wilhelm Intelligence
One gateway, every model.
Wilhelm-nativeAIInfrastructureApache-2.0
chat
Talk where the work happens.
Wilhelm-nativeWilhelm coreNextcloud appProprietaryChatGPT, Copilot
Wilhelm Cloud
Your server in one minute.
Wilhelm-nativeInfrastructureInfrastructureProprietary
Codeflow
See code instead of reading it.
Wilhelm-nativeToolsInfrastructureApache-2.0
CRM
Customers in view, not in spreadsheets.
Twenty CRMCRMExternal serviceAGPL-3.0Salesforce, HubSpot
Data Broker
Wilhelm-nativeSecurityInfrastructureApache-2.0
Design
Design in the browser, as a team.
PenpotDesignExternal serviceMPL-2.0Figma, Adobe XD
Enter
The editor that thinks along.
code-server (Coder)ToolsExternal serviceMIT
evi
Elevators, assets, everything in view.
EviToolsEmbedded appApache-2.0
Fabi AI
Fabi's projects, one board.
FabiToolsEmbedded appApache-2.0
Finance
Your portfolio, clearly.
GhostfolioFinanceExternal serviceAGPL-3.0Yahoo Finance, Portfolio Performance
Forms
Ask. Answer. Done.
FormbricksFormsExternal serviceAGPL-3.0Typeform, Google Forms
garyn.ai
Your network - and it remembers.
Wilhelm-nativeCRMNextcloud appApache-2.0
home
All of Wilhelm, one door.
Wilhelm-nativeWilhelm coreNextcloud appProprietary
HTML67
HTML, thought further.
Wilhelm-nativeWilhelm coreSpecificationProprietary
imagegen
Pictures from words.
Wilhelm-nativeWilhelm coreNextcloud appProprietary
Integrations
Everything talks to everything.
Wilhelm-nativeInfrastructureInfrastructureProprietary
llm
Models local, answers instant.
OllamaServicesExternal serviceMITOpenAI API, Azure AI
Mail
Mail under your own roof.
mailcow: dockerizedMailExternal serviceGPL-3.0
MarketingMachine
Reach without friction.
Wilhelm-nativeWilhelm coreNextcloud appProprietary
Medical
Medical knowledge, docked in.
Wilhelm-nativeMedicalInfrastructureProprietary
Uptime Kuma
Green means green.
Uptime KumaMonitoringExternal serviceMITPingdom, UptimeRobot
n8n Workflows
Workflows that click.
n8nAutomationExternal serviceFair-Code-SULZapier, Make, Power Automate
newsletter
Mail that arrives.
listmonkServicesExternal serviceAGPL-3.0Mailchimp, SendGrid
NocoDB
A database without SQL anxiety.
NocoDBDatabaseExternal serviceFair-Code-SULAirtable, Google Sheets
notify
A heads-up when it counts.
Wilhelm-nativeWilhelm coreNextcloud appProprietaryFirebase FCM, Pushover
o14n - open n8n
Automation, fair and open.
Wilhelm-nativeAutomationHosted appApache-2.0
OCR Gateway
One gateway, all text recognition.
Wilhelm-nativeWilhelm coreInfrastructureApache-2.0
pdf
PDFs, done.
Wilhelm-nativeWilhelm coreNextcloud appProprietaryAdobe Acrobat, SmallPDF
Photos
Your pictures, your server.
ImmichPhotosExternal serviceAGPL-3.0Google Photos, iCloud Photos
Projects
Projects in flow.
PlaneProjectsExternal serviceAGPL-3.0Jira, Linear, Asana
Prometheus
Every metric, one place.
PrometheusMonitoringInfrastructureApache-2.0
rag
Knowledge that answers.
Wilhelm-nativeWilhelm coreNextcloud appProprietary
Wilhelm S3
Nextcloud speaks S3.
Wilhelm-nativeStorageIntegrationAGPL-3.0
SAP Adapter
SAP in the Wilhelm stack - clean REST instead of RFC pain.
Wilhelm-nativeAdaptersInfrastructureApache-2.0
search
Find instead of search.
Wilhelm-nativeWilhelm coreNextcloud appProprietaryAlgolia, Elasticsearch
settings
One place for every setting.
Wilhelm-nativeWilhelm coreNextcloud appProprietary
Amazing Shop
Sell without a landlord.
MedusaCommerceExternal serviceMITShopify, WooCommerce
Sign
Signatures, digital and binding.
DocumensoDocumentsExternal serviceAGPL-3.0DocuSign, Adobe Sign
storefront
Your shop, your look.
Medusa Next.js StarterServicesExternal serviceMIT
swagger
APIs you can touch.
Swagger UIWilhelm coreNextcloud appProprietaryPostman, ReadMe.io
TaskHQ
The stack in a Task Manager.
Wilhelm taskhq (@wilhelm/taskhq)CoreExternal serviceMIT
tell
A mailbox with brains.
Wilhelm tell-imapServicesExternal serviceMIT
tools
Tools for all the small things.
Wilhelm-nativeWilhelm coreNextcloud appProprietary
Tusch3D
CAD in the browser, with a pen.
Chili3dCADExternal serviceAGPL-3.0
Wilhelm UI
One standard, every interface.
Wilhelm-nativeWilhelm coreNextcloud appProprietary
Vault
Passwords, safe at home.
VaultwardenSecurityExternal serviceAGPL-3.01Password, LastPass, Bitwarden
website
Your site from one folder.
Wilhelm-nativeWilhelm coreNextcloud appProprietaryWordPress, Squarespace
Website Builder
Build websites like Lego.
WebwowWebsiteExternal serviceMIT
WilheLLM
AI chat with character.
WilhellmToolsHosted appApache-2.0
Wilhelm MCP Server
The stack as a toolbox.
Wilhelm-nativeWilhelm coreNextcloud appProprietary
wMovie
Cut video in the browser.
Wilhelm-nativeToolsHosted appMIT

What it replaces

The ecosystem reference in apps/README.md maps every tool in the stack to the proprietary product it stands in for. Rows link to the app page where one exists; the rest is shared infrastructure (databases, gateway, office, conversion).

Wilhelm nameToolReplacesLicenceStatus
Wilhelm CloudNextcloudGoogle Workspace, Microsoft 365AGPL-3.0Live
Wilhelm GatewayTraefikCloudflare, nginx Proxy ManagerMITLive
infrastructureMariaDBManaged MySQLGPL-2.0Live
infrastructurePostgreSQLManaged PostgreSQLPostgreSQL LicenseLive
infrastructureRedisManaged RedisBSD-3-ClauseLive
Wilhelm Automaten8n
n8n
Zapier, Make, Power AutomateSustainable UseLive
Wilhelm APIWilhelm APICustom backendMITLive
Wilhelm DocsSwagger UI
swagger
Postman, ReadMe.ioApache-2.0Live
Wilhelm DataNocoDB
nocodb
Airtable, Google SheetsSustainable UseLive
Wilhelm GraphNeo4jAWS NeptuneAGPL-3.0Live
Wilhelm SearchMeilisearch
search
Algolia, ElasticsearchMITPlanned
Wilhelm BrainOllama
llm
OpenAI API, Azure AIMITLive
Wilhelm AIOpen WebUI
chat
ChatGPT, CopilotMITLive
Wilhelm OCRTesseractAdobe OCR, AWS TextractApache-2.0Live
Wilhelm VisionNC RecognizeGoogle Photos AIAGPL-3.0Live
Wilhelm OfficeCollaboraGoogle Docs, Office OnlineMPL-2.0Live
Wilhelm ConvertGotenbergCloudConvert, ZamzarMITLive
Wilhelm PDFStirling-PDF
pdf
Adobe Acrobat, SmallPDFMITLive
Wilhelm SignDocumenso
sign
DocuSign, Adobe SignAGPL-3.0Planned
Wilhelm BoardExcalidrawMiro, FigJamMITLive
Wilhelm ShopMedusa
shop
Shopify, WooCommerceMITLive
Wilhelm CRMTwenty
crm
Salesforce, HubSpotAGPL-3.0Planned
Wilhelm BookingCal.com
booking
Calendly, MS BookingsAGPL-3.0Planned
Wilhelm FinanceGhostfolio
finance
Yahoo Finance, Portfolio PerformanceAGPL-3.0Planned
Wilhelm MailListmonk
newsletter
Mailchimp, SendGridAGPL-3.0Planned
Wilhelm NotifyNtfy
notify
Firebase FCM, PushoverApache-2.0 / GPL-2.0Planned
Wilhelm FormsFormbricks
forms
Typeform, Google FormsAGPL-3.0Planned
Wilhelm StatusUptime Kuma
monitoring
Pingdom, UptimeRobotMITLive
Wilhelm MonitorGrafanaDatadog, New RelicAGPL-3.0Live
Wilhelm LogsLoki + PromtailSplunk, Datadog LogsAGPL-3.0Live
Wilhelm AnalyticsPlausible
analytics
Google Analytics, HotjarAGPL-3.0Planned
Wilhelm VaultVaultwarden
vault
1Password, LastPass, BitwardenAGPL-3.0Planned
Wilhelm DesignPenpot
design
Figma, Adobe XDMPL-2.0Planned
Wilhelm PhotosImmich
photos
Google Photos, iCloud PhotosAGPL-3.0Planned
Wilhelm ProjectsPlane
projects
Jira, Linear, AsanaAGPL-3.0Planned
Wilhelm WebWilhelm Website
website
WordPress, SquarespaceMITLive

Architecture

Nextcloud is the kernel every other app plugs into; n8n orchestrates; NocoDB, Neo4j and Meilisearch hold and index the data; Traefik terminates HTTPS in front of everything.

From apps/README.md
══════════════════════════════════════════════════════════════════════
                   WILHELM CLOUD (Nextcloud)
                   The Kernel - SSO, Files, Calendar,
                   Contacts, Mail, Dashboard
══════════════════════════════════════════════════════════════════════
         │         │          │         │          │
         ▼         ▼          ▼         ▼          ▼
   ┌──────────┐ ┌────────┐ ┌──────┐ ┌───────┐ ┌────────┐
   │  Office  │ │ Board  │ │Vision│ │ Vault │ │Booking │
   │Collabora │ │Excali- │ │Recog.│ │Vault- │ │Cal.com │
   │          │ │draw    │ │      │ │warden │ │        │
   └──────────┘ └────────┘ └──┬───┘ └───────┘ └───┬────┘
                              │                    │
                              │  CalDAV Sync ◄─────┘
                              ▼
══════════════════════════════════════════════════════════════════════
             WILHELM AUTOMATE (n8n) - Orchestrates everything
══════════════════════════════════════════════════════════════════════
   │       │       │       │       │       │       │       │
   ▼       ▼       ▼       ▼       ▼       ▼       ▼       ▼
┌──────┐┌──────┐┌──────┐┌──────┐┌──────┐┌──────┐┌──────┐┌──────┐
│ Shop ││ CRM  ││ Mail ││Forms ││ Sign ││Notify││Finan.││Proj. │
│Medusa││Twenty││List- ││Form- ││Docu- ││Ntfy  ││Ghost-││Plane │
│      ││      ││monk  ││bricks││menso ││      ││folio ││      │
└──┬───┘└──┬───┘└──┬───┘└──┬───┘└──┬───┘└──┬───┘└──────┘└──────┘
   │       │       │       │       │       │
   ▼       ▼       ▼       ▼       ▼       ▼
══════════════════════════════════════════════════════════════════════
          WILHELM DATA (NocoDB) - Central data layer
══════════════════════════════════════════════════════════════════════
                   │              │
                   ▼              ▼
            ┌────────────┐ ┌──────────┐
            │   Graph    │ │  Search  │
            │   Neo4j    │ │  Meili-  │
            │(Relations) │ │  search  │
            └────────────┘ └─────┬────┘
                                 │
                   ┌─────────────┼─────────────┐
                   ▼             ▼             ▼
            ┌──────────┐ ┌──────────┐ ┌──────────┐
            │  Brain   │ │   OCR    │ │ Convert  │
            │  Ollama  │ │Tesseract │ │Gotenberg │
            │(Embedd.) │ │(Img→Txt) │ │(Doc→PDF) │
            └────┬─────┘ └──────────┘ └──────────┘
                 │
                 ▼
            ┌──────────┐
            │    AI    │
            │Open WebUI│
            └──────────┘

══════════════════════════════════════════════════════════════════════
                   Monitoring & Analytics
══════════════════════════════════════════════════════════════════════
┌──────────┐ ┌──────────┐ ┌──────────┐ ┌──────────┐ ┌──────────┐
│  Status  │ │ Monitor  │ │   Logs   │ │Analytics │ │   PDF    │
│  Uptime  │ │ Grafana  │ │ Loki +   │ │Plausible │ │Stirling  │
│  Kuma    │ │          │ │ Promtail │ │          │ │  PDF     │
└──────────┘ └──────────┘ └──────────┘ └──────────┘ └──────────┘

══════════════════════════════════════════════════════════════════════
                   Creative & Media
══════════════════════════════════════════════════════════════════════
┌──────────┐ ┌──────────┐ ┌──────────┐
│  Design  │ │  Photos  │ │   Web    │
│  Penpot  │ │  Immich  │ │ Wilhelm  │
│          │ │          │ │ Website  │
└──────────┘ └──────────┘ └──────────┘

══════════════════════════════════════════════════════════════════════
 WILHELM GATEWAY (Traefik) - HTTPS, Routing, Certificates
══════════════════════════════════════════════════════════════════════

Compliance

What each app can prove, and for whom. Hover a cell for scope and note. A certificate held by the vendor's cloud offering does not carry over to a self-hosted instance - the per-app notes say so where it matters.

certified formal certificate   attested audit report   compliant demonstrably compliant (DPA, feature set)   conformant conforms to the standard   vendor claim vendor statement only   in progress announced   planned announced

App21 CFR Part 11CCPADPAEAA / BFSGeIDAS (SES)ESIGN / UETAGDPRHIPAAISO 9241ISO/IEC 27001SOC 2 Type IIWCAG
ACIDconformant
Analyticsvendor claimcompliantcompliant
Blueduneconformant
Bookingvendor claimcompliantvendor claimattested
Wilhelm Intelligenceconformant
chatconformant
Wilhelm Cloudconformant
Codeflowconformant
CRMcompliantconformantin progress
Data Brokerconformant
Designcompliantconformant
Enterin progressconformantin progressin progressattestedin progress
eviconformant
Fabi AIconformant
Financevendor claim
Formscompliantvendor claimvendor claimvendor claim
garyn.aiin progressconformantin progressin progressin progress
homeconformant
HTML67conformant
imagegenconformant
Integrationsconformant
llmvendor claim
Mailcompliantcompliant
MarketingMachineconformant
Medicalconformant
Uptime Kumaconformant
n8n Workflowscompliantattested
newsletterconformant
NocoDBconformant
notifyconformant
o14n - open n8nconformant
OCR Gatewayconformant
pdfconformant
Photosconformant
Projectscompliantvendor claimcertifiedattested
Prometheusconformant
ragin progressconformantin progressin progressin progress
Wilhelm S3conformant
SAP Adapterconformant
searchconformant
settingsconformant
Amazing Shopcompliantconformant
Signvendor claimcompliantcompliantvendor claimvendor claim
storefrontconformant
swaggerconformant
TaskHQin progressconformantin progressin progressin progress
tellconformant
toolsconformant
Tusch3Din progressconformantin progressin progressin progress
Wilhelm UIconformant
Vaultconformant
websiteconformant
Website Builderin progressconformantin progressin progressin progress
WilheLLMconformant
Wilhelm MCP Serverconformant
wMovieconformant

The manifest standard

Every app is one folder under apps/ with one manifest.json validated against schema/app-manifest-v2.json. Tools derive the rest: tools/app-assets the icons, tools/app-preview the screenshots, scripts/generate-standalone.mjs the compose files, scripts/generate-desktop-app.mjs the desktop builds, tools/stack-docs this page.

id · domain · vendorFolder name, the self-explanatory domain term (booking, photos) and the upstream project name (calcom, immich).
name · description · version · tags · homepageWhat the store, the launcher and this page show.
licenseThree licences: service (the upstream), wrapper (the Wilhelm integration), wilhelm (Wilhelm-authored code).
type · categorync-app, external, infrastructure, hosted, embedded, spec … and the category the sidebar groups by.
icon · emoji · pixelIcon · primaryColorOne brand SVG is the source of every derived asset; the emoji and pixel icon serve the text and retro surfaces (TaskHQ start menu).
complianceCertifications with status (certified, attested, compliant, claimed, in progress) and scope (vendor, cloud, software, operator), plus an honest one-line assessment.
web · previewPublic page (serving copy of the asset set, OpenGraph card) and the preview media slots the App Store and website read.
componentsservice (image, port, health check), nextcloudApp, embed (subdomain, container, profile, auth gate), widgets (contributed HTML67 elements), vscode (presence inside Enter).
desktop · taskhqElectron desktop build and the TaskHQ desktop window.
resources · permissionsMemory, CPU, storage; host network, privileged mode, egress domains.
dependencies · mcp · oidcCapability · secretsRefsWhat the app needs and provides, the MCP server it contributes, its SSO role, and where its required secrets are declared.
marketplace · skinVisibility, pricing, support URL; slogan, logo, theme and agent persona.
signatureOptional signature over the canonicalised manifest.

Folder layout

apps/<id>/
  manifest.json        the one source of truth
  icon.svg             brand mark (manifest.icon)
  appinfo/             derived: appicon.svg, favicon.svg, favicon-32.png, apple-touch-icon.png, og-image.png, site.webmanifest
  preview/             desktop.png, mobile.png, gallery/, widgets/, SOURCES.md
  README.md            standalone header block (generated) + editable body
  doc/                 sources.md, reference notes, upstream docs
  docker-compose.yml   self-contained compose (generated)
  secrets.spec.yaml    required secrets - names and purpose, never values
  nextcloud/ service/  the Nextcloud app and the service code

New app: node scripts/new-app.mjs <id>. Validate: node scripts/validate-app-manifests.mjs. Rebuild this page: npm run docs:stack.

chat

Talk where the work happens.

Nextcloud appWilhelm coreProprietaryv2.0.0free

Wilhelm chat app

What it does

Chat is Open WebUI, the self-hosted chat interface that gives a team what the ChatGPT web app gives an individual - conversations, model switching, prompt library, documents you can ask questions about, image generation hooks - against whichever backend you choose.

In the Wilhelm stack it is embedded in Nextcloud as a thin app and talks to the stack's own model gateway (Wilhelm Intelligence) or directly to Ollama, so the model choice stays with the operator.

Features

Chat with any backend

OpenAI-compatible and Ollama backends; switch models per conversation.

Documents and RAG

Upload documents and ask questions over them.

Multi-user

Accounts, roles and shared prompt library.

Prompt library and tools

Reusable prompts, functions and image generation hooks.

Nextcloud embed

One login - the Nextcloud session is the authentication.

Why it is in the stack

  • Talk where the work happens: the chat UI inside the Nextcloud shell, next to files and mail.
  • Replaces ChatGPT and Copilot subscriptions with a self-hosted interface and a model choice that is yours.
  • Zero backend code of its own to maintain - a pure wrapper around a widely used upstream.

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs chat.

At a glance

Based onWilhelm-native - no upstream project
ReplacesChatGPT, Copilot · listed as Wilhelm AI in the ecosystem reference
Type · categoryNextcloud app · Wilhelm core
Licenceservice Proprietary  ·  wrapper Proprietary  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support/chat
Public URLhttps://ai.<your-domain>
Compose profileopen-webui
Nextcloud app idwilhelmopenwebui · Nextcloud 30-32
Folderapps/chat/manifest.json

Icon & assets

BrandBrand-SquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 📦Emoji #0369FF one brand SVG → tools/app-assetsappinfo/

Configuration

Embedding in Nextcloud

Registry id · labelopen-webui · Open WebUI (AI Chat)
Subdomainai
Containeropen-webui:8080
Embed-proxy port (localhost)8895
Compose profileopen-webui
Nextcloud config keyopenwebui_url

Nextcloud app

App idwilhelmopenwebui
Path.
Nextcloud versions30 - 32

Dependencies

Requiresnextcloud >=30

Skin & branding

SloganTalk where the work happens.
Themeprimary #0369FF  ·  mode system
Logo./appinfo/icon.svg

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.

Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idchat
domainchat
vendorwilhelm
namechat
descriptionWilhelm chat app
version2.0.0
licenseservice, wrapper, wilhelm
serviceProprietary
wrapperProprietary
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typenc-app
categorywilhelm-core
emoji📦
pixelIcon
............
.KKKKKKKKKK.
.KWWWWWWWWK.
.KWKKKKKWWK.
.KWKWWWKWWK.
.KWKWWWKWWK.
.KWKKKKKWWK.
.KWWKWWWWWK.
.KWWWWWWWWK.
.KKKKKKKKKK.
............
primaryColor#0369FF
tags[ ]
compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
componentsnextcloudApp, embed, vscode
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmopenwebui
path.
minNcVersion30
maxNcVersion32
embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile
idopen-webui
labelOpen WebUI (AI Chat)
ncConfigKeyopenwebui_url
subdomainai
containeropen-webui
containerPort8080
embedProxyPort8895
profileopen-webui
vscodeextensions, extension
extensions[ ]
extensionnull
dependenciesrequires, optional
requires1 item
0id, version
idnextcloud
version>=30
optional[ ]
skinslogan, logo, theme
sloganTalk where the work happens.
themeprimary, mode
primary#0369FF
modesystem
marketplacevisibility, pricing, supportUrl
visibilitypublic
pricingfree

Support  ·  apps/chat/

doc/ai-notes.md  ·  doc/api.md  ·  doc/sources.md

home

All of Wilhelm, one door.

Nextcloud appWilhelm coreProprietaryv2.0.0free

Wilhelm home app

What it does

Home is the stack's start screen: a Nextcloud app that turns the dashboard into a widget board - profile, photos, files, office, notes, calendar, quota, and the apps of the stack - configurable per user and per installation, with a 'create new document' flow that opens an office document in one click.

It is native Nextcloud: authentication and data come from the session, the front end aggregates the Activity, DAV, Deck, Calendar and Notes APIs directly, and a failing app leaves only its widget empty.

Features

Widget board

Per-user visible widgets; sensible defaults.

App tiles

Admin-wide overrides re-point tiles to Wilhelm apps without patching Nextcloud.

Create new

Pick a template, create the office file, land in the editor.

Aggregated APIs

Activity, files, deck, calendar and notes on one screen.

Quota and groups

Storage use and group membership at a glance.

Why it is in the stack

  • All of Wilhelm, one door - one start screen that pulls the stack together.
  • Pure Nextcloud-native: no extra service, no extra login.

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs home.

At a glance

Based onWilhelm-native - no upstream project
Type · categoryNextcloud app · Wilhelm core
Licenceservice Proprietary  ·  wrapper Proprietary  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support/home
Nextcloud app idwilhelmhome · Nextcloud 30-32
Folderapps/home/manifest.json

Icon & assets

BrandBrand-SquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 📦Emoji #0369FF one brand SVG → tools/app-assetsappinfo/

Configuration

Nextcloud app

App idwilhelmhome
Path.
Nextcloud versions30 - 32

Dependencies

Requiresnextcloud >=30

Skin & branding

SloganAll of Wilhelm, one door.
Themeprimary #0369FF  ·  mode system
Logo./appinfo/icon.svg

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.

Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idhome
domainhome
vendorwilhelm
namehome
descriptionWilhelm home app
version2.0.0
licenseservice, wrapper, wilhelm
serviceProprietary
wrapperProprietary
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typenc-app
categorywilhelm-core
emoji📦
pixelIcon
............
.KKKKKKKKKK.
.KWWWKKWWWK.
.KWWKWWKWWK.
.KWKWWWWKWK.
.KWKKKKKKWK.
.KWKWWWWKWK.
.KWKWGGWKWK.
.KWKKKKKKWK.
.KKKKKKKKKK.
............
primaryColor#0369FF
tags[ ]
compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
componentsnextcloudApp, vscode
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmhome
path.
minNcVersion30
maxNcVersion32
vscodeextensions, extension
extensions[ ]
extensionnull
dependenciesrequires, optional
requires1 item
0id, version
idnextcloud
version>=30
optional[ ]
skinslogan, logo, theme
sloganAll of Wilhelm, one door.
themeprimary, mode
primary#0369FF
modesystem
marketplacevisibility, pricing, supportUrl
visibilitypublic
pricingfree

Support  ·  apps/home/

doc/ai-notes.md  ·  doc/api.md  ·  doc/sources.md

HTML67

HTML, thought further.

SpecificationWilhelm coreProprietaryv0.1.0free

One base, two leaps. A standard the way C++/C#/TypeScript are (published spec + reference runtime, just not WHATWG-ratified), a superset of HTML5, not a fork, resolved at runtime by the @wilhelm/ui runtime. HTML6 = UI, presentation & text (components, <wl-include> native partials, GlyphUp as <wl-glyph>); HTML7 = living vocabularies (law/science, correctness layer). The umbrella over apps/ui + apps/wilhe-llm/glyphup. Spec: SPEC.md, live demo: apps/ui/index.html at localhost:4321/.

What it does

HTML67 is a published standard plus a reference runtime, not an app: a superset of HTML5 - no fork, no new browser - that adds the two layers HTML never got natively. HTML6 covers UI, presentation and text: cards, charts, maps, tabs, native partials and the GlyphUp text layer as bare tags. HTML7 covers living domain vocabularies - law, science, licences, units, citations - as a correctness layer the page carries itself.

Every HTML67 page is valid HTML5; one script upgrades the bare tags in place. The Wilhelm site, its editors and this documentation are written in it. A standard the way C++, C# or TypeScript are standards: published spec, reference implementation, just not WHATWG-ratified.

Features

120 elements on top of HTML5

Plus 32 web components and short-form aliases, generated and counted from the source.

One script, no build step

A single script tag; pages stay valid HTML5 and work in today's browsers.

Native partials and GlyphUp

<wl-include> for partials, <wl-glyph> for the GlyphUp annotation layer.

HTML7 vocabularies

<norm>, <cite>, <unit>, <license>, <frist> and friends resolve law, sources, units and deadlines.

Single-file distribution

The whole site bundles into one .html that runs from file://.

Governance

Spec, changelog, audit gates and a candidate list under a vocabulary freeze.

Why it is in the stack

  • HTML, thought further: a superset, documented candidly, including what it is not.
  • No bundler, no framework lock-in; disciplined vocabulary before any new tag ships.
  • The umbrella over Wilhelm UI and WilheLLM's GlyphUp.

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs html67.

At a glance

Based onWilhelm-native - no upstream project
Type · categorySpecification · Wilhelm core
Licenceservice Proprietary  ·  wrapper Proprietary  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Homepagewilhelm.tech
Tagshtml67standardspecglyphupuiwilhelm-core
Folderapps/html67/manifest.json

Icon & assets

BrandBrand-SquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 📄Emoji #0369FF one brand SVG → tools/app-assetsappinfo/

Configuration

Dependencies

Requiresui >=2
Providesspec

Skin & branding

SloganHTML, thought further.
Themeprimary #0369FF  ·  mode system
Logo./icon.svg

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.

Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idhtml67
domainhtml67
vendorwilhelm
nameHTML67
descriptionOne base, two leaps. A standard the way C++/C#/TypeScript are (published spec + reference runtime, just not WHATWG-ratified), a superset of HTML5, not a fork, resolved at runtime by the @wilhelm/ui runtime. HTML6 = UI, presentation & text (components, <wl-include> native partials, GlyphUp as <wl-glyph>); HTML7 = living vocabularies (law/science, correctness layer). The umbrella over apps/ui + apps/wilhe-llm/glyphup. Spec: SPEC.md, live demo: apps/ui/index.html at localhost:4321/.
version0.1.0
licenseservice, wrapper, wilhelm
serviceProprietary
wrapperProprietary
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typespec
categorywilhelm-core
emoji📄
pixelIcon
............
.KKKKKKKKKK.
.KWWWWWWWWK.
.KWWKWWKWWK.
.KWKWWWWKWK.
.KKWWWWWWKK.
.KWKWWWWKWK.
.KWWKWWKWWK.
.KWWWWWWWWK.
.KKKKKKKKKK.
............
primaryColor#0369FF
homepagewilhelm.tech
tagshtml67standardspecglyphupuiwilhelm-core
compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
dependenciesrequires, optional, provides
requires1 item
0id, version
idui
version>=2
optional[ ]
providesspec
skinslogan, logo, theme
sloganHTML, thought further.
themeprimary, mode
primary#0369FF
modesystem
marketplacevisibility, pricing
visibilitypublic
pricingfree
componentsvscode
vscodeextensions, extension
extensions[ ]
extensionnull

Homepage  ·  apps/html67/

doc/sources.md

imagegen

Pictures from words.

Nextcloud appWilhelm coreProprietaryv2.0.0free

Wilhelm imagegen app

What it does

ImageGen is ComfyUI, the node-graph interface for Stable Diffusion and related models, embedded in Nextcloud: text-to-image, image-to-image and whatever workflow you wire on the canvas, on your own GPU - the self-hosted counterpart to Midjourney or DALL·E.

Generation happens in the ComfyUI container; the Nextcloud app is a shell with one route. n8n drives it over the queue API with the generic HTTP node.

Features

Node-graph workflows

Checkpoint loader, prompts, sampler, VAE decode - compose any pipeline visually.

Stable Diffusion checkpoints

Bring your own models; runs on the GPU box under its own compose profile.

Queue API

Submit a prompt, poll history, fetch the result - scriptable from n8n.

Nextcloud embed

Clipboard access in the iframe; the session is the login.

Why it is in the stack

  • Pictures from words, on your own hardware - no per-image cloud credits.
  • Full ComfyUI workflow power, not a locked-down prompt box.
  • Appears as a normal app in the Nextcloud sidebar.

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs imagegen.

At a glance

Based onWilhelm-native - no upstream project
Type · categoryNextcloud app · Wilhelm core
Licenceservice Proprietary  ·  wrapper Proprietary  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support/imagegen
Public URLhttps://imagegen.<your-domain>
Compose profileimagegen
Nextcloud app idwilhelmimagegen · Nextcloud 30-32
Folderapps/imagegen/manifest.json

Icon & assets

BrandBrand-SquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 📦Emoji #0369FF one brand SVG → tools/app-assetsappinfo/

Configuration

Embedding in Nextcloud

Registry id · labelcomfyui · ComfyUI / ImageGen
Subdomainimagegen
Containercomfyui:8188
Embed-proxy port (localhost)8910
Compose profileimagegen
Nextcloud config keycomfyui_url

Nextcloud app

App idwilhelmimagegen
Path.
Nextcloud versions30 - 32

Dependencies

Requiresnextcloud >=30

Skin & branding

SloganPictures from words.
Themeprimary #0369FF  ·  mode system
Logo./appinfo/icon.svg

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.

Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idimagegen
domainimagegen
vendorwilhelm
nameimagegen
descriptionWilhelm imagegen app
version2.0.0
licenseservice, wrapper, wilhelm
serviceProprietary
wrapperProprietary
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typenc-app
categorywilhelm-core
emoji📦
pixelIcon
............
.KKKKKKKKKK.
.KWKKKKKKWK.
.KWKWWGWKWK.
.KWKWWWWKWK.
.KWKWKWWKWK.
.KWKKWKWKWK.
.KWKKKKKKWK.
.KWWWWWWWWK.
.KKKKKKKKKK.
............
primaryColor#0369FF
tags[ ]
compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
componentsnextcloudApp, embed, vscode
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmimagegen
path.
minNcVersion30
maxNcVersion32
embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile
idcomfyui
labelComfyUI / ImageGen
ncConfigKeycomfyui_url
subdomainimagegen
containercomfyui
containerPort8188
embedProxyPort8910
profileimagegen
vscodeextensions, extension
extensions[ ]
extensionnull
dependenciesrequires, optional
requires1 item
0id, version
idnextcloud
version>=30
optional[ ]
skinslogan, logo, theme
sloganPictures from words.
themeprimary, mode
primary#0369FF
modesystem
marketplacevisibility, pricing, supportUrl
visibilitypublic
pricingfree

Support  ·  apps/imagegen/

doc/ai-notes.md  ·  doc/api.md  ·  doc/n8n.md  ·  doc/sources.md

Wilhelm Techstack / Wilhelm core / MarketingMachine

MarketingMachine

Reach without friction.

Nextcloud appWilhelm coreProprietaryv2.0.0free

Central company operating system - D-DNA, media, outputs. Radically separates content from design: one source produces websites, flyers, business cards, social posts, legal texts and catalogues.

What it does

MarketingMachine is a central company operating system that separates content from design radically: one database - the D-DNA - holds everything that defines the company, and every output is generated from it: websites, flyers, business cards, social posts, legal texts, catalogues. A website and a flyer are the same thing; only the medium differs.

Today it is a thin UI skeleton with four sections; the logic is specified in seven specs that name the stack roles - n8n for generation, NocoDB as database, Neo4j for relations, Ollama for the AI 'advocates', Gotenberg for PDF, Tesseract for OCR.

Features

D-DNA

The single source of truth for brand, entities and content.

Entities and outputs

Manage what the company is; generate what it publishes.

Output pipeline

Print and web artefacts from one source.

Advocates

AI agents that draft and adapt content (spec).

Integrations hub

API and connectors to the rest of the stack (spec).

Why it is in the stack

  • Reach without friction: one source instead of copy-pasting brand content across tools.
  • Outputs are generated, not hand-maintained per medium.
  • Built entirely on self-hosted stack components; the specs are the roadmap, not the current state.

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs marketing.

At a glance

Based onWilhelm-native - no upstream project
Type · categoryNextcloud app · Wilhelm core
Licenceservice Proprietary  ·  wrapper Proprietary  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support/marketing
Nextcloud app idmarketingmachine · Nextcloud 30-32
Folderapps/marketing/manifest.json

Icon & assets

BrandBrandSquircleSquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 🧬Emoji #0369FF one brand SVG → tools/app-assetsappinfo/

Configuration

Nextcloud app

App idmarketingmachine
Path.
Nextcloud versions30 - 32

Dependencies

Requiresnextcloud >=30

Skin & branding

SloganReach without friction.
Themeprimary #0369FF  ·  mode system
Logo./appinfo/icon.svg

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.

Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idmarketing
domainmarketing
vendorwilhelm
nameMarketingMachine
descriptionCentral company operating system - D-DNA, media, outputs. Radically separates content from design: one source produces websites, flyers, business cards, social posts, legal texts and catalogues.
version2.0.0
licenseservice, wrapper, wilhelm
serviceProprietary
wrapperProprietary
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typenc-app
categorywilhelm-core
emoji🧬
pixelIcon
............
.KKKKKKKKKK.
.KWWKWWWWWK.
.KWKKWGWWWK.
.KKKKWWGWWK.
.KKKKWWGWWK.
.KWKKWGWWWK.
.KWWKWWWWWK.
.KWWWWWWWWK.
.KKKKKKKKKK.
............
primaryColor#0369FF
tags[ ]
compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
componentsnextcloudApp, vscode
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidmarketingmachine
path.
minNcVersion30
maxNcVersion32
vscodeextensions, extension
extensions[ ]
extensionnull
dependenciesrequires, optional
requires1 item
0id, version
idnextcloud
version>=30
optional[ ]
skinslogan, logo, theme
sloganReach without friction.
themeprimary, mode
primary#0369FF
modesystem
marketplacevisibility, pricing, supportUrl
visibilitypublic
pricingfree

README

The README is not in English - see apps/marketing/README.md.

Support  ·  apps/marketing/

doc/ai-notes.md  ·  doc/api.md  ·  doc/sources.md

notify

A heads-up when it counts.

Nextcloud appWilhelm coreProprietaryv2.0.0free

Wilhelm notify app

What it does

notify is ntfy, the self-hosted push notification service: publish a message to a topic over HTTP, and every phone, desktop or browser subscribed to that topic gets it - without Firebase, Pushover or any vendor holding the content.

The Kernel API wraps it in one push endpoint that n8n workflows and apps call with the stack token; the Nextcloud app embeds the ntfy web UI for reading and subscribing.

Features

Topics

Publish and subscribe by topic name; default topic for the stack.

Every device

Android and iOS apps, desktop and web - no account needed on the receiving side.

Kernel endpoint

One authenticated push call for the whole stack; title and message become an ntfy notification.

Priorities, tags, actions

Upstream features for richer notifications.

Why it is in the stack

  • A heads-up when it counts, without a third party reading your notifications.
  • One uniform endpoint any workflow can call; no per-message quota.

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs notify.

At a glance

Based onWilhelm-native - no upstream project
ReplacesFirebase FCM, Pushover · listed as Wilhelm Notify in the ecosystem reference
Type · categoryNextcloud app · Wilhelm core
Licenceservice Proprietary  ·  wrapper Proprietary  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support/notify
Public URLhttps://notify.<your-domain>
Compose profilentfy
Nextcloud app idwilhelmnotify · Nextcloud 30-32
Folderapps/notify/manifest.json

Icon & assets

BrandBrand-SquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 📦Emoji #0369FF one brand SVG → tools/app-assetsappinfo/

Configuration

Embedding in Nextcloud

Registry id · labelntfy · ntfy Notifications
Subdomainnotify
Containerntfy:80
Embed-proxy port (localhost)8898
Compose profilentfy
Nextcloud config keyntfy_url

Nextcloud app

App idwilhelmnotify
Path.
Nextcloud versions30 - 32

Dependencies

Requiresnextcloud >=30

Skin & branding

SloganA heads-up when it counts.
Themeprimary #0369FF  ·  mode system
Logo./appinfo/icon.svg

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.

Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idnotify
domainnotify
vendorwilhelm
namenotify
descriptionWilhelm notify app
version2.0.0
licenseservice, wrapper, wilhelm
serviceProprietary
wrapperProprietary
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typenc-app
categorywilhelm-core
emoji📦
pixelIcon
............
.KKKKKKKKKK.
.KWWWKKWWWK.
.KWWKKKKWWK.
.KWWKKKKWWK.
.KWWKKKKWWK.
.KWKKKKKKWK.
.KWWWKKWWWK.
.KWWWWWWWWK.
.KKKKKKKKKK.
............
primaryColor#0369FF
tags[ ]
compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
componentsnextcloudApp, embed, vscode
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmnotify
path.
minNcVersion30
maxNcVersion32
embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile
idntfy
labelntfy Notifications
ncConfigKeyntfy_url
subdomainnotify
containerntfy
containerPort80
embedProxyPort8898
profilentfy
vscodeextensions, extension
extensions[ ]
extensionnull
dependenciesrequires, optional
requires1 item
0id, version
idnextcloud
version>=30
optional[ ]
skinslogan, logo, theme
sloganA heads-up when it counts.
themeprimary, mode
primary#0369FF
modesystem
marketplacevisibility, pricing, supportUrl
visibilitypublic
pricingfree

Support  ·  apps/notify/

doc/ai-notes.md  ·  doc/api.md  ·  doc/n8n.md  ·  doc/sources.md

OCR Gateway

One gateway, all text recognition.

InfrastructureWilhelm coreApache-2.0v1.0.0freeinternal

One API gateway in front of all OCR engines (Tesseract, Stirling, PaddleOCR, Unlimited-OCR, Text-Extract) with file-type conversion and an optional Ollama post-processing pass.

What it does

OCR Gateway is one API in front of every text-recognition engine in the stack: Tesseract, Stirling PDF, PaddleOCR, Unlimited-OCR (a vision model) and plain text extraction. The caller picks an engine; the gateway detects the file type, converts Office documents through Gotenberg, renders multipage PDFs, routes to the engine, normalises the result and optionally runs an Ollama post-pass - the self-hosted counterpart to AWS Textract or Google Vision.

It is a dependency-free Node service in the style of the Kernel API; engines are plain URL adapters, so adding one never changes the API.

Features

One endpoint

POST a file with a name, choose an engine, get text, a searchable PDF or full JSON with blocks and confidence.

Five engines

text, stirling, tesseract, paddle, unlimited - CPU-fast or GPU-vision per request.

Conversion

Office and HTML inputs become PDF through Gotenberg; multipage PDFs are rendered page by page.

LLM post-pass

Optional Ollama step attached to the result.

Token auth and MCP

Stack token on every call; an MCP directory for agent access.

Why it is in the stack

  • One gateway, all text recognition - swap engines without touching callers.
  • Documents never leave the stack; GPU engines run on the GPU box under their own profile.

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs ocr.

At a glance

Based onWilhelm-native - no upstream project
Type · categoryInfrastructure · Wilhelm core
Licenceservice Apache-2.0  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support/ocr
Tagsocrtesseractpaddleocrstirlingdocumentextraction
Folderapps/ocr/manifest.json

Icon & assets

BrandBrand-SquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 🔍Emoji #0369FF one brand SVG → tools/app-assetsappinfo/

Configuration

Service

Compose fragment./service/compose.fragment.yml
Health checkhttp /healthz every 30s · timeout 5s · 3 retries

Desktop build (Electron)

Enabledno - opted out

Dependencies

Requiresnothing
Optionalpdf >=2, llm >=1

MCP (Model Context Protocol)

Servermcp/server.js
Transportstdio
Toolsocr_enginesocr_extract
EnvironmentOCR_URLWILHELM_API_TOKEN

Skin & branding

SloganOne gateway, all text recognition.
Themeprimary #0369FF  ·  mode system
Logo./icon.svg

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.

Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idocr
domainocr
vendorwilhelm
nameOCR Gateway
descriptionOne API gateway in front of all OCR engines (Tesseract, Stirling, PaddleOCR, Unlimited-OCR, Text-Extract) with file-type conversion and an optional Ollama post-processing pass.
version1.0.0
licenseservice, wilhelm
serviceApache-2.0
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typeinfrastructure
categorywilhelm-core
emoji🔍
pixelIcon
............
.KKKKKKKKKK.
.KWWWWWWWWK.
.KWWKKKKWWK.
.KWKWWWWKWK.
.KKWWKKWWKK.
.KWKWWWWKWK.
.KWWKKKKWWK.
.KWWWWWWWWK.
.KKKKKKKKKK.
............
primaryColor#0369FF
tagsocrtesseractpaddleocrstirlingdocumentextraction
compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
componentsservice, vscode
servicecompose, container, containerPort, profile, healthCheck
containerocr-gateway
containerPort3000
profileocr
healthChecktype, path, interval, timeout, retries
typehttp
path/healthz
interval30s
timeout5s
retries3
vscodeextensions, extension
extensions[ ]
extensionnull
desktopenabled
enabledfalse
dependenciesrequires, optional
requires[ ]
optional2 items
0id, version
idpdf
version>=2
1id, version
idllm
version>=1
mcpserver, transport, tools, env, grants
servermcp/server.js
transportstdio
toolsocr_enginesocr_extract
envOCR_URL, WILHELM_API_TOKEN
OCR_URL${OCR_URL:-http://ocr-gateway:3000}
WILHELM_API_TOKEN${WILHELM_API_TOKEN}
grants[ ]
skinslogan, logo, theme
sloganOne gateway, all text recognition.
themeprimary, mode
primary#0369FF
modesystem
marketplacevisibility, pricing, supportUrl
visibilityinternal
pricingfree

Standalone compose

Every service app can run on its own: cd apps/ocr && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.

docker-compose.yml
# OCR Gateway - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/ocr/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
#   cp .env.example .env && docker compose up -d
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
  ocr:
    build:
      context: ./service
    restart: unless-stopped
    env_file:
      - .env
    networks:
      - ocr
    # TODO: persistent volume(s) if this image stores state. e.g.:
    #   volumes: [ "ocr_data:/data" ]

networks:
  ocr:
    name: ocr
.env.example
# OCR Gateway - standalone env. Copy to .env and fill in.
# GENERATED by scripts/generate-standalone.mjs

# No declared secrets. Add image-specific env vars here as needed.

README

The README is not in English - see apps/ocr/README.md.

Support  ·  apps/ocr/

doc/ai-notes.md  ·  doc/sources.md

pdf

PDFs, done.

Nextcloud appWilhelm coreProprietaryv2.0.0free

Wilhelm pdf app

What it does

pdf is Stirling PDF embedded in Nextcloud - merge, split, compress, rotate, OCR, watermark, protect, extract, convert - plus Gotenberg behind the Kernel API for creating PDFs from URLs, HTML, Markdown and Office documents: what people open Adobe Acrobat or a web PDF tool for, on your own server.

The Nextcloud app is the UI shell; the Kernel API carries the programmable part with two paths - Stirling for manipulation, Gotenberg for generation - both behind the stack token and reachable from n8n.

Features

Manipulate

Merge, split, compress, rotate, reorder, watermark, password-protect.

OCR

Searchable PDFs, German by default.

Extract and inspect

Text, images and metadata.

Generate

URL, HTML, Markdown and Office to PDF via Gotenberg.

API

Base64 in and out for every operation; n8n-ready.

Why it is in the stack

  • PDFs, done - without uploading documents to a web tool.
  • Manipulation and generation behind one token-authenticated API.

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs pdf.

At a glance

Based onWilhelm-native - no upstream project
ReplacesAdobe Acrobat, SmallPDF · listed as Wilhelm PDF in the ecosystem reference
Type · categoryNextcloud app · Wilhelm core
Licenceservice Proprietary  ·  wrapper Proprietary  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support/pdf
Public URLhttps://pdf.<your-domain> · behind AppAPI auth
Compose profilestirling-pdf
Nextcloud app idwilhelmpdf · Nextcloud 30-32
Folderapps/pdf/manifest.json

Icon & assets

BrandBrand-SquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 📦Emoji #0369FF one brand SVG → tools/app-assetsappinfo/

Configuration

Embedding in Nextcloud

Registry id · labelstirling-pdf · Stirling PDF
Subdomainpdf
Containerstirling-pdf:8080
Embed-proxy port (localhost)8894
Compose profilestirling-pdf
Nextcloud config keypdf_url
Auth gateyes - served as ExApp behind AppAPI auth ({"id":"wilhelmpdf","adapter":"stirling-pdf-exapp","upstream":"http://stirling-pdf:8080","prefix":""})

Nextcloud app

App idwilhelmpdf
Path.
Nextcloud versions30 - 32

Desktop build (Electron)

Enabledyes
Start path/index.php/apps/wilhelmpdf/
Hide Nextcloud chromeyes

Dependencies

Requiresnextcloud >=30

Skin & branding

SloganPDFs, done.
Themeprimary #0369FF  ·  mode system
Logo./appinfo/icon.svg

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.

Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idpdf
domainpdf
vendorwilhelm
namepdf
descriptionWilhelm pdf app
version2.0.0
licenseservice, wrapper, wilhelm
serviceProprietary
wrapperProprietary
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typenc-app
categorywilhelm-core
emoji📦
pixelIcon
............
.KKKKKKKKKK.
.KWKKKKKWWK.
.KWKWWWKKWK.
.KWKWWWWKWK.
.KWKGGWWKWK.
.KWKGGGWKWK.
.KWKWWWWKWK.
.KWKKKKKKWK.
.KKKKKKKKKK.
............
primaryColor#0369FF
tags[ ]
compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
componentsnextcloudApp, embed, vscode
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmpdf
path.
minNcVersion30
maxNcVersion32
embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile, gate, exapp
idstirling-pdf
labelStirling PDF
ncConfigKeypdf_url
subdomainpdf
containerstirling-pdf
containerPort8080
embedProxyPort8894
profilestirling-pdf
gatetrue
exappid, adapter, upstream, prefix
idwilhelmpdf
adapterstirling-pdf-exapp
prefix
vscodeextensions, extension
extensions[ ]
extensionnull
desktopenabled, startPath, hideNextcloudChrome
enabledtrue
startPath/index.php/apps/wilhelmpdf/
hideNextcloudChrometrue
dependenciesrequires, optional
requires1 item
0id, version
idnextcloud
version>=30
optional[ ]
skinslogan, logo, theme
sloganPDFs, done.
themeprimary, mode
primary#0369FF
modesystem
marketplacevisibility, pricing, supportUrl
visibilitypublic
pricingfree

Support  ·  apps/pdf/

doc/ai-notes.md  ·  doc/api.md  ·  doc/n8n.md  ·  doc/sources.md

rag

Knowledge that answers.

Nextcloud appWilhelm coreProprietaryv2.0.0free

Wilhelm rag app

What it does

rag is the stack's knowledge base: semantic search and answers with sources over Nextcloud files, NocoDB records, shop products and the Wilhelm app documentation. The Nextcloud app embeds the Qdrant dashboard; the work happens in the Kernel API, which embeds documents with Ollama and stores the vectors in Qdrant - the self-hosted counterpart to Pinecone plus a hosted RAG service.

Agents reach it as an MCP tool; the Enter chat pulls it on demand rather than on every message. Ingest is idempotent and collections size themselves from the first embedding.

Features

Query and ask

Semantic search, or an answer generated with citations.

Ingest

Embed with a local model, upsert by stable id, collection created on first run.

Four collections

App docs, Nextcloud files, NocoDB records, shop products.

MCP tool

rag_search for any MCP-capable client, Enter included.

Local end to end

Ollama embeddings, Qdrant vectors, no hosted vector service.

Why it is in the stack

  • Knowledge that answers: your own files become answerable, with sources, without leaving the stack.
  • On-demand retrieval keeps chats fast; the index trigger endpoint is still a stub and says so.

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs rag.

At a glance

Based onWilhelm-native - no upstream project
Type · categoryNextcloud app · Wilhelm core
Licenceservice Proprietary  ·  wrapper Proprietary  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support/rag
Public URLhttps://vectors.<your-domain>
Compose profilerag
Nextcloud app idwilhelmrag · Nextcloud 30-32
Folderapps/rag/manifest.json

Icon & assets

BrandBrand-SquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 📦Emoji #0369FF one brand SVG → tools/app-assetsappinfo/

Configuration

Embedding in Nextcloud

Registry id · labelqdrant · Qdrant Vector DB
Subdomainvectors
Containerqdrant:6333
Embed-proxy port (localhost)8912
Compose profilerag
Nextcloud config keyqdrant_dash_url

Nextcloud app

App idwilhelmrag
Path.
Nextcloud versions30 - 32

Dependencies

Requiresnextcloud >=30

Skin & branding

SloganKnowledge that answers.
Themeprimary #0369FF  ·  mode system
Logo./appinfo/icon.svg

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
ISO/IEC 27001
Information security
in progresssoftwareWilhelm certification programme - implementation for all Wilhelm apps in progress.
WCAG
Accessibility
in progresssoftwareWilhelm certification programme - implementation for all Wilhelm apps in progress.
ISO 9241
Usability / ergonomics
in progresssoftwareWilhelm certification programme - implementation for all Wilhelm apps in progress.
EAA / BFSG
Accessibility
in progresssoftwareWilhelm certification programme - implementation for all Wilhelm apps in progress.

Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idrag
domainrag
vendorwilhelm
namerag
descriptionWilhelm rag app
version2.0.0
licenseservice, wrapper, wilhelm
serviceProprietary
wrapperProprietary
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typenc-app
categorywilhelm-core
emoji📦
pixelIcon
............
.KKKKKKKKKK.
.KWWWWWWWWK.
.KKKKWWKKKK.
.KKWWKKWWKK.
.KKWWKKWWKK.
.KKWWKKWWKK.
.KKKKKKKKKK.
.KWWWWWWWWK.
.KKKKKKKKKK.
............
primaryColor#0369FF
tags[ ]
compliancecertifications, note
certifications5 items
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
1id, status, scope, note
idiso-27001
statusin-progress
scopesoftware
noteWilhelm certification programme - implementation for all Wilhelm apps in progress.
2id, status, scope, note
idwcag
statusin-progress
scopesoftware
noteWilhelm certification programme - implementation for all Wilhelm apps in progress.
3id, status, scope, note
idiso-9241
statusin-progress
scopesoftware
noteWilhelm certification programme - implementation for all Wilhelm apps in progress.
4id, status, scope, note
ideaa
statusin-progress
scopesoftware
noteWilhelm certification programme - implementation for all Wilhelm apps in progress.
noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
componentsnextcloudApp, embed, vscode
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmrag
path.
minNcVersion30
maxNcVersion32
embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile
idqdrant
labelQdrant Vector DB
ncConfigKeyqdrant_dash_url
subdomainvectors
containerqdrant
containerPort6333
embedProxyPort8912
profilerag
vscodeextensions, extension
extensions[ ]
extensionnull
dependenciesrequires, optional
requires1 item
0id, version
idnextcloud
version>=30
optional[ ]
skinslogan, logo, theme
sloganKnowledge that answers.
themeprimary, mode
primary#0369FF
modesystem
marketplacevisibility, pricing, supportUrl
visibilitypublic
pricingfree

Support  ·  apps/rag/

doc/ai-notes.md  ·  doc/api.md  ·  doc/caret-rag.md  ·  doc/n8n.md  ·  doc/sources.md

settings

One place for every setting.

Nextcloud appWilhelm coreProprietaryv2.0.0free

Wilhelm settings app

What it does

settings is the Wilhelm admin panel inside Nextcloud's settings area: general, services, Nextcloud, branding and credentials sections that forward everything to the Kernel API - edit the central environment, list and restart Docker services, manage the credentials of every stack app - without a shell.

It has no business logic of its own; the Kernel is the single source of truth for configuration and Docker control.

Features

Environment editing

Central .env through the Kernel.

Services

Docker service list and restart control.

Credentials

n8n, NocoDB, Neo4j, database, Vaultwarden, Medusa, Plausible, Twenty, Immich and more in one place.

Branding

Stack-wide branding settings.

Why it is in the stack

  • One place for every setting, inside the login you already have.
  • No shell access needed for the everyday operations.

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs settings.

At a glance

Based onWilhelm-native - no upstream project
Type · categoryNextcloud app · Wilhelm core
Licenceservice Proprietary  ·  wrapper Proprietary  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support/settings
Nextcloud app idwilhelmsettings · Nextcloud 30-32
Folderapps/settings/manifest.json

Icon & assets

BrandBrand-SquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 📦Emoji #0369FF one brand SVG → tools/app-assetsappinfo/

Configuration

Nextcloud app

App idwilhelmsettings
Path.
Nextcloud versions30 - 32

Dependencies

Requiresnextcloud >=30

Skin & branding

SloganOne place for every setting.
Themeprimary #0369FF  ·  mode system
Logo./appinfo/icon.svg

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.

Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idsettings
domainsettings
vendorwilhelm
namesettings
descriptionWilhelm settings app
version2.0.0
licenseservice, wrapper, wilhelm
serviceProprietary
wrapperProprietary
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typenc-app
categorywilhelm-core
emoji📦
pixelIcon
............
.KKKKKKKKKK.
.KWWKWWKWWK.
.KWKKKKKKWK.
.KKKKWWKKKK.
.KKKWWWWKKK.
.KKKKWWKKKK.
.KWKKKKKKWK.
.KWWKWWKWWK.
.KKKKKKKKKK.
............
primaryColor#0369FF
tags[ ]
compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
componentsnextcloudApp, vscode
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmsettings
path.
minNcVersion30
maxNcVersion32
vscodeextensions, extension
extensions[ ]
extensionnull
dependenciesrequires, optional
requires1 item
0id, version
idnextcloud
version>=30
optional[ ]
skinslogan, logo, theme
sloganOne place for every setting.
themeprimary, mode
primary#0369FF
modesystem
marketplacevisibility, pricing, supportUrl
visibilitypublic
pricingfree

Support  ·  apps/settings/

doc/ai-notes.md  ·  doc/api.md  ·  doc/sources.md

swagger

APIs you can touch.

Nextcloud appWilhelm coreProprietaryv2.0.0free

Wilhelm swagger app

What it does

swagger is Swagger UI packaged as a Nextcloud app: the stack's own API explorer. It renders the OpenAPI specifications of the Wilhelm apps as interactive pages - browse endpoints, inspect schemas, try requests against the real API - behind the Nextcloud login, with no container or port of its own.

It stands in for hosted API-documentation portals such as SwaggerHub or ReadMe.

Features

Interactive docs

OpenAPI 2 and 3; try-it-out against live endpoints.

Multi-spec

A dropdown over the specs of every app.

Auth in the tester

API key, bearer and OAuth2 flows.

Deep links

Link to a single operation.

Why it is in the stack

  • APIs you can touch - one in-house explorer for the whole stack.
  • Zero extra infrastructure; rides along in Nextcloud.

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs swagger.

At a glance

Based onSwagger UI · source · docs
ReplacesPostman, ReadMe.io · listed as Wilhelm Docs in the ecosystem reference
Type · categoryNextcloud app · Wilhelm core
Licenceservice Proprietary  ·  wrapper Proprietary  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support/swagger
Compose profilen8n
Nextcloud app idwilhelmswagger · Nextcloud 30-32
Folderapps/swagger/manifest.json

Icon & assets

BrandBrand-SquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 📦Emoji #0369FF one brand SVG → tools/app-assetsappinfo/

Configuration

Nextcloud app

App idwilhelmswagger
Path.
Nextcloud versions30 - 32

Dependencies

Requiresnextcloud >=30

Skin & branding

SloganAPIs you can touch.
Themeprimary #0369FF  ·  mode system
Logo./appinfo/icon.svg

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.

Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idswagger
domainswagger
vendorwilhelm
nameswagger
descriptionWilhelm swagger app
version2.0.0
licenseservice, wrapper, wilhelm
serviceProprietary
wrapperProprietary
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typenc-app
categorywilhelm-core
emoji📦
pixelIcon
............
.KKKKKKKKKK.
.KWWKWWKWWK.
.KWKWWWWKWK.
.KWKWWWWKWK.
.KKWWWWWWKK.
.KWKWWWWKWK.
.KWKWWWWKWK.
.KWWKWWKWWK.
.KKKKKKKKKK.
............
primaryColor#0369FF
tags[ ]
compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
componentsnextcloudApp, vscode
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmswagger
path.
minNcVersion30
maxNcVersion32
vscodeextensions, extension
extensions[ ]
extensionnull
dependenciesrequires, optional
requires1 item
0id, version
idnextcloud
version>=30
optional[ ]
skinslogan, logo, theme
sloganAPIs you can touch.
themeprimary, mode
primary#0369FF
modesystem
marketplacevisibility, pricing, supportUrl
visibilitypublic
pricingfree

Upstream docs  ·  Upstream source  ·  Support  ·  apps/swagger/

doc/ai-notes.md  ·  doc/api.md  ·  doc/n8n.md  ·  doc/sources.md  ·  doc/swagger-reference.md

tools

Tools for all the small things.

Nextcloud appWilhelm coreProprietaryv2.0.0free

Wilhelm tools app

What it does

tools adds document conversion and PDF manipulation as right-click actions on files in Nextcloud: compress, OCR, split, rotate, merge, PDF to image and back via Stirling PDF; HTML, Markdown and Office to PDF and URL screenshots via Gotenberg. What people open Acrobat or a web converter for, where the files already live.

A single controller passes the file to the stack-internal service and returns the result as a download; operations are whitelisted so only the intended endpoints are reachable.

Features

14 operations

Whitelisted transforms registered as Nextcloud file actions.

Stirling PDF

Compress, OCR (German), split, rotate, merge, PDF and image conversion.

Gotenberg

HTML, Markdown, Office to PDF; URL to PDF.

Safe by design

Sanitised operation names, whitelist, timeouts.

Why it is in the stack

  • Tools for all the small things - without uploading files to a third-party web tool.
  • No per-document pricing; no Kernel, n8n or database coupling.

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs tools.

At a glance

Based onWilhelm-native - no upstream project
Type · categoryNextcloud app · Wilhelm core
Licenceservice Proprietary  ·  wrapper Proprietary  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support/tools
Nextcloud app idwilhelmtools · Nextcloud 30-32
Folderapps/tools/manifest.json

Icon & assets

BrandBrand-SquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 📦Emoji #0369FF one brand SVG → tools/app-assetsappinfo/

Configuration

Nextcloud app

App idwilhelmtools
Path.
Nextcloud versions30 - 32

Dependencies

Requiresnextcloud >=30

Skin & branding

SloganTools for all the small things.
Themeprimary #0369FF  ·  mode system
Logo./appinfo/icon.svg

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.

Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idtools
domaintools
vendorwilhelm
nametools
descriptionWilhelm tools app
version2.0.0
licenseservice, wrapper, wilhelm
serviceProprietary
wrapperProprietary
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typenc-app
categorywilhelm-core
emoji📦
pixelIcon
............
.KKKKKKKKKK.
.KWWWWKWKWK.
.KWWWWWKKWK.
.KWWWWKKWWK.
.KWWWKKWWWK.
.KWWKKWWWWK.
.KWKKWWWWWK.
.KKKWWWWWWK.
.KKKKKKKKKK.
............
primaryColor#0369FF
tags[ ]
compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
componentsnextcloudApp, vscode
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmtools
path.
minNcVersion30
maxNcVersion32
vscodeextensions, extension
extensions[ ]
extensionnull
dependenciesrequires, optional
requires1 item
0id, version
idnextcloud
version>=30
optional[ ]
skinslogan, logo, theme
sloganTools for all the small things.
themeprimary, mode
primary#0369FF
modesystem
marketplacevisibility, pricing, supportUrl
visibilitypublic
pricingfree

Support  ·  apps/tools/

doc/ai-notes.md  ·  doc/api.md  ·  doc/sources.md

website

Your site from one folder.

Nextcloud appWilhelm coreProprietaryv2.0.0free

Wilhelm website app

What it does

website turns a Nextcloud group folder into the source of the public website: editors publish and unpublish pages by working with normal files - a leading underscore means draft, no underscore means published - and the index file of each folder becomes its start page. Delivery is done by the Webwow backend behind the gateway.

Publishing is file management in a tool the team already uses: no CMS login, and the content keeps Nextcloud's sharing and versioning.

Features

Draft and publish

A file rename toggles the state; drafts are unmistakable at a glance.

Files integration

Sidebar tab and file action in the Files app.

Markdown pages

index.md or README.md per folder, rendered to HTML.

Shared source

One group folder as the site's content.

Why it is in the stack

  • Your site from one folder - publishing without a separate CMS.
  • Content stays in Nextcloud with sharing and versions.

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs website.

At a glance

Based onWilhelm-native - no upstream project
ReplacesWordPress, Squarespace · listed as Wilhelm Web in the ecosystem reference
Type · categoryNextcloud app · Wilhelm core
Licenceservice Proprietary  ·  wrapper Proprietary  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support/website
Compose profilenextcloud
Nextcloud app idwilhelmwebsite · Nextcloud 30-32
Folderapps/website/manifest.json

Icon & assets

BrandBrandSquircleSquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 📦Emoji #0369FF one brand SVG → tools/app-assetsappinfo/ · serving copy in ./site

Configuration

Nextcloud app

App idwilhelmwebsite
Path.
Nextcloud versions30 - 32

Dependencies

Requiresnextcloud >=30

Skin & branding

SloganYour site from one folder.
Themeprimary #0369FF  ·  mode system
Logo./appinfo/icon.svg

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.

Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idwebsite
domainwebsite
vendorwilhelm
namewebsite
descriptionWilhelm website app
version2.0.0
licenseservice, wrapper, wilhelm
serviceProprietary
wrapperProprietary
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typenc-app
categorywilhelm-core
emoji📦
pixelIcon
............
.KKKKKKKKKK.
.KWKWWWWWWK.
.KKKKKKKKKK.
.KWWWWWWWWK.
.KWKKKWWWWK.
.KWWWWWWWWK.
.KWKKKKKKWK.
.KWWWWWWWWK.
.KKKKKKKKKK.
............
............
primaryColor#0369FF
tags[ ]
compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
webpublicDir
publicDir./site
componentsnextcloudApp, vscode
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmwebsite
path.
minNcVersion30
maxNcVersion32
vscodeextensions, extension
extensions[ ]
extensionnull
dependenciesrequires, optional
requires1 item
0id, version
idnextcloud
version>=30
optional[ ]
skinslogan, logo, theme
sloganYour site from one folder.
themeprimary, mode
primary#0369FF
modesystem
marketplacevisibility, pricing, supportUrl
visibilitypublic
pricingfree

Support  ·  apps/website/

doc/ai-notes.md  ·  doc/api.md  ·  doc/sources.md

Wilhelm Techstack / Wilhelm core / Wilhelm MCP Server

Wilhelm MCP Server

The stack as a toolbox.

Nextcloud appWilhelm coreProprietaryv2.0.0free

Nextcloud wrapper for the Wilhelm MCP server (embeds the MCP dashboard).

What it does

Wilhelm MCP Server exposes the stack to AI clients as Model Context Protocol tools: Nextcloud files and calendar, NocoDB queries, Meilisearch, Ollama generation, ntfy notifications, ComfyUI image generation and optionally Qdrant search - one authenticated door for Claude, Enter or any MCP-capable client. Pure Node, no npm dependencies.

The Nextcloud app embeds its status dashboard; the server itself speaks SSE and streamable HTTP and shares the stack's token scheme with the Wilhelm API.

Features

Eight tools

nextcloud_files, nextcloud_calendar, nocodb_query, meilisearch, ollama_generate, ntfy_send, comfyui_generate, qdrant_search.

Two transports

SSE and streamable HTTP; JSON-RPC initialize, ping, tools/list, tools/call.

Diagnostics

Health and status pages.

Server-side credentials

Service credentials never reach the model client.

Optional auth

Enabled by setting the stack token.

Why it is in the stack

  • The stack as a toolbox - one MCP door into everything.
  • Zero dependencies keeps the attack surface and maintenance small.

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs wilhelmmcp.

At a glance

Based onWilhelm-native - no upstream project
Type · categoryNextcloud app · Wilhelm core
Licenceservice Proprietary  ·  wrapper Proprietary  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support/mcp
Public URLhttps://mcp.<your-domain>
Compose profilemcp
Nextcloud app idwilhelmmcp · Nextcloud 30-32
Tagsmcpai
Folderapps/wilhelmmcp/manifest.json

Icon & assets

BrandBrand-SquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 🤖Emoji #6366F1 one brand SVG → tools/app-assetsappinfo/

Configuration

Embedding in Nextcloud

Registry id · labelmcp · Wilhelm MCP Server
Subdomainmcp
Containerwilhelm-mcp:3040
Embed-proxy port (localhost)8911
Compose profilemcp
Nextcloud config keymcp_url

Nextcloud app

App idwilhelmmcp
Path.
Nextcloud versions30 - 32

Dependencies

Requiresnextcloud >=30

Skin & branding

SloganThe stack as a toolbox.
Themeprimary #6366F1  ·  mode system
Logo./app/img/app.svg

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.

Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idwilhelmmcp
domainmcp
vendorwilhelm
nameWilhelm MCP Server
descriptionNextcloud wrapper for the Wilhelm MCP server (embeds the MCP dashboard).
version2.0.0
licenseservice, wrapper, wilhelm
serviceProprietary
wrapperProprietary
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typenc-app
categorywilhelm-core
emoji🤖
pixelIcon
............
.KKKKKKKKKK.
.KWGWKWGWWK.
.KGWWKWWGWK.
.KWWWKWWWWK.
.KWWKKKWWWK.
.KWWKKKWWWK.
.KWKKKKKWWK.
.KWWWWWWWWK.
.KKKKKKKKKK.
............
primaryColor#6366F1
tagsmcpai
compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
componentsnextcloudApp, embed, vscode
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmmcp
path.
minNcVersion30
maxNcVersion32
embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile
idmcp
labelWilhelm MCP Server
ncConfigKeymcp_url
subdomainmcp
containerwilhelm-mcp
containerPort3040
embedProxyPort8911
profilemcp
vscodeextensions, extension
extensions[ ]
extensionnull
dependenciesrequires, optional
requires1 item
0id, version
idnextcloud
version>=30
optional[ ]
skinslogan, logo, theme
sloganThe stack as a toolbox.
themeprimary, mode
primary#6366F1
modesystem
marketplacevisibility, pricing, supportUrl
visibilitypublic
pricingfree

Support  ·  apps/wilhelmmcp/

doc/ai-notes.md  ·  doc/api.md  ·  doc/sources.md

Wilhelm UI

One standard, every interface.

Nextcloud appWilhelm coreProprietaryv2.0.0free

Wilhelm design system: Lit web components + Open Props design tokens, no bundler. Ships the shared <wl-*> elements, the --wl-* tokens and a zero-dependency dev environment with live reload (npm run dev). The front-end foundation for new Wilhelm apps instead of React.

What it does

Wilhelm UI is the shared front-end layer of every Wilhelm app: Lit web components and Open Props design tokens, served without a bundler. Every app gets the same <wl-*> elements and the same --wl-* tokens without inheriting a build step - deliberately React-free, and the foundation new Wilhelm apps are built on.

Its second face is HTML67: the same components as bare tags, one script, no build step. A Nextcloud app restyles the Nextcloud interface itself, and the runtime is vendored into apps such as WilheLLM so chat output shares the same markup and tokens.

Features

126 components

App shell, cards, panels, buttons, charts, maps, editors - per-component imports for lean apps.

Tokens

A thin Wilhelm semantic layer over Open Props; dark mode by preference; components reference tokens only.

Zero-dependency dev server

Live reload; the index page doubles as playground and gallery.

Three lines to adopt

Stylesheet, import map, module.

Nextcloud restyle

App-grid dropdown and slimmer header via the wilhelmui app.

Why it is in the stack

  • One standard, every interface - one visual language across the stack.
  • No bundler, no node_modules monster: browsers do import maps and custom properties natively.
  • Theming is central because components never hard-code values.

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs ui.

At a glance

Based onWilhelm-native - no upstream project
Type · categoryNextcloud app · Wilhelm core
Licenceservice Proprietary  ·  wrapper Proprietary  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Homepagewilhelm.tech
Supportwilhelm.tech/support/ui
Nextcloud app idwilhelmui · Nextcloud 30-32
Tagsfrontenddesign-systemlitopenpropswilhelm-core
Folderapps/ui/manifest.json

Icon & assets

BrandBrand-SquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 🎨Emoji #0369FF one brand SVG → tools/app-assetsappinfo/ · serving copy in .

Configuration

Nextcloud app

App idwilhelmui
Path.
Nextcloud versions30 - 32

Dependencies

Requiresnextcloud >=30
Providesnc-appui-component
Required byhtml67

Skin & branding

SloganOne standard, every interface.
Themeprimary #0369FF  ·  mode system
Logo./favicon.svg

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.

Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idui
domainui
vendorwilhelm
nameWilhelm UI
descriptionWilhelm design system: Lit web components + Open Props design tokens, no bundler. Ships the shared <wl-*> elements, the --wl-* tokens and a zero-dependency dev environment with live reload (npm run dev). The front-end foundation for new Wilhelm apps instead of React.
version2.0.0
licenseservice, wrapper, wilhelm
serviceProprietary
wrapperProprietary
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typenc-app
categorywilhelm-core
emoji🎨
pixelIcon
............
.KKKKKKKKK..
.KWWWWWWWK..
.KWKKKKKWK..
.KWWWWWWWK..
.KKKKKKKKK..
......K.....
......KK....
......KKK...
......KKKK..
......K.K...
............
primaryColor#0369FF
homepagewilhelm.tech
tagsfrontenddesign-systemlitopenpropswilhelm-core
compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
webpublicDir
publicDir.
componentsnextcloudApp, vscode
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmui
path.
minNcVersion30
maxNcVersion32
vscodeextensions, extension
extensions[ ]
extensionnull
dependenciesrequires, optional, provides
requires1 item
0id, version
idnextcloud
version>=30
optional[ ]
providesnc-appui-component
skinslogan, logo, theme
sloganOne standard, every interface.
themeprimary, mode
primary#0369FF
modesystem
marketplacevisibility, pricing, supportUrl
visibilitypublic
pricingfree

README

The README is not in English - see apps/ui/README.md.

Homepage  ·  Support  ·  apps/ui/

doc/ai-notes.md  ·  doc/api.md  ·  doc/sources.md  ·  doc/using-the-design-system.md

Wilhelm Techstack / Adapters / SAP Adapter

SAP Adapter

SAP in the Wilhelm stack - clean REST instead of RFC pain.

InfrastructureAdaptersApache-2.0v0.1.0free

Adapter that fronts a SAP / HANA system behind clean REST + MCP so the Wilhelm stack (Enter, n8n, Gary) can read and write it. Reusable 'adapter' pattern for proprietary systems.

What it does

SAP Adapter fronts an existing SAP / HANA system with clean REST and MCP so that Enter, n8n, Gary and the Kernel can read and write SAP without RFC, BAPI or the raw HANA SQL port. It is the canonical adapter pattern for proprietary systems - the same shape is meant to be reused for Dynamics, Salesforce or Lexware.

It ships a generic 'ERP' n8n node with a provider dropdown (SAP active, Odoo and Lexoffice planned), two workflows, an MCP server with query and read tools, a complete secrets specification, and an optional local HANA Express profile for development.

Features

REST

/healthz and /query; OData read path works, HANA-SQL path is a stub.

MCP

sap_query and sap_read for agents.

ERP node for n8n

One node, many providers - never renamed as providers are added.

Workflows

Scheduled HANA query into Wilhelm; inbound webhook into SAP.

Loopback only

Reachable through the Kernel API and the Nextcloud proxy.

Dev HANA

HANA Express under a separate profile, off by default.

Why it is in the stack

  • SAP in the Wilhelm stack - clean REST instead of RFC pain; the rest of the stack only ever talks to the adapter.
  • Connects to your existing SAP; no vendor cloud middleware.

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs sap.

At a glance

Based onWilhelm-native - no upstream project
Type · categoryInfrastructure · Adapters
Licenceservice Apache-2.0  ·  wilhelm Apache-2.0
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support
Docker imagewilhelm/sap-adapter:0.1.0
Nextcloud app idwilhelmsap · Nextcloud 30-32
Resourcesmemory 256Mi  ·  cpu 0.25  ·  storage 1Gi
Tagssaperpadapterhanan8n-node
Folderapps/sap/manifest.json

Icon & assets

BrandBrand-SquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 🧩Emoji #0FAAFF one brand SVG → tools/app-assetsappinfo/

Configuration

Service

Imagewilhelm/sap-adapter:0.1.0
Compose fragment./service/compose.fragment.yml
Init script./service/init.sh
Health checkhttp /healthz every 30s · timeout 5s · 3 retries

Nextcloud app

App idwilhelmsap
Path./nextcloud
Nextcloud versions30 - 32

Desktop build (Electron)

Enabledno - opted out

Resources & permissions

Memory · CPU · storage256Mi · 0.25 · 1Gi
Host networkno
Privilegedno
Egress domainsnone - no outbound connections declared

Dependencies

Requiresnextcloud >=30
Optionaln8n
Providesnc-appn8n-workflowsn8n-erp-nodemcp

MCP (Model Context Protocol)

Servermcp/server.js
Transportstdio
Toolssap_querysap_read

Single sign-on (OIDC)

As clientno
As providerno
Fallbacknone

Skin & branding

SloganSAP in the Wilhelm stack - clean REST instead of RFC pain.
Themeprimary #0FAAFF  ·  mode system
Logo./skin/logo.svg
Agent personaSAP-Adapter - “Ask me about HANA data.”

Secrets

Declared in apps/sap/secrets.spec.yaml - names and purpose only, values live in .env / the secret store.

NameRequiredPurpose
SAP_HOSTyesHostname/IP of the SAP HANA server the adapter connects to. Defaults to the local sap-hana container in dev. e.g. hana.example.com
SAP_PORTyesHANA SQL port (SQL/MDX). 39017 for HXE SYSTEMDB, 3<inst>15 for tenant DBs on standard SAP. e.g. 39017
SAP_USERyesHANA/SAP technical user the adapter authenticates as. Give it read-only rights unless write-back is needed. e.g. WILHELM_RO
SAP_PASSWORD 🔒yesPassword for SAP_USER. Store in the secret vault, never commit.
HANA_DByesTarget HANA database/tenant name. HXE for HANA Express. e.g. HXE
SAP_ODATA_BASEnoBase URL of the SAP OData (gateway) service, if OData reads are used. Enables the /query op=odata path. e.g. https://sap.example.com/sap/opu/odata/sap
HANA_ENCRYPTnoEnable TLS for the HANA SQL connection (encrypt=true). Required by HANA Cloud, usually off for local HANA Express. Set to true/1/yes. e.g. true
HANA_CONNECT_TIMEOUTnoHANA connect timeout in milliseconds for the @sap/hana-client driver. e.g. 15000
HANA_POOL_SIZEnoMax size of the reused HANA connection pool. e.g. 5
SAP_ADAPTER_PORTnoHost loopback port the adapter is published on (127.0.0.1 only). e.g. 8897
WILHELM_API_TOKEN 🔒noShared stack token. If set, the adapter requires it as Bearer on all non-health routes. Shared with the MCP server.

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.

Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idsap
domainsap
vendorwilhelm
nameSAP Adapter
descriptionAdapter that fronts a SAP / HANA system behind clean REST + MCP so the Wilhelm stack (Enter, n8n, Gary) can read and write it. Reusable 'adapter' pattern for proprietary systems.
version0.1.0
licenseservice, wilhelm
serviceApache-2.0
wilhelmApache-2.0
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typeinfrastructure
categoryadapter
emoji🧩
pixelIcon
............
.KKKKKKKKKK.
.KWWWKKWWWK.
.KWKKWWKKWK.
.KKWWWWWWKK.
.KKWWWWWWKK.
.KWKKWWKKWK.
.KWWWKKWWWK.
.KWWWWWWWWK.
.KKKKKKKKKK.
............
primaryColor#0FAAFF
tagssaperpadapterhanan8n-node
compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
componentsservice, nextcloudApp, vscode
serviceimage, compose, init, healthCheck
imagewilhelm/sap-adapter:0.1.0
healthChecktype, path, interval, timeout, retries
typehttp
path/healthz
interval30s
timeout5s
retries3
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmsap
minNcVersion30
maxNcVersion32
vscodeextensions, extension
extensions[ ]
extensionnull
desktopenabled
enabledfalse
resourcesmemory, cpu, storage
memory256Mi
cpu0.25
storage1Gi
permissionsneedsHostNetwork, needsPrivileged, egressDomains
needsHostNetworkfalse
needsPrivilegedfalse
egressDomains[ ]
dependenciesrequires, optional, provides
requires1 item
0id, version
idnextcloud
version>=30
optional1 item
0id
idn8n
providesnc-appn8n-workflowsn8n-erp-nodemcp
mcpserver, transport, tools, grants
servermcp/server.js
transportstdio
toolssap_querysap_read
grants[ ]
oidcCapabilityasClient, asProvider, fallback
asClientfalse
asProviderfalse
fallbacknone
skinslogan, logo, theme, agent
sloganSAP in the Wilhelm stack - clean REST instead of RFC pain.
themeprimary, mode
primary#0FAAFF
modesystem
agentname, greeting, persona
nameSAP-Adapter
greetingAsk me about HANA data.
marketplacevisibility, screenshots, pricing, supportUrl
visibilitypublic
screenshots[ ]
pricingfree

From the README

Adapter that fronts a SAP / HANA system behind clean REST + MCP so the rest of the Wilhelm stack (Enter, n8n, Gary, Kernel-API) can read and write it without touching RFC/BAPI or the raw HANA SQL port.

This is the canonical "adapter" pattern (category: "adapter"): a small always-on service that speaks a proprietary protocol on one side and clean Wilhelm REST/MCP on the other. Reuse it for Dynamics/Salesforce/etc.

Read on: apps/sap/README.md

Support  ·  apps/sap/

doc/ai-notes.md  ·  doc/api.md  ·  doc/sources.md

Wilhelm Techstack / AI / Wilhelm Intelligence

Wilhelm Intelligence

One gateway, every model.

InfrastructureAIApache-2.0v1.0.0free

OpenAI-compatible LLM gateway: OCR + RAG + pre-prompts in front of Claude

What it does

Wilhelm Intelligence is the stack's one door to language models: an OpenAI-compatible gateway with a pipeline behind it - OCR pre-processing for scans, retrieval from the knowledge base, a versioned Wilhelm persona as system prompt - in front of Claude, an n8n-routed backend, or a local Ollama model.

The value is the pipeline and the persona, not a model of its own. Every AI consumer in the stack (Open WebUI, n8n, WilheLLM, o14n) points its OpenAI base URL at the gateway and gets the same context, the same rules and the same switchable backend.

Features

OpenAI-compatible

/v1/models and /v1/chat/completions with streaming - existing clients work unchanged.

Switchable backend

Anthropic Claude (streaming, adaptive thinking, prompt caching), n8n routing, or Ollama for an offline, data-sovereign path.

Retrieval

Opt-in RAG against the Qdrant knowledge base through the Wilhelm API.

OCR pre-pass

Opt-in Tesseract for poor scans before the model sees them.

Versioned persona

The Wilhelm system prompt lives in prompts/system.md and is versioned like code.

n8n workflow

Ships a routing workflow so credentials and routing can be managed in the n8n editor.

Why it is in the stack

  • One gateway, every model: one API surface for all AI consumers, one place to switch providers.
  • A better pipeline around a best-in-class model instead of a weak model of one's own; honest about the terms it runs under.
  • The Ollama path keeps everything inside the house when it has to.

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs brain.

At a glance

Based onWilhelm-native - no upstream project
Type · categoryInfrastructure · AI
Licenceservice Apache-2.0  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support/brain
Docker imagewilhelm/brain:latest · port 3000
Tagsaillmgatewayragclaude
Folderapps/brain/manifest.json

Icon & assets

BrandBrand-SquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 🧠Emoji #7C3AED one brand SVG → tools/app-assetsappinfo/

Configuration

Service

Imagewilhelm/brain:latest
Port3000
Health checkhttp /healthz every 30s · timeout 5s · 3 retries

Dependencies

Requiresnothing
Optionaln8n, rag, llm, tools
Providesapi

Skin & branding

SloganOne gateway, every model.
Themeprimary #7C3AED  ·  mode system
Logo./appinfo/icon.svg

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.

Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idbrain
domainbrain
vendorwilhelm
nameWilhelm Intelligence
descriptionOpenAI-compatible LLM gateway: OCR + RAG + pre-prompts in front of Claude
version1.0.0
licenseservice, wilhelm
serviceApache-2.0
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typeinfrastructure
categoryai
emoji🧠
pixelIcon
............
.KKKKKKKKKK.
.KWWWWWWWWK.
.KWWKKKKWWK.
.KWKKWKWKWK.
.KWKWKKWKWK.
.KWKKWKKKWK.
.KWKWKWKWWK.
.KWWKKKKWWK.
.KKKKKKKKKK.
............
primaryColor#7C3AED
tagsaillmgatewayragclaude
compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
skinslogan, logo, theme
sloganOne gateway, every model.
themeprimary, mode
primary#7C3AED
modesystem
componentsservice
serviceimage, port, healthCheck
imagewilhelm/brain:latest
port3000
healthChecktype, path, interval, timeout, retries
typehttp
path/healthz
interval30s
timeout5s
retries3
dependenciesrequires, optional, provides
requires[ ]
optional4 items
0id
idn8n
1id
idrag
2id
idllm
3id
idtools
providesapi
marketplacevisibility, pricing, supportUrl
visibilitypublic
pricingfree

Standalone compose

Every service app can run on its own: cd apps/brain && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.

.env.example
# ── Wilhelm Intelligence (brain) ─────────────────────────────────────────────
# Gateway settings. The ANTHROPIC_API_KEY secret belongs in the root .env.

# Which model backend handles inference:
#   anthropic  - call Claude directly (real streaming, adaptive thinking, caching)
#   n8n        - route through the n8n workflow (flexible: swap models/prompts in the editor)
#   ollama     - local Ollama (offline / data-sovereign)
BRAIN_BACKEND=anthropic

# Default model id used when callers ask for "wilhelm-intelligence".
BRAIN_MODEL=claude-opus-4-8
BRAIN_MAX_TOKENS=64000

# REQUIRED for the anthropic backend - set this in the ROOT .env, not here.
ANTHROPIC_API_KEY=

# Optional bearer key to protect the gateway. Empty = open inside the Docker net.
BRAIN_API_KEY=

# Host port (bound to 127.0.0.1).
BRAIN_PORT=3032

# RAG retrieval (Wilhelm RAG / Qdrant). Off by default; flip to true to enable.
BRAIN_RAG_ENABLED=false
BRAIN_RAG_COLLECTION=wilhelm
BRAIN_RAG_TOP_K=5
BRAIN_WILHELM_API_URL=http://wilhelm-api:3000
# WILHELM_API_TOKEN is inherited from the root .env.

# OCR pre-processing (Tesseract). Off by default; Claude reads images natively.
BRAIN_OCR_ENABLED=false
# TESSERACT_URL inherited from root .env (default http://tesseract:3000)

# n8n routing backend.
BRAIN_INFER_WEBHOOK=http://n8n:5678/webhook/brain-infer

# Ollama fallback backend.
BRAIN_OLLAMA_URL=http://ollama:11434
OLLAMA_MODEL=

README

The README is not in English - see apps/brain/README.md.

Support  ·  apps/brain/

doc/ai-notes.md  ·  doc/api.md

Analytics

Web analytics without snooping.

External serviceAnalyticsAGPL-3.0v2.0.0free

Plausible Analytics in Nextcloud

What it does

Analytics is Plausible Community Edition: privacy-friendly, cookie-less web analytics that shows what matters on one screen - visitors, sources, pages, countries, devices, goals - instead of the report maze of Google Analytics. A lightweight script records page views and events; no personal data, no cookie banner.

The Wilhelm website and shop are its tracking sources. The Kernel holds the API key, so n8n can build weekly reports or mirror key figures into NocoDB.

Features

Cookie-less tracking

A script under 1 KB, no cookies, no personal data - GDPR, CCPA and PECR friendly by design.

One-page dashboard

Visitors, visits, page views, bounce rate, visit duration, top pages, sources, locations and devices.

Goals and funnels

Custom events, conversions and funnels; revenue attribution.

Stats API

Query metrics, dimensions and filters programmatically; real-time, aggregate, time-series and breakdown endpoints.

Public dashboards

Share a dashboard openly or by secret link.

Invite-only accounts

Registration is invite-only by default.

Why it is in the stack

  • Web analytics without snooping: the data stays in your stack, and there is nothing to consent to.
  • Replaces Google Analytics and Hotjar for the questions a company actually asks.
  • Embedded in Nextcloud with single sign-on; reachable for n8n and the Kernel through the stats API.

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs analytics.

At a glance

Based onPlausible Analytics · source · docs · API
ReplacesGoogle Analytics, Hotjar · listed as Wilhelm Analytics in the ecosystem reference
Type · categoryExternal service · Analytics
Licenceservice AGPL-3.0  ·  wrapper Proprietary  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support/analytics
Docker imageplausible/community:latest · port 8000
Public URLhttps://analytics.<your-domain>
Compose profileplausible
Nextcloud app idwilhelmanalytics · Nextcloud 30-32
Tagsanalyticsprivacy
Folderapps/analytics/manifest.json

Icon & assets

BrandBrand-SquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 📊Emoji #5850EC one brand SVG → tools/app-assetsappinfo/

Configuration

Service

Imageplausible/community:latest
Port8000
Init script./service/init-plausible.sh
Health checkhttp /api/health every 30s · timeout 5s · 3 retries

Embedding in Nextcloud

Registry id · labelplausible · Plausible Analytics
Subdomainanalytics
Containerplausible:8000
Embed-proxy port (localhost)8899
Compose profileplausible
Nextcloud config keyplausible_url

Nextcloud app

App idwilhelmanalytics
Path./nextcloud
Nextcloud versions30 - 32

Dependencies

Requiresnextcloud >=30
Optionalvault

Single sign-on (OIDC)

As clientyes
As providerno
Fallbackvaultwarden

Skin & branding

SloganWeb analytics without snooping.
Themeprimary #5850EC  ·  mode system
Logo./nextcloud/appinfo/icon.svg

Secrets

Declared in secretsRefs but apps/analytics/secrets.spec.yaml does not exist in the repository.

Compliance

StandardStatusScopeNote
GDPR
Privacy
compliantcloud offeringPrivacy-first without cookies or personal data (legally reviewed); hosting exclusively in the EU (Germany). source
DPA
Privacy
compliantcloud offeringPublic DPA, automatically valid for all cloud customers. source
CCPA
Privacy
vendor claimcloud offeringCCPA compliance according to the vendor, since no personal data is collected. source

Strong privacy story by design; formal audits such as SOC 2 or ISO 27001 do not exist.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idanalytics
domainanalytics
vendorplausible
nameAnalytics
descriptionPlausible Analytics in Nextcloud
version2.0.0
licenseservice, wrapper, wilhelm
serviceAGPL-3.0
wrapperProprietary
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typeexternal
categoryanalytics
emoji📊
pixelIcon
............
.KKKKKKKKKK.
.KWWWWWWWWK.
.KWWWWWWKWK.
.KWWWWWWKWK.
.KWWWWKWKWK.
.KWWWWKWKWK.
.KWWKWKWKWK.
.KWWKWKWKWK.
.KKKKKKKKKK.
............
primaryColor#5850EC
tagsanalyticsprivacy
compliancecertifications, note
certifications3 items
0id, status, scope, source, note
idgdpr
statuscompliant
scopecloud
notePrivacy-first without cookies or personal data (legally reviewed); hosting exclusively in the EU (Germany).
1id, status, scope, source, note
idgdpr-avv
statuscompliant
scopecloud
notePublic DPA, automatically valid for all cloud customers.
2id, status, scope, source, note
idccpa
statusclaimed
scopecloud
noteCCPA compliance according to the vendor, since no personal data is collected.
noteStrong privacy story by design; formal audits such as SOC 2 or ISO 27001 do not exist.
componentsservice, nextcloudApp, embed, vscode
serviceimage, port, healthCheck, init
imageplausible/community:latest
port8000
healthChecktype, path, interval, timeout, retries
typehttp
path/api/health
interval30s
timeout5s
retries3
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmanalytics
minNcVersion30
maxNcVersion32
embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile
idplausible
labelPlausible Analytics
ncConfigKeyplausible_url
subdomainanalytics
containerplausible
containerPort8000
embedProxyPort8899
profileplausible
vscodeextensions, extension
extensions[ ]
extensionnull
dependenciesrequires, optional
requires1 item
0id, version
idnextcloud
version>=30
optional1 item
0id
idvault
oidcCapabilityasClient, asProvider, fallback
asClienttrue
asProviderfalse
fallbackvaultwarden
secretsRefs./secrets.spec.yaml
skinslogan, logo, theme
sloganWeb analytics without snooping.
themeprimary, mode
primary#5850EC
modesystem
marketplacevisibility, screenshots, pricing, supportUrl
visibilitypublic
screenshots[ ]
pricingfree

Standalone compose

Every service app can run on its own: cd apps/analytics && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.

docker-compose.yml
# Analytics - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/analytics/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
#   cp .env.example .env && docker compose up -d
#   → http://localhost:${ANALYTICS_PORT:-8000}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
  analytics:
    image: plausible/community:latest
    restart: unless-stopped
    env_file:
      - .env
    ports:
      - "${ANALYTICS_PORT:-8000}:8000"
    healthcheck:
      test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:8000/api/health"]
      interval: 30s
      timeout: 5s
      retries: 3
      start_period: 20s
    networks:
      - analytics
    # TODO: persistent volume(s) if this image stores state. e.g.:
    #   volumes: [ "analytics_data:/data" ]

networks:
  analytics:
    name: analytics
.env.example
# Analytics - standalone env. Copy to .env and fill in.
# GENERATED by scripts/generate-standalone.mjs

# Host port the app is published on.
ANALYTICS_PORT=8000

# Required secrets are specified in:
#   ./secrets.spec.yaml
# Add the matching KEY=VALUE lines here.

README

The README is not in English - see apps/analytics/README.md.

Upstream docs  ·  Upstream API  ·  Upstream source  ·  Support  ·  apps/analytics/

doc/ai-notes.md  ·  doc/analytics-reference.md  ·  doc/api.md  ·  doc/n8n.md  ·  doc/sources.md

Wilhelm Techstack / Automation / n8n Workflows

n8n Workflows

Workflows that click.

External serviceAutomationFair-Code-SULv2.0.0free

n8n workflow builder in Nextcloud

What it does

n8n is the workflow automation platform the Wilhelm stack uses where others use Zapier, Make or Power Automate: a visual editor in which triggers (a webhook, a schedule, a new mail, a form submission) are wired to nodes that call APIs, transform data, branch, loop and write results back - with several hundred integrations built in and a code node for everything else.

Its AI nodes make it an agent builder as well: an AI Agent node with a chat model, memory, tools and a structured output parser can classify mails, answer questions over your data or drive multi-step tasks, using the stack's own model gateway or any provider.

Features

Visual workflow editor

Drag nodes onto a canvas, connect them, run them step by step and inspect the data flowing through every edge.

Triggers

Webhooks, schedules, manual runs, chat messages, app events (mail received, record created, form submitted).

Hundreds of integrations

Native nodes for the apps in this stack (Nextcloud, NocoDB, Twenty, Plane, Documenso, Cal.com …) and for external services.

Logic and code

If, switch, merge, loop, wait; JavaScript or Python code nodes; expressions everywhere.

AI agents

AI Agent node with chat model, memory, tools and structured output; chat trigger for conversational workflows.

Executions and error handling

Execution history with the data of every node, retries, error workflows.

Credentials and variables

Centrally stored, encrypted credentials; environment variables per instance.

Templates

A library of ready-made workflows to start from.

Why it is in the stack

  • Wilhelm Automate: n8n orchestrates the whole stack - shop, CRM, mail, forms, signatures, notifications, finance and projects all connect through it.
  • Self-hosted under n8n's sustainable-use licence: no per-task pricing, your credentials and data stay on your server.
  • Embedded in Nextcloud with single sign-on; the Wilhelm API and every app's n8n notes (doc/n8n.md) document the available triggers and actions.

Screenshots

An AI agent workflow in the editor
An AI agent workflow in the editor

A chat trigger feeds an AI Agent node; the agent is wired to a chat model, a window buffer memory, a search tool and a sub-workflow tool. An If node routes the result to a success or failure message. The Chat button at the bottom runs the workflow interactively.

01-workflow-editor.jpg
A minimal workflow
A minimal workflow

Manual trigger, a Twitter node that creates a tweet, an If node that branches on the result, and a NoOp - the shape every automation has: trigger, action, decision.

02-example-workflow.jpg
Classify incoming messages with an agent
Classify incoming messages with an agent

A webhook receives a message; an AI Agent with a chat model and a structured output parser calculates its category and priority, returning JSON the following nodes can act on.

03-ai-workflow.jpg
Describe a workflow, get it built
Describe a workflow, get it built

The n8n AI assistant turns a prose description (fetch AI news every morning, summarise, generate an image, send to Telegram, keep a chat history) into nodes, connections and parameters, with setup instructions for the credentials it needs.

04-ai-builder.jpg

Screenshots are the upstream project's official product shots (see preview/SOURCES.md) until the stack runs with demo data and tools/app-preview shoots real Wilhelm screens. Images © their respective projects.

At a glance

Based onn8n · source · docs · API
ReplacesZapier, Make, Power Automate · listed as Wilhelm Automate in the ecosystem reference
Type · categoryExternal service · Automation
Licenceservice Fair-Code-SUL  ·  wrapper Proprietary  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support/n8n
Docker imagen8nio/n8n:latest · port 5678
Public URLhttps://n8n.<your-domain>
Compose profilen8n
Nextcloud app idwilhelmn8n · Nextcloud 30-32
Tagsautomationworkflows
Folderapps/n8n/manifest.json

Icon & assets

BrandBrandSquircleSquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 🔗Emoji #EA4B71 one brand SVG → tools/app-assetsappinfo/

Configuration

Service

Imagen8nio/n8n:latest
Port5678
Health checkhttp /healthz every 30s · timeout 5s · 3 retries

Embedding in Nextcloud

Registry id · labeln8n · n8n Workflow Engine
Subdomainn8n
Containern8n:5678
Embed-proxy port (localhost)8891
Compose profilen8n
Nextcloud config keyn8n_url

Nextcloud app

App idwilhelmn8n
Path./nextcloud
Nextcloud versions30 - 32

Desktop build (Electron)

Enabledyes
Start path/index.php/apps/wilhelmn8n/
Hide Nextcloud chromeyes

Dependencies

Requiresnextcloud >=30
Optionalvault

Single sign-on (OIDC)

As clientyes
As providerno
Fallbackvaultwarden

Skin & branding

SloganWorkflows that click.
Themeprimary #EA4B71  ·  mode system
Logo./nextcloud/appinfo/icon.svg

Secrets

Declared in secretsRefs but apps/n8n/secrets.spec.yaml does not exist in the repository.

Compliance

StandardStatusScopeNote
SOC 2 Type II
Information security
attestedcloud offeringAnnual SOC 2 Type II audit for n8n Cloud (SOC 3 report public, report via trust.n8n.io); does not apply to self-hosted instances. source
GDPR
Privacy
compliantcloud offeringDPA published for n8n Cloud; for self-hosting n8n publishes a CAIQ self-assessment questionnaire. source

Certificates apply to n8n Cloud - the self-hosted instance does not inherit them but benefits from the same software controls.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idn8n
domainn8n
vendorn8n
namen8n Workflows
descriptionn8n workflow builder in Nextcloud
version2.0.0
licenseservice, wrapper, wilhelm
serviceFair-Code-SUL
wrapperProprietary
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typeexternal
categoryautomation
emoji🔗
pixelIcon
............
.KKK........
.KWK.KKK....
.KKKKKWK....
...KKKKKKK..
......KKKWK.
........KKK.
............
primaryColor#EA4B71
tagsautomationworkflows
compliancecertifications, note
certifications2 items
0id, status, scope, source, note
idsoc2-type2
statusattested
scopecloud
noteAnnual SOC 2 Type II audit for n8n Cloud (SOC 3 report public, report via trust.n8n.io); does not apply to self-hosted instances.
1id, status, scope, source, note
idgdpr
statuscompliant
scopecloud
noteDPA published for n8n Cloud; for self-hosting n8n publishes a CAIQ self-assessment questionnaire.
noteCertificates apply to n8n Cloud - the self-hosted instance does not inherit them but benefits from the same software controls.
componentsservice, nextcloudApp, embed, vscode
serviceimage, port, healthCheck
imagen8nio/n8n:latest
port5678
healthChecktype, path, interval, timeout, retries
typehttp
path/healthz
interval30s
timeout5s
retries3
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmn8n
minNcVersion30
maxNcVersion32
embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile
idn8n
labeln8n Workflow Engine
ncConfigKeyn8n_url
subdomainn8n
containern8n
containerPort5678
embedProxyPort8891
profilen8n
vscodeextensions, extension
extensions[ ]
extensionnull
desktopenabled, startPath, hideNextcloudChrome
enabledtrue
startPath/index.php/apps/wilhelmn8n/
hideNextcloudChrometrue
dependenciesrequires, optional
requires1 item
0id, version
idnextcloud
version>=30
optional1 item
0id
idvault
oidcCapabilityasClient, asProvider, fallback
asClienttrue
asProviderfalse
fallbackvaultwarden
secretsRefs./secrets.spec.yaml
skinslogan, logo, theme
sloganWorkflows that click.
themeprimary, mode
primary#EA4B71
modesystem
previewdir, gallery
gallery4 items
0src, caption, kind
captionWorkflow editor
kinddesktop
1src, caption, kind
captionExample workflow
kinddesktop
2src, caption, kind
captionAI workflow with an agent
kinddesktop
3src, caption, kind
captionAI workflow builder
kinddesktop
marketplacevisibility, screenshots, pricing, supportUrl

Standalone compose

Every service app can run on its own: cd apps/n8n && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.

docker-compose.yml
# n8n Workflows - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/n8n/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
#   cp .env.example .env && docker compose up -d
#   → http://localhost:${N8N_PORT:-5678}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
  n8n:
    image: n8nio/n8n:latest
    restart: unless-stopped
    env_file:
      - .env
    ports:
      - "${N8N_PORT:-5678}:5678"
    healthcheck:
      test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:5678/healthz"]
      interval: 30s
      timeout: 5s
      retries: 3
      start_period: 20s
    networks:
      - n8n
    # TODO: persistent volume(s) if this image stores state. e.g.:
    #   volumes: [ "n8n_data:/data" ]

networks:
  n8n:
    name: n8n
.env.example
# n8n Workflows - standalone env. Copy to .env and fill in.
# GENERATED by scripts/generate-standalone.mjs

# Host port the app is published on.
N8N_PORT=5678

# Required secrets are specified in:
#   ./secrets.spec.yaml
# Add the matching KEY=VALUE lines here.

README

The README is not in English - see apps/n8n/README.md.

Upstream docs  ·  Upstream API  ·  Upstream source  ·  Support  ·  apps/n8n/

doc/ai-notes.md  ·  doc/api.md  ·  doc/n8n-reference.md  ·  doc/n8n.md  ·  doc/restart-runbook.md  ·  doc/sources.md

Wilhelm Techstack / Automation / o14n - open n8n

o14n - open n8n

Automation, fair and open.

Hosted appAutomationApache-2.0v0.1.0free

Fair-code-free n8n alternative: a React-Flow node editor that visualises APIs Swagger-UI-style, driving a headless Node-RED engine (Apache-2.0) over its Admin API.

What it does

o14n - open n8n - is the licence-clean alternative to n8n for the cases where n8n's sustainable-use licence is a problem: Node-RED's battle-tested editor and engine, Wilhelm-skinned, with a node pack that turns any API into nodes from its OpenAPI spec, speaks to the stack's model gateway, and can hand off to n8n when an n8n integration is the shortest path.

The value is deliberately in the node pack, not in a reimplemented editor: an earlier custom front end was lossy and was removed. Node-RED stays unforked, so upstream improvements arrive for free.

Features

OpenAPI node

Load a spec by URL or inline, pick an operation, map path, query and body parameters.

LangChain node

Talk to the Wilhelm Intelligence gateway with templated system prompts, tool calling and RAG sources.

n8n bridge node

Trigger an n8n workflow by webhook instead of rebuilding its integrations.

Shared auth node

Bearer, API key or basic credentials once, reused across nodes.

Whole Node-RED ecosystem

Every node-red-contrib package works.

Wilhelm skin

Editor theme and CSS overlay; no fork.

Why it is in the stack

  • Automation, fair and open: Apache-2.0 end to end, commercially unrestricted.
  • APIs become nodes automatically from their spec.
  • Roadmap stated: full dark theme, OIDC in front of the editor, OpenAPI import as subflow.

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs o14n.

At a glance

Based onWilhelm-native - no upstream project
Type · categoryHosted app · Automation
Licenceservice Apache-2.0  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Homepagewilhelm.tech/o14n
Supportwilhelm.tech/support/o14n
Docker imagewilhelm/o14n:latest · port 5680
Resourcesmemory 256Mi  ·  cpu 0.25  ·  storage 1Gi
Tagsautomationworkflowsnode-editoropenapireact-flownode-red
Folderapps/o14n/manifest.json

Icon & assets

BrandBrand-SquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 🪢Emoji #00B8A9 one brand SVG → tools/app-assetsappinfo/

Configuration

Service

Imagewilhelm/o14n:latest
Port5680
Compose fragment./service/compose.fragment.yml
Health checkhttp /healthz every 30s · timeout 5s · 3 retries

Resources & permissions

Memory · CPU · storage256Mi · 0.25 · 1Gi
Host networkno
Privilegedno
Egress domainsnone - no outbound connections declared

Dependencies

Requiresnothing
Optionaln8n, swagger, nocodb
Providesn8n-workflowsapiui-component

Single sign-on (OIDC)

As clientyes
As providerno
Fallbacknone

Skin & branding

SloganAutomation, fair and open.
Themeprimary #00B8A9  ·  mode system
Logo./appinfo/icon.svg

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.

Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

ido14n
domaino14n
vendorwilhelm
nameo14n - open n8n
descriptionFair-code-free n8n alternative: a React-Flow node editor that visualises APIs Swagger-UI-style, driving a headless Node-RED engine (Apache-2.0) over its Admin API.
version0.1.0
licenseservice, wilhelm
serviceApache-2.0
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typehosted
categoryautomation
emoji🪢
pixelIcon
............
.KKKKKKKKKK.
.KKKWWWWWWK.
.KKKKWWWWWK.
.KWWWKKWWWK.
.KWWWKKKWWK.
.KWWWWWWKKK.
.KWWWWWWKKK.
.KWWWWWWWWK.
.KKKKKKKKKK.
............
primaryColor#00B8A9
tagsautomationworkflowsnode-editoropenapireact-flownode-red
compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
previewdir, desktop, mobile, capture
dir./preview
desktop./preview/desktop.png
mobile./preview/mobile.png
captureurl, wait
wait1500
componentsservice, vscode
serviceimage, port, compose, healthCheck
imagewilhelm/o14n:latest
port5680
healthChecktype, path, interval, timeout, retries
typehttp
path/healthz
interval30s
timeout5s
retries3
vscodeextensions, extension
extensions[ ]
extensionnull
resourcesmemory, cpu, storage
memory256Mi
cpu0.25
storage1Gi
permissionsneedsHostNetwork, needsPrivileged, egressDomains
needsHostNetworkfalse
needsPrivilegedfalse
egressDomains[ ]
dependenciesrequires, optional, provides
requires[ ]
optional3 items
0id
idn8n
1id
idswagger
2id
idnocodb
providesn8n-workflowsapiui-component
oidcCapabilityasClient, asProvider, fallback
asClienttrue
asProviderfalse
fallbacknone
skinslogan, logo, theme
sloganAutomation, fair and open.
themeprimary, mode
primary#00B8A9
modesystem
marketplacevisibility, screenshots, pricing, supportUrl
visibilitypublic
screenshots[ ]
pricingfree

Standalone compose

Every service app can run on its own: cd apps/o14n && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.

docker-compose.yml
# o14n - open n8n - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/o14n/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
#   cp .env.example .env && docker compose up -d
#   → http://localhost:${O14N_PORT:-5680}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
  o14n:
    image: wilhelm/o14n:latest
    restart: unless-stopped
    env_file:
      - .env
    ports:
      - "${O14N_PORT:-5680}:5680"
    healthcheck:
      test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:5680/healthz"]
      interval: 30s
      timeout: 5s
      retries: 3
      start_period: 20s
    networks:
      - o14n
    # TODO: persistent volume(s) if this image stores state. e.g.:
    #   volumes: [ "o14n_data:/data" ]

networks:
  o14n:
    name: o14n
.env.example
# o14n - open n8n - standalone env. Copy to .env and fill in.
# GENERATED by scripts/generate-standalone.mjs

# Host port the app is published on.
O14N_PORT=5680

# No declared secrets. Add image-specific env vars here as needed.

README

The README is not in English - see apps/o14n/README.md.

Homepage  ·  Support  ·  apps/o14n/

doc/ai-notes.md  ·  doc/api.md  ·  doc/n8n-licensing.md  ·  doc/proposal.md  ·  doc/sources.md

Tusch3D

CAD in the browser, with a pen.

External serviceCADAGPL-3.0v0.1.0free

Browser-based CAD with touch and pencil support, in the tradition of German precision tools. Based on Chili3D (AGPL-3.0) - the Tusch3D bridge is a separate sidecar with a clearly separated licence boundary.

What it does

Tusch3D is browser-based CAD with touch and pencil support - the self-hostable alternative to Shapr3D, named after Tusche, the black drafting ink of classical technical drawing. Underneath runs the unmodified Chili3D engine: the OpenCascade kernel compiled to WebAssembly with a three.js renderer, entirely client-side.

Wilhelm adds a slim sidecar bridge for touch gestures and pencil pressure behind a deliberate licence boundary: the AGPL upstream image stays untouched, the MIT bridge talks to it only over HTTP, WebSocket and postMessage.

Features

Primitives and sketching

Box, cylinder, cone, sphere, pyramid; lines, arcs, circles, curves.

Booleans and modelling

Union, difference, intersection; extrude, revolve, sweep, loft; chamfer, fillet, trim.

Client-side

No install; documents, undo and redo in the browser; import and export.

Touch and pencil

Bridge endpoints for touch events and pencil pressure.

Why it is in the stack

  • CAD in the browser, with a pen - no per-seat iPad CAD licences, no proprietary cloud.
  • Runs on any tablet browser; models never leave your stack; upstream stays unpatched.

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs tusch3d.

At a glance

Based onChili3d · source · docs
Type · categoryExternal service · CAD
Licenceservice AGPL-3.0  ·  wrapper MIT  ·  wilhelm MIT
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Homepagewilhelm.tech
Supportwilhelm.tech/support
Docker imageghcr.io/xiangechen/chili3d:latest · port 8910
Resourcesmemory 1Gi  ·  cpu 1.0  ·  storage 5Gi
Tagscad3dtouchpencilshapr3d-alternativechili3dopencascade
Folderapps/tusch3d/manifest.json

Icon & assets

BrandBrandSquircleSquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 📐Emoji #1F4E79 one brand SVG → tools/app-assetsappinfo/

Configuration

Service

Imageghcr.io/xiangechen/chili3d:latest
Port8910
Compose fragment./docker-compose.yml
Health checkhttp / every 30s · timeout 5s · 3 retries

Resources & permissions

Memory · CPU · storage1Gi · 1.0 · 5Gi
Host networkno
Privilegedno
Egress domainsnone - no outbound connections declared

Dependencies

Requiresnothing
Optionalnextcloud, traefik
Providesembedded-app

Single sign-on (OIDC)

As clientno
As providerno
Fallbacknone

Skin & branding

SloganCAD in the browser, with a pen.
Themeprimary #1F4E79  ·  mode system
Logo./appinfo/icon.svg

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
ISO/IEC 27001
Information security
in progresssoftwareWilhelm certification programme - implementation for all Wilhelm apps in progress.
WCAG
Accessibility
in progresssoftwareWilhelm certification programme - implementation for all Wilhelm apps in progress.
ISO 9241
Usability / ergonomics
in progresssoftwareWilhelm certification programme - implementation for all Wilhelm apps in progress.
EAA / BFSG
Accessibility
in progresssoftwareWilhelm certification programme - implementation for all Wilhelm apps in progress.

Community project without formal certifications - GDPR compliance follows from self-hosting and rests with the operator.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idtusch3d
domaincad
vendortusch3d
nameTusch3D
descriptionBrowser-based CAD with touch and pencil support, in the tradition of German precision tools. Based on Chili3D (AGPL-3.0) - the Tusch3D bridge is a separate sidecar with a clearly separated licence boundary.
version0.1.0
homepagewilhelm.tech
licenseservice, wrapper, wilhelm
serviceAGPL-3.0
wrapperMIT
wilhelmMIT
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typeexternal
categorycad
emoji📐
pixelIcon
............
.KKKKKKKKKK.
.KWWWKKWWWK.
.KWKKWWKKWK.
.KKWWWWWWKK.
.KKWWKKWWKK.
.KKWWKKWWKK.
.KWKKKKKKWK.
.KWWWKKWWWK.
.KKKKKKKKKK.
............
primaryColor#1F4E79
tagscad3dtouchpencilshapr3d-alternativechili3dopencascade
compliancecertifications, note
certifications5 items
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
1id, status, scope, note
idiso-27001
statusin-progress
scopesoftware
noteWilhelm certification programme - implementation for all Wilhelm apps in progress.
2id, status, scope, note
idwcag
statusin-progress
scopesoftware
noteWilhelm certification programme - implementation for all Wilhelm apps in progress.
3id, status, scope, note
idiso-9241
statusin-progress
scopesoftware
noteWilhelm certification programme - implementation for all Wilhelm apps in progress.
4id, status, scope, note
ideaa
statusin-progress
scopesoftware
noteWilhelm certification programme - implementation for all Wilhelm apps in progress.
noteCommunity project without formal certifications - GDPR compliance follows from self-hosting and rests with the operator.
componentsservice, vscode
serviceimage, port, compose, healthCheck
imageghcr.io/xiangechen/chili3d:latest
port8910
healthChecktype, path, interval, timeout, retries
typehttp
path/
interval30s
timeout5s
retries3
vscodeextensions, extension
extensions[ ]
extensionnull
resourcesmemory, cpu, storage
memory1Gi
cpu1.0
storage5Gi
permissionsneedsHostNetwork, needsPrivileged, egressDomains
needsHostNetworkfalse
needsPrivilegedfalse
egressDomains[ ]
dependenciesrequires, optional, provides
requires[ ]
optional2 items
0id
idnextcloud
1id
idtraefik
providesembedded-app
oidcCapabilityasClient, asProvider, fallback
asClientfalse
asProviderfalse
fallbacknone
skinslogan, logo, theme
sloganCAD in the browser, with a pen.
themeprimary, mode
primary#1F4E79
modesystem
marketplacevisibility, screenshots, pricing, supportUrl
visibilitypublic
screenshots[ ]
pricingfree

Standalone compose

Every service app can run on its own: cd apps/tusch3d && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.

docker-compose.yml
# ============================================================================
# Tusch3D - Browser-CAD (profile: tusch3d)
# ============================================================================
# Zwei-Schichten-Architektur:
#
#   Layer 1: chili3d           - unmodifiziertes Upstream-Image (AGPL-3.0)
#                                OpenCascade (WASM) + Three.js sind enthalten.
#                                KEINE Patches, KEIN Code-Mount in diesen
#                                Container - sonst greift AGPL-Copyleft
#                                auf Tusch3D-Eigenleistung über.
#
#   Layer 2: tusch3d-bridge    - eigener Node.js-Sidecar (MIT).
#                                Sprache zu Chili3D ausschliesslich über
#                                öffentliche Wege: HTTP-API, WebSocket,
#                                postMessage. KEINE shared processes,
#                                KEINE shared volumes mit ausführbarem Code.
#
# Aktivieren: COMPOSE_PROFILES=tusch3d (oder im .env COMPOSE_PROFILES anhängen)
# ============================================================================

services:
  # --------------------------------------------------------------------------
  # Layer 1: Chili3D - Upstream Browser-CAD (AGPL-3.0, unmodifiziert)
  # --------------------------------------------------------------------------
  # Hinweis: Falls xiangechen/chili3d kein offizielles Image veröffentlicht,
  # ersetzen durch ein Build-Recipe gegen den Upstream-Master OHNE Patches.
  # In diesem Fall: nur Build-Args setzen, NIEMALS Source-Patches einbauen.
  chili3d:
    image: ghcr.io/xiangechen/chili3d:latest
    restart: unless-stopped
    ports:
      - "127.0.0.1:${TUSCH3D_PORT:-8910}:80"
    volumes:
      # Persistente Modelle/Projekte. Nur Daten - kein Code-Mount in den
      # Container, damit die AGPL-Schicht "unmodified" bleibt.
      - tusch3d_models:/data
    networks:
      - proxy
    healthcheck:
      test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost/"]
      interval: 30s
      timeout: 5s
      retries: 3
      start_period: 20s
    labels:
      - "traefik.enable=true"
      - "traefik.http.routers.tusch3d.rule=Host(`cad.${WILHELM_DOMAIN:-localhost}`)"
      - "traefik.http.routers.tusch3d.entrypoints=websecure"
      - "traefik.http.routers.tusch3d.tls.certresolver=letsencrypt"
      - "traefik.http.services.tusch3d.loadbalancer.server.port=80"
      - "traefik.http.routers.tusch3d.middlewares=embed-headers@docker"
    profiles: ["tusch3d"]

  # --------------------------------------------------------------------------
  # Layer 2: Tusch3D-Bridge - Touch/Pencil-Sidecar (MIT, Wilhelm-Eigenleistung)
  # --------------------------------------------------------------------------
  # Spricht mit chili3d ausschliesslich über HTTP/WebSocket/postMessage.
  # Liest/schreibt KEINE Dateien im chili3d-Container, läuft NICHT im selben
  # JS-Kontext. Lizenzgrenze: siehe README.md → "Lizenz-Architektur".
  tusch3d-bridge:
    build:
      context: ./bridge
      dockerfile: Dockerfile
    restart: unless-stopped
    environment:
      - NODE_ENV=production
      - PORT=8911
      - LOG_LEVEL=${TUSCH3D_BRIDGE_LOG_LEVEL:-info}
      # Nur die öffentliche URL - keine Internals.
      - CHILI3D_PUBLIC_URI=http://chili3d:80
    ports:
      - "127.0.0.1:${TUSCH3D_BRIDGE_PORT:-8911}:8911"
    networks:
      - proxy
    depends_on:
      chili3d:
        condition: service_healthy
    healthcheck:
      test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:8911/healthz"]
      interval: 30s
      timeout: 5s
      retries: 3
      start_period: 15s
    labels:
      - "traefik.enable=true"
      - "traefik.http.routers.tusch3d-bridge.rule=Host(`cad-bridge.${WILHELM_DOMAIN:-localhost}`)"
      - "traefik.http.routers.tusch3d-bridge.entrypoints=websecure"
      - "traefik.http.routers.tusch3d-bridge.tls.certresolver=letsencrypt"
      - "traefik.http.services.tusch3d-bridge.loadbalancer.server.port=8911"
    profiles: ["tusch3d"]

volumes:
  tusch3d_models:
    name: tusch3d_models

networks:
  proxy:
    external: true
    name: wilhelm-techstack_proxy
.env.example
# ── Tusch3D (Browser-CAD mit Touch + Pencil) ────────────────────────────────
# Chili3D Upstream-UI (unmodifiziert, AGPL-3.0)
TUSCH3D_PORT=8910
TUSCH3D_PUBLIC_URI=http://localhost:8910

# Tusch3D-Bridge (eigener Sidecar, MIT) - Touch-/Pencil-Mapping
TUSCH3D_BRIDGE_PORT=8911
TUSCH3D_BRIDGE_LOG_LEVEL=info

# Embed-Proxy-Port (für iframe-Einbettung in Nextcloud, optional)
EMBED_TUSCH3D_PORT=8912

README

The README is not in English - see apps/tusch3d/README.md.

Homepage  ·  Upstream docs  ·  Upstream source  ·  Support  ·  apps/tusch3d/

doc/ai-notes.md  ·  doc/api.md  ·  doc/n8n.md  ·  doc/sources.md  ·  doc/tusch3d-reference.md

Wilhelm Techstack / Commerce / Amazing Shop

Amazing Shop

Sell without a landlord.

External serviceCommerceMITv2.0.0free

Amazing Shop: headless commerce (Medusa v2) with storefront, Nextcloud dashboard and stack branding

What it does

Wilhelm Shop is Medusa, the open-source headless commerce engine: products, variants, prices, inventory, regions and currencies, carts, checkout, orders, promotions, payments and fulfilment, with separate Store and Admin APIs and its own admin panel - what Shopify or commercetools provide, on your own PostgreSQL, under MIT.

The storefront is a separate app. In the Wilhelm stack Medusa signs in through the Kernel, its events flow to n8n (invoice to finance and sign, customer to the newsletter), and its products feed the search index and the Wilhelm Cloud product.

Features

Catalogue

Products, variants, price lists, inventory, categories and collections.

Regions

Multi-region, multi-currency, taxes and shipping rules.

Orders

Cart, checkout, order workflows, promotions, returns.

Admin panel

A React admin for the back office.

Extensible

Modules, workflows, subscribers, OpenAPI spec.

Why it is in the stack

  • Sell without a landlord: no per-order or per-seat platform fee.
  • Headless - the storefront is yours; order data is reachable by the rest of the stack.

Screenshots

Main page · desktop
Main page · desktopdesktop.png
Bestellungen mit Sales-Dashboard
Bestellungen mit Sales-Dashboardadmin-orders.png
Bestelldetail
Bestelldetailadmin-order-detail.png
Kunden
Kundenadmin-customers.png
Theme-Editor mit Live-Preview der Storefront
Theme-Editor mit Live-Preview der Storefrontadmin-theme-editor.png
Plugin Store
Plugin Storeadmin-plugin-store.png

At a glance

Based onMedusa · source · docs · API
ReplacesShopify, WooCommerce · listed as Wilhelm Shop in the ecosystem reference
Type · categoryExternal service · Commerce
Licenceservice MIT  ·  wrapper Proprietary  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support/shop
Docker imageghcr.io/the-wilhelm-project/wilhelm-medusa:latest · port 9000
Compose profilemedusa
Nextcloud app idwilhelmshop · Nextcloud 30-32
Tagsamazingcommerceecommerceshop
Folderapps/shop/manifest.json

Icon & assets

BrandBrandSquircleSquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 🎁Emoji #1C1C1C one brand SVG → tools/app-assetsappinfo/

Configuration

Service

Imageghcr.io/the-wilhelm-project/wilhelm-medusa:latest
Port9000
Health checkhttp /health every 30s · timeout 5s · 3 retries

Nextcloud app

App idwilhelmshop
Path./nextcloud
Nextcloud versions30 - 32

Dependencies

Requiresnextcloud >=30
Optionalvault, storefront, search, n8n

Single sign-on (OIDC)

As clientyes
As providerno
Fallbackvaultwarden

Skin & branding

SloganSell without a landlord.
Themeprimary #1C1C1C  ·  mode system
Logo./nextcloud/appinfo/icon.svg

Secrets

Declared in apps/shop/secrets.spec.yaml - names and purpose only, values live in .env / the secret store.

NameRequiredPurpose
MEDUSA_DB_PASSWORD 🔒yesPassword of the medusa Postgres user (medusa-db container).
MEDUSA_JWT_SECRET 🔒yesSigns admin/customer JWTs. Rotating it logs everyone out.
MEDUSA_COOKIE_SECRET 🔒yesSigns the admin session cookie.
MEDUSA_ADMIN_EMAILyesFirst admin user, created on every start if missing. e.g. admin@wilhelm.local
MEDUSA_ADMIN_PASSWORD 🔒yesPassword of the first admin user. Also handed to the Nextcloud app (wilhelmshop) for the admin proxy.
MEDUSA_PUBLISHABLE_KEYyesStore API key of the public sales channel. Generated by the seed; read it from the admin (Settings → Publishable API Keys) and put it here, then restart storefront + nextcloud bootstrap. e.g. pk_...
MEDUSA_B2B_PUBLISHABLE_KEYnoStore API key of the internal B2B sales channel used by the Nextcloud app's "Interner Shop" tab. e.g. pk_...
MEDUSA_STRIPE_KEYnoStripe publishable key for the storefront checkout (NEXT_PUBLIC_STRIPE_KEY). e.g. pk_test_...
STRIPE_API_KEY 🔒noStripe secret key for the backend payment provider.
STRIPE_WEBHOOK_SECRET 🔒noSigning secret of the Stripe webhook pointed at /hooks/payment/stripe.
MOLLIE_API_KEY 🔒noMollie API key (test_… or live_…). Provider stays inert without it.
PAYPAL_CLIENT_IDnoPayPal REST client id.
PAYPAL_CLIENT_SECRET 🔒noPayPal REST client secret.
SENDCLOUD_PUBLIC_KEYnoSendcloud API public key. The Sendcloud fulfillment provider is only registered when set.
SENDCLOUD_SECRET_KEY 🔒noSendcloud API secret key.
RESEND_API_KEY 🔒noResend API key for transactional e-mail (order confirmations). Alternative to SENDGRID_API_KEY.
SLACK_WEBHOOK_URL 🔒noIncoming webhook for the "alerts" notification channel.

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
DPA
Privacy
compliantcloud offeringDPA under Art. 28 GDPR for Medusa Cloud customers. source

Framework without certificates of its own - PCI DSS / GDPR in the finished shop is established by the implementer.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idshop
domainshop
vendormedusa
nameAmazing Shop
descriptionAmazing Shop: headless commerce (Medusa v2) with storefront, Nextcloud dashboard and stack branding
version2.0.0
licenseservice, wrapper, wilhelm
serviceMIT
wrapperProprietary
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typeexternal
categorycommerce
emoji🎁
pixelIcon
............
.K..........
.KK.........
..KKKKKKKK..
..KWWWWWWK..
..KWWWWWWK..
..KKKKKKKK..
...K....K...
..KKK..KKK..
..KKK..KKK..
............
primaryColor#1C1C1C
tagsamazingcommerceecommerceshop
compliancecertifications, note
certifications2 items
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
1id, status, scope, source, note
idgdpr-avv
statuscompliant
scopecloud
noteDPA under Art. 28 GDPR for Medusa Cloud customers.
noteFramework without certificates of its own - PCI DSS / GDPR in the finished shop is established by the implementer.
previewdir, desktop, gallery
gallery5 items
0src, caption, kind
captionBestellungen mit Sales-Dashboard
kinddesktop
1src, caption, kind
captionBestelldetail
kinddesktop
2src, caption, kind
captionKunden
kinddesktop
3src, caption, kind
captionTheme-Editor mit Live-Preview der Storefront
kinddesktop
4src, caption, kind
captionPlugin Store
kinddesktop
componentsservice, nextcloudApp, vscode
serviceimage, port, healthCheck
imageghcr.io/the-wilhelm-project/wilhelm-medusa:latest
port9000
healthChecktype, path, interval, timeout, retries
typehttp
path/health
interval30s
timeout5s
retries3
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmshop
minNcVersion30
maxNcVersion32
vscodeextensions, extension
extensions[ ]
extensionnull
dependenciesrequires, optional
requires1 item
0id, version
idnextcloud
version>=30
optional4 items
0id
idvault
1id
idstorefront
2id
idsearch
3id
idn8n
oidcCapabilityasClient, asProvider, fallback
asClienttrue
asProviderfalse
fallbackvaultwarden
skinslogan, logo, theme
sloganSell without a landlord.
themeprimary, mode
primary#1C1C1C
modesystem
marketplacevisibility, screenshots, pricing, supportUrl

Standalone compose

Every service app can run on its own: cd apps/shop && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.

docker-compose.yml
# Wilhelm Shop - standalone Docker compose (hand-authored)
#
# Medusa needs Postgres + Redis, so the generic standalone generator
# (scripts/generate-standalone.mjs) is NOT used for this app - it only knows
# single-container images. This file is left alone by the generator.
#
# Quickstart:
#   cp .env.example .env && docker compose up -d
#   → API   http://localhost:${MEDUSA_BACKEND_PORT:-9000}   (admin: /app)
#   → Shop  http://localhost:${MEDUSA_STOREFRONT_PORT:-8000}
#
# Inside the Wilhelm monorepo the same services live in the root
# docker-compose.yml (profile "medusa", shared traefik + Nextcloud app).
services:
  medusa:
    image: ghcr.io/the-wilhelm-project/wilhelm-medusa:latest
    build: ./service/app
    restart: unless-stopped
    env_file:
      - .env
    environment:
      - NODE_ENV=production
      - PORT=9000
      - DATABASE_URL=postgres://medusa:${MEDUSA_DB_PASSWORD:-change_me}@medusa-db:5432/medusa
      - REDIS_URL=redis://medusa-redis:6379
      - JWT_SECRET=${MEDUSA_JWT_SECRET:-change_me_jwt}
      - COOKIE_SECRET=${MEDUSA_COOKIE_SECRET:-change_me_cookie}
      - STORE_CORS=${MEDUSA_STORE_CORS:-http://localhost:8000}
      - ADMIN_CORS=${MEDUSA_ADMIN_CORS:-http://localhost:9000}
      - AUTH_CORS=${MEDUSA_AUTH_CORS:-http://localhost:9000}
      - DISABLE_MEDUSA_ADMIN=${MEDUSA_DISABLE_ADMIN:-false}
      - MEDUSA_BACKEND_URL=${NEXT_PUBLIC_MEDUSA_BACKEND_URL:-http://localhost:9000}
      - STOREFRONT_URL=${MEDUSA_STOREFRONT_URL:-http://localhost:8000}
    depends_on:
      medusa-db:
        condition: service_healthy
      medusa-redis:
        condition: service_started
    ports:
      - "${MEDUSA_BACKEND_PORT:-9000}:9000"
    volumes:
      - medusa_uploads:/server/uploads
    healthcheck:
      test: ["CMD-SHELL", "wget -qO- http://127.0.0.1:9000/health || exit 1"]
      interval: 15s
      timeout: 10s
      retries: 20
      start_period: 120s
    networks:
      - shop

  medusa-db:
    image: postgres:16-alpine
    restart: unless-stopped
    environment:
      - POSTGRES_DB=medusa
      - POSTGRES_USER=medusa
      - POSTGRES_PASSWORD=${MEDUSA_DB_PASSWORD:-change_me}
    volumes:
      - medusa_db:/var/lib/postgresql/data
    healthcheck:
      test: ["CMD-SHELL", "pg_isready -U medusa"]
      interval: 10s
      timeout: 5s
      retries: 5
    networks:
      - shop

  medusa-redis:
    image: redis:7-alpine
    restart: unless-stopped
    command: redis-server --appendonly yes
    volumes:
      - medusa_redis:/data
    networks:
      - shop

  medusa-storefront:
    image: ghcr.io/the-wilhelm-project/wilhelm-medusa-storefront:latest
    build:
      context: ../storefront/app
      args:
        NEXT_PUBLIC_MEDUSA_BACKEND_URL: ${NEXT_PUBLIC_MEDUSA_BACKEND_URL:-http://localhost:9000}
        NEXT_PUBLIC_BASE_URL: ${MEDUSA_STOREFRONT_URL:-http://localhost:8000}
        NEXT_PUBLIC_MEDUSA_PUBLISHABLE_KEY: ${MEDUSA_PUBLISHABLE_KEY:-pk_build_placeholder}
    restart: unless-stopped
    env_file:
      - .env
    environment:
      - MEDUSA_BACKEND_URL=http://medusa:9000
      - NEXT_PUBLIC_MEDUSA_BACKEND_URL=${NEXT_PUBLIC_MEDUSA_BACKEND_URL:-http://localhost:9000}
      - NEXT_PUBLIC_BASE_URL=${MEDUSA_STOREFRONT_URL:-http://localhost:8000}
      - NEXT_PUBLIC_MEDUSA_PUBLISHABLE_KEY=${MEDUSA_PUBLISHABLE_KEY:-}
      - NEXT_PUBLIC_STRIPE_KEY=${MEDUSA_STRIPE_KEY:-}
    depends_on:
      medusa:
        condition: service_healthy
    ports:
      - "${MEDUSA_STOREFRONT_PORT:-8000}:8000"
    networks:
      - shop

volumes:
  medusa_db:
  medusa_redis:
  medusa_uploads:

networks:
  shop:
    name: shop
.env.example
# ── Wilhelm Shop (Medusa v2, Headless Commerce) ─────────────────────────────
# Inside the Wilhelm stack these live in the root .env (see secrets.spec.yaml).
# Standalone (this folder's docker-compose.yml) reads this file directly.

# Postgres / secrets
MEDUSA_DB_PASSWORD=change_me
MEDUSA_JWT_SECRET=change_me_jwt
MEDUSA_COOKIE_SECRET=change_me_cookie

# First admin (created on start if missing)
MEDUSA_ADMIN_EMAIL=admin@wilhelm.local
MEDUSA_ADMIN_PASSWORD=change_me

# Public URLs (CORS + links in mails/redirects)
MEDUSA_BACKEND_PORT=9000
NEXT_PUBLIC_MEDUSA_BACKEND_URL=http://localhost:9000
MEDUSA_STOREFRONT_PORT=8000
MEDUSA_STOREFRONT_URL=http://localhost:8000
MEDUSA_STORE_CORS=http://localhost:8000
MEDUSA_ADMIN_CORS=http://localhost:9000
MEDUSA_AUTH_CORS=http://localhost:9000

# Store API keys (from the admin after the first start / seed)
MEDUSA_PUBLISHABLE_KEY=
MEDUSA_B2B_PUBLISHABLE_KEY=
MEDUSA_B2B_GROUP=InternalShop

# Payments (all optional - providers stay visible in the admin but inert)
MEDUSA_STRIPE_KEY=
STRIPE_API_KEY=
STRIPE_WEBHOOK_SECRET=
MOLLIE_API_KEY=
PAYPAL_CLIENT_ID=
PAYPAL_CLIENT_SECRET=
PAYPAL_ENVIRONMENT=sandbox

# Fulfillment / notifications / search (optional)
SENDCLOUD_PUBLIC_KEY=
SENDCLOUD_SECRET_KEY=
RESEND_API_KEY=
RESEND_FROM=
SLACK_WEBHOOK_URL=
MEILI_HTTP_ADDR=
MEILI_MASTER_KEY=

MEDUSA_DISABLE_ADMIN=false

# ── Brand (inherited from the stack: config/stack.defaults.env) ─────────────
# Served by GET /store/brand → storefront + Nextcloud app. The admin theme
# editor layers overrides on top of these.
WILHELM_BRAND_NAME=Wilhelm
WILHELM_BRAND_SHORT_NAME=Wilhelm
WILHELM_BRAND_SLOGAN=
WILHELM_BRAND_PRIMARY_COLOR=#0369FF
WILHELM_BRAND_ACCENT_COLOR=#FFCC00
WILHELM_BRAND_BACKGROUND_COLOR=#FFFFFF
WILHELM_BRAND_FOREGROUND_COLOR=#111111
WILHELM_BRAND_MUTED_COLOR=#6B7280
WILHELM_BRAND_BORDER_COLOR=#E5E7EB
WILHELM_BRAND_SURFACE_COLOR=#F9FAFB
WILHELM_BRAND_FONT_FAMILY=Inter, -apple-system, BlinkMacSystemFont, sans-serif
WILHELM_BRAND_FONT_DISPLAY=Inter, -apple-system, BlinkMacSystemFont, sans-serif
WILHELM_BRAND_RADIUS=12px
WILHELM_BRAND_LOGO_URL=
WILHELM_BRAND_LOGO_DARK_URL=
WILHELM_BRAND_FAVICON_URL=
WILHELM_BRAND_URL=
WILHELM_BRAND_IMPRINT_URL=
WILHELM_BRAND_PRIVACY_URL=
WILHELM_BRAND_TERMS_URL=
WILHELM_BRAND_SUPPORT_EMAIL=
WILHELM_BRAND_LUCID_NUMBER=
WILHELM_BRAND_VAT_ID=
WILHELM_BRAND_TRUST_SEAL_ID=

README

The README is not in English - see apps/shop/README.md.

Upstream docs  ·  Upstream API  ·  Upstream source  ·  Support  ·  apps/shop/

doc/ai-notes.md  ·  doc/api.md  ·  doc/n8n.md  ·  doc/shop-reference.md  ·  doc/sources.md

TaskHQ

The stack in a Task Manager.

External serviceCoreMITv2.0.0free

Windows 95 desktop (react95) for Docker: program windows with a window manager, start menu and taskbar. A Task-Manager-style Docker manager (Apps/Kernel/Performance/Info), the Wilhelm graph as an embedded node-canvas window, Setup/Configs/Terminal/My Computer as programs of their own; the raw canvas stays reachable via ?view=canvas.

What it does

TaskHQ is the stack's control plane, styled as a Windows 95 desktop: a window manager, start menu and taskbar in which every Wilhelm app opens as a program window. A Task-Manager-style Docker manager shows apps, kernel, performance and info; Boot, Setup, Configs, Terminal and Workplace are programs of their own; the Wilhelm graph is a node canvas window. It replaces Portainer and Docker Desktop for this stack.

The rule across the repository is that nobody runs docker compose by hand - the stack is started, restarted, stopped and shut down through TaskHQ (or the ARM Wilhelm CLI), with a traffic light, a boot-order plan, diagnostics and a gate doctor that tells you which services are exposed unintentionally.

Features

Wilhelm Boot

Start, restart, stop, shut down the whole stack with a progress line and a stack traffic light.

Profiles and estimates

Edit compose profiles with live image and RAM estimates.

Diagnostics

Boot-order plan, ports and stack doctor findings, history, backup, installer.

Logs and events

Per-service log streams, error and event tabs.

Network map

Traefik routers, firewall, gate classification: gated, open by design, sealed, internal.

Apps from manifests

Every app becomes a desktop program with no front-end code; window geometry from the manifest.

Two modes

Host mode works before the stack is up; container mode mounts the Docker socket.

REST and SSE API

Everything the desktop does is an authenticated API call.

Why it is in the stack

  • The stack in a Task Manager - one real desktop to operate a self-hosted company stack.
  • A safe operations vocabulary instead of raw compose commands; new apps appear automatically.
  • The gate doctor makes unintended exposure visible.

Screenshots

The TaskHQ desktop
The TaskHQ desktop

The Task Manager window with CPU and memory history and container counters, the Workplace window listing disks and network drives, a Wilhelm root terminal and an Enter terminal running the coding agent. Desktop icons for Enter, processes, settings, setup, the Wilhelm graph and the terminals; the taskbar at the bottom lists the open windows.

desktop.png
Mobile layout
Mobile layout

The desktop on a phone-sized viewport.

mobile.png
Stack control: profiles and containers
Stack control: profiles and containers01-stack-canvas.jpg
Wilhelm Boot on the Win95 desktop
Wilhelm Boot on the Win95 desktop02-wilhelm-boot.jpg

Screenshots are the upstream project's official product shots (see preview/SOURCES.md) until the stack runs with demo data and tools/app-preview shoots real Wilhelm screens. Images © their respective projects.

At a glance

Based onWilhelm taskhq (@wilhelm/taskhq)
Type · categoryExternal service · Core
Licenceservice MIT  ·  wrapper Proprietary  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support/tasks
Docker imagetaskhq/taskhq:latest · port 3060
Public URLhttps://admin.<your-domain>
Compose profiletaskhq
Nextcloud app idwilhelmtaskhq · Nextcloud 30-32
Tagsadmindockercore
Folderapps/tasks/manifest.json

Icon & assets

BrandBrandSquircleSquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel Emoji #0369FF one brand SVG → tools/app-assetsappinfo/ · serving copy in ./service/app/public

Configuration

Service

Imagetaskhq/taskhq:latest
Port3060
Health checkhttp / every 30s · timeout 5s · 3 retries

Embedding in Nextcloud

Registry id · labeltaskhq · Wilhelm TaskHQ
Subdomainadmin · gateway mode taskhq
Containertaskhq:3060
Embed-proxy port (localhost)8975
Compose profiletaskhq
Nextcloud config keytaskhq_url

Nextcloud app

App idwilhelmtaskhq
Path./nextcloud
Nextcloud versions30 - 32

Dependencies

Requiresnextcloud >=30
Optionalvault

Single sign-on (OIDC)

As clientyes
As providerno
Fallbackvaultwarden

Skin & branding

SloganThe stack in a Task Manager.
Themeprimary #0369FF  ·  mode system
Logo./service/appinfo/icon.svg

Secrets

Declared in secretsRefs but apps/tasks/secrets.spec.yaml does not exist in the repository.

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
ISO/IEC 27001
Information security
in progresssoftwareWilhelm certification programme - implementation for all Wilhelm apps in progress.
WCAG
Accessibility
in progresssoftwareWilhelm certification programme - implementation for all Wilhelm apps in progress.
ISO 9241
Usability / ergonomics
in progresssoftwareWilhelm certification programme - implementation for all Wilhelm apps in progress.
EAA / BFSG
Accessibility
in progresssoftwareWilhelm certification programme - implementation for all Wilhelm apps in progress.

Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idtasks
domaintasks
vendortaskhq
nameTaskHQ
descriptionWindows 95 desktop (react95) for Docker: program windows with a window manager, start menu and taskbar. A Task-Manager-style Docker manager (Apps/Kernel/Performance/Info), the Wilhelm graph as an embedded node-canvas window, Setup/Configs/Terminal/My Computer as programs of their own; the raw canvas stays reachable via ?view=canvas.
version2.0.0
licenseservice, wrapper, wilhelm
serviceMIT
wrapperProprietary
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typeexternal
categorycore
emoji
pixelIcon
............
.KKKKKKKKKK.
.KWWWWWWWWK.
.KWWWWWWKWK.
.KWWWWWKKWK.
.KWKWWKKWWK.
.KWKKKKWWWK.
.KWWKKWWWWK.
.KWWWWWWWWK.
.KKKKKKKKKK.
............
primaryColor#0369FF
tagsadmindockercore
compliancecertifications, note
certifications5 items
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
1id, status, scope, note
idiso-27001
statusin-progress
scopesoftware
noteWilhelm certification programme - implementation for all Wilhelm apps in progress.
2id, status, scope, note
idwcag
statusin-progress
scopesoftware
noteWilhelm certification programme - implementation for all Wilhelm apps in progress.
3id, status, scope, note
idiso-9241
statusin-progress
scopesoftware
noteWilhelm certification programme - implementation for all Wilhelm apps in progress.
4id, status, scope, note
ideaa
statusin-progress
scopesoftware
noteWilhelm certification programme - implementation for all Wilhelm apps in progress.
noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
previewdir, desktop, mobile, gallery, capture
gallery2 items
0src, caption, kind
captionStack control: profiles and containers
kinddesktop
1src, caption, kind
captionWilhelm Boot on the Win95 desktop
kinddesktop
captureurl, wait
wait1200
componentsservice, nextcloudApp, embed, vscode
serviceimage, port, healthCheck
imagetaskhq/taskhq:latest
port3060
healthChecktype, path, interval, timeout, retries
typehttp
path/
interval30s
timeout5s
retries3
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmtaskhq
minNcVersion30
maxNcVersion32
embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile, gatewaySubdomain
idtaskhq
labelWilhelm TaskHQ
ncConfigKeytaskhq_url
subdomainadmin
containertaskhq
containerPort3060
embedProxyPort8975
profiletaskhq
gatewaySubdomaintaskhq
vscodeextensions, extension
extensions[ ]
extensionnull
dependenciesrequires, optional
requires1 item
0id, version
idnextcloud
version>=30
optional1 item
0id
idvault
oidcCapabilityasClient, asProvider, fallback
asClienttrue
asProviderfalse
fallbackvaultwarden
secretsRefs./secrets.spec.yaml
skinslogan, logo, theme
sloganThe stack in a Task Manager.
themeprimary, mode
primary#0369FF
modesystem
marketplacevisibility, screenshots, pricing, supportUrl
webpublicDir

Standalone compose

Every service app can run on its own: cd apps/tasks && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.

docker-compose.yml
# TaskHQ - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/tasks/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
#   cp .env.example .env && docker compose up -d
#   → http://localhost:${TASKS_PORT:-3060}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
  tasks:
    image: taskhq/taskhq:latest
    restart: unless-stopped
    env_file:
      - .env
    ports:
      - "${TASKS_PORT:-3060}:3060"
    healthcheck:
      test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:3060/"]
      interval: 30s
      timeout: 5s
      retries: 3
      start_period: 20s
    networks:
      - tasks
    # TODO: persistent volume(s) if this image stores state. e.g.:
    #   volumes: [ "tasks_data:/data" ]

networks:
  tasks:
    name: tasks
.env.example
# TaskHQ - standalone env. Copy to .env and fill in.
# GENERATED by scripts/generate-standalone.mjs

# Host port the app is published on.
TASKS_PORT=3060

# Required secrets are specified in:
#   ./secrets.spec.yaml
# Add the matching KEY=VALUE lines here.

README

The README is not in English - see apps/tasks/README.md.

Support  ·  apps/tasks/

doc/ai-notes.md  ·  doc/api.md  ·  doc/sources.md  ·  doc/tasks-reference.md

CRM

Customers in view, not in spreadsheets.

External serviceCRMAGPL-3.0v2.0.0free

Twenty CRM embedded in Nextcloud

What it does

CRM is Twenty, the open-source CRM that sets out to be what Salesforce and HubSpot are for sales teams - people, companies, opportunities, pipelines, notes, tasks and e-mail in one place - without the licence model that makes every additional seat and every additional object a negotiation.

Twenty's data model is fully customisable: standard objects such as companies and opportunities can be extended with fields, and entirely new objects can be added, all of them available in table and kanban views with sorting, filtering and grouping. Workflows, an API, webhooks and, in newer versions, AI agents that answer questions across your records make it a platform rather than a contact list.

Features

Custom data model

Standard objects (companies, people, opportunities) plus your own objects and fields, with relations between them.

Kanban and table views

Every object in a spreadsheet-like table or a kanban board, with saved sorts and filters.

E-mail and calendar sync

Connect mailboxes and calendars so conversations and meetings appear on the record they belong to.

Workflows

Trigger-action automation inside the CRM - when a person is created, search records and send an e-mail.

Live dashboards

Charts over pipeline, revenue and activity that update with the data.

AI agents and Ask AI

Natural-language questions over your CRM data and agents that draft e-mails or act on records, using the model of your choice.

Extensible

Custom objects, tools, serverless functions, widgets, layout pages and commands - build the CRM you need on top of Twenty.

REST and GraphQL API, webhooks

Everything in the UI is reachable from code and from n8n.

Why it is in the stack

  • Replaces Salesforce and HubSpot for the everyday work of a sales team, under an AGPL licence, on your own server.
  • The Wilhelm skin turns Twenty into garyn.ai, the emotional contact manager - same data, a different face.
  • Data lives in your Wilhelm stack next to mail, calendar and files; SSO, n8n workflows and the Wilhelm API connect it to everything else.

Screenshots

The tools of a good CRM
The tools of a good CRM

Custom data model, kanban views, custom workflows, sorts and filters, e-mail and calendar sync, live dashboards and a command palette - the standard CRM feature set, all of it in the open-source core.

01-crm-tools.jpg
AI agents and chats
AI agents and chats

Choose the model behind your agents, let an agent write an e-mail as a workflow step, or ask the CRM directly what deals you have in the pipeline. Model access can be routed through the stack's own gateway.

02-ai-agents.jpg
Build your own apps on the CRM
Build your own apps on the CRM

Front-end components and code live in a normal repository: a coding agent creates a component to display your close rate, commits it, and the CRM picks it up.

03-build-apps.jpg
Data model, logic and layout
Data model, logic and layout

The three extension layers: custom objects and fields (data model), tools, serverless functions and skills (logic), and views, widgets, layout pages and commands (layout).

04-all-tools.jpg

Screenshots are the upstream project's official product shots (see preview/SOURCES.md) until the stack runs with demo data and tools/app-preview shoots real Wilhelm screens. Images © their respective projects.

At a glance

Based onTwenty CRM · source · docs · API
ReplacesSalesforce, HubSpot · listed as Wilhelm CRM in the ecosystem reference
Type · categoryExternal service · CRM
Licenceservice AGPL-3.0  ·  wrapper Proprietary  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support/crm
Docker imagetwentycrm/twenty:latest · port 3000
Compose profilecrm
Nextcloud app idwilhelmcrm · Nextcloud 30-32
Tagscrmcontacts
Folderapps/crm/manifest.json

Icon & assets

BrandBrandSquircleSquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 🤝Emoji #1C1C1C one brand SVG → tools/app-assetsappinfo/

Configuration

Service

Imagetwentycrm/twenty:latest
Port3000
Init script./service/init-twenty.sh
Health checkhttp /healthz every 30s · timeout 5s · 3 retries

Nextcloud app

App idwilhelmcrm
Path./nextcloud
Nextcloud versions30 - 32

Dependencies

Requiresnextcloud >=30
Optionalvault
Required bygaryn

Single sign-on (OIDC)

As clientyes
As providerno
Fallbackvaultwarden

Skin & branding

SloganCustomers in view, not in spreadsheets.
Themeprimary #1C1C1C  ·  mode system
Logo./nextcloud/appinfo/icon.svg

Secrets

Declared in secretsRefs but apps/crm/secrets.spec.yaml does not exist in the repository.

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
DPA
Privacy
compliantcloud offeringPublished DPA with SCC safeguards for EEA/UK/CH data transfers. source
SOC 2 Type II
Information security
in progresscloud offeringSOC 2 Type II in progress according to the trust center, no completed audit report yet. source

Young project: DPA available, SOC 2 in progress; no ISO/WCAG evidence.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idcrm
domaincrm
vendortwenty
nameCRM
descriptionTwenty CRM embedded in Nextcloud
version2.0.0
licenseservice, wrapper, wilhelm
serviceAGPL-3.0
wrapperProprietary
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typeexternal
categorycrm
emoji🤝
pixelIcon
............
.KKKKKKKKKK.
.KWWWWWWWWK.
.KWWKKWWWWK.
.KWWKKWKKWK.
.KWWWWWWWWK.
.KWKKKKWWWK.
.KWKKKKKKWK.
.KWWWWWWWWK.
.KKKKKKKKKK.
............
............
primaryColor#1C1C1C
tagscrmcontacts
compliancecertifications, note
certifications3 items
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
1id, status, scope, source, note
idgdpr-avv
statuscompliant
scopecloud
notePublished DPA with SCC safeguards for EEA/UK/CH data transfers.
2id, status, scope, source, note
idsoc2-type2
statusin-progress
scopecloud
noteSOC 2 Type II in progress according to the trust center, no completed audit report yet.
noteYoung project: DPA available, SOC 2 in progress; no ISO/WCAG evidence.
componentsservice, nextcloudApp, vscode
serviceimage, port, healthCheck, init
imagetwentycrm/twenty:latest
port3000
healthChecktype, path, interval, timeout, retries
typehttp
path/healthz
interval30s
timeout5s
retries3
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmcrm
minNcVersion30
maxNcVersion32
vscodeextensions, extension
extensions[ ]
extensionnull
dependenciesrequires, optional
requires1 item
0id, version
idnextcloud
version>=30
optional1 item
0id
idvault
oidcCapabilityasClient, asProvider, fallback
asClienttrue
asProviderfalse
fallbackvaultwarden
secretsRefs./secrets.spec.yaml
skinslogan, logo, theme
sloganCustomers in view, not in spreadsheets.
themeprimary, mode
primary#1C1C1C
modesystem
previewdir, gallery
gallery4 items
0src, caption, kind
captionCRM tools: contacts, pipeline, dashboards
kinddesktop
1src, caption, kind
captionAI agents and chats
kinddesktop
2src, caption, kind
captionCustom apps and data models
kinddesktop
3src, caption, kind
captionBuilding blocks
kinddesktop
marketplacevisibility, screenshots, pricing, supportUrl

Standalone compose

Every service app can run on its own: cd apps/crm && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.

docker-compose.yml
# CRM - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/crm/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
#   cp .env.example .env && docker compose up -d
#   → http://localhost:${CRM_PORT:-3000}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
  crm:
    image: twentycrm/twenty:latest
    restart: unless-stopped
    env_file:
      - .env
    ports:
      - "${CRM_PORT:-3000}:3000"
    healthcheck:
      test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:3000/healthz"]
      interval: 30s
      timeout: 5s
      retries: 3
      start_period: 20s
    networks:
      - crm
    # TODO: persistent volume(s) if this image stores state. e.g.:
    #   volumes: [ "crm_data:/data" ]

networks:
  crm:
    name: crm
.env.example
# CRM - standalone env. Copy to .env and fill in.
# GENERATED by scripts/generate-standalone.mjs

# Host port the app is published on.
CRM_PORT=3000

# Required secrets are specified in:
#   ./secrets.spec.yaml
# Add the matching KEY=VALUE lines here.

README

The README is not in English - see apps/crm/README.md.

Upstream docs  ·  Upstream API  ·  Upstream source  ·  Support  ·  apps/crm/

doc/ai-notes.md  ·  doc/api.md  ·  doc/crm-reference.md  ·  doc/n8n.md  ·  doc/sources.md

Wilhelm Techstack / CRM / garyn.ai

garyn.ai

Your network - and it remembers.

Nextcloud appCRMApache-2.0v2.0.0free

Emotional contact manager on top of Twenty: Excel sync, Nextcloud contacts, Gary chatbot. Looks like WhatsApp x LinkedIn x Instagram.

What it does

garyn.ai is the emotional contact manager: it looks like WhatsApp × LinkedIn × Instagram, thinks like a CRM and talks like WilheLLM. Contacts come from an Excel file on Nextcloud, land in Twenty as the data hub, and are then usable in sync from Nextcloud Contacts, Nextcloud Mail and the Gary chat.

Twenty stays unforked and headless underneath; garyn adds three clean layers - a Twenty SDK app that brings the WilheLLM engine in as an agent tool, a Gary app with personality and sync logic, and the social-style front end wrapped in Nextcloud. Status: phase 0, scaffold and documentation.

Features

Excel to CRM sync

A spreadsheet on Nextcloud is the source; star topology with documented conflict rules.

Gary chatbot

Ask questions over your own contact graph; Gary remembers.

Social look

Feed, profiles and chat instead of tables.

Nextcloud Contacts and Mail in sync

The same people everywhere.

Data model and build plan

Schemas and a phased plan ship with the app.

Why it is in the stack

  • Your network - and it remembers: consumer-grade UX on top of CRM data.
  • No fork of Twenty, so upgrades stay possible.
  • The relationship graph and the AI on top of it stay on your own server.

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs garyn.

At a glance

Based onWilhelm-native - no upstream project
Type · categoryNextcloud app · CRM
Licenceservice Apache-2.0  ·  wilhelm Apache-2.0
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support
Nextcloud app idgaryn · Nextcloud 30-32
Resourcesmemory 256Mi  ·  cpu 0.25  ·  storage 1Gi
Tagscrmcontactschatbotrelationshipstwentywilhe-llm
Folderapps/garyn/manifest.json

Icon & assets

BrandBrand-SquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 🫂Emoji #FF6B5C one brand SVG → tools/app-assetsappinfo/ · serving copy in ./service/app/public

Configuration

Service

Compose fragment./service/compose.fragment.yml
Init script./service/init.sh
Health checkhttp /healthz every 30s · timeout 5s · 3 retries

Nextcloud app

App idgaryn
Path./nextcloud
Nextcloud versions30 - 32

Desktop build (Electron)

Enabledno - opted out
Start path/index.php/apps/garyn/
Hide Nextcloud chromeyes

Resources & permissions

Memory · CPU · storage256Mi · 0.25 · 1Gi
Host networkno
Privilegedno
Egress domainsnone - no outbound connections declared

Dependencies

Requiresnextcloud >=30, crm
Optionaln8n, wilhe-llm, vault
Providesnc-appn8n-workflowsapi

Single sign-on (OIDC)

As clientno
As providerno
Fallbacknone

Skin & branding

SloganYour network - and it remembers.
Themeprimary #FF6B5C  ·  accent #1A1A2E  ·  mode system
Logo./brand/gary-mascot.svg
Agent personaGary - “Hi, I'm Gary!”
Whitelabel targetcrm

Secrets

Declared in secretsRefs but apps/garyn/secrets.spec.yaml does not exist in the repository.

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
ISO/IEC 27001
Information security
in progresssoftwareWilhelm certification programme - implementation for all Wilhelm apps in progress.
WCAG
Accessibility
in progresssoftwareWilhelm certification programme - implementation for all Wilhelm apps in progress.
ISO 9241
Usability / ergonomics
in progresssoftwareWilhelm certification programme - implementation for all Wilhelm apps in progress.
EAA / BFSG
Accessibility
in progresssoftwareWilhelm certification programme - implementation for all Wilhelm apps in progress.

Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idgaryn
domaincontacts
vendorwilhelm
namegaryn.ai
descriptionEmotional contact manager on top of Twenty: Excel sync, Nextcloud contacts, Gary chatbot. Looks like WhatsApp x LinkedIn x Instagram.
version2.0.0
licenseservice, wilhelm
serviceApache-2.0
wilhelmApache-2.0
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typenc-app
categorycrm
emoji🫂
pixelIcon
............
..KK...KK...
.KWWK.KWWK..
.KWWWKWWWK..
.KWWWWWWWK..
..KWWWWWK...
...KWWWK....
....KWK.....
.....K......
............
............
............
primaryColor#FF6B5C
tagscrmcontactschatbotrelationshipstwentywilhe-llm
compliancecertifications, note
certifications5 items
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
1id, status, scope, note
idiso-27001
statusin-progress
scopesoftware
noteWilhelm certification programme - implementation for all Wilhelm apps in progress.
2id, status, scope, note
idwcag
statusin-progress
scopesoftware
noteWilhelm certification programme - implementation for all Wilhelm apps in progress.
3id, status, scope, note
idiso-9241
statusin-progress
scopesoftware
noteWilhelm certification programme - implementation for all Wilhelm apps in progress.
4id, status, scope, note
ideaa
statusin-progress
scopesoftware
noteWilhelm certification programme - implementation for all Wilhelm apps in progress.
noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
webpublicDir
previewdir, desktop, mobile, capture
dir./preview
desktop./preview/desktop.png
mobile./preview/mobile.png
captureurl, wait
wait1000
componentsservice, nextcloudApp, vscode
serviceimage, compose, init, healthCheck
image
healthChecktype, path, interval, timeout, retries
typehttp
path/healthz
interval30s
timeout5s
retries3
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidgaryn
minNcVersion30
maxNcVersion32
vscodeextensions, extension
extensions[ ]
extensionnull
desktopenabled, startPath, hideNextcloudChrome
enabledfalse
startPath/index.php/apps/garyn/
hideNextcloudChrometrue
resourcesmemory, cpu, storage
memory256Mi
cpu0.25
storage1Gi
permissionsneedsHostNetwork, needsPrivileged, egressDomains
needsHostNetworkfalse
needsPrivilegedfalse
egressDomains[ ]
dependenciesrequires, optional, provides
requires2 items
0id, version
idnextcloud
version>=30
1id
idcrm
optional3 items
0id
idn8n
1id
idwilhe-llm
2id
idvault
providesnc-appn8n-workflowsapi
oidcCapabilityasClient, asProvider, fallback
asClientfalse
asProviderfalse
fallbacknone
secretsRefs./secrets.spec.yaml
skinslogan, logo, wordmark, signet, icon, favicon, theme, agent, overlay, whitelabel, env
sloganYour network - and it remembers.
themeprimary, accent, mode
primary#FF6B5C
accent#1A1A2E
modesystem
agentname, greeting, persona
nameGary
greetingHi, I'm Gary!
overlayjs, css, assets
whitelabeltarget, applyWith
targetcrm
envPWA_NAME
PWA_NAMEGaryN
marketplacevisibility, screenshots, pricing, supportUrl
visibilitypublic
screenshots[ ]
pricingfree

Standalone compose

Every service app can run on its own: cd apps/garyn && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.

docker-compose.yml
# garyn.ai - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/garyn/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
#   cp .env.example .env && docker compose up -d
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
  garyn:
    build:
      context: ./service
    restart: unless-stopped
    env_file:
      - .env
    networks:
      - garyn
    # TODO: persistent volume(s) if this image stores state. e.g.:
    #   volumes: [ "garyn_data:/data" ]

networks:
  garyn:
    name: garyn
.env.example
# garyn.ai - standalone env. Copy to .env and fill in.
# GENERATED by scripts/generate-standalone.mjs

# Required secrets are specified in:
#   ./secrets.spec.yaml
# Add the matching KEY=VALUE lines here.

README

The README is not in English - see apps/garyn/README.md.

Support  ·  apps/garyn/

doc/ai-notes.md  ·  doc/api.md  ·  doc/datamodel.md  ·  doc/sources.md  ·  doc/sync.md

ACID

Documents in, formats out.

External serviceDashboardsMITv2.0.0free

ACID dashboard embedded in Nextcloud

What it does

ACID - the Augmented Content Identifier - is the Wilhelm document pipeline's dashboard: drop files in, name the JSON schema you want them extracted against, and watch them become structured records with a confidence score. It is the visible front of what document-capture products such as ABBYY or the cloud OCR/IDP services do behind a form.

ACID itself is a React single-page app with no backend of its own. It talks to the converter API in the Kernel, and n8n orchestrates the pipeline behind it; the extracted results are filed into NocoDB as ordinary records the rest of the stack can query.

Features

Upload against a schema

Send files with a target JSON schema; the pipeline extracts fields, not just text.

Inbound and results

See what is in the queue, what is processing and what is done, with the extracted data and confidence per file.

Live status

Online check and a live feed of the pipeline while it runs.

Visualisations

Flow graph, map, globe and charts over the extracted entities and their relations.

Schema templates

Schemas are kept locally and reused across uploads.

Nextcloud bridge

Send a file from Nextcloud straight into the pipeline.

Demo mode

Simulates a processing cycle without a backend, for evaluation and screenshots.

Why it is in the stack

  • Documents in, formats out: a PDF pile becomes structured business data in NocoDB, ready for the CRM, finance or search.
  • The whole pipeline (OCR gateway, n8n, NocoDB) runs in your own stack; nothing is uploaded to an IDP vendor.
  • A dashboard-first view on a batch process that is otherwise invisible.

Screenshots

Geo-intel view of extracted entities
Geo-intel view of extracted entities

Entities extracted from eight documents - companies, documents, persons, locations - placed on a map with their relations (document reference, ownership, location) drawn between them. The header shows the pipeline counters (in, processing, done) and the live feed; the left rail switches between dashboard, files, schema templates and map.

desktop.png
Mobile layout
Mobile layout

The same dashboard on a phone-sized viewport.

mobile.png

At a glance

Based onWilhelm acid
Type · categoryExternal service · Dashboards
Licenceservice MIT  ·  wrapper Proprietary  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support/acid
Docker imageacid/acid:latest · port 3050
Public URLhttps://acid.<your-domain>
Compose profileacid
Nextcloud app idwilhelmacid · Nextcloud 30-32
Tagsdashboardadmin
Folderapps/acid/manifest.json

Icon & assets

BrandBrand-SquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 🧪Emoji #FFCC00 one brand SVG → tools/app-assetsappinfo/ · serving copy in ./service/app/public

Configuration

Service

Imageacid/acid:latest
Port3050
Health checkhttp /healthz every 30s · timeout 5s · 3 retries

Embedding in Nextcloud

Registry id · labelacid · ACID Document Pipeline
Subdomainacid
Containeracid:3050
Embed-proxy port (localhost)8914
Compose profileacid
Nextcloud config keyacid_app_url

Nextcloud app

App idwilhelmacid
Path./nextcloud
Nextcloud versions30 - 32

Dependencies

Requiresnextcloud >=30
Optionalvault

Single sign-on (OIDC)

As clientyes
As providerno
Fallbackvaultwarden

Skin & branding

SloganDocuments in, formats out.
Themeprimary #FFCC00  ·  mode system
Logo./nextcloud/appinfo/icon.svg

Secrets

Declared in secretsRefs but apps/acid/secrets.spec.yaml does not exist in the repository.

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.

Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idacid
domainacid
vendoracid
nameACID
descriptionACID dashboard embedded in Nextcloud
version2.0.0
licenseservice, wrapper, wilhelm
serviceMIT
wrapperProprietary
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typeexternal
categorydashboard
emoji🧪
pixelIcon
............
.KKKKKKKKKK.
.KWWWKKWWWK.
.KWWWKKWWWK.
.KWWKWWKWWK.
.KWKWWWWKWK.
.KWKGGGGKWK.
.KWKGGGGKWK.
.KWWKKKKWWK.
.KKKKKKKKKK.
............
primaryColor#FFCC00
tagsdashboardadmin
compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
webpublicDir
previewdir, desktop, mobile, capture
captureurl, wait
wait800
componentsservice, nextcloudApp, embed, vscode
serviceimage, port, healthCheck
imageacid/acid:latest
port3050
healthChecktype, path, interval, timeout, retries
typehttp
path/healthz
interval30s
timeout5s
retries3
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmacid
minNcVersion30
maxNcVersion32
embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile
idacid
labelACID Document Pipeline
ncConfigKeyacid_app_url
subdomainacid
containeracid
containerPort3050
embedProxyPort8914
profileacid
vscodeextensions, extension
extensions[ ]
extensionnull
dependenciesrequires, optional
requires1 item
0id, version
idnextcloud
version>=30
optional1 item
0id
idvault
oidcCapabilityasClient, asProvider, fallback
asClienttrue
asProviderfalse
fallbackvaultwarden
secretsRefs./secrets.spec.yaml
skinslogan, logo, theme
sloganDocuments in, formats out.
themeprimary, mode
primary#FFCC00
modesystem
marketplacevisibility, screenshots, pricing, supportUrl
visibilitypublic
pricingfree

Standalone compose

Every service app can run on its own: cd apps/acid && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.

docker-compose.yml
# ACID - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/acid/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
#   cp .env.example .env && docker compose up -d
#   → http://localhost:${ACID_PORT:-3050}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
  acid:
    image: acid/acid:latest
    restart: unless-stopped
    env_file:
      - .env
    ports:
      - "${ACID_PORT:-3050}:3050"
    healthcheck:
      test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:3050/healthz"]
      interval: 30s
      timeout: 5s
      retries: 3
      start_period: 20s
    networks:
      - acid
    # TODO: persistent volume(s) if this image stores state. e.g.:
    #   volumes: [ "acid_data:/data" ]

networks:
  acid:
    name: acid
.env.example
# ACID - standalone env. Copy to .env and fill in.
# GENERATED by scripts/generate-standalone.mjs

# Host port the app is published on.
ACID_PORT=3050

# Required secrets are specified in:
#   ./secrets.spec.yaml
# Add the matching KEY=VALUE lines here.

README

The README is not in English - see apps/acid/README.md.

Support  ·  apps/acid/

doc/acid-reference.md  ·  doc/ai-notes.md  ·  doc/api.md  ·  doc/n8n.md  ·  doc/sources.md

NocoDB

A database without SQL anxiety.

External serviceDatabaseFair-Code-SULv2.0.0free

NocoDB database interface in Nextcloud

What it does

NocoDB turns any database into a smart spreadsheet - the open-source alternative to Airtable and to the Google Sheets that quietly became a company's database. Tables, relations, views, forms, automations and an API on top of PostgreSQL, MySQL or SQLite, with an interface that anyone who has used a spreadsheet already knows.

In the Wilhelm stack NocoDB is the central data layer: the place where n8n workflows write their results, where forms land, and where the other apps' data is joined, curated and shared as grids, galleries, kanban boards and forms.

Features

Grid view

A spreadsheet-like table with typed columns: text, numbers, dates, single and multi select, attachments, links to other tables, formulas, lookups and rollups.

Gallery, kanban, form and calendar views

The same table as a card gallery, a board grouped by a select field, a public form for data entry, or a calendar.

Fields, filters, grouping, sorting

Per-view configuration of visible fields, filters, groupings and sorts, shared with the team or kept private.

Forms

Drag-and-drop form builder on any table; share a public link and collect records without giving database access.

Relations and lookups

Link records across tables and pull fields through, the way a relational database is meant to be used.

REST API and webhooks

Every base gets a documented API and webhooks on record events - the glue for n8n.

Bring your own database

Connect an existing PostgreSQL or MySQL database and get the spreadsheet interface on top of it.

Roles and sharing

Workspace and base roles from viewer to owner; shared views and public forms.

Why it is in the stack

  • Replaces Airtable and spreadsheet-as-database with a fair-code tool that runs on your own PostgreSQL.
  • The stack's central data layer: n8n workflows, forms and the Wilhelm API read and write the same tables.
  • Embedded in Nextcloud with the stack's single sign-on; a database interface without SQL anxiety for the whole team.

Screenshots

Grid view
Grid view

A media project table as a spreadsheet: album, thumbnail attachment, platform and status as coloured select fields, release date, linked staff records and budget. Fields, filter, group-by and sort sit in the toolbar; the views of this table are listed on the right.

01-grid-view.jpg
Gallery view
Gallery view

The same records as cards with the attachment field as cover image and the platform underneath - a view configuration, not a copy of the data.

02-gallery-view.jpg
Kanban view
Kanban view

Records stacked by the platform field into columns; drag a card to another column and the field changes. Each column shows its record count and an add button.

03-kanban-view.jpg
Form view
Form view

A form built from the table's fields by drag and drop - title, description, which fields to show - shared as a public link so records can be collected without database access.

04-form-view.jpg

Screenshots are the upstream project's official product shots (see preview/SOURCES.md) until the stack runs with demo data and tools/app-preview shoots real Wilhelm screens. Images © their respective projects.

At a glance

Based onNocoDB · source · docs · API
ReplacesAirtable, Google Sheets · listed as Wilhelm Data in the ecosystem reference
Type · categoryExternal service · Database
Licenceservice Fair-Code-SUL  ·  wrapper Proprietary  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support/nocodb
Docker imagenocodb/nocodb:latest · port 8080
Public URLhttps://db.<your-domain> · behind AppAPI auth
Compose profilenocodb
Nextcloud app idwilhelmnocodb · Nextcloud 30-32
Tagsdatabasenocode
Folderapps/nocodb/manifest.json

Icon & assets

BrandBrandSquircleSquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 🗄️Emoji #7f4e8a one brand SVG → tools/app-assetsappinfo/

Configuration

Service

Imagenocodb/nocodb:latest
Port8080
Init script./service/init-nocodb.sh
Health checkhttp /api/v1/health every 30s · timeout 5s · 3 retries

Embedding in Nextcloud

Registry id · labelnocodb · NocoDB
Subdomaindb
Containernocodb:8080
Embed-proxy port (localhost)8892
Compose profilenocodb
Nextcloud config keynocodb_url
Auth gateyes - served as ExApp behind AppAPI auth ({"id":"wilhelmnocodb","adapter":"nocodb-exapp","upstream":"http://nocodb:8080","prefix":""})

Nextcloud app

App idwilhelmnocodb
Path./nextcloud
Nextcloud versions30 - 32

Desktop build (Electron)

Enabledyes
Start path/index.php/apps/wilhelmnocodb/
Hide Nextcloud chromeyes

Dependencies

Requiresnextcloud >=30
Optionalvault

Single sign-on (OIDC)

As clientyes
As providerno
Fallbackvaultwarden

Skin & branding

SloganA database without SQL anxiety.
Themeprimary #7f4e8a  ·  mode system
Logo./nextcloud/appinfo/icon.svg

Secrets

Declared in secretsRefs but apps/nocodb/secrets.spec.yaml does not exist in the repository.

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.

No formal certifications found (no SOC 2, ISO 27001 or DPA). GDPR compliance follows from self-hosting and rests with the operator.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idnocodb
domainnocodb
vendornocodb
nameNocoDB
descriptionNocoDB database interface in Nextcloud
version2.0.0
licenseservice, wrapper, wilhelm
serviceFair-Code-SUL
wrapperProprietary
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typeexternal
categorydatabase
emoji🗄️
pixelIcon
............
.KKKKKKKKKK.
.KWKKKKKKWK.
.KWKWWKWKWK.
.KWKKKKKKWK.
.KWKWWKWKWK.
.KWKKKKKKWK.
.KWKWWKWKWK.
.KWKKKKKKWK.
.KKKKKKKKKK.
............
primaryColor#7f4e8a
tagsdatabasenocode
compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
noteNo formal certifications found (no SOC 2, ISO 27001 or DPA). GDPR compliance follows from self-hosting and rests with the operator.
componentsservice, nextcloudApp, embed, vscode
serviceimage, port, healthCheck, init
imagenocodb/nocodb:latest
port8080
healthChecktype, path, interval, timeout, retries
typehttp
path/api/v1/health
interval30s
timeout5s
retries3
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmnocodb
minNcVersion30
maxNcVersion32
embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile, gate, exapp
idnocodb
labelNocoDB
ncConfigKeynocodb_url
subdomaindb
containernocodb
containerPort8080
embedProxyPort8892
profilenocodb
gatetrue
exappid, adapter, upstream, prefix
idwilhelmnocodb
adapternocodb-exapp
upstreamnocodb:8080
prefix
vscodeextensions, extension
extensions[ ]
extensionnull
desktopenabled, startPath, hideNextcloudChrome
enabledtrue
startPath/index.php/apps/wilhelmnocodb/
hideNextcloudChrometrue
dependenciesrequires, optional
requires1 item
0id, version
idnextcloud
version>=30
optional1 item
0id
idvault
oidcCapabilityasClient, asProvider, fallback
asClienttrue
asProviderfalse
fallbackvaultwarden
secretsRefs./secrets.spec.yaml
skinslogan, logo, theme
sloganA database without SQL anxiety.
themeprimary, mode
primary#7f4e8a
modesystem
previewdir, gallery
gallery4 items
0src, caption, kind
captionGrid view
kinddesktop
1src, caption, kind
captionGallery view
kinddesktop
2src, caption, kind
captionKanban
kinddesktop
3src, caption, kind
captionForm view
kinddesktop
marketplacevisibility, screenshots, pricing, supportUrl

Standalone compose

Every service app can run on its own: cd apps/nocodb && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.

docker-compose.yml
# NocoDB - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/nocodb/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
#   cp .env.example .env && docker compose up -d
#   → http://localhost:${NOCODB_PORT:-8080}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
  nocodb:
    image: nocodb/nocodb:latest
    restart: unless-stopped
    env_file:
      - .env
    ports:
      - "${NOCODB_PORT:-8080}:8080"
    healthcheck:
      test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:8080/api/v1/health"]
      interval: 30s
      timeout: 5s
      retries: 3
      start_period: 20s
    networks:
      - nocodb
    # TODO: persistent volume(s) if this image stores state. e.g.:
    #   volumes: [ "nocodb_data:/data" ]

networks:
  nocodb:
    name: nocodb
.env.example
# NocoDB - standalone env. Copy to .env and fill in.
# GENERATED by scripts/generate-standalone.mjs

# Host port the app is published on.
NOCODB_PORT=8080

# Required secrets are specified in:
#   ./secrets.spec.yaml
# Add the matching KEY=VALUE lines here.

README

The README is not in English - see apps/nocodb/README.md.

Upstream docs  ·  Upstream API  ·  Upstream source  ·  Support  ·  apps/nocodb/

doc/ai-notes.md  ·  doc/api.md  ·  doc/n8n.md  ·  doc/nocodb-reference.md  ·  doc/sources.md

Design

Design in the browser, as a team.

External serviceDesignMPL-2.0v2.0.0free

Penpot design tool in Nextcloud

What it does

Design is Penpot, the open-source design and prototyping platform that does what Figma and Adobe XD do - design, prototype and hand off to developers, together, in the browser - on an open SVG-based format and on your own server.

In the Wilhelm stack login runs exclusively through the Kernel (password login and registration are disabled), so the design team shares the stack's identity, and Penpot's webhooks let n8n react to design changes.

Features

Design and prototyping

Vector design, components, flex and grid layouts, interactive prototypes.

Developer hand-off

Inspect mode with measurements, CSS and assets; open SVG format, no proprietary lock-in.

Teams and libraries

Teams, projects, files and shared component libraries.

Comments

Comment threads on files for review.

Webhooks and API

Team-level webhooks; personal access tokens with expiry; RPC API.

Why it is in the stack

  • Design in the browser, as a team - Figma-class tooling without per-editor pricing.
  • Design files stay in your PostgreSQL and object store; SSO through the stack.
  • MPL-2.0 lets you run it as a service without opening the Wilhelm wrapper.

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs design.

At a glance

Based onPenpot · source · docs · API
ReplacesFigma, Adobe XD · listed as Wilhelm Design in the ecosystem reference
Type · categoryExternal service · Design
Licenceservice MPL-2.0  ·  wrapper Proprietary  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support/design
Docker imagepenpotapp/frontend:latest · port 8080
Public URLhttps://design.<your-domain>
Compose profilepenpot
Nextcloud app idwilhelmdesign · Nextcloud 30-32
Tagsdesignui
Folderapps/design/manifest.json

Icon & assets

BrandBrandSquircleSquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 🎨Emoji #7238B2 one brand SVG → tools/app-assetsappinfo/

Configuration

Service

Imagepenpotapp/frontend:latest
Port8080
Init script./service/init-penpot.sh
Health checkhttp / every 30s · timeout 5s · 3 retries

Embedding in Nextcloud

Registry id · labelpenpot · Penpot Design
Subdomaindesign
Containerpenpot-frontend:80
Embed-proxy port (localhost)8907
Compose profilepenpot
Nextcloud config keypenpot_url

Nextcloud app

App idwilhelmdesign
Path./nextcloud
Nextcloud versions30 - 32

Dependencies

Requiresnextcloud >=30
Optionalvault

Single sign-on (OIDC)

As clientyes
As providerno
Fallbackvaultwarden

Skin & branding

SloganDesign in the browser, as a team.
Themeprimary #7238B2  ·  mode system
Logo./nextcloud/appinfo/icon.svg

Secrets

Declared in secretsRefs but apps/design/secrets.spec.yaml does not exist in the repository.

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
DPA
Privacy
compliantcloud offeringPublic DPA with Kaleidos (EU hosting in Spain, no third-country transfers planned). source

Only GDPR/DPA documented for the Penpot SaaS; despite accessibility design features there is no WCAG conformance statement for the product.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

iddesign
domaindesign
vendorpenpot
nameDesign
descriptionPenpot design tool in Nextcloud
version2.0.0
licenseservice, wrapper, wilhelm
serviceMPL-2.0
wrapperProprietary
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typeexternal
categorydesign
emoji🎨
pixelIcon
............
.KKKKKKKKKK.
.KWWWKKWWWK.
.KWWKWWKWWK.
.KWWKWWKWWK.
.KWWKGGKWWK.
.KWWWKKWWWK.
.KWWWKKWWWK.
.KWWWWWWWWK.
.KKKKKKKKKK.
............
primaryColor#7238B2
tagsdesignui
compliancecertifications, note
certifications2 items
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
1id, status, scope, source, note
idgdpr-avv
statuscompliant
scopecloud
notePublic DPA with Kaleidos (EU hosting in Spain, no third-country transfers planned).
noteOnly GDPR/DPA documented for the Penpot SaaS; despite accessibility design features there is no WCAG conformance statement for the product.
componentsservice, nextcloudApp, embed, vscode
serviceimage, port, healthCheck, init
imagepenpotapp/frontend:latest
port8080
healthChecktype, path, interval, timeout, retries
typehttp
path/
interval30s
timeout5s
retries3
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmdesign
minNcVersion30
maxNcVersion32
embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile
idpenpot
labelPenpot Design
ncConfigKeypenpot_url
subdomaindesign
containerpenpot-frontend
containerPort80
embedProxyPort8907
profilepenpot
vscodeextensions, extension
extensions[ ]
extensionnull
dependenciesrequires, optional
requires1 item
0id, version
idnextcloud
version>=30
optional1 item
0id
idvault
oidcCapabilityasClient, asProvider, fallback
asClienttrue
asProviderfalse
fallbackvaultwarden
secretsRefs./secrets.spec.yaml
skinslogan, logo, theme
sloganDesign in the browser, as a team.
themeprimary, mode
primary#7238B2
modesystem
marketplacevisibility, screenshots, pricing, supportUrl
visibilitypublic
screenshots[ ]
pricingfree

Standalone compose

Every service app can run on its own: cd apps/design && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.

docker-compose.yml
# Design - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/design/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
#   cp .env.example .env && docker compose up -d
#   → http://localhost:${DESIGN_PORT:-8080}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
  design:
    image: penpotapp/frontend:latest
    restart: unless-stopped
    env_file:
      - .env
    ports:
      - "${DESIGN_PORT:-8080}:8080"
    healthcheck:
      test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:8080/"]
      interval: 30s
      timeout: 5s
      retries: 3
      start_period: 20s
    networks:
      - design
    # TODO: persistent volume(s) if this image stores state. e.g.:
    #   volumes: [ "design_data:/data" ]

networks:
  design:
    name: design
.env.example
# Design - standalone env. Copy to .env and fill in.
# GENERATED by scripts/generate-standalone.mjs

# Host port the app is published on.
DESIGN_PORT=8080

# Required secrets are specified in:
#   ./secrets.spec.yaml
# Add the matching KEY=VALUE lines here.

README

The README is not in English - see apps/design/README.md.

Upstream docs  ·  Upstream API  ·  Upstream source  ·  Support  ·  apps/design/

doc/ai-notes.md  ·  doc/api.md  ·  doc/design-reference.md  ·  doc/n8n.md  ·  doc/sources.md

Sign

Signatures, digital and binding.

External serviceDocumentsAGPL-3.0v2.0.0free

Documenso document signing in Nextcloud

What it does

Sign is Documenso, the open-source alternative to DocuSign and Adobe Sign: upload a PDF, place signature and form fields, add recipients in order, send - and get back a cryptographically signed PDF with an audit trail. Templates, teams, embedding and an API make it part of a process rather than a one-off.

In the Wilhelm stack it signs in through the Kernel, takes PDFs from Nextcloud Files, and n8n creates envelopes from templates and receives status webhooks. Today it provides simple electronic signatures; qualified signatures (eIDAS AES/QES) are announced upstream.

Features

Fields and recipients

Drag signature, text, date and checkbox fields; signing order.

Templates

Reusable documents with pre-placed fields.

Signed PDFs

Certificate-based signing with an audit trail.

Teams

Shared documents and templates.

Embedding and API

Sign inside your own apps; envelope-based API v2.

Why it is in the stack

  • Signatures, digital and binding - without per-envelope pricing.
  • Documents and signing certificates stay on your server; same SSO and file storage as the rest of the office.

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs sign.

At a glance

Based onDocumenso · source · docs · API
ReplacesDocuSign, Adobe Sign · listed as Wilhelm Sign in the ecosystem reference
Type · categoryExternal service · Documents
Licenceservice AGPL-3.0  ·  wrapper Proprietary  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support/sign
Docker imagedocumenso/documenso:latest · port 3000
Public URLhttps://sign.<your-domain>
Compose profiledocumenso
Nextcloud app idwilhelmsign · Nextcloud 30-32
Tagssigningdocuments
Folderapps/sign/manifest.json

Icon & assets

BrandBrand-SquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel ✍️Emoji #1E7980 one brand SVG → tools/app-assetsappinfo/

Configuration

Service

Imagedocumenso/documenso:latest
Port3000
Init script./service/init-documenso.sh
Health checkhttp /api/health every 30s · timeout 5s · 3 retries

Embedding in Nextcloud

Registry id · labeldocumenso · Documenso E-Signing
Subdomainsign
Containerdocumenso:3000
Embed-proxy port (localhost)8903
Compose profiledocumenso
Nextcloud config keydocumenso_url

Nextcloud app

App idwilhelmsign
Path./nextcloud
Nextcloud versions30 - 32

Dependencies

Requiresnextcloud >=30
Optionalvault

Single sign-on (OIDC)

As clientyes
As providerno
Fallbackvaultwarden

Skin & branding

SloganSignatures, digital and binding.
Themeprimary #1E7980  ·  mode system
Logo./nextcloud/appinfo/icon.svg

Secrets

Declared in secretsRefs but apps/sign/secrets.spec.yaml does not exist in the repository.

Compliance

StandardStatusScopeNote
eIDAS (SES)
Electronic signature
compliantsoftwareSimple electronic signature (SES) under eIDAS; AES/QES announced for H2 2026. source
ESIGN / UETA
Electronic signature
compliantsoftwareCompliant with the US ESIGN Act and UETA. source
SOC 2 Type II
Information security
vendor claimcloud offeringListed as "compliant", without public auditor details. source
21 CFR Part 11
Healthcare
vendor claimcloud offeringListed as "compliant"; Part 11 suitability depends heavily on the processes of the organisation using it. source
GDPR
Privacy
vendor claimcloud offeringGDPR handling documented for the hosted service; self-hosters are their own controller. source

Honest compliance matrix: today SES level plus ESIGN/UETA; ISO 27001, ZertES and eIDAS AES/QES are announced for 2026. Not yet suitable for qualified signatures (QES).

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idsign
domainsign
vendordocumenso
nameSign
descriptionDocumenso document signing in Nextcloud
version2.0.0
licenseservice, wrapper, wilhelm
serviceAGPL-3.0
wrapperProprietary
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typeexternal
categorydocuments
emoji✍️
pixelIcon
............
.KKKKKKKKKK.
.KWWWWWKKWK.
.KWWWWKKKWK.
.KWWWKKKWWK.
.KWWKKKWWWK.
.KWKKWWWWWK.
.KWWWWWWWWK.
.KGGWGGWGGK.
.KKKKKKKKKK.
............
primaryColor#1E7980
tagssigningdocuments
compliancecertifications, note
certifications5 items
0id, status, scope, source, note
ideidas-ses
statuscompliant
scopesoftware
noteSimple electronic signature (SES) under eIDAS; AES/QES announced for H2 2026.
1id, status, scope, source, note
idesign-ueta
statuscompliant
scopesoftware
noteCompliant with the US ESIGN Act and UETA.
2id, status, scope, source, note
idsoc2-type2
statusclaimed
scopecloud
noteListed as "compliant", without public auditor details.
3id, status, scope, source, note
id21-cfr-part-11
statusclaimed
scopecloud
noteListed as "compliant"; Part 11 suitability depends heavily on the processes of the organisation using it.
4id, status, scope, source, note
idgdpr
statusclaimed
scopecloud
noteGDPR handling documented for the hosted service; self-hosters are their own controller.
noteHonest compliance matrix: today SES level plus ESIGN/UETA; ISO 27001, ZertES and eIDAS AES/QES are announced for 2026. Not yet suitable for qualified signatures (QES).
componentsservice, nextcloudApp, embed, vscode
serviceimage, port, healthCheck, init
imagedocumenso/documenso:latest
port3000
healthChecktype, path, interval, timeout, retries
typehttp
path/api/health
interval30s
timeout5s
retries3
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmsign
minNcVersion30
maxNcVersion32
embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile
iddocumenso
labelDocumenso E-Signing
ncConfigKeydocumenso_url
subdomainsign
containerdocumenso
containerPort3000
embedProxyPort8903
profiledocumenso
vscodeextensions, extension
extensions[ ]
extensionnull
dependenciesrequires, optional
requires1 item
0id, version
idnextcloud
version>=30
optional1 item
0id
idvault
oidcCapabilityasClient, asProvider, fallback
asClienttrue
asProviderfalse
fallbackvaultwarden
secretsRefs./secrets.spec.yaml
skinslogan, logo, theme
sloganSignatures, digital and binding.
themeprimary, mode
primary#1E7980
modesystem
marketplacevisibility, screenshots, pricing, supportUrl
visibilitypublic
screenshots[ ]
pricingfree

Standalone compose

Every service app can run on its own: cd apps/sign && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.

docker-compose.yml
# Sign - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/sign/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
#   cp .env.example .env && docker compose up -d
#   → http://localhost:${SIGN_PORT:-3000}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
  sign:
    image: documenso/documenso:latest
    restart: unless-stopped
    env_file:
      - .env
    ports:
      - "${SIGN_PORT:-3000}:3000"
    healthcheck:
      test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:3000/api/health"]
      interval: 30s
      timeout: 5s
      retries: 3
      start_period: 20s
    networks:
      - sign
    # TODO: persistent volume(s) if this image stores state. e.g.:
    #   volumes: [ "sign_data:/data" ]

networks:
  sign:
    name: sign
.env.example
# Sign - standalone env. Copy to .env and fill in.
# GENERATED by scripts/generate-standalone.mjs

# Host port the app is published on.
SIGN_PORT=3000

# Required secrets are specified in:
#   ./secrets.spec.yaml
# Add the matching KEY=VALUE lines here.

README

The README is not in English - see apps/sign/README.md.

Upstream docs  ·  Upstream API  ·  Upstream source  ·  Support  ·  apps/sign/

doc/ai-notes.md  ·  doc/api.md  ·  doc/n8n.md  ·  doc/sign-reference.md  ·  doc/sources.md

Finance

Your portfolio, clearly.

External serviceFinanceAGPL-3.0v2.0.0free

Ghostfolio portfolio tracker in Nextcloud

What it does

Finance is Ghostfolio, the open-source wealth-management software that tracks a portfolio across accounts and asset classes - stocks, ETFs, crypto - and delivers performance and risk analysis, the way Portfolio Performance or a broker's dashboard would, on your own server.

Transactions can be imported from any source, so n8n can feed it from bank exports or shop orders and pull snapshots back out for reports and notifications.

Features

Multi-account portfolio

Stocks, ETFs, crypto and cash across any number of accounts and currencies.

Performance analysis

Returns over today, year-to-date, up to five years and all time.

Risk and allocation

Diversification by asset class, sector, region and currency; risk indicators.

Import and export

Buy, sell, dividend, fee, interest and liability activities via API or CSV.

Public portfolio link

A read-only share of your portfolio without giving away account access.

Market data providers

Configurable data sources for prices.

Why it is in the stack

  • Your portfolio, clearly - financial data on your own server instead of a broker's cloud.
  • No subscription; feed it from any source through the API.
  • Embedded in Nextcloud with single sign-on; reports via n8n.

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs finance.

At a glance

Based onGhostfolio · source · docs · API
ReplacesYahoo Finance, Portfolio Performance · listed as Wilhelm Finance in the ecosystem reference
Type · categoryExternal service · Finance
Licenceservice AGPL-3.0  ·  wrapper Proprietary  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support/finance
Docker imageghostfolio/ghostfolio:latest · port 3333
Public URLhttps://finance.<your-domain>
Compose profileghostfolio
Nextcloud app idwilhelmfinance · Nextcloud 30-32
Tagsfinanceportfolio
Folderapps/finance/manifest.json

Icon & assets

BrandBrandSquircleSquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 💰Emoji #F97316 one brand SVG → tools/app-assetsappinfo/

Configuration

Service

Imageghostfolio/ghostfolio:latest
Port3333
Init script./service/init-ghostfolio.sh
Health checkhttp /api/v1/health every 30s · timeout 5s · 3 retries

Embedding in Nextcloud

Registry id · labelghostfolio · Ghostfolio Finance
Subdomainfinance
Containerghostfolio:3333
Embed-proxy port (localhost)8909
Compose profileghostfolio
Nextcloud config keyghostfolio_url

Nextcloud app

App idwilhelmfinance
Path./nextcloud
Nextcloud versions30 - 32

Dependencies

Requiresnextcloud >=30
Optionalvault

Single sign-on (OIDC)

As clientyes
As providerno
Fallbackvaultwarden

Skin & branding

SloganYour portfolio, clearly.
Themeprimary #F97316  ·  mode system
Logo./nextcloud/appinfo/icon.svg

Secrets

Declared in secretsRefs but apps/finance/secrets.spec.yaml does not exist in the repository.

Compliance

StandardStatusScopeNote
GDPR
Privacy
vendor claimcloud offeringPrivacy policy of the SaaS (operated from Zurich under Swiss data protection law); no audited certification. source

Swiss community project without formal certifications - privacy via self-hosting.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idfinance
domainfinance
vendorghostfolio
nameFinance
descriptionGhostfolio portfolio tracker in Nextcloud
version2.0.0
licenseservice, wrapper, wilhelm
serviceAGPL-3.0
wrapperProprietary
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typeexternal
categoryfinance
emoji💰
pixelIcon
............
.KKKKKKKKKK.
.KWWWWWKKWK.
.KWWWWWWKWK.
.KWWWWWKWWK.
.KWWWWKWWWK.
.KWWWKWWWWK.
.KWWKWWWWWK.
.KWKWWWWWWK.
.KKKKKKKKKK.
............
primaryColor#F97316
tagsfinanceportfolio
compliancecertifications, note
certifications1 item
0id, status, scope, source, note
idgdpr
statusclaimed
scopecloud
notePrivacy policy of the SaaS (operated from Zurich under Swiss data protection law); no audited certification.
noteSwiss community project without formal certifications - privacy via self-hosting.
componentsservice, nextcloudApp, embed, vscode
serviceimage, port, healthCheck, init
imageghostfolio/ghostfolio:latest
port3333
healthChecktype, path, interval, timeout, retries
typehttp
path/api/v1/health
interval30s
timeout5s
retries3
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmfinance
minNcVersion30
maxNcVersion32
embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile
idghostfolio
labelGhostfolio Finance
ncConfigKeyghostfolio_url
subdomainfinance
containerghostfolio
containerPort3333
embedProxyPort8909
profileghostfolio
vscodeextensions, extension
extensions[ ]
extensionnull
dependenciesrequires, optional
requires1 item
0id, version
idnextcloud
version>=30
optional1 item
0id
idvault
oidcCapabilityasClient, asProvider, fallback
asClienttrue
asProviderfalse
fallbackvaultwarden
secretsRefs./secrets.spec.yaml
skinslogan, logo, theme
sloganYour portfolio, clearly.
themeprimary, mode
primary#F97316
modesystem
marketplacevisibility, screenshots, pricing, supportUrl
visibilitypublic
screenshots[ ]
pricingfree

Standalone compose

Every service app can run on its own: cd apps/finance && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.

docker-compose.yml
# Finance - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/finance/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
#   cp .env.example .env && docker compose up -d
#   → http://localhost:${FINANCE_PORT:-3333}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
  finance:
    image: ghostfolio/ghostfolio:latest
    restart: unless-stopped
    env_file:
      - .env
    ports:
      - "${FINANCE_PORT:-3333}:3333"
    healthcheck:
      test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:3333/api/v1/health"]
      interval: 30s
      timeout: 5s
      retries: 3
      start_period: 20s
    networks:
      - finance
    # TODO: persistent volume(s) if this image stores state. e.g.:
    #   volumes: [ "finance_data:/data" ]

networks:
  finance:
    name: finance
.env.example
# Finance - standalone env. Copy to .env and fill in.
# GENERATED by scripts/generate-standalone.mjs

# Host port the app is published on.
FINANCE_PORT=3333

# Required secrets are specified in:
#   ./secrets.spec.yaml
# Add the matching KEY=VALUE lines here.

README

The README is not in English - see apps/finance/README.md.

Upstream docs  ·  Upstream API  ·  Upstream source  ·  Support  ·  apps/finance/

doc/ai-notes.md  ·  doc/api.md  ·  doc/finance-reference.md  ·  doc/n8n.md  ·  doc/sources.md

Forms

Ask. Answer. Done.

External serviceFormsAGPL-3.0v2.0.0free

Formbricks forms in Nextcloud

What it does

Forms is Formbricks, the open-source experience-management platform for surveys and forms: in-app surveys triggered by what users do, link surveys for everyone else, and evaluation of the answers - what Typeform, Qualtrics and Google Forms do, with the responses in your own database.

In the Wilhelm stack it signs in through the Kernel, and its webhooks push every response into n8n, where it can become a NocoDB record, a CRM note or a notification.

Features

Link and in-app surveys

Share a link or trigger a survey on user actions in your product.

Templates

NPS, onboarding, product feedback, churn and classic forms to start from.

Logic and targeting

Conditional logic; contacts with attributes for targeting.

Analysis

Summaries, filters and response exports.

Management and client API

Surveys, responses, contacts and webhooks via API; a public client API for the web SDK.

OIDC SSO

Single sign-on built in.

Why it is in the stack

  • Ask. Answer. Done. - survey responses stay in your own database, which matters for customer and employee feedback.
  • No per-response pricing; unmodified upstream image behind the Wilhelm wrapper.
  • Every response is an automation trigger via n8n.

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs forms.

At a glance

Based onFormbricks · source · docs · API
ReplacesTypeform, Google Forms · listed as Wilhelm Forms in the ecosystem reference
Type · categoryExternal service · Forms
Licenceservice AGPL-3.0  ·  wrapper Proprietary  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support/forms
Docker imageformbricks/formbricks:latest · port 3000
Public URLhttps://forms.<your-domain>
Compose profileformbricks
Nextcloud app idwilhelmforms · Nextcloud 30-32
Tagsformssurveys
Folderapps/forms/manifest.json

Icon & assets

BrandBrand-SquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 📝Emoji #5349D3 one brand SVG → tools/app-assetsappinfo/

Configuration

Service

Imageformbricks/formbricks:latest
Port3000
Init script./service/init-formbricks.sh
Health checkhttp /health every 30s · timeout 5s · 3 retries

Embedding in Nextcloud

Registry id · labelformbricks · Formbricks Forms
Subdomainforms
Containerformbricks:3000
Embed-proxy port (localhost)8902
Compose profileformbricks
Nextcloud config keyformbricks_url

Nextcloud app

App idwilhelmforms
Path./nextcloud
Nextcloud versions30 - 32

Dependencies

Requiresnextcloud >=30
Optionalvault

Single sign-on (OIDC)

As clientyes
As providerno
Fallbackvaultwarden

Skin & branding

SloganAsk. Answer. Done.
Themeprimary #5349D3  ·  mode system
Logo./nextcloud/appinfo/icon.svg

Secrets

Declared in secretsRefs but apps/forms/secrets.spec.yaml does not exist in the repository.

Compliance

StandardStatusScopeNote
GDPR
Privacy
compliantcloud offeringGerman vendor, cloud hosting in Germany, DPA linked - GDPR by design. source
SOC 2 Type II
Information security
vendor claimcloud offeringSOC 2 Type II according to the privacy page; no publicly linked audit report. source
ISO/IEC 27001
Information security
vendor claimcloud offeringISO 27001 according to the privacy page; sources disagree on whether the certification is complete. source
HIPAA
Healthcare
vendor claimsoftwareHIPAA use promoted primarily via self-hosting (the customer controls PHI); no BAA programme documented. source

Strong GDPR story (German company, hosting in Germany); SOC 2 / ISO 27001 are vendor claims without a public trust center.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idforms
domainforms
vendorformbricks
nameForms
descriptionFormbricks forms in Nextcloud
version2.0.0
licenseservice, wrapper, wilhelm
serviceAGPL-3.0
wrapperProprietary
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typeexternal
categoryforms
emoji📝
pixelIcon
............
.KKKKKKKKKK.
.KWGWKKKWWK.
.KWWWWWWWWK.
.KWGWKKKWWK.
.KWWWWWWWWK.
.KWGWKKKWWK.
.KWWWWWWWWK.
.KWWWWWWWWK.
.KKKKKKKKKK.
............
primaryColor#5349D3
tagsformssurveys
compliancecertifications, note
certifications4 items
0id, status, scope, source, note
idgdpr
statuscompliant
scopecloud
noteGerman vendor, cloud hosting in Germany, DPA linked - GDPR by design.
1id, status, scope, source, note
idsoc2-type2
statusclaimed
scopecloud
noteSOC 2 Type II according to the privacy page; no publicly linked audit report.
2id, status, scope, source, note
idiso-27001
statusclaimed
scopecloud
noteISO 27001 according to the privacy page; sources disagree on whether the certification is complete.
3id, status, scope, source, note
idhipaa
statusclaimed
scopesoftware
noteHIPAA use promoted primarily via self-hosting (the customer controls PHI); no BAA programme documented.
noteStrong GDPR story (German company, hosting in Germany); SOC 2 / ISO 27001 are vendor claims without a public trust center.
componentsservice, nextcloudApp, embed, vscode
serviceimage, port, healthCheck, init
imageformbricks/formbricks:latest
port3000
healthChecktype, path, interval, timeout, retries
typehttp
path/health
interval30s
timeout5s
retries3
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmforms
minNcVersion30
maxNcVersion32
embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile
idformbricks
labelFormbricks Forms
ncConfigKeyformbricks_url
subdomainforms
containerformbricks
containerPort3000
embedProxyPort8902
profileformbricks
vscodeextensions, extension
extensions[ ]
extensionnull
dependenciesrequires, optional
requires1 item
0id, version
idnextcloud
version>=30
optional1 item
0id
idvault
oidcCapabilityasClient, asProvider, fallback
asClienttrue
asProviderfalse
fallbackvaultwarden
secretsRefs./secrets.spec.yaml
skinslogan, logo, theme
sloganAsk. Answer. Done.
themeprimary, mode
primary#5349D3
modesystem
marketplacevisibility, screenshots, pricing, supportUrl
visibilitypublic
screenshots[ ]
pricingfree

Standalone compose

Every service app can run on its own: cd apps/forms && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.

docker-compose.yml
# Forms - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/forms/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
#   cp .env.example .env && docker compose up -d
#   → http://localhost:${FORMS_PORT:-3000}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
  forms:
    image: formbricks/formbricks:latest
    restart: unless-stopped
    env_file:
      - .env
    ports:
      - "${FORMS_PORT:-3000}:3000"
    healthcheck:
      test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:3000/health"]
      interval: 30s
      timeout: 5s
      retries: 3
      start_period: 20s
    networks:
      - forms
    # TODO: persistent volume(s) if this image stores state. e.g.:
    #   volumes: [ "forms_data:/data" ]

networks:
  forms:
    name: forms
.env.example
# Forms - standalone env. Copy to .env and fill in.
# GENERATED by scripts/generate-standalone.mjs

# Host port the app is published on.
FORMS_PORT=3000

# Required secrets are specified in:
#   ./secrets.spec.yaml
# Add the matching KEY=VALUE lines here.

README

The README is not in English - see apps/forms/README.md.

Upstream docs  ·  Upstream API  ·  Upstream source  ·  Support  ·  apps/forms/

doc/ai-notes.md  ·  doc/api.md  ·  doc/forms-reference.md  ·  doc/n8n.md  ·  doc/sources.md

Integrations

Everything talks to everything.

InfrastructureInfrastructureProprietaryv2.0.0

integrations infrastructure (Wilhelm-managed)

What it does

Integrations is a reserved namespace for Wilhelm-managed integration infrastructure - the place where cross-app connectors will live. Today it ships nothing executable: manifest and icon only.

It is listed so that the catalogue and the graph already know the slot; the notes say plainly that it is currently without function.

Features

Reserved infrastructure namespace

No service container, no API surface, no Nextcloud app yet

Why it is in the stack

  • Everything talks to everything - the intent; status: placeholder.

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs integrations.

At a glance

Based onWilhelm-native - no upstream project
Type · categoryInfrastructure · Infrastructure
Licenceservice Proprietary  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Tagsinfrastructure
Folderapps/integrations/manifest.json

Icon & assets

BrandBrand-SquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 🔧Emoji #6B7280 one brand SVG → tools/app-assetsappinfo/

Configuration

Skin & branding

SloganEverything talks to everything.
Themeprimary #6B7280  ·  mode system
Logo./appinfo/icon.svg

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.

Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idintegrations
domainintegrations
vendorwilhelm
nameIntegrations
descriptionintegrations infrastructure (Wilhelm-managed)
version2.0.0
licenseservice, wilhelm
serviceProprietary
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typeinfrastructure
categoryinfrastructure
emoji🔧
pixelIcon
............
.KKKKKKKKKK.
.KWWKWKWWWK.
.KWWKWKWWWK.
.KWKKKKKWWK.
.KWKKKKKWWK.
.KWWWKWWWWK.
.KWWWKWWWWK.
.KWWWWKKWWK.
.KKKKKKKKKK.
............
primaryColor#6B7280
tagsinfrastructure
compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
skinslogan, logo, theme
sloganEverything talks to everything.
themeprimary, mode
primary#6B7280
modesystem
componentsvscode
vscodeextensions, extension
extensions[ ]
extensionnull

apps/integrations/

doc/ai-notes.md  ·  doc/api.md  ·  doc/sources.md

Wilhelm Cloud

Your server in one minute.

InfrastructureInfrastructureProprietaryv0.1.0

Managed Wilhelm server: bought in the shop (Medusa/PayPal), provisioned automatically through the Hetzner Cloud API (white-label), delivered as a fully installed stack.

What it does

Wilhelm Cloud turns the stack into a product you can sell: a customer buys a Wilhelm server in your Medusa shop, pays by PayPal, and receives a fully installed stack under their own subdomain - provisioned automatically through the Hetzner Cloud API, white-label, so the infrastructure provider never appears in the UI, the mails or the invoices.

It is wiring of existing stack pieces rather than new software: the shop, an n8n order workflow, a dependency-free provisioner with cloud-init, the mail server for the welcome mail, and TaskHQ for operating the provisioned servers afterwards.

Features

Shop product

A 'Wilhelm Server' product with plan and subdomain metadata in Medusa; PayPal as payment provider - no own payment code.

Order workflow

n8n assigns the subdomain, calls the provisioner, sets the DNS record and sends the welcome mail.

Provisioner

Zero-dependency Node script with dry-run, webhook mode for n8n and a manual CLI; server self-installs via cloud-init.

Configurable servers

Server type, location and image are parameters.

Operations

Provisioned servers appear in TaskHQ under 'Connect to server' over hardened SSH.

Why it is in the stack

  • Your server in one minute: sell managed Wilhelm servers under your own brand, end to end automated.
  • Reuses the stack instead of adding bespoke code; the provider is named as processor where GDPR requires it.
  • Status is stated plainly: provisioner done, shop and workflow wiring in progress.

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs cloud.

At a glance

Based onWilhelm-native - no upstream project
Type · categoryInfrastructure · Infrastructure
Licenceservice Proprietary  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Tagscloudprovisioninghosting
Folderapps/cloud/manifest.json

Icon & assets

BrandBrand-SquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel ☁️Emoji #0369FF one brand SVG → tools/app-assetsappinfo/

Configuration

Skin & branding

SloganYour server in one minute.
Themeprimary #0369FF  ·  mode system
Logo./icon.svg

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.

Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idcloud
domaincloud
vendorwilhelm
nameWilhelm Cloud
descriptionManaged Wilhelm server: bought in the shop (Medusa/PayPal), provisioned automatically through the Hetzner Cloud API (white-label), delivered as a fully installed stack.
version0.1.0
licenseservice, wilhelm
serviceProprietary
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typeinfrastructure
categoryinfrastructure
emoji☁️
primaryColor#0369FF
pixelIcon
............
............
....KKKK....
...KWWWWK...
..KWWWWWWK..
.KWWWWWWWWK.
.KWWWWWWWWK.
..KKKKKKKK..
............
............
tagscloudprovisioninghosting
compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
skinslogan, logo, theme
sloganYour server in one minute.
themeprimary, mode
primary#0369FF
modesystem

README

The README is not in English - see apps/cloud/README.md.

apps/cloud/

doc/sources.md

Mail

Mail under your own roof.

External serviceMailGPL-3.0v2.0.0free

E-mail integration in Nextcloud

What it does

Mail is mailcow, the dockerised mail server suite: Postfix, Dovecot, Rspamd, SOGo webmail with calendar and contacts, ActiveSync for phones, and an admin interface that makes running your own mail server a matter of adding domains and mailboxes. It stands in for Google Workspace mail and Microsoft 365 Exchange.

Everything a mailbox owner would expect from a hosted provider is there - spam filtering with adjustable thresholds, aliases and temporary addresses, plus-address tagging into folders, whitelists and blacklists, sync jobs to pull in old accounts - under your own domain, on your own server.

Features

Full mail stack

SMTP, IMAP, POP3, Sieve filters, DKIM, DMARC, SPF, TLS out of the box.

Spam filtering

Rspamd with per-mailbox low and high score thresholds, learning from junk moves, whitelists and blacklists.

Webmail, calendar, contacts

SOGo groupware with CalDAV and CardDAV; ActiveSync for mobile mail, calendar and contacts.

Aliases and tagging

Domain and mailbox aliases, temporary random aliases with a lifetime, plus-address tags that sort into subfolders.

Admin interface

Domains, mailboxes, quotas, resources, domain admins, per-user settings - no config files.

Sync jobs

Pull mail from an existing external account on a schedule during migration.

Encryption policy

Enforce TLS for specific domains or peers.

Backups and updates

Scripted backup and restore; the update script keeps the suite current.

Why it is in the stack

  • Your mail under your own domain and roof - no provider reads, mines or rate-limits it; the best German GDPR story in the stack.
  • Embedded in Nextcloud alongside Nextcloud Mail, calendar and contacts, with the stack's single sign-on.
  • Newsletter (listmonk) and Tell (IMAP intelligence) build on it for bulk sending and smart inbox handling.

Screenshots

Per-mailbox spam thresholds
Per-mailbox spam thresholds

Two sliders set the low and high spam score: below the first is not spam, between them mail is tagged and moved to junk, above the second the server rejects it. Whitelist and blacklist entries with wildcards sit underneath.

01-spam-filter.jpg
Temporary e-mail aliases
Temporary e-mail aliases

Generate a random alias with a lifetime of a few hours, extend or remove it - a throwaway address for sign-ups that never exposes the real mailbox.

02-spam-alias.jpg
Plus-address tagging
Plus-address tagging

Mail to you+Facebook@example.org lands in the subfolder INBOX/Facebook or gets the tag prepended to the subject - a filing system without filter rules. The mailbox quota and the ActiveSync device cache reset live on the same page.

03-tagging.jpg
Whitelist and blacklist
Whitelist and blacklist

Addresses or wildcard patterns that are never classified as spam, and ones that are always rejected - per mailbox, in addition to the domain-wide rules.

04-blacklist-whitelist.jpg

Screenshots are the upstream project's official product shots (see preview/SOURCES.md) until the stack runs with demo data and tools/app-preview shoots real Wilhelm screens. Images © their respective projects.

At a glance

Based onmailcow: dockerized · source · docs · API
Type · categoryExternal service · Mail
Licenceservice GPL-3.0  ·  wrapper Proprietary  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support/mailcow
Docker imagemailcow/mailcow:latest · port 8080
Public URLhttps://mail.<your-domain>
Compose profilelistmonk
Nextcloud app idwilhelmmail · Nextcloud 30-32
Tagsmailemailserver
Folderapps/mailcow/manifest.json

Icon & assets

BrandBrandSquircleSquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 📧Emoji #0369FF one brand SVG → tools/app-assetsappinfo/

Configuration

Service

Imagemailcow/mailcow:latest
Port8080
Init script./service/setup-mailcow.sh
Health checkhttp / every 30s · timeout 5s · 3 retries

Embedding in Nextcloud

Registry id · labellistmonk · Listmonk Newsletter
Subdomainmail
Containerlistmonk:9000
Embed-proxy port (localhost)8900
Compose profilelistmonk
Nextcloud config keylistmonk_url

Nextcloud app

App idwilhelmmail
Path./nextcloud
Nextcloud versions30 - 32

Dependencies

Requiresnextcloud >=30
Optionalvault

Single sign-on (OIDC)

As clientyes
As providerno
Fallbackvaultwarden

Skin & branding

SloganMail under your own roof.
Themeprimary #0369FF  ·  mode system
Logo./nextcloud/appinfo/icon.svg

Secrets

Declared in secretsRefs but apps/mailcow/secrets.spec.yaml does not exist in the repository.

Compliance

StandardStatusScopeNote
GDPR
Privacy
compliantvendorGerman vendor (tinc GmbH, Willich) with GDPR privacy policies for all offerings. source
DPA
Privacy
compliantcloud offeringDPA under Art. 28 GDPR can be concluded directly in the Servercow customer profile; hosted mailcow runs in Frankfurt. source

The best German GDPR story in the stack (German GmbH, German data centre, self-service DPA); no ISO 27001 / SOC 2 certificates.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idmailcow
domainmailcow
vendormailcow
nameMail
descriptionE-mail integration in Nextcloud
version2.0.0
licenseservice, wrapper, wilhelm
serviceGPL-3.0
wrapperProprietary
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typeexternal
categorymail
emoji📧
pixelIcon
............
.KKKKKKKKKK.
.KWKKKKKKWK.
.KWKKWWKKWK.
.KWKWKKWKWK.
.KWKWWWWKWK.
.KWKWWWWKWK.
.KWKKKKKKWK.
.KWWWWWWWWK.
.KKKKKKKKKK.
............
primaryColor#0369FF
tagsmailemailserver
compliancecertifications, note
certifications2 items
0id, status, scope, source, note
idgdpr
statuscompliant
scopevendor
noteGerman vendor (tinc GmbH, Willich) with GDPR privacy policies for all offerings.
1id, status, scope, source, note
idgdpr-avv
statuscompliant
scopecloud
noteDPA under Art. 28 GDPR can be concluded directly in the Servercow customer profile; hosted mailcow runs in Frankfurt.
noteThe best German GDPR story in the stack (German GmbH, German data centre, self-service DPA); no ISO 27001 / SOC 2 certificates.
componentsservice, nextcloudApp, embed, vscode
serviceimage, port, healthCheck, init
imagemailcow/mailcow:latest
port8080
healthChecktype, path, interval, timeout, retries
typehttp
path/
interval30s
timeout5s
retries3
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmmail
minNcVersion30
maxNcVersion32
embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile
idlistmonk
labelListmonk Newsletter
ncConfigKeylistmonk_url
subdomainmail
containerlistmonk
containerPort9000
embedProxyPort8900
profilelistmonk
vscodeextensions, extension
extensions[ ]
extensionnull
dependenciesrequires, optional
requires1 item
0id, version
idnextcloud
version>=30
optional1 item
0id
idvault
oidcCapabilityasClient, asProvider, fallback
asClienttrue
asProviderfalse
fallbackvaultwarden
secretsRefs./secrets.spec.yaml
skinslogan, logo, theme
sloganMail under your own roof.
themeprimary, mode
primary#0369FF
modesystem
previewdir, gallery
gallery4 items
0src, caption, kind
captionSpam filter
kinddesktop
1src, caption, kind
captionSpam alias
kinddesktop
2src, caption, kind
captionTagging
kinddesktop
3src, caption, kind
captionBlacklist / whitelist
kinddesktop
marketplacevisibility, screenshots, pricing, supportUrl

Standalone compose

Every service app can run on its own: cd apps/mailcow && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.

docker-compose.yml
# Mail - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/mailcow/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
#   cp .env.example .env && docker compose up -d
#   → http://localhost:${MAILCOW_PORT:-8080}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
  mailcow:
    image: mailcow/mailcow:latest
    restart: unless-stopped
    env_file:
      - .env
    ports:
      - "${MAILCOW_PORT:-8080}:8080"
    healthcheck:
      test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:8080/"]
      interval: 30s
      timeout: 5s
      retries: 3
      start_period: 20s
    networks:
      - mailcow
    # TODO: persistent volume(s) if this image stores state. e.g.:
    #   volumes: [ "mailcow_data:/data" ]

networks:
  mailcow:
    name: mailcow
.env.example
# Mail - standalone env. Copy to .env and fill in.
# GENERATED by scripts/generate-standalone.mjs

# Host port the app is published on.
MAILCOW_PORT=8080

# Required secrets are specified in:
#   ./secrets.spec.yaml
# Add the matching KEY=VALUE lines here.

README

The README is not in English - see apps/mailcow/README.md.

Upstream docs  ·  Upstream API  ·  Upstream source  ·  Support  ·  apps/mailcow/

doc/ai-notes.md  ·  doc/api.md  ·  doc/mailcow-reference.md  ·  doc/n8n.md  ·  doc/sources.md

Medical

Medical knowledge, docked in.

InfrastructureMedicalProprietaryv0.1.0private

Medical knowledge via the AMBOSS integration (TODO: API wrapper)

What it does

Medical is the planned door to medical knowledge through an AMBOSS integration: licence-compliant queries of AMBOSS endpoints with a key from the vault, results normalised into NocoDB records, and optionally fed into the Wilhelm knowledge base - no scraping, by policy.

It is documented as blocked: AMBOSS is a commercial platform, its free APIs may not be used commercially, and a licence agreement has to come first. The code currently under the app folder is unrelated - a 3D embossing-stamp generator that exports STL files.

Features

Planned: AMBOSS GraphQL queries with a vault-held API key

Planned: normalisation into NocoDB, selective caching

Planned: licence-permitted content into the RAG index

Policy: no scraping of the web platform

Why it is in the stack

  • Medical knowledge, docked in - once the licence question is settled.
  • The documentation states the blocker instead of hiding it.

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs medical.

At a glance

Based onWilhelm-native - no upstream project
Type · categoryInfrastructure · Medical
Licenceservice Proprietary  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Tagsmedicalambosswip
Folderapps/medical/manifest.json

Icon & assets

BrandBrand-SquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 🏥Emoji #0EA5E9 one brand SVG → tools/app-assetsappinfo/ · serving copy in ./app/public

Configuration

Skin & branding

SloganMedical knowledge, docked in.
Themeprimary #0EA5E9  ·  mode system
Logo./icon.svg

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.

Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idmedical
domainmedical
vendorwilhelm
nameMedical
descriptionMedical knowledge via the AMBOSS integration (TODO: API wrapper)
version0.1.0
licenseservice, wilhelm
serviceProprietary
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typeinfrastructure
categorymedical
emoji🏥
pixelIcon
............
.KKKKKKKKKK.
.KWWWKKWWWK.
.KWWWKKWWWK.
.KWKKKKKKWK.
.KWKKKKKKWK.
.KWWWKKWWWK.
.KWWWKKWWWK.
.KWWWWWWWWK.
.KKKKKKKKKK.
............
primaryColor#0EA5E9
tagsmedicalambosswip
compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
webpublicDir
publicDir./app/public
previewdir, desktop, mobile, capture
dir./preview
desktop./preview/desktop.png
mobile./preview/mobile.png
captureurl, wait
wait800
skinslogan, logo, theme
sloganMedical knowledge, docked in.
themeprimary, mode
primary#0EA5E9
modesystem
marketplacevisibility
visibilityprivate
componentsvscode
vscodeextensions, extension
extensions[ ]
extensionnull

Standalone compose

Every service app can run on its own: cd apps/medical && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.

.env.example
# Amboss - keine serverseitigen Env-Variablen nötig (reine Client-App)

apps/medical/

doc/ai-notes.md  ·  doc/api.md  ·  doc/medical-reference.md  ·  doc/sources.md

Prometheus

Every metric, one place.

InfrastructureMonitoringApache-2.0v1.0.0

Metrics-collection config (alertmanager + alerts + scrape config). Mounted into the prometheus container by docker-compose.

What it does

Prometheus is the stack's metrics layer, shipped as configuration: scrape jobs, alert rules and Alertmanager routing that docker-compose mounts into the Prometheus container. It pulls metrics from the gateway, the shop, identity and the databases and provides the data behind Grafana dashboards and alerts - the metrics half of what Datadog sells.

Logs are Loki's job; the two are correlated in Grafana, not here.

Features

Scrape jobs

Traefik, Medusa, Keycloak and the PostgreSQL instances every 15 seconds.

Alert rules

ServiceDown, HighErrorRate, PaymentWebhookFailure as code in the repo.

Alertmanager

Routing configuration; receivers to be pointed at real webhooks.

Query API

Live stack state for dashboards, workflows and agents.

Reload without restart

Configuration reloads on signal.

Why it is in the stack

  • Every metric, one place - full ownership without a per-host observability subscription.
  • Alert rules are versioned with the stack.

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs prometheus.

At a glance

Based onPrometheus · source · docs · API
Type · categoryInfrastructure · Monitoring
Licenceservice Apache-2.0  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Tagsmonitoringmetrics
Folderapps/prometheus/manifest.json

Icon & assets

BrandBrand-SquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 📈Emoji #E6522C one brand SVG → tools/app-assetsappinfo/

Configuration

Skin & branding

SloganEvery metric, one place.
Themeprimary #E6522C  ·  mode system
Logo./icon.svg

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.

CNCF project without certifications; security audits by cure53 (CNCF-funded). Compliance rests entirely with the operator.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idprometheus
domainprometheus
vendorprometheus
namePrometheus
descriptionMetrics-collection config (alertmanager + alerts + scrape config). Mounted into the prometheus container by docker-compose.
version1.0.0
licenseservice, wilhelm
serviceApache-2.0
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typeinfrastructure
categorymonitoring
emoji📈
pixelIcon
............
.KKKKKKKKKK.
.KWWWWKWWWK.
.KWWWKKWWWK.
.KWWKKKKWWK.
.KWKKGGKKWK.
.KWKKGGKKWK.
.KWWKKKKWWK.
.KWWWWWWWWK.
.KKKKKKKKKK.
............
primaryColor#E6522C
tagsmonitoringmetrics
compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
noteCNCF project without certifications; security audits by cure53 (CNCF-funded). Compliance rests entirely with the operator.
skinslogan, logo, theme
sloganEvery metric, one place.
themeprimary, mode
primary#E6522C
modesystem
componentsvscode
vscodeextensions, extension
extensions[ ]
extensionnull

Upstream docs  ·  Upstream API  ·  Upstream source  ·  apps/prometheus/

doc/ai-notes.md  ·  doc/api.md  ·  doc/n8n.md  ·  doc/prometheus-reference.md  ·  doc/sources.md

Uptime Kuma

Green means green.

External serviceMonitoringMITv2.0.0free

Uptime Kuma monitoring in Nextcloud

What it does

Uptime Kuma watches every service in the stack and speaks up before your users do: HTTP, keyword, JSON, TCP, ping, DNS, Docker container and push monitors on intervals from twenty seconds, a live dashboard with response-time charts, public status pages on your own domain, and notifications through ninety-plus channels - the self-hosted alternative to Pingdom and UptimeRobot.

In the Wilhelm stack it is embedded in Nextcloud and initialised with an admin user by script; Prometheus deliberately does not scrape it - it is the standalone status tool.

Features

Monitor types

HTTP(s), keyword, JSON query, TCP, ping, DNS, WebSocket, push, Steam, Docker container.

Status pages

Multiple public status pages, optionally on their own domain; status badges.

Notifications

Telegram, Slack, Discord, e-mail, ntfy and dozens more.

Certificates

TLS expiry information per monitor.

Push heartbeats

Jobs report in; silence becomes an alert.

Two-factor login, multi-language, Prometheus metrics

Why it is in the stack

  • Green means green - one dashboard for every service, no per-monitor subscription.
  • Status pages hosted on your own domain.
  • Integration is via Socket.io rather than REST; the notes say so.

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs monitoring.

At a glance

Based onUptime Kuma · source · docs
ReplacesPingdom, UptimeRobot · listed as Wilhelm Status in the ecosystem reference
Type · categoryExternal service · Monitoring
Licenceservice MIT  ·  wrapper Proprietary  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support/monitoring
Docker imagelouislam/uptime-kuma:latest · port 3001
Public URLhttps://status.<your-domain>
Compose profileuptime-kuma
Nextcloud app idwilhelmkuma · Nextcloud 30-32
Tagsmonitoringstatus
Folderapps/monitoring/manifest.json

Icon & assets

BrandBrand-SquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 💓Emoji #5CDD8B one brand SVG → tools/app-assetsappinfo/

Configuration

Service

Imagelouislam/uptime-kuma:latest
Port3001
Init script./service/init-uptime-kuma.sh
Health checkhttp / every 30s · timeout 5s · 3 retries

Embedding in Nextcloud

Registry id · labeluptime-kuma · Uptime Kuma
Subdomainstatus
Containeruptime-kuma:3001
Embed-proxy port (localhost)8893
Compose profileuptime-kuma
Nextcloud config keykuma_url

Nextcloud app

App idwilhelmkuma
Path./nextcloud
Nextcloud versions30 - 32

Dependencies

Requiresnextcloud >=30
Optionalvault

Single sign-on (OIDC)

As clientyes
As providerno
Fallbackvaultwarden

Skin & branding

SloganGreen means green.
Themeprimary #5CDD8B  ·  mode system
Logo./nextcloud/appinfo/icon.svg

Secrets

Declared in secretsRefs but apps/monitoring/secrets.spec.yaml does not exist in the repository.

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.

Pure community project without a legal entity and without certifications; a GitHub label tracks accessibility work, but there is no WCAG conformance statement.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idmonitoring
domainmonitoring
vendoruptime-kuma
nameUptime Kuma
descriptionUptime Kuma monitoring in Nextcloud
version2.0.0
licenseservice, wrapper, wilhelm
serviceMIT
wrapperProprietary
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typeexternal
categorymonitoring
emoji💓
pixelIcon
............
.KKKKKKKKKK.
.KWWWWWWWWK.
.KWWWKWWWWK.
.KWWKWKWWWK.
.KKKWWWKKKK.
.KWWWWWWWWK.
.KWWWWWWWWK.
.KWWWWWWWWK.
.KKKKKKKKKK.
............
primaryColor#5CDD8B
tagsmonitoringstatus
compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
notePure community project without a legal entity and without certifications; a GitHub label tracks accessibility work, but there is no WCAG conformance statement.
componentsservice, nextcloudApp, embed, vscode
serviceimage, port, healthCheck, init
imagelouislam/uptime-kuma:latest
port3001
healthChecktype, path, interval, timeout, retries
typehttp
path/
interval30s
timeout5s
retries3
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmkuma
minNcVersion30
maxNcVersion32
embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile
iduptime-kuma
labelUptime Kuma
ncConfigKeykuma_url
subdomainstatus
containeruptime-kuma
containerPort3001
embedProxyPort8893
profileuptime-kuma
vscodeextensions, extension
extensions[ ]
extensionnull
dependenciesrequires, optional
requires1 item
0id, version
idnextcloud
version>=30
optional1 item
0id
idvault
oidcCapabilityasClient, asProvider, fallback
asClienttrue
asProviderfalse
fallbackvaultwarden
secretsRefs./secrets.spec.yaml
skinslogan, logo, theme
sloganGreen means green.
themeprimary, mode
primary#5CDD8B
modesystem
marketplacevisibility, screenshots, pricing, supportUrl
visibilitypublic
screenshots[ ]
pricingfree

Standalone compose

Every service app can run on its own: cd apps/monitoring && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.

docker-compose.yml
# Uptime Kuma - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/monitoring/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
#   cp .env.example .env && docker compose up -d
#   → http://localhost:${MONITORING_PORT:-3001}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
  monitoring:
    image: louislam/uptime-kuma:latest
    restart: unless-stopped
    env_file:
      - .env
    ports:
      - "${MONITORING_PORT:-3001}:3001"
    healthcheck:
      test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:3001/"]
      interval: 30s
      timeout: 5s
      retries: 3
      start_period: 20s
    networks:
      - monitoring
    # TODO: persistent volume(s) if this image stores state. e.g.:
    #   volumes: [ "monitoring_data:/data" ]

networks:
  monitoring:
    name: monitoring
.env.example
# Uptime Kuma - standalone env. Copy to .env and fill in.
# GENERATED by scripts/generate-standalone.mjs

# Host port the app is published on.
MONITORING_PORT=3001

# Required secrets are specified in:
#   ./secrets.spec.yaml
# Add the matching KEY=VALUE lines here.

README

The README is not in English - see apps/monitoring/README.md.

Upstream docs  ·  Upstream source  ·  Support  ·  apps/monitoring/

doc/ai-notes.md  ·  doc/api.md  ·  doc/monitoring-reference.md  ·  doc/n8n.md  ·  doc/sources.md

Photos

Your pictures, your server.

External servicePhotosAGPL-3.0v2.0.0free

Immich photo gallery in Nextcloud

What it does

Photos is Immich, the self-hosted photo and video platform built to give you back what Google Photos and iCloud Photos do - automatic backup from your phone, a timeline, albums, sharing, a map, people, and a search that understands what is in a picture - with the originals on your own server.

Machine learning runs locally: face recognition, object and scene detection and CLIP-based context search work on your hardware, so a query like 'sunrise on the beach' finds the picture without any image ever leaving the house.

Features

Mobile backup

iOS and Android apps upload photos and videos automatically, in the background, with per-album selection.

Timeline, albums, favourites, archive

The library organised by date, with albums, favourites, archive and trash.

People and places

Faces grouped into people you can name; photos on a map from their GPS data.

Context search

Search by what is in the image, by file name, description or recognised text (OCR), by people, tags, place, camera, date and media type.

Sharing

Shared albums with other users, public links, partner sharing for a second person's library.

Editor

Rotate, flip, crop to any aspect ratio in the web app.

RAW, HEIC, live photos, video

Full-resolution originals with thumbnails and transcoding for the web.

Multi-user, external libraries

Users with quotas; index existing folders on disk as external libraries.

Why it is in the stack

  • Replaces Google Photos and iCloud Photos with an AGPL tool; the originals stay on your server, the ML stays on your hardware.
  • Embedded in Nextcloud with single sign-on next to the files, so the photo library is part of the cloud instead of a second cloud.
  • No end-to-end encryption - the protection is the self-hosted deployment, which the compliance note says plainly.

Screenshots

Web and mobile in one library
Web and mobile in one library

The web timeline and map on the left, the mobile app on the right: search with people and places, albums, the detail view of a single photo with EXIF data and location, and the backup screen that shows what is uploaded and what is left.

01-overview.jpg
Shared album
Shared album

An album shared with two users and via link: every photo shows who added it, viewers can like and comment, and the toolbar offers adding photos, sharing, map, slideshow and download.

02-shared-album.jpg
The web editor
The web editor

Orientation (rotate, flip) and crop with free or fixed aspect ratios, straight in the browser, non-destructively with a reset.

03-web-editor.jpg
Search options
Search options

Search by people, by context ('sunrise on the beach'), file name, description or OCR text, by tags, place (country, state, city), camera make, model and lens, date range, media type and album membership - all computed locally.

04-search-filters.jpg

Screenshots are the upstream project's official product shots (see preview/SOURCES.md) until the stack runs with demo data and tools/app-preview shoots real Wilhelm screens. Images © their respective projects.

At a glance

Based onImmich · source · docs · API
ReplacesGoogle Photos, iCloud Photos · listed as Wilhelm Photos in the ecosystem reference
Type · categoryExternal service · Photos
Licenceservice AGPL-3.0  ·  wrapper Proprietary  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support/photos
Docker imageghcr.io/immich-app/immich-server · port 3001
Public URLhttps://photos.<your-domain>
Compose profileimmich
Nextcloud app idwilhelmphotos · Nextcloud 30-32
Tagsphotosbackup
Folderapps/photos/manifest.json

Icon & assets

BrandBrandSquircleSquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 📷Emoji #4250AF one brand SVG → tools/app-assetsappinfo/

Configuration

Service

Imageghcr.io/immich-app/immich-server
Port3001
Init script./service/init-immich.sh
Health checkhttp /api/server-info/ping every 30s · timeout 5s · 3 retries

Embedding in Nextcloud

Registry id · labelimmich · Immich Photos
Subdomainphotos
Containerimmich-server:2283
Embed-proxy port (localhost)8908
Compose profileimmich
Nextcloud config keyimmich_url

Nextcloud app

App idwilhelmphotos
Path./nextcloud
Nextcloud versions30 - 32

Dependencies

Requiresnextcloud >=30
Optionalvault

Single sign-on (OIDC)

As clientyes
As providerno
Fallbackvaultwarden

Skin & branding

SloganYour pictures, your server.
Themeprimary #4250AF  ·  mode system
Logo./nextcloud/appinfo/icon.svg

Secrets

Declared in secretsRefs but apps/photos/secrets.spec.yaml does not exist in the repository.

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.

FUTO-backed project without a cloud offering and without certificates - data stays entirely with the operator. Note: no end-to-end encryption; protection at rest rests with the host.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idphotos
domainphotos
vendorimmich
namePhotos
descriptionImmich photo gallery in Nextcloud
version2.0.0
licenseservice, wrapper, wilhelm
serviceAGPL-3.0
wrapperProprietary
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typeexternal
categoryphotos
emoji📷
pixelIcon
............
.KKKKKKKKKK.
.KWWKKWWWWK.
.KWKKKKKKWK.
.KWKWGGWKWK.
.KWKWGGWKWK.
.KWKWWWWKWK.
.KWKKKKKKWK.
.KWWWWWWWWK.
.KKKKKKKKKK.
............
primaryColor#4250AF
tagsphotosbackup
compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
noteFUTO-backed project without a cloud offering and without certificates - data stays entirely with the operator. Note: no end-to-end encryption; protection at rest rests with the host.
componentsservice, nextcloudApp, embed, vscode
serviceimage, port, healthCheck, init
imageghcr.io/immich-app/immich-server
port3001
healthChecktype, path, interval, timeout, retries
typehttp
path/api/server-info/ping
interval30s
timeout5s
retries3
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmphotos
minNcVersion30
maxNcVersion32
embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile
idimmich
labelImmich Photos
ncConfigKeyimmich_url
subdomainphotos
containerimmich-server
containerPort2283
embedProxyPort8908
profileimmich
vscodeextensions, extension
extensions[ ]
extensionnull
dependenciesrequires, optional
requires1 item
0id, version
idnextcloud
version>=30
optional1 item
0id
idvault
oidcCapabilityasClient, asProvider, fallback
asClienttrue
asProviderfalse
fallbackvaultwarden
secretsRefs./secrets.spec.yaml
skinslogan, logo, theme
sloganYour pictures, your server.
themeprimary, mode
primary#4250AF
modesystem
previewdir, gallery
gallery4 items
0src, caption, kind
captionOverview, web & mobile
kinddesktop
1src, caption, kind
captionShared album
kinddesktop
2src, caption, kind
captionWeb editor
kinddesktop
3src, caption, kind
captionSearch filters
kinddesktop
marketplacevisibility, screenshots, pricing, supportUrl

Standalone compose

Every service app can run on its own: cd apps/photos && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.

docker-compose.yml
# Photos - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/photos/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
#   cp .env.example .env && docker compose up -d
#   → http://localhost:${PHOTOS_PORT:-3001}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
  photos:
    image: ghcr.io/immich-app/immich-server
    restart: unless-stopped
    env_file:
      - .env
    ports:
      - "${PHOTOS_PORT:-3001}:3001"
    healthcheck:
      test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:3001/api/server-info/ping"]
      interval: 30s
      timeout: 5s
      retries: 3
      start_period: 20s
    networks:
      - photos
    # TODO: persistent volume(s) if this image stores state. e.g.:
    #   volumes: [ "photos_data:/data" ]

networks:
  photos:
    name: photos
.env.example
# Photos - standalone env. Copy to .env and fill in.
# GENERATED by scripts/generate-standalone.mjs

# Host port the app is published on.
PHOTOS_PORT=3001

# Required secrets are specified in:
#   ./secrets.spec.yaml
# Add the matching KEY=VALUE lines here.

README

The README is not in English - see apps/photos/README.md.

Upstream docs  ·  Upstream API  ·  Upstream source  ·  Support  ·  apps/photos/

doc/ai-notes.md  ·  doc/api.md  ·  doc/n8n.md  ·  doc/photos-reference.md  ·  doc/sources.md

Projects

Projects in flow.

External serviceProjectsAGPL-3.0v2.0.0free

Plane project management in Nextcloud

What it does

Projects is Plane, the open-source project and product management tool that covers the ground Jira, Linear and Asana share: work items with states, priorities, labels and assignees; cycles for time-boxed sprints; modules for larger pieces of work; pages for specs and notes; and analytics across all of it. It runs on your own server inside the Wilhelm stack.

Where Jira grows into a configuration project of its own, Plane stays opinionated: a small set of well-designed concepts (work items, cycles, modules, views, pages, intake) that map onto how software and product teams actually work, with a clean interface that does not need training.

Features

Work items

Issues with states, priorities, labels, estimates, sub-items, relations and attachments; list, board, calendar, spreadsheet and Gantt views on the same data.

Cycles

Time-boxed iterations with progress, burndown and scope-change tracking - the sprint, without the ceremony.

Modules

Group work items into features or epics with their own lead, members, dates and progress chart.

Views & filters

Save any filtered, grouped and sorted combination as a shared or private view.

Pages

Rich-text documents for specs, meeting notes and decisions, living next to the work they describe.

Intake

A triage queue for requests that are not yet work items - accept, decline, snooze.

Analytics

Workspace and project dashboards: throughput, states, priorities, assignees, custom insights.

Teamspaces & initiatives

Organise projects by team and roll several projects up into a strategic initiative.

Why it is in the stack

  • Replaces Jira, Linear and Asana with one AGPL-licensed tool - no per-seat pricing, no data outside your infrastructure.
  • Embedded in Nextcloud with the stack's single sign-on; project links open inside the Wilhelm cloud, not in another SaaS tab.
  • A REST API and n8n nodes let workflows create and update work items automatically - from forms, mails, support tickets or the CRM.

Screenshots

Board view of a project's work items
Board view of a project's work items

Work items grouped by state (Backlog, Todo, In progress) as a kanban board. Every card carries its identifier, priority, state, due date and assignees; the left rail switches between epics, work items, cycles, modules, views, pages and intake of the selected project.

01-overview.jpg
Timeline and board on the same data
Timeline and board on the same data

The same work items as a Gantt-style timeline with dependencies drawn between them, and as a board with custom states such as Blocked, Planning and Permits awaited. Views are layouts, not copies - a change in one is a change everywhere.

02-work-items.jpg
Cycle progress and burndown
Cycle progress and burndown

A running cycle shows completed, started, unstarted and backlog items, the burndown against the ideal line, pending work and the priority items still open - per team, at a glance.

03-cycles.jpg
Modules with lead, members and scope tracking
Modules with lead, members and scope tracking

Modules group work items into a feature or epic. The detail panel shows dates, lead, members and a progress chart in which scope creep (+29 %) is visible instead of hidden.

04-modules.jpg
Workspace analytics
Workspace analytics

Totals for users, projects and work items with month-on-month change, a radar of project activity over the last 30 days and per-project custom insights, for example open items by priority.

05-analytics.jpg

Screenshots are the upstream project's official product shots (see preview/SOURCES.md) until the stack runs with demo data and tools/app-preview shoots real Wilhelm screens. Images © their respective projects.

At a glance

Based onPlane · source · docs · API
ReplacesJira, Linear, Asana · listed as Wilhelm Projects in the ecosystem reference
Type · categoryExternal service · Projects
Licenceservice AGPL-3.0  ·  wrapper Proprietary  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support/projects
Docker imagemakeplane/plane-frontend:latest · port 3000
Public URLhttps://projects.<your-domain>
Compose profileplane
Nextcloud app idwilhelmprojects · Nextcloud 30-32
Tagsprojectsmanagement
Folderapps/projects/manifest.json

Icon & assets

BrandBrandSquircleSquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel ✈️Emoji #3A61D8 one brand SVG → tools/app-assetsappinfo/

Configuration

Service

Imagemakeplane/plane-frontend:latest
Port3000
Init script./service/init-plane.sh
Health checkhttp / every 30s · timeout 5s · 3 retries

Embedding in Nextcloud

Registry id · labelplane · Plane Project Mgmt
Subdomainprojects
Containerplane-web:3000
Embed-proxy port (localhost)8906
Compose profileplane
Nextcloud config keyplane_url

Nextcloud app

App idwilhelmprojects
Path./nextcloud
Nextcloud versions30 - 32

Dependencies

Requiresnextcloud >=30
Optionalvault

Single sign-on (OIDC)

As clientyes
As providerno
Fallbackvaultwarden

Skin & branding

SloganProjects in flow.
Themeprimary #3A61D8  ·  mode system
Logo./nextcloud/appinfo/icon.svg

Secrets

Declared in secretsRefs but apps/projects/secrets.spec.yaml does not exist in the repository.

Compliance

StandardStatusScopeNote
ISO/IEC 27001
Information security
certified
2025-01
vendorISO 27001:2022 certification of Plane's ISMS. source
SOC 2 Type II
Information security
attested
2025-01
cloud offeringSOC 2 Type II via independent audit; attestation of the vendor's controls, not of your own instance. source
GDPR
Privacy
compliantcloud offeringGDPR compliance statement for Plane's data processing. source
HIPAA
Healthcare
vendor claimcloud offeringHIPAA-compliant PHI processing claimed for Plane Cloud. source

Unusually strong compliance package for an open-source PM tool (January 2025) - applies to vendor/cloud; self-hosting inherits the controls, not the certificates.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idprojects
domainprojects
vendorplane
nameProjects
descriptionPlane project management in Nextcloud
version2.0.0
licenseservice, wrapper, wilhelm
serviceAGPL-3.0
wrapperProprietary
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typeexternal
categoryprojects
emoji✈️
pixelIcon
............
.KKKKKKKKKK.
.KKKWKKWKKK.
.KKKWKKWKKK.
.KWWWKKWWWK.
.KKKWWWWKKK.
.KKKWWWWKKK.
.KWWWWWWWWK.
.KWWWWWWWWK.
.KKKKKKKKKK.
............
primaryColor#3A61D8
tagsprojectsmanagement
compliancecertifications, note
certifications4 items
0id, status, scope, since, source, note
idiso-27001
statuscertified
scopevendor
since2025-01
noteISO 27001:2022 certification of Plane's ISMS.
1id, status, scope, since, source, note
idsoc2-type2
statusattested
scopecloud
since2025-01
noteSOC 2 Type II via independent audit; attestation of the vendor's controls, not of your own instance.
2id, status, scope, source, note
idgdpr
statuscompliant
scopecloud
noteGDPR compliance statement for Plane's data processing.
3id, status, scope, source, note
idhipaa
statusclaimed
scopecloud
noteHIPAA-compliant PHI processing claimed for Plane Cloud.
noteUnusually strong compliance package for an open-source PM tool (January 2025) - applies to vendor/cloud; self-hosting inherits the controls, not the certificates.
componentsservice, nextcloudApp, embed, vscode
serviceimage, port, healthCheck, init
imagemakeplane/plane-frontend:latest
port3000
healthChecktype, path, interval, timeout, retries
typehttp
path/
interval30s
timeout5s
retries3
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmprojects
minNcVersion30
maxNcVersion32
embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile
idplane
labelPlane Project Mgmt
ncConfigKeyplane_url
subdomainprojects
containerplane-web
containerPort3000
embedProxyPort8906
profileplane
vscodeextensions, extension
extensions[ ]
extensionnull
dependenciesrequires, optional
requires1 item
0id, version
idnextcloud
version>=30
optional1 item
0id
idvault
oidcCapabilityasClient, asProvider, fallback
asClienttrue
asProviderfalse
fallbackvaultwarden
secretsRefs./secrets.spec.yaml
skinslogan, logo, theme
sloganProjects in flow.
themeprimary, mode
primary#3A61D8
modesystem
previewdir, gallery
gallery5 items
0src, caption, kind
captionOverview
kinddesktop
1src, caption, kind
captionWork Items
kinddesktop
2src, caption, kind
captionCycles
kinddesktop
3src, caption, kind
captionModules
kinddesktop
4src, caption, kind
captionAnalytics
kinddesktop
marketplacevisibility, screenshots, pricing, supportUrl

Standalone compose

Every service app can run on its own: cd apps/projects && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.

docker-compose.yml
# Projects - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/projects/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
#   cp .env.example .env && docker compose up -d
#   → http://localhost:${PROJECTS_PORT:-3000}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
  projects:
    image: makeplane/plane-frontend:latest
    restart: unless-stopped
    env_file:
      - .env
    ports:
      - "${PROJECTS_PORT:-3000}:3000"
    healthcheck:
      test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:3000/"]
      interval: 30s
      timeout: 5s
      retries: 3
      start_period: 20s
    networks:
      - projects
    # TODO: persistent volume(s) if this image stores state. e.g.:
    #   volumes: [ "projects_data:/data" ]

networks:
  projects:
    name: projects
.env.example
# Projects - standalone env. Copy to .env and fill in.
# GENERATED by scripts/generate-standalone.mjs

# Host port the app is published on.
PROJECTS_PORT=3000

# Required secrets are specified in:
#   ./secrets.spec.yaml
# Add the matching KEY=VALUE lines here.

README

The README is not in English - see apps/projects/README.md.

Upstream docs  ·  Upstream API  ·  Upstream source  ·  Support  ·  apps/projects/

doc/ai-notes.md  ·  doc/api.md  ·  doc/n8n.md  ·  doc/projects-reference.md  ·  doc/sources.md

Booking

Appointments that book themselves.

External serviceSchedulingAGPL-3.0v2.0.0free

Cal.com bookings in Nextcloud

What it does

Booking is Cal.com, the open-source scheduling platform built as the alternative to Calendly and Microsoft Bookings: define event types and availability, share a link, and guests book free slots that land in everyone's calendar with reminders, video links and confirmations.

In the Wilhelm stack it syncs with the Nextcloud calendar over CalDAV, and every booking is an event other apps react to: a confirmation mail, a contact in the CRM, a task in the project tool.

Features

Event types and availability

Durations, buffers, limits, schedules per event type; team and round-robin events.

Booking pages

Public pages per user, team or event type; embeddable booking widgets.

Calendar integrations

Google, Outlook and CalDAV - the Nextcloud calendar included.

Video and reminders

Conferencing links and e-mail/SMS reminders on every booking.

Teams and organisations

Shared event types, managed users, OAuth platform clients.

API v2 and webhooks

Create, read, cancel and reschedule bookings; webhooks on created, cancelled and rescheduled.

Why it is in the stack

  • Appointments that book themselves - Calendly features without per-seat subscription, on your own server.
  • Booking data and calendar credentials stay in your PostgreSQL; CalDAV keeps the Nextcloud calendar in sync.
  • Booking events are automation triggers for the whole stack via n8n.

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs booking.

At a glance

Based onCal.com · source · docs · API
ReplacesCalendly, MS Bookings · listed as Wilhelm Booking in the ecosystem reference
Type · categoryExternal service · Scheduling
Licenceservice AGPL-3.0  ·  wrapper Proprietary  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support/booking
Docker imagecalcom/cal.com:latest · port 3000
Public URLhttps://booking.<your-domain>
Compose profilecalcom
Nextcloud app idwilhelmbooking · Nextcloud 30-32
Tagsbookingcalendarscheduling
Folderapps/booking/manifest.json

Icon & assets

BrandBrandSquircleSquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 📅Emoji #292929 one brand SVG → tools/app-assetsappinfo/

Configuration

Service

Imagecalcom/cal.com:latest
Port3000
Init script./service/init-calcom.sh
Health checkhttp /api/health every 30s · timeout 5s · 3 retries

Embedding in Nextcloud

Registry id · labelcalcom · Cal.com Booking
Subdomainbooking
Containercalcom:3000
Embed-proxy port (localhost)8904
Compose profilecalcom
Nextcloud config keycalcom_url

Nextcloud app

App idwilhelmbooking
Path./nextcloud
Nextcloud versions30 - 32

Dependencies

Requiresnextcloud >=30
Optionalvault

Single sign-on (OIDC)

As clientyes
As providerno
Fallbackvaultwarden

Skin & branding

SloganAppointments that book themselves.
Themeprimary #292929  ·  mode system
Logo./nextcloud/appinfo/icon.svg

Secrets

Declared in secretsRefs but apps/booking/secrets.spec.yaml does not exist in the repository.

Compliance

StandardStatusScopeNote
SOC 2 Type II
Information security
attestedcloud offeringSOC 2 Type II with annual independent audits; report via trust.cal.com. source
ISO/IEC 27001
Information security
vendor claimcloud offeringISO/IEC 27001 listed on the compliance page; certificate details only via the trust center. source
HIPAA
Healthcare
compliantcloud offeringHIPAA via encryption, access controls and BAAs (attestation, not certification). source
GDPR
Privacy
vendor claimcloud offeringGDPR compliance according to the compliance page, for the cloud offering. source

The broadest compliance portfolio in the stack - all evidence applies to Cal.com Cloud, not to the self-hosted instance.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idbooking
domainbooking
vendorcalcom
nameBooking
descriptionCal.com bookings in Nextcloud
version2.0.0
licenseservice, wrapper, wilhelm
serviceAGPL-3.0
wrapperProprietary
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typeexternal
categoryscheduling
emoji📅
pixelIcon
............
.KKKKKKKKKK.
.KWWKWWKWWK.
.KWKKKKKKWK.
.KWKWWWWKWK.
.KWKKKKKKWK.
.KWKWGWWKWK.
.KWKWWWWKWK.
.KWKKKKKKWK.
.KKKKKKKKKK.
............
primaryColor#292929
tagsbookingcalendarscheduling
compliancecertifications, note
certifications4 items
0id, status, scope, source, note
idsoc2-type2
statusattested
scopecloud
noteSOC 2 Type II with annual independent audits; report via trust.cal.com.
1id, status, scope, source, note
idiso-27001
statusclaimed
scopecloud
noteISO/IEC 27001 listed on the compliance page; certificate details only via the trust center.
2id, status, scope, source, note
idhipaa
statuscompliant
scopecloud
noteHIPAA via encryption, access controls and BAAs (attestation, not certification).
3id, status, scope, source, note
idgdpr
statusclaimed
scopecloud
noteGDPR compliance according to the compliance page, for the cloud offering.
noteThe broadest compliance portfolio in the stack - all evidence applies to Cal.com Cloud, not to the self-hosted instance.
componentsservice, nextcloudApp, embed, vscode
serviceimage, port, healthCheck, init
imagecalcom/cal.com:latest
port3000
healthChecktype, path, interval, timeout, retries
typehttp
path/api/health
interval30s
timeout5s
retries3
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmbooking
minNcVersion30
maxNcVersion32
embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile
idcalcom
labelCal.com Booking
ncConfigKeycalcom_url
subdomainbooking
containercalcom
containerPort3000
embedProxyPort8904
profilecalcom
vscodeextensions, extension
extensions[ ]
extensionnull
dependenciesrequires, optional
requires1 item
0id, version
idnextcloud
version>=30
optional1 item
0id
idvault
oidcCapabilityasClient, asProvider, fallback
asClienttrue
asProviderfalse
fallbackvaultwarden
secretsRefs./secrets.spec.yaml
skinslogan, logo, theme
sloganAppointments that book themselves.
themeprimary, mode
primary#292929
modesystem
marketplacevisibility, screenshots, pricing, supportUrl
visibilitypublic
screenshots[ ]
pricingfree

Standalone compose

Every service app can run on its own: cd apps/booking && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.

docker-compose.yml
# Booking - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/booking/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
#   cp .env.example .env && docker compose up -d
#   → http://localhost:${BOOKING_PORT:-3000}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
  booking:
    image: calcom/cal.com:latest
    restart: unless-stopped
    env_file:
      - .env
    ports:
      - "${BOOKING_PORT:-3000}:3000"
    healthcheck:
      test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:3000/api/health"]
      interval: 30s
      timeout: 5s
      retries: 3
      start_period: 20s
    networks:
      - booking
    # TODO: persistent volume(s) if this image stores state. e.g.:
    #   volumes: [ "booking_data:/data" ]

networks:
  booking:
    name: booking
.env.example
# Booking - standalone env. Copy to .env and fill in.
# GENERATED by scripts/generate-standalone.mjs

# Host port the app is published on.
BOOKING_PORT=3000

# Required secrets are specified in:
#   ./secrets.spec.yaml
# Add the matching KEY=VALUE lines here.

README

The README is not in English - see apps/booking/README.md.

Upstream docs  ·  Upstream API  ·  Upstream source  ·  Support  ·  apps/booking/

doc/ai-notes.md  ·  doc/api.md  ·  doc/booking-reference.md  ·  doc/n8n.md  ·  doc/sources.md

Wilhelm Techstack / Security / Data Broker

Data Broker

InfrastructureSecurityApache-2.0v2.0.0free

API-key gateway in front of the Wilhelm API: one endpoint tree per key (allow/block/empty/broker); broker mode substitutes sensitive data based on a case file

What it does

Data Broker is the bouncer with a memory: an API-key gateway in front of the Wilhelm API, the MCP servers and the native app APIs. Every key carries an endpoint tree that decides what the caller may reach - and in broker mode the answer is not just allow or deny: sensitive content is substituted with placeholders according to a case file before it leaves the house.

It exists so that data can be shared with third parties and AI agents without sharing secrets. The policy engine and the redaction rules are implemented and tested; the reverse-proxy service around them is roadmap.

Features

Per-key endpoint tree

Three namespaces (Wilhelm API, MCP, apps) with inheritance and deny-by-default at the root.

Four modes

allow, block (403), empty (a type-correct empty body so the client sees 'no data', not 'blocked'), broker.

Case-file substitution

Rules by literal, JSON property (any depth), file-name glob or regex, applied to requests and responses.

Managed in TaskHQ

Keys and trees are edited in a settings window; the plaintext token is shown once.

Schemas and tests

JSON schemas for keys and case files; pure, tested reference implementation.

Why it is in the stack

  • Share data with agents and partners without sharing secrets; deny by default, fine-grained per key.
  • 'Empty' as a stealth deny keeps client apps working while revealing nothing.
  • One policy over API, MCP and app endpoints alike.

Screenshots

Contributed HTML67 widgets

no preview shot yet
<wl-card> Example: a wl-* component this app contributes - the tag must exist in apps/ui/wl-html-data.json (tools/doctor warns otherwise).

At a glance

Based onWilhelm-native - no upstream project
Type · categoryInfrastructure · Security
Licenceservice Apache-2.0  ·  wilhelm Apache-2.0
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support
Resourcesmemory 256Mi  ·  cpu 0.25  ·  storage 1Gi
Tagssecuritygatewayapi-keysprivacybroker
Folderapps/databroker/manifest.json

Icon & assets

BrandBrand-SquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 🗝️Emoji #8B0000 one brand SVG → tools/app-assetsappinfo/ · serving copy in ./service/app/public

Configuration

Service

Compose fragment./service/compose.fragment.yml
Init script./service/init.sh
Health checkhttp /healthz every 30s · timeout 5s · 3 retries

Desktop build (Electron)

Enabledno - opted out
Start path/index.php/apps/example/
Hide Nextcloud chromeyes

TaskHQ desktop window

Shownyes
Window760 × 520 px

Resources & permissions

Memory · CPU · storage256Mi · 0.25 · 1Gi
Host networkno
Privilegedno
Egress domainsnone - no outbound connections declared

Dependencies

Requiresnextcloud >=30
Optionaln8n, nocodb
Providesnc-appn8n-workflowsnocodb-schema

MCP (Model Context Protocol)

Servermcp/server.js
Transportstdio

Single sign-on (OIDC)

As clientno
As providerno
Fallbacknone

Skin & branding

Themeprimary #6B7280  ·  mode system
Logo./skin/logo.svg
Agent personaAgent - “Hi!”

Secrets

Declared in secretsRefs but apps/databroker/secrets.spec.yaml does not exist in the repository.

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.

Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

iddatabroker
domaindatabroker
vendorwilhelm
nameData Broker
descriptionAPI-key gateway in front of the Wilhelm API: one endpoint tree per key (allow/block/empty/broker); broker mode substitutes sensitive data based on a case file
version2.0.0
licenseservice, wilhelm
serviceApache-2.0
wilhelmApache-2.0
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typeinfrastructure
categorysecurity
emoji🗝️
pixelIcon
............
....KKKK....
...KWWWWK...
...KWKKWK...
...KWWWWK...
....KWWK....
....KWWK....
....KWWKK...
....KWWK....
....KWWKK...
....KKKK....
............
primaryColor#8B0000
tagssecuritygatewayapi-keysprivacybroker
compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
webpublicDir
previewdir, desktop, mobile, gallery, video, capture
desktop./preview/desktop.png
mobile./preview/mobile.png
gallery1 item
0src, caption, kind
src./preview/gallery/example.png
captionExample screenshot
kindflow
videosrc, poster
src./preview/demo.webm
poster./preview/demo-poster.png
captureurl, wait, widgetsUrl
componentsservice, widgets
serviceimage, compose, init, healthCheck
image
healthChecktype, path, interval, timeout, retries
typehttp
path/healthz
interval30s
timeout5s
retries3
widgets1 item
0tag, description, since, preview
tagwl-card
descriptionExample: a wl-* component this app contributes - the tag must exist in apps/ui/wl-html-data.json (tools/doctor warns otherwise).
since0.1.0
preview./preview/widgets/wl-card.png
desktopenabled, startPath, hideNextcloudChrome
enabledfalse
startPath/index.php/apps/example/
hideNextcloudChrometrue
resourcesmemory, cpu, storage
memory256Mi
cpu0.25
storage1Gi
permissionsneedsHostNetwork, needsPrivileged, egressDomains
needsHostNetworkfalse
needsPrivilegedfalse
egressDomains[ ]
dependenciesrequires, optional, provides
requires1 item
0id, version
idnextcloud
version>=30
optional2 items
0id
idn8n
1id
idnocodb
providesnc-appn8n-workflowsnocodb-schema
mcpserver, transport, grants
servermcp/server.js
transportstdio
grants[ ]
oidcCapabilityasClient, asProvider, fallback
asClientfalse
asProviderfalse
fallbacknone
secretsRefs./secrets.spec.yaml
skinslogan, logo, icon, theme, agent, dashboards
slogan
icon./skin/icon/512.png
themeprimary, mode
primary#6B7280
modesystem
agentname, greeting, persona
nameAgent
greetingHi!
dashboards./skin/dashboards/*.json
marketplacevisibility, screenshots, pricing, supportUrl
visibilitypublic
screenshots[ ]
pricingfree
taskhqenabled, width, height
enabledtrue
width760
height520

README

The README is not in English - see apps/databroker/README.md.

Support  ·  apps/databroker/

doc/ai-notes.md  ·  doc/api.md  ·  doc/sources.md

Vault

Passwords, safe at home.

External serviceSecurityAGPL-3.0v2.0.0free

Vaultwarden password manager in Nextcloud

What it does

Vault is Vaultwarden, the lightweight, unofficial server implementation of the Bitwarden API: the official Bitwarden apps and browser extensions connect to it, so you get a full password manager - vaults, organisations, sharing, two-step login, passkeys, secure notes, cards and identities - on your own server, replacing 1Password, LastPass and the Bitwarden cloud.

Because the clients are Bitwarden's own, the experience is the polished one users know; because the server is yours, the encrypted vault never leaves your infrastructure. Bitwarden's certificates (ISO 27001, SOC 2) do not carry over to Vaultwarden, which the compliance note states rather than glosses over.

Features

Bitwarden-compatible

Works with the official browser extensions, desktop and mobile apps, CLI and web vault.

Vault items

Logins, cards, identities and secure notes with folders, favourites, attachments and a trash.

Organisations and collections

Share items with teams via organisations, collections and groups; admin console.

Two-step login

E-mail codes, authenticator apps, passkeys / FIDO2 security keys, YubiKey OTP, Duo.

Password generator and reports

Generate strong passwords and passphrases; exposed, weak and reused password reports.

Send

Share text or files securely with expiry and access limits.

Emergency access

Trusted contacts can request access to a vault after a waiting period.

Import and export

Import from other password managers; encrypted exports.

Why it is in the stack

  • Replaces 1Password, LastPass and Bitwarden cloud with an AGPL server that needs a fraction of the resources.
  • Passwords, safe at home: the encrypted vault is stored in your Wilhelm stack, embedded in Nextcloud with single sign-on.
  • The official clients on every platform - nothing to teach, nothing to switch.

Screenshots

All vaults
All vaults

Personal vault and organisation vault in one list: a company credit card owned by the organisation, a mailing address identity, logins and a secure note. Filters by vault, item type, folder and collection on the left; generator, import and export under tools.

01-all-vaults.jpg
Two-step login
Two-step login

Security settings with master password, two-step login and keys. A recovery code protects against lock-out; providers can be enabled side by side.

02-security-2fa.jpg
Two-step login providers
Two-step login providers

E-mail, authenticator app, passkey (biometrics or a FIDO2 key), Yubico OTP and Duo - the same choice the Bitwarden cloud offers, served by your own instance.

03-2fa-providers.jpg

Screenshots are the upstream project's official product shots (see preview/SOURCES.md) until the stack runs with demo data and tools/app-preview shoots real Wilhelm screens. Images © their respective projects.

At a glance

Based onVaultwarden · source · docs · API
Replaces1Password, LastPass, Bitwarden · listed as Wilhelm Vault in the ecosystem reference
Type · categoryExternal service · Security
Licenceservice AGPL-3.0  ·  wrapper Proprietary  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support/vault
Docker imagevaultwarden/server:latest · port 80
Public URLhttps://vault.<your-domain>
Compose profilevaultwarden
Nextcloud app idwilhelmvault · Nextcloud 30-32
Tagspasswordssecurity
Folderapps/vault/manifest.json

Icon & assets

BrandBrandSquircleSquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 🔐Emoji #175DDC one brand SVG → tools/app-assetsappinfo/

Configuration

Service

Imagevaultwarden/server:latest
Port80
Health checkhttp /alive every 30s · timeout 5s · 3 retries

Embedding in Nextcloud

Registry id · labelvaultwarden · Vaultwarden Passwords
Subdomainvault
Containervaultwarden:80
Embed-proxy port (localhost)8901
Compose profilevaultwarden
Nextcloud config keyvault_url

Nextcloud app

App idwilhelmvault
Path./nextcloud
Nextcloud versions30 - 32

Dependencies

Requiresnextcloud >=30
Optionalvault

Single sign-on (OIDC)

As clientyes
As providerno
Fallbackvaultwarden

Skin & branding

SloganPasswords, safe at home.
Themeprimary #175DDC  ·  mode system
Logo./nextcloud/appinfo/icon.svg

Secrets

Declared in secretsRefs but apps/vault/secrets.spec.yaml does not exist in the repository.

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.

Unofficial community reimplementation of the Bitwarden server: Bitwarden's certificates (ISO 27001, SOC 2/3, HIPAA audits) do NOT apply to Vaultwarden. No audit, no vendor - unsuitable where vendor-backed attestation is contractually required. The Bitwarden client apps themselves are audited.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idvault
domainvault
vendorvaultwarden
nameVault
descriptionVaultwarden password manager in Nextcloud
version2.0.0
licenseservice, wrapper, wilhelm
serviceAGPL-3.0
wrapperProprietary
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typeexternal
categorysecurity
emoji🔐
pixelIcon
............
.KKKKKKKKKK.
.KWWKKKKWWK.
.KWWKWWKWWK.
.KWKKKKKKWK.
.KWKWWWWKWK.
.KWKWGGWKWK.
.KWKWWWWKWK.
.KWKKKKKKWK.
.KKKKKKKKKK.
............
primaryColor#175DDC
tagspasswordssecurity
compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
noteUnofficial community reimplementation of the Bitwarden server: Bitwarden's certificates (ISO 27001, SOC 2/3, HIPAA audits) do NOT apply to Vaultwarden. No audit, no vendor - unsuitable where vendor-backed attestation is contractually required. The Bitwarden client apps themselves are audited.
componentsservice, nextcloudApp, embed, vscode
serviceimage, port, volumes, environment, healthCheck
imagevaultwarden/server:latest
port80
volumesvault_data:/data
environmentSIGNUPS_ALLOWED, DOMAIN, ADMIN_TOKEN
SIGNUPS_ALLOWEDfalse
ADMIN_TOKEN
healthChecktype, path, interval, timeout, retries
typehttp
path/alive
interval30s
timeout5s
retries3
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmvault
minNcVersion30
maxNcVersion32
embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile
idvaultwarden
labelVaultwarden Passwords
ncConfigKeyvault_url
subdomainvault
containervaultwarden
containerPort80
embedProxyPort8901
profilevaultwarden
vscodeextensions, extension
extensions[ ]
extensionnull
dependenciesrequires, optional
requires1 item
0id, version
idnextcloud
version>=30
optional1 item
0id
idvault
oidcCapabilityasClient, asProvider, fallback
asClienttrue
asProviderfalse
fallbackvaultwarden
secretsRefs./secrets.spec.yaml
skinslogan, logo, theme
sloganPasswords, safe at home.
themeprimary, mode
primary#175DDC
modesystem
previewdir, gallery
gallery3 items
0src, caption, kind
captionAll vaults
kinddesktop
1src, caption, kind
captionSecurity & 2FA
kinddesktop
2src, caption, kind
caption2FA providers
kinddesktop
marketplacevisibility, screenshots, pricing, supportUrl

Standalone compose

Every service app can run on its own: cd apps/vault && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.

docker-compose.yml
# Vault - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/vault/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
#   cp .env.example .env && docker compose up -d
#   → http://localhost:${VAULT_PORT:-80}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
  vault:
    image: vaultwarden/server:latest
    restart: unless-stopped
    env_file:
      - .env
    ports:
      - "${VAULT_PORT:-80}:80"
    environment:
      SIGNUPS_ALLOWED: ${SIGNUPS_ALLOWED:-false}
      DOMAIN: ${DOMAIN:-http://localhost:80}
      ADMIN_TOKEN: ${ADMIN_TOKEN:-}
    healthcheck:
      test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:80/alive"]
      interval: 30s
      timeout: 5s
      retries: 3
      start_period: 20s
    networks:
      - vault
    volumes:
      - "vault_data:/data"

networks:
  vault:
    name: vault

volumes:
  vault_data:
.env.example
# Vault - standalone env. Copy to .env and fill in.
# GENERATED by scripts/generate-standalone.mjs

# Host port the app is published on.
VAULT_PORT=80

# Service configuration (compose falls back to these defaults if unset).
SIGNUPS_ALLOWED=false
DOMAIN=http://localhost:80
ADMIN_TOKEN=

# Required secrets are specified in:
#   ./secrets.spec.yaml
# Add the matching KEY=VALUE lines here.

README

The README is not in English - see apps/vault/README.md.

Upstream docs  ·  Upstream API  ·  Upstream source  ·  Support  ·  apps/vault/

doc/ai-notes.md  ·  doc/api.md  ·  doc/n8n.md  ·  doc/sources.md  ·  doc/vault-reference.md

llm

Models local, answers instant.

External serviceServicesMITv2.0.0free

ollama integration for the Wilhelm stack

What it does

llm is Ollama, the local inference engine of the stack: it downloads open-weight models (Llama, Mistral, Gemma, Qwen, Phi and more), keeps them warm and serves them over a slim HTTP API - completion, chat with tool calling, embeddings, model management - with no cloud dependency at all.

Its OpenAI-compatible endpoints mean existing clients work unchanged; the RAG pipeline uses it for embeddings, Wilhelm Intelligence can route to it as the offline backend, and Open WebUI chats against it.

Features

Open-weight models

Pull, create, copy and delete models from a Modelfile, GGUF or Safetensors.

Chat, completion, embeddings

Native API plus /v1/chat/completions, /v1/embeddings, /v1/models.

Streaming and structured output

Streamed responses; JSON and JSON-schema constrained output.

Multimodal

Image input for vision models.

GPU or CPU

NVIDIA acceleration where available; models persist in a volume.

Auto-pull

A model is pulled at startup by configuration.

Why it is in the stack

  • Models local, answers instant - no token ever leaves the house, no per-token billing.
  • Drop-in for OpenAI-compatible clients.
  • Protection is at the network level; the notes say so.

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs llm.

At a glance

Based onOllama · source · docs · API
ReplacesOpenAI API, Azure AI · listed as Wilhelm Brain in the ecosystem reference
Type · categoryExternal service · Services
Licenceservice MIT  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support/llm
Docker imageollama/ollama:latest · port 11434
Compose profileollama
Folderapps/llm/manifest.json

Icon & assets

BrandBrand-SquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 📦Emoji #6B7280 one brand SVG → tools/app-assetsappinfo/

Configuration

Service

Imageollama/ollama:latest
Port11434
Health checkhttp / every 30s · timeout 5s · 3 retries

Dependencies

Requiresnothing

Skin & branding

SloganModels local, answers instant.
Themeprimary #6B7280  ·  mode system
Logo./appinfo/icon.svg

Secrets

Declared in secretsRefs but apps/llm/secrets.spec.yaml does not exist in the repository.

Compliance

StandardStatusScopeNote
GDPR
Privacy
vendor claimcloud offeringThe privacy policy addresses GDPR data-subject rights for ollama.com; no DPA, no EU data residency. source

The local runtime processes everything inside your own stack - an architectural property, not a certification. No formal audits.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idllm
domainllm
vendorollama
namellm
descriptionollama integration for the Wilhelm stack
version2.0.0
licenseservice, wilhelm
serviceMIT
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typeexternal
categoryservice
emoji📦
pixelIcon
............
.KKKKKKKKKK.
.KWWWKWWWWK.
.KWWKKKWWWK.
.KWKKKKKWWK.
.KWWKKKWWWK.
.KWWWKWWWWK.
.KWWWWWWGWK.
.KWWWWWWWWK.
.KKKKKKKKKK.
............
primaryColor#6B7280
tags[ ]
compliancecertifications, note
certifications1 item
0id, status, scope, source, note
idgdpr
statusclaimed
scopecloud
noteThe privacy policy addresses GDPR data-subject rights for ollama.com; no DPA, no EU data residency.
noteThe local runtime processes everything inside your own stack - an architectural property, not a certification. No formal audits.
componentsservice, vscode
serviceimage, port, healthCheck
imageollama/ollama:latest
port11434
healthChecktype, path, interval, timeout, retries
typehttp
path/
interval30s
timeout5s
retries3
vscodeextensions, extension
extensions[ ]
extensionnull
dependenciesrequires, optional
requires[ ]
optional[ ]
secretsRefs./secrets.spec.yaml
skinslogan, logo, theme
sloganModels local, answers instant.
themeprimary, mode
primary#6B7280
modesystem
marketplacevisibility, pricing, supportUrl
visibilitypublic
pricingfree

Standalone compose

Every service app can run on its own: cd apps/llm && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.

docker-compose.yml
# llm - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/llm/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
#   cp .env.example .env && docker compose up -d
#   → http://localhost:${LLM_PORT:-11434}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
  llm:
    image: ollama/ollama:latest
    restart: unless-stopped
    env_file:
      - .env
    ports:
      - "${LLM_PORT:-11434}:11434"
    healthcheck:
      test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:11434/"]
      interval: 30s
      timeout: 5s
      retries: 3
      start_period: 20s
    networks:
      - llm
    # TODO: persistent volume(s) if this image stores state. e.g.:
    #   volumes: [ "llm_data:/data" ]

networks:
  llm:
    name: llm
.env.example
# ── Ollama (Local LLM) ───────────────────────────────────────────────────────
OLLAMA_PORT=11434
# Optional: Auto-pull model on startup (e.g. llama3.2:latest)
# OLLAMA_PULL_MODEL=llama3.2:latest
# Optional: Model storage path (default in container: /root/.ollama)
# OLLAMA_MODELS=/path/to/models
# Optional: How long model stays in RAM after use (default 5m)
# OLLAMA_DEFAULT_KEEPALIVE=30m
OLLAMA_EMBED_MODEL=nomic-embed-text

README

The README is not in English - see apps/llm/README.md.

Upstream docs  ·  Upstream API  ·  Upstream source  ·  Support  ·  apps/llm/

doc/ai-notes.md  ·  doc/api.md  ·  doc/llm-reference.md  ·  doc/n8n.md  ·  doc/sources.md

newsletter

Mail that arrives.

External serviceServicesAGPL-3.0v2.0.0free

listmonk integration for the Wilhelm stack

What it does

newsletter is listmonk, the self-hosted newsletter and mailing-list manager: subscribers, lists, campaigns, templates and transactional mail in a single Go binary on PostgreSQL that handles lists in the millions - the alternative to Mailchimp and SendGrid marketing.

In the Wilhelm stack the lists 'All contacts', 'Customers' and 'Buyers' are created at initialisation, and n8n keeps them in sync with the shop: new customers and orders flow into the right list automatically.

Features

Subscribers and lists

Attributes, list memberships, public double-opt-in lists, bulk operations by query.

Campaigns

Templates, test sends, scheduling, a public archive.

Transactional mail

Send templated single mails through the API.

Analytics

Views, clicks, bounces per campaign.

API and permissions

Complete HTTP API with per-user API permissions; Swagger docs on the instance.

Why it is in the stack

  • Mail that arrives: newsletters without a middleman and without subscription fees.
  • Subscriber data stays in your PostgreSQL; sending goes through your own mail server.
  • Pre-wired to the shop so lists maintain themselves.

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs newsletter.

At a glance

Based onlistmonk · source · docs · API
ReplacesMailchimp, SendGrid · listed as Wilhelm Mail in the ecosystem reference
Type · categoryExternal service · Services
Licenceservice AGPL-3.0  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support/newsletter
Docker imagelistmonk/listmonk:latest · port 9000
Compose profilelistmonk
Folderapps/newsletter/manifest.json

Icon & assets

BrandBrandSquircleSquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 📦Emoji #6B7280 one brand SVG → tools/app-assetsappinfo/

Configuration

Service

Imagelistmonk/listmonk:latest
Port9000
Init script./init-listmonk.sh
Health checkhttp /health every 30s · timeout 5s · 3 retries

Dependencies

Requiresnothing

Skin & branding

SloganMail that arrives.
Themeprimary #6B7280  ·  mode system
Logo./appinfo/icon.svg

Secrets

Declared in secretsRefs but apps/newsletter/secrets.spec.yaml does not exist in the repository.

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareGDPR-supporting features (self-service data export, one-click deletion, self-service blocklist, anonymous tracking) - compliance is established by the operator. source

Zerodha-backed FOSS project without certifications and without its own hosting offering.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idnewsletter
domainnewsletter
vendorlistmonk
namenewsletter
descriptionlistmonk integration for the Wilhelm stack
version2.0.0
licenseservice, wilhelm
serviceAGPL-3.0
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typeexternal
categoryservice
emoji📦
pixelIcon
............
.KKKKKKKKKK.
.KWWWWWWWWK.
.KWWWWWKKWK.
.KWWWKKKKWK.
.KWKKKKKWWK.
.KWWWKKWWWK.
.KWWWKWWWWK.
.KWWWWWWWWK.
.KKKKKKKKKK.
............
primaryColor#6B7280
tags[ ]
compliancecertifications, note
certifications1 item
0id, status, scope, source, note
idgdpr
statusconformant
scopesoftware
noteGDPR-supporting features (self-service data export, one-click deletion, self-service blocklist, anonymous tracking) - compliance is established by the operator.
noteZerodha-backed FOSS project without certifications and without its own hosting offering.
componentsservice, vscode
serviceimage, port, healthCheck, init
imagelistmonk/listmonk:latest
port9000
healthChecktype, path, interval, timeout, retries
typehttp
path/health
interval30s
timeout5s
retries3
vscodeextensions, extension
extensions[ ]
extensionnull
dependenciesrequires, optional
requires[ ]
optional[ ]
secretsRefs./secrets.spec.yaml
skinslogan, logo, theme
sloganMail that arrives.
themeprimary, mode
primary#6B7280
modesystem
marketplacevisibility, pricing, supportUrl
visibilitypublic
pricingfree

Standalone compose

Every service app can run on its own: cd apps/newsletter && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.

docker-compose.yml
# newsletter - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/newsletter/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
#   cp .env.example .env && docker compose up -d
#   → http://localhost:${NEWSLETTER_PORT:-9000}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
  newsletter:
    image: listmonk/listmonk:latest
    restart: unless-stopped
    env_file:
      - .env
    ports:
      - "${NEWSLETTER_PORT:-9000}:9000"
    healthcheck:
      test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:9000/health"]
      interval: 30s
      timeout: 5s
      retries: 3
      start_period: 20s
    networks:
      - newsletter
    # TODO: persistent volume(s) if this image stores state. e.g.:
    #   volumes: [ "newsletter_data:/data" ]

networks:
  newsletter:
    name: newsletter
.env.example
# ── Listmonk (Newsletter & Mailing Lists) ────────────────────────────────────
LISTMONK_PORT=9001
EMBED_LISTMONK_PORT=8900
LISTMONK_ADMIN_USER=admin
LISTMONK_ADMIN_PASSWORD=change_me
LISTMONK_DB_PASSWORD=change_me

README

The README is not in English - see apps/newsletter/README.md.

Upstream docs  ·  Upstream API  ·  Upstream source  ·  Support  ·  apps/newsletter/

doc/ai-notes.md  ·  doc/api.md  ·  doc/n8n.md  ·  doc/newsletter-reference.md  ·  doc/sources.md

storefront

Your shop, your look.

External serviceServicesMITv2.0.0free

medusa-storefront integration for the Wilhelm stack

What it does

storefront is the Medusa Next.js starter - the customer-facing shop: product listings, product pages, cart, multi-step checkout and customer accounts, as a pure client of the Store API with no database of its own.

It ships with Stripe and PayPal, mirrors the backend's regions and currencies, and can be restyled or replaced freely because it only speaks the public API.

Features

Catalogue and product pages

Search, filters, variants, images.

Cart and checkout

Multi-step checkout with shipping and payment.

Customer accounts

Registration, login, order history, addresses.

Payments

Stripe and PayPal out of the box.

Next.js

App Router, TypeScript, server and client rendering.

Why it is in the stack

  • Your shop, your look - a production-shaped storefront whose source you own.
  • No hosted-storefront subscription; customer analytics can go to Plausible.

Screenshots

Main page · desktop
Main page · desktopdesktop.png
Main page · mobile
Main page · mobilemobile.png
Navigation mit Ober- und Unterkategorien
Navigation mit Ober- und Unterkategorienmegamenu.png
Kategorieseite
Kategorieseitecategory.png
Produktseite
Produktseiteproduct.png
Brand-Override aus dem Theme-Editor
Brand-Override aus dem Theme-Editoradmin-override.png

At a glance

Based onMedusa Next.js Starter · source · docs
Type · categoryExternal service · Services
Licenceservice MIT  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support/storefront
Docker imagemedusajs/nextjs-starter-medusa · port 9000
Folderapps/storefront/manifest.json

Icon & assets

BrandBrand-SquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 📦Emoji #6B7280 one brand SVG → tools/app-assetsappinfo/ · serving copy in ./app/public

Configuration

Service

Imagemedusajs/nextjs-starter-medusa
Port9000
Health checkhttp / every 30s · timeout 5s · 3 retries

Dependencies

Requiresnothing

Skin & branding

SloganYour shop, your look.
Themeprimary #6B7280  ·  mode system
Logo./appinfo/icon.svg

Secrets

Declared in secretsRefs but apps/storefront/secrets.spec.yaml does not exist in the repository.

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.

Next.js starter frontend - compliance follows the shop instance (see app "shop").

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idstorefront
domainstorefront
vendormedusa-storefront
namestorefront
descriptionmedusa-storefront integration for the Wilhelm stack
version2.0.0
licenseservice, wilhelm
serviceMIT
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typeexternal
categoryservice
emoji📦
pixelIcon
............
.KKKKKKKKKK.
.KKKKKKKKKK.
.KKWKWKWKWK.
.KWWWWWWWWK.
.KWKWWWWKWK.
.KWKWKKWKWK.
.KWKWKKWKWK.
.KWKKKKKKWK.
.KKKKKKKKKK.
............
primaryColor#6B7280
tags[ ]
compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
noteNext.js starter frontend - compliance follows the shop instance (see app "shop").
webpublicDir
publicDir./app/public
previewdir, desktop, mobile, gallery
gallery4 items
0src, caption, kind
captionNavigation mit Ober- und Unterkategorien
kinddesktop
1src, caption, kind
captionKategorieseite
kinddesktop
2src, caption, kind
captionProduktseite
kinddesktop
3src, caption, kind
captionBrand-Override aus dem Theme-Editor
kinddesktop
componentsservice, vscode
serviceimage, port, healthCheck
imagemedusajs/nextjs-starter-medusa
port9000
healthChecktype, path, interval, timeout, retries
typehttp
path/
interval30s
timeout5s
retries3
vscodeextensions, extension
extensions[ ]
extensionnull
dependenciesrequires, optional
requires[ ]
optional[ ]
secretsRefs./secrets.spec.yaml
skinslogan, logo, theme
sloganYour shop, your look.
themeprimary, mode
primary#6B7280
modesystem
marketplacevisibility, pricing, supportUrl, screenshots

Standalone compose

Every service app can run on its own: cd apps/storefront && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.

docker-compose.yml
# storefront - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/storefront/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
#   cp .env.example .env && docker compose up -d
#   → http://localhost:${STOREFRONT_PORT:-9000}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
  storefront:
    image: medusajs/nextjs-starter-medusa
    restart: unless-stopped
    env_file:
      - .env
    ports:
      - "${STOREFRONT_PORT:-9000}:9000"
    healthcheck:
      test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:9000/"]
      interval: 30s
      timeout: 5s
      retries: 3
      start_period: 20s
    networks:
      - storefront
    # TODO: persistent volume(s) if this image stores state. e.g.:
    #   volumes: [ "storefront_data:/data" ]

networks:
  storefront:
    name: storefront
.env.example
# ── Medusa Storefront ────────────────────────────────────────────────────────
# Inherits MEDUSA_* from medusa/.env or root .env
MEDUSA_STOREFRONT_PORT=8000
MEDUSA_STOREFRONT_URL=http://localhost:8000

# ── Wilhelm Brand (zentrale Single Source of Truth) ────────────────────────
# Setze diese Werte in der Root-.env (siehe config/stack.defaults.env).
# docker-compose mappt sie auf NEXT_PUBLIC_BRAND_* - im Storefront verfügbar
# über getBrand() aus @lib/brand.
#
# WILHELM_BRAND_NAME="Wilhelm"
# WILHELM_BRAND_PRIMARY_COLOR="#0369FF"
# WILHELM_BRAND_ACCENT_COLOR="#FFCC00"
# WILHELM_BRAND_LOGO_URL=

README

The README is not in English - see apps/storefront/README.md.

Upstream docs  ·  Upstream source  ·  Support  ·  apps/storefront/

doc/ai-notes.md  ·  doc/api.md  ·  doc/n8n.md  ·  doc/sources.md  ·  doc/storefront-reference.md

tell

A mailbox with brains.

External serviceServicesMITv2.0.0free

tell-imap integration for the Wilhelm stack

What it does

tell is a mailbox with brains: a very lean IMAP-to-webhook bridge that watches a mailbox over IMAP IDLE and pushes every new mail as JSON to n8n - the entry trigger for all mail-based workflows, without a cloud automation service ever seeing the mail.

One file, one dependency, a reconnect loop and a health endpoint. The usual source is the stack's own mail server.

Features

IMAP IDLE

Live watching, no polling.

Webhook

Each mail becomes a JSON POST, optionally with the body.

Reconnect

Robust loop with configurable delay.

Health

A health endpoint; restartable from the settings app.

Why it is in the stack

  • Event-driven mail automation with a tiny footprint and no state.
  • Mail credentials never leave the stack.

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs tell.

At a glance

Based onWilhelm tell-imap
Type · categoryExternal service · Services
Licenceservice MIT  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support/tell
Docker imagewilhelm/tell-imap:latest · port 3000
Folderapps/tell/manifest.json

Icon & assets

BrandBrand-SquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 📦Emoji #6B7280 one brand SVG → tools/app-assetsappinfo/

Configuration

Service

Imagewilhelm/tell-imap:latest
Port3000
Health checkhttp / every 30s · timeout 5s · 3 retries

Dependencies

Requiresnothing

Skin & branding

SloganA mailbox with brains.
Themeprimary #6B7280  ·  mode system
Logo./appinfo/icon.svg

Secrets

Declared in secretsRefs but apps/tell/secrets.spec.yaml does not exist in the repository.

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.

Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idtell
domaintell
vendortell-imap
nametell
descriptiontell-imap integration for the Wilhelm stack
version2.0.0
licenseservice, wilhelm
serviceMIT
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typeexternal
categoryservice
emoji📦
pixelIcon
............
.KKKKKKKKKK.
.KWKKKKKKWK.
.KWKWWWGKWK.
.KWKWWWWKWK.
.KWKGGWWKWK.
.KWKGGGWKWK.
.KWKKKKKKWK.
.KWWWWWWWWK.
.KKKKKKKKKK.
............
primaryColor#6B7280
tags[ ]
compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
componentsservice, vscode
serviceimage, port, healthCheck
imagewilhelm/tell-imap:latest
port3000
healthChecktype, path, interval, timeout, retries
typehttp
path/
interval30s
timeout5s
retries3
vscodeextensions, extension
extensions[ ]
extensionnull
dependenciesrequires, optional
requires[ ]
optional[ ]
secretsRefs./secrets.spec.yaml
skinslogan, logo, theme
sloganA mailbox with brains.
themeprimary, mode
primary#6B7280
modesystem
marketplacevisibility, pricing, supportUrl
visibilitypublic
pricingfree

Standalone compose

Every service app can run on its own: cd apps/tell && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.

docker-compose.yml
# tell - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/tell/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
#   cp .env.example .env && docker compose up -d
#   → http://localhost:${TELL_PORT:-3000}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
  tell:
    image: wilhelm/tell-imap:latest
    restart: unless-stopped
    env_file:
      - .env
    ports:
      - "${TELL_PORT:-3000}:3000"
    healthcheck:
      test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:3000/"]
      interval: 30s
      timeout: 5s
      retries: 3
      start_period: 20s
    networks:
      - tell
    # TODO: persistent volume(s) if this image stores state. e.g.:
    #   volumes: [ "tell_data:/data" ]

networks:
  tell:
    name: tell
.env.example
# ── Tell IMAP (IMAP → n8n Bridge) ────────────────────────────────────────────
# Inherits IMAP_* from root .env or set here
IMAP_HOST=mailcow
IMAP_PORT=993
IMAP_USER=
IMAP_PASS=
IMAP_TLS=true
IMAP_MAILBOX=INBOX
TELL_IMAP_WEBHOOK_URL=http://n8n:5678/webhook/tell-imap
IMAP_FETCH_BODY=false
IMAP_RECONNECT_DELAY_MS=5000

README

The README is not in English - see apps/tell/README.md.

Support  ·  apps/tell/

doc/ai-notes.md  ·  doc/api.md  ·  doc/n8n.md  ·  doc/sources.md

Wilhelm Techstack / Storage / Wilhelm S3

Wilhelm S3

Nextcloud speaks S3.

IntegrationStorageAGPL-3.0v0.1.0free

Native Nextcloud app that turns Nextcloud into an S3 server. Buckets are real Nextcloud folders, objects are real files (with sharing, versions, quota). Other apps such as Twenty CRM speak S3 while the files sit right in the Nextcloud file browser. No second object store.

What it does

Wilhelm S3 turns Nextcloud into an S3 server: a native Nextcloud app that maps S3 buckets to top-level folders and object keys to file paths. An S3 PUT from Twenty CRM or any AWS-SDK client lands as a real file in a user's Nextcloud Files - with sharing, versions and quota - instead of in a second object store such as MinIO.

Requests are verified with AWS Signature V4; access keys map to a Nextcloud user whose Files hold the buckets. Deployment is a script with health check and rollback, and a smoke test does a put-head-get round trip.

Features

S3 verbs on Nextcloud Files

Buckets are folders, objects are files.

Signature V4

The AWS SDK default; no Nextcloud session or CSRF needed.

Credential store

Access key to secret and user, managed with occ.

Path-style endpoint

Point any client at the app path with forcePathStyle.

Deploy and smoke test scripts

Why it is in the stack

  • Nextcloud speaks S3: one storage system instead of two.
  • Objects stay visible and manageable in the normal Nextcloud UI.

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs s3proxy.

At a glance

Based onWilhelm-native - no upstream project
Type · categoryIntegration · Storage
Licenceservice AGPL-3.0  ·  wilhelm Apache-2.0
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support
Nextcloud app idwilhelms3
Resourcesmemory 128Mi  ·  cpu 0.25  ·  storage 1Gi
Tagss3storagenextcloudapi
Folderapps/s3proxy/manifest.json

Icon & assets

BrandBrand-SquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 🪣Emoji #3B82F6 one brand SVG → tools/app-assetsappinfo/

Configuration

Nextcloud app

App idwilhelms3
Path.

Desktop build (Electron)

Enabledno - opted out

Resources & permissions

Memory · CPU · storage128Mi · 0.25 · 1Gi
Host networkno
Privilegedno
Egress domainsnone - no outbound connections declared

Dependencies

Requiresnextcloud >=30
Optionaltwenty
Providess3-endpoint

Single sign-on (OIDC)

As clientno
As providerno
Fallbacknone

Skin & branding

SloganNextcloud speaks S3.
Themeprimary #3B82F6  ·  mode system
Logo./icon.svg

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.

Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

ids3proxy
domains3proxy
vendorwilhelm
nameWilhelm S3
descriptionNative Nextcloud app that turns Nextcloud into an S3 server. Buckets are real Nextcloud folders, objects are real files (with sharing, versions, quota). Other apps such as Twenty CRM speak S3 while the files sit right in the Nextcloud file browser. No second object store.
version0.1.0
licenseservice, wilhelm
serviceAGPL-3.0
wilhelmApache-2.0
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typeintegration
categorystorage
emoji🪣
pixelIcon
............
.KKKKKKKKKK.
.KWKKKKKKWK.
.KWKWWWWKWK.
.KWWKWWKWWK.
.KWWKGGKWWK.
.KWWWKKWWWK.
.KWWWWWWWWK.
.KWWWWWWWWK.
.KKKKKKKKKK.
............
primaryColor#3B82F6
tagss3storagenextcloudapi
compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
componentsnextcloudApp, vscode
nextcloudAppappid, path
appidwilhelms3
path.
vscodeextensions, extension
extensions[ ]
extensionnull
desktopenabled
enabledfalse
resourcesmemory, cpu, storage
memory128Mi
cpu0.25
storage1Gi
permissionsneedsHostNetwork, needsPrivileged, egressDomains
needsHostNetworkfalse
needsPrivilegedfalse
egressDomains[ ]
dependenciesrequires, optional, provides
requires1 item
0id, version
idnextcloud
version>=30
optional1 item
0id
idtwenty
providess3-endpoint
oidcCapabilityasClient, asProvider, fallback
asClientfalse
asProviderfalse
fallbacknone
skinslogan, logo, theme
sloganNextcloud speaks S3.
themeprimary, mode
primary#3B82F6
modesystem
marketplacevisibility, pricing, supportUrl
visibilitypublic
pricingfree

Support  ·  apps/s3proxy/

doc/sources.md

Wilhelm Techstack / Tools / Blackwell

Blackwell

Embedded appToolsApache-2.0v0.1.0freeprivate

A news letterpress

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs blackwell.

At a glance

Based onBlackwell
Type · categoryEmbedded app · Tools
Licenceservice Apache-2.0  ·  wilhelm Apache-2.0
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Docker imagenginx:alpine · port 80
Tagsnewsverlagrssbundestagthemen
Folderapps/blackwell/manifest.json

Icon & assets

BrandBrand-SquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest 📰Emoji #1A1A1A one brand SVG → tools/app-assetsappinfo/ · serving copy in ./service/app/public

Configuration

Service

Imagenginx:alpine
Port80
Compose fragment./service/compose.fragment.yml
Health checkhttp /healthz every 30s · timeout 5s · 3 retries

Dependencies

Requiresnextcloud >=30

Single sign-on (OIDC)

As clientno
As providerno
Fallbacknone

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idblackwell
domainblackwell
vendorblackwell
nameBlackwell
descriptionA news letterpress
version0.1.0
licenseservice, wilhelm
serviceApache-2.0
wilhelmApache-2.0
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typeembedded
categorytools
emoji📰
primaryColor#1A1A1A
tagsnewsverlagrssbundestagthemen
webpublicDir
componentsservice, vscode
serviceimage, compose, port, healthCheck
imagenginx:alpine
port80
healthChecktype, path, interval, timeout, retries
typehttp
path/healthz
interval30s
timeout5s
retries3
vscodeextensions, extension
extensions[ ]
extensionnull
dependenciesrequires, optional, provides
requires1 item
0id, version
idnextcloud
version>=30
optional[ ]
provides[ ]
oidcCapabilityasClient, asProvider, fallback
asClientfalse
asProviderfalse
fallbacknone
secretsRefs[ ]
marketplacevisibility, screenshots, pricing, supportUrl
visibilityprivate
screenshots[ ]
pricingfree
supportUrl

From the README

Add workflows/ for n8n exports, schemas/ for NocoDB tables, service/ for a Docker service, or nextcloud/ for a native NC app - see the canonical apps/_template/ and the root README - Building an App.

Read on: apps/blackwell/README.md

apps/blackwell/

Bluedune

Full-stack HTML, done.

Embedded appToolsApache-2.0v0.1.0freeprivate

Fullstack HTML Framework

What it does

Bluedune is a full-stack HTML framework in the Wilhelm family - the idea that a page, its data and its behaviour can be written as HTML, in the spirit of HTML67, without a separate frontend and backend project.

The app is scaffolded from the Wilhelm template: manifest, icon and README exist, the service image and port are still to be defined. This page documents the contract, not yet a running product.

Features

Embedded app type - runs inside the Nextcloud shell once a service exists

Apache-2.0 licensed, unusually permissive for the stack

Template slots for n8n workflows, NocoDB schemas, a service and a Nextcloud app

Why it is in the stack

  • Full-stack HTML, done: one language for the whole page.
  • Status is honest - scaffold only; the manifest is the specification to build against.

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs bluedune.

At a glance

Based onBluedune
Type · categoryEmbedded app · Tools
Licenceservice Apache-2.0  ·  wilhelm Apache-2.0
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Docker imageTODO/replace-me:latest
Folderapps/bluedune/manifest.json

Icon & assets

BrandBrand-SquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 🏜️Emoji #6B7280 one brand SVG → tools/app-assetsappinfo/

Configuration

Service

ImageTODO/replace-me:latest
Health checkhttp /healthz every 30s · timeout 5s · 3 retries

Dependencies

Requiresnextcloud >=30

Single sign-on (OIDC)

As clientno
As providerno
Fallbacknone

Skin & branding

SloganFull-stack HTML, done.
Themeprimary #6B7280  ·  mode system
Logo./icon.svg

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.

Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idbluedune
domainbluedune
vendorbluedune
nameBluedune
descriptionFullstack HTML Framework
version0.1.0
licenseservice, wilhelm
serviceApache-2.0
wilhelmApache-2.0
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typeembedded
categorytools
emoji🏜️
pixelIcon
............
.KKKKKKKKKK.
.KWWWWWWWWK.
.KWWWWWWWWK.
.KWWWKKWWWK.
.KWWKWWKWWK.
.KWKWWWWKWK.
.KKWWWWWWKK.
.KGGGGGGGGK.
.KKKKKKKKKK.
............
primaryColor#6B7280
tags[ ]
compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
componentsservice, vscode
serviceimage, port, healthCheck
imageTODO/replace-me:latest
port0
healthChecktype, path, interval, timeout, retries
typehttp
path/healthz
interval30s
timeout5s
retries3
vscodeextensions, extension
extensions[ ]
extensionnull
dependenciesrequires, optional, provides
requires1 item
0id, version
idnextcloud
version>=30
optional[ ]
provides[ ]
oidcCapabilityasClient, asProvider, fallback
asClientfalse
asProviderfalse
fallbacknone
secretsRefs[ ]
skinslogan, logo, theme
sloganFull-stack HTML, done.
themeprimary, mode
primary#6B7280
modesystem
marketplacevisibility, screenshots, pricing, supportUrl
visibilityprivate
screenshots[ ]
pricingfree
supportUrl

From the README

Add workflows/ for n8n exports, schemas/ for NocoDB tables, service/ for a Docker service, or nextcloud/ for a native NC app - see the canonical apps/_template/ and the root README - Building an App.

Read on: apps/bluedune/README.md

apps/bluedune/

doc/sources.md

Codeflow

See code instead of reading it.

InfrastructureToolsApache-2.0v0.1.0freeprivate

ReactFlow-based code visualizer + editor - bundled into Enter as a VS Code extension

What it does

Codeflow shows code instead of making you read it: a visualiser and editor for the real symbol graph of a repository - functions, components, classes, methods and their call, render and import edges - plus the stack-level artefacts around them: app manifests, n8n workflows, compose dependencies, JSON schemas.

It is bundled into Enter as a VS Code extension. The graph is extracted by a tool into the repo, and the view refreshes whenever the graph changes - including when a coding agent rewrites it.

Features

Four layouts

Force (animated physics), Layer (call direction left to right), Bundle (hierarchical edge bundling) and Circles (zoomable circle packing of directories, files and symbols).

Navigate

Pan, zoom, hover to highlight callers and callees, click to jump to file and line.

Noise control

Toggle utility symbols and file-level import edges.

Whole-stack graph

Manifest dependencies, n8n node graphs, docker-compose depends_on and schemas in the same picture.

Graph files as app config

Every app carries a graph.codeflow file with its own custom editor.

Zero runtime dependencies

The renderer is vanilla; the d3-style layouts are ports.

Why it is in the stack

  • See the architecture as it is, extracted from the code, not as it was drawn once.
  • Lives in the editor the team already uses; the agent can open it from a chat answer.
  • Replaces commercial code-map tools without sending the source anywhere.

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs codeflow.

At a glance

Based onWilhelm-native - no upstream project
Type · categoryInfrastructure · Tools
Licenceservice Apache-2.0  ·  wilhelm Apache-2.0
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support/codeflow
Tagseditorvisualizationreactflowgraph
Folderapps/codeflow/manifest.json

Icon & assets

BrandBrand-SquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 🪢Emoji #A855F7 one brand SVG → tools/app-assetsappinfo/

Configuration

Inside Enter (code-server)

Bundled extension./extension

Dependencies

Requiresnothing
Providesui-component

Single sign-on (OIDC)

As clientno
As providerno
Fallbacknone

Skin & branding

SloganSee code instead of reading it.
Themeprimary #A855F7  ·  mode system
Logo./icon.svg

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.

Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idcodeflow
domaincodeflow
vendorwilhelm
nameCodeflow
descriptionReactFlow-based code visualizer + editor - bundled into Enter as a VS Code extension
version0.1.0
licenseservice, wilhelm
serviceApache-2.0
wilhelmApache-2.0
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typeinfrastructure
categorytools
emoji🪢
pixelIcon
............
.KKKKKKKKKK.
.KWKKWWWWWK.
.KWKKWWWWWK.
.KWWWKWWWWK.
.KWWWWKWWWK.
.KWWWWWWWWK.
.KWWWWWKKWK.
.KWWWWWKKWK.
.KKKKKKKKKK.
............
primaryColor#A855F7
tagseditorvisualizationreactflowgraph
compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
dependenciesrequires, optional, provides
requires[ ]
optional[ ]
providesui-component
oidcCapabilityasClient, asProvider, fallback
asClientfalse
asProviderfalse
fallbacknone
secretsRefs[ ]
skinslogan, logo, theme
sloganSee code instead of reading it.
themeprimary, mode
primary#A855F7
modesystem
marketplacevisibility, screenshots, pricing, supportUrl
visibilityprivate
screenshots[ ]
pricingfree
componentsvscode
vscodeextensions, extension
extensions[ ]
extension./extension

From the README

Status: functional. Renders the real symbol graph (functions, React components, classes, methods) with call / render / import edges - plus the app-level artifacts: app manifests (requires dependencies between apps), n8n workflows (node-to-node flow), docker-compose services (depends_on), JSON schemas. The graph is produced by tools/codeflow-extract (ts-morph + artifact scan) and written to .wilhelm/codeflow/graph.json; the webview picks it up automatically.

A file watcher on .wilhelm/codeflow/*.json opens/refreshes the webview whenever a graph is (re)written - including when the Caret agent runs the extractor. Caret can also open it explicitly by emitting <CODEFLOW src="…" /> in a chat answer (parsed in apps/enter/.../plan-render.ts).

Read on: apps/codeflow/README.md

Support  ·  apps/codeflow/

doc/sources.md

Enter

The editor that thinks along.

External serviceToolsMITv0.1.0free

Cursor-style AI code editor (code-server + Enter Chat extension) - Plan / Inspect / Agent modes powered by Anthropic Claude

What it does

Enter is Wilhelm's Cursor alternative: browser-based VS Code (code-server) with a bundled chat extension that gives you Cursor's three ways of working - Plan, Inspect and Agent - powered by Anthropic Claude. The chat is a pinned pane in the first editor column; files open next to it; Ctrl/Cmd+L focuses the chat.

The decisive difference to Cursor is how it talks to the model: the extension shells out to the local Claude Code CLI, so the existing Anthropic subscription does the work - no API key, no per-token bill, no SaaS backend in between. Every tool call streams into the chat as it happens.

Features

Plan mode

Read-only planning - the agent reads and reasons, no edits, no shell.

Inspect mode

Conversational questions about the codebase, read-only.

Agent mode

Full agent with edits and shell inside the sandboxed workspace mount.

Full VS Code

Terminal, extensions, settings sync, a built-in port proxy for the apps you run.

Codeflow built in

The code graph extension ships in the same image; the agent can open graphs from a chat answer.

Versioned prompts

System prompts live in the extension source and are appended to every run.

App memory

Every app's memory and notes are loaded into the chat when you work on that app.

Why it is in the stack

  • The editor that thinks along - Cursor's workflow, fully open-source and self-hosted.
  • No API key and no token cost: it reuses the subscription session you already have.
  • Runs in the existing Docker stack, embedded in Nextcloud, with the whole repository as the workspace.

Screenshots

Main page · desktop
Main page · desktopdesktop.png
Enter chat next to the editor
Enter chat next to the editor01-chat-and-editor.jpg
Wilhelm Apps view in the activity bar
Wilhelm Apps view in the activity bar02-wilhelm-apps.jpg

Screenshots are the upstream project's official product shots (see preview/SOURCES.md) until the stack runs with demo data and tools/app-preview shoots real Wilhelm screens. Images © their respective projects.

At a glance

Based oncode-server (Coder) · source · docs
Type · categoryExternal service · Tools
Licenceservice MIT  ·  wrapper Apache-2.0  ·  wilhelm Apache-2.0
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support/enter
Docker imagecodercom/code-server:4.96.4 · port 8443
Public URLhttps://enter.<your-domain>/?folder=/workspace/wilhelm-techstack
Compose profileenter
Nextcloud app idwilhelmenter · Nextcloud 30-32
Resourcesmemory 1Gi  ·  cpu 1.0  ·  storage 5Gi
Tagseditoraiidecodingclaude
Folderapps/enter/manifest.json

Icon & assets

BrandBrandSquircleSquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel ⌨️Emoji #0F172A one brand SVG → tools/app-assetsappinfo/

Configuration

Service

Imagecodercom/code-server:4.96.4
Port8443
Health checkhttp /healthz every 30s · timeout 5s · 5 retries

Embedding in Nextcloud

Registry id · labelenter · Enter - AI Code Editor
Subdomainenter
Containerenter:8443
Embed-proxy port (localhost)8976
Compose profileenter
Nextcloud config keyenter_app_url
iframe path/?folder=/workspace/wilhelm-techstack

Nextcloud app

App idwilhelmenter
Path./nextcloud
Nextcloud versions30 - 32

Inside Enter (code-server)

Bundled extension./service/extension

Desktop build (Electron)

Enabledyes
Reader path/proxy/8765/

Resources & permissions

Memory · CPU · storage1Gi · 1.0 · 5Gi
Host networkno
Privilegedno
Egress domainsnone - no outbound connections declared

Dependencies

Requiresnextcloud >=30
Optionalvault
Providesembedded-appnc-app

MCP (Model Context Protocol)

Grantsthe agent additionally gets the MCP of webwow

Single sign-on (OIDC)

As clientno
As providerno
Fallbacknone

Skin & branding

SloganThe editor that thinks along.
Themeprimary #0F172A  ·  mode system
Logo./icon.svg

Secrets

Declared in secretsRefs but apps/enter/secrets.spec.yaml does not exist in the repository.

Compliance

StandardStatusScopeNote
SOC 2 Type II
Information security
attestedvendorSOC 2 Type II of the company Coder; does not carry over to self-hosted code-server. source
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
ISO/IEC 27001
Information security
in progresssoftwareWilhelm certification programme - implementation for all Wilhelm apps in progress.
WCAG
Accessibility
in progresssoftwareWilhelm certification programme - implementation for all Wilhelm apps in progress.
ISO 9241
Usability / ergonomics
in progresssoftwareWilhelm certification programme - implementation for all Wilhelm apps in progress.
EAA / BFSG
Accessibility
in progresssoftwareWilhelm certification programme - implementation for all Wilhelm apps in progress.

code-server itself is uncertified open-source software; the Coder attestation applies to the company.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

identer
domainenter
vendorwilhelm
nameEnter
descriptionCursor-style AI code editor (code-server + Enter Chat extension) - Plan / Inspect / Agent modes powered by Anthropic Claude
version0.1.0
licenseservice, wrapper, wilhelm
serviceMIT
wrapperApache-2.0
wilhelmApache-2.0
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typeexternal
categorytools
emoji⌨️
pixelIcon
............
..........K.
..........K.
..........K.
...K......K.
..KK......K.
.KKKKKKKKKK.
..KK........
...K........
............
primaryColor#0F172A
tagseditoraiidecodingclaude
compliancecertifications, note
certifications6 items
0id, status, scope, source, note
idsoc2-type2
statusattested
scopevendor
noteSOC 2 Type II of the company Coder; does not carry over to self-hosted code-server.
1id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
2id, status, scope, note
idiso-27001
statusin-progress
scopesoftware
noteWilhelm certification programme - implementation for all Wilhelm apps in progress.
3id, status, scope, note
idwcag
statusin-progress
scopesoftware
noteWilhelm certification programme - implementation for all Wilhelm apps in progress.
4id, status, scope, note
idiso-9241
statusin-progress
scopesoftware
noteWilhelm certification programme - implementation for all Wilhelm apps in progress.
5id, status, scope, note
ideaa
statusin-progress
scopesoftware
noteWilhelm certification programme - implementation for all Wilhelm apps in progress.
notecode-server itself is uncertified open-source software; the Coder attestation applies to the company.
desktopreaderPath
readerPath/proxy/8765/
componentsservice, nextcloudApp, embed, vscode
serviceimage, port, healthCheck
imagecodercom/code-server:4.96.4
port8443
healthChecktype, path, interval, timeout, retries
typehttp
path/healthz
interval30s
timeout5s
retries5
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmenter
minNcVersion30
maxNcVersion32
embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile, iframePath
identer
labelEnter - AI Code Editor
ncConfigKeyenter_app_url
subdomainenter
containerenter
containerPort8443
embedProxyPort8976
profileenter
iframePath/?folder=/workspace/wilhelm-techstack
vscodeextensions, extension
extensions[ ]
resourcesmemory, cpu, storage
memory1Gi
cpu1.0
storage5Gi
permissionsneedsHostNetwork, needsPrivileged, egressDomains
needsHostNetworkfalse
needsPrivilegedfalse
egressDomains[ ]
mcpgrants
grantswebwow
dependenciesrequires, optional, provides
requires1 item
0id, version
idnextcloud
version>=30
optional1 item
0id
idvault
providesembedded-appnc-app
oidcCapabilityasClient, asProvider, fallback
asClientfalse
asProviderfalse
fallbacknone
secretsRefs./secrets.spec.yaml
skinslogan, logo, theme
sloganThe editor that thinks along.
themeprimary, mode
primary#0F172A
modesystem
previewdir, desktop, gallery
gallery2 items
0src, caption, kind
captionEnter chat next to the editor
kinddesktop
1src, caption, kind
captionWilhelm Apps view in the activity bar
kinddesktop
marketplacevisibility, screenshots, pricing, supportUrl

Standalone compose

Every service app can run on its own: cd apps/enter && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.

docker-compose.yml
# Enter - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/enter/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
#   cp .env.example .env && docker compose up -d
#   → http://localhost:${ENTER_PORT:-8443}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
  enter:
    image: codercom/code-server:4.96.4
    restart: unless-stopped
    env_file:
      - .env
    ports:
      - "${ENTER_PORT:-8443}:8443"
    healthcheck:
      test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:8443/healthz"]
      interval: 30s
      timeout: 5s
      retries: 5
      start_period: 20s
    networks:
      - enter
    # TODO: persistent volume(s) if this image stores state. e.g.:
    #   volumes: [ "enter_data:/data" ]

networks:
  enter:
    name: enter
.env.example
# Enter - standalone env. Copy to .env and fill in.
# GENERATED by scripts/generate-standalone.mjs

# Host port the app is published on.
ENTER_PORT=8443

# Required secrets are specified in:
#   ./secrets.spec.yaml
# Add the matching KEY=VALUE lines here.

From the README

Cursor-style AI code editor, fully open-source, self-hosted in Wilhelm. Browser-based VS Code (code-server) plus the bundled Caret chat extension with three Cursor-style modes - Plan, Inspect, Agent - that shell out to your local Claude Code CLI. No API key. No token cost. Your existing Anthropic Pro/Max subscription does all the work.

Cursor is closed-source and bills per-token via its own backend. Wilhelm needed a 1:1 replacement that:

Read on: apps/enter/README.md

Upstream docs  ·  Upstream source  ·  Support  ·  apps/enter/

doc/ai-notes.md  ·  doc/api.md  ·  doc/enter-reference.md  ·  doc/n8n.md  ·  doc/sources.md

evi

Elevators, assets, everything in view.

Embedded appToolsApache-2.0v0.1.0freeprivate

elevator intelligence, property management and asset lifecycle platform

What it does

evi is an elevator-intelligence, property-management and asset-lifecycle platform by elevator intelligence GmbH, positioned as an embedded partner app in the Wilhelm catalogue: lifts, assets and their lifecycle in one view, next to the company's files, mail and projects.

Only the app contract exists in this repository so far - manifest, icon and README. The service image and port follow with the partner's delivery.

Features

Declared domain: elevator intelligence, property management, asset lifecycle

Embedded app type - runs inside the Nextcloud shell

Apache-2.0 licensed; requires Nextcloud 30 or newer

Why it is in the stack

  • Elevators, assets, everything in view - a vertical application on the same self-hosted foundation as the rest of the stack.
  • Status is honest: scaffold and contract; no data flows anywhere yet.

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs evi.

At a glance

Based onEvi
Type · categoryEmbedded app · Tools
Licenceservice Apache-2.0  ·  wilhelm Apache-2.0
Maintainerelevator intelligence GmbH · tobias@ev-i.de · www.elevatorintelligence.com
Docker imageTODO/replace-me:latest
Folderapps/evi/manifest.json

Icon & assets

BrandBrand-SquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 🏢Emoji #6B7280 one brand SVG → tools/app-assetsappinfo/

Configuration

Service

ImageTODO/replace-me:latest
Health checkhttp /healthz every 30s · timeout 5s · 3 retries

Dependencies

Requiresnextcloud >=30

Single sign-on (OIDC)

As clientno
As providerno
Fallbacknone

Skin & branding

SloganElevators, assets, everything in view.
Themeprimary #6B7280  ·  mode system
Logo./icon.svg

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.

Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idevi
domainevi
vendorevi
nameevi
descriptionelevator intelligence, property management and asset lifecycle platform
version0.1.0
licenseservice, wilhelm
serviceApache-2.0
wilhelmApache-2.0
maintainername, email, url
nameelevator intelligence GmbH
emailtobias@ev-i.de
typeembedded
categorytools
emoji🏢
pixelIcon
............
.KKKKKKKKKK.
.KWWWKWWWWK.
.KWWWKWWWWK.
.KWKKKKKWWK.
.KWWWKWWWWK.
.KWWWKWWWWK.
.KWWWWWWGWK.
.KWWWWWWWWK.
.KKKKKKKKKK.
............
primaryColor#6B7280
tags[ ]
compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
componentsservice, vscode
serviceimage, port, healthCheck
imageTODO/replace-me:latest
port0
healthChecktype, path, interval, timeout, retries
typehttp
path/healthz
interval30s
timeout5s
retries3
vscodeextensions, extension
extensions[ ]
extensionnull
dependenciesrequires, optional, provides
requires1 item
0id, version
idnextcloud
version>=30
optional[ ]
provides[ ]
oidcCapabilityasClient, asProvider, fallback
asClientfalse
asProviderfalse
fallbacknone
secretsRefs[ ]
skinslogan, logo, theme
sloganElevators, assets, everything in view.
themeprimary, mode
primary#6B7280
modesystem
marketplacevisibility, screenshots, pricing, supportUrl
visibilityprivate
screenshots[ ]
pricingfree
supportUrl

From the README

elevator intelligence, property management and asset lifecycle platform

Add workflows/ for n8n exports, schemas/ for NocoDB tables, service/ for a Docker service, or nextcloud/ for a native NC app - see the canonical apps/_template/ and the root README - Building an App.

Read on: apps/evi/README.md

apps/evi/

doc/sources.md

Fabi AI

Fabi's projects, one board.

Embedded appToolsApache-2.0v0.1.0freeprivate

Fabi's app

What it does

Fabi AI is a personal project board - Fabi's projects, one board - shipped as a static page straight from the app folder, with a letter template and an n8n workflow that sends a physical letter through Deutsche Post.

It shows the smallest possible Wilhelm app: a web directory published through the manifest, branded assets, and automation attached through n8n instead of a backend of its own.

Features

Static single-page project board served from the app folder

Letter template for printed correspondence

n8n workflow: send a physical letter via Deutsche Post

Branded asset set: favicons, touch icon, OpenGraph card

Why it is in the stack

  • Paper output from a web app via n8n - without an extra SaaS.
  • Everything an app needs to exist in the stack, in a handful of files.

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs fabi.

At a glance

Based onFabi
Type · categoryEmbedded app · Tools
Licenceservice Apache-2.0  ·  wilhelm Apache-2.0
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Docker imageTODO/replace-me:latest
Folderapps/fabi/manifest.json

Icon & assets

BrandBrand-SquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 💕Emoji #6B7280 one brand SVG → tools/app-assetsappinfo/ · serving copy in .

Configuration

Service

ImageTODO/replace-me:latest
Health checkhttp /healthz every 30s · timeout 5s · 3 retries

Dependencies

Requiresnextcloud >=30

Single sign-on (OIDC)

As clientno
As providerno
Fallbacknone

Skin & branding

SloganFabi's projects, one board.
Themeprimary #6B7280  ·  mode system
Logo./icon.svg

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.

Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idfabi
domainfabi
vendorfabi
nameFabi AI
descriptionFabi's app
version0.1.0
licenseservice, wilhelm
serviceApache-2.0
wilhelmApache-2.0
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typeembedded
categorytools
emoji💕
pixelIcon
............
.KKKKKKKKKK.
.KWWWWWWWWK.
.KWKKWWKKWK.
.KKWWKKWWKK.
.KKWWWWWWKK.
.KWKWWWWKWK.
.KWWKWWKWWK.
.KWWWKKWWWK.
.KKKKKKKKKK.
............
primaryColor#6B7280
tags[ ]
compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
webpublicDir
publicDir.
componentsservice, vscode
serviceimage, port, healthCheck
imageTODO/replace-me:latest
port0
healthChecktype, path, interval, timeout, retries
typehttp
path/healthz
interval30s
timeout5s
retries3
vscodeextensions, extension
extensions[ ]
extensionnull
dependenciesrequires, optional, provides
requires1 item
0id, version
idnextcloud
version>=30
optional[ ]
provides[ ]
oidcCapabilityasClient, asProvider, fallback
asClientfalse
asProviderfalse
fallbacknone
secretsRefs[ ]
skinslogan, logo, theme
sloganFabi's projects, one board.
themeprimary, mode
primary#6B7280
modesystem
marketplacevisibility, screenshots, pricing, supportUrl
visibilityprivate
screenshots[ ]
pricingfree
supportUrl

From the README

Add workflows/ for n8n exports, schemas/ for NocoDB tables, service/ for a Docker service, or nextcloud/ for a native NC app - see the canonical apps/_template/ and the root README - Building an App.

Read on: apps/fabi/README.md

apps/fabi/

doc/sources.md

WilheLLM

AI chat with character.

Hosted appToolsApache-2.0v0.1.0freeprivate

Wilhelm

What it does

WilheLLM is the consumer-style AI assistant you host yourself - built to match the claude.ai and Claude Desktop experience: streaming answers with a stop button, rich rendering, an animated avatar with voice and face, characters with personality. It runs an agent engine in the container with your own key and can be pointed at any Anthropic-compatible endpoint, including a fully local Ollama route.

Two things no hosted client offers: GlyphUp, a text annotation markup that is a strict superset of Markdown and travels as plain text through any chat API, and HTML67 rich messages rendered and sanitised in the chat. A feature matrix tracks the gaps against claude.ai honestly - no model picker, no history sidebar, no file upload yet.

Features

Streaming chat

Interrupt and stop; light and dark themes synced to the Wilhelm tokens.

GlyphUp

Marked, uncertain, emphasised and emotional text as plain UTF-8; renderer, patch applier, tests.

HTML67 messages

Cards, charts, tables and maps in answers, sanitised.

Voice, face, prosody

A 3D dot avatar and synthesised speech.

Characters

Personas such as the Clause family with their own greeting and voice.

World knowledge

Built-in Wilhelm context in the system prompt, switchable.

Fun media

GIFs and memes on request, switchable off.

Web and desktop

Twin builds kept in parity by a sync tool.

Why it is in the stack

  • AI chat with character - a Claude-style surface you host, with your own key and endpoint.
  • Conversations and context stay in your stack; no per-seat SaaS subscription.
  • Expressive output (GlyphUp, HTML67) no hosted client has.

Screenshots

Chat with a character
Chat with a character

The Clause character family - Santa greets with the persona's own introduction; the sidebar keeps the conversation history, the composer at the bottom takes text and attachments. The whole interface is rendered with the Wilhelm UI tokens.

desktop.png
Mobile layout
Mobile layout

The same chat on a phone-sized viewport.

mobile.png

At a glance

Based onWilhellm
Type · categoryHosted app · Tools
Licenceservice Apache-2.0  ·  wilhelm Apache-2.0
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech
Docker imagewilhelm/wilhe-llm:latest · port 3058
Folderapps/wilhe-llm/manifest.json

Icon & assets

BrandBrand-SquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 💘Emoji #6B7280 one brand SVG → tools/app-assetsappinfo/ · serving copy in ./service/app/public

Configuration

Service

Imagewilhelm/wilhe-llm:latest
Port3058
Compose fragment./service/compose.fragment.yml
Health checkhttp /healthz every 30s · timeout 5s · 3 retries

Dependencies

Requiresnothing

Single sign-on (OIDC)

As clientno
As providerno
Fallbacknone

Skin & branding

SloganAI chat with character.
Themeprimary #6B7280  ·  mode system
Logo./icon.svg

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.

Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idwilhe-llm
domainwilhe-llm
vendorwilhellm
nameWilheLLM
descriptionWilhelm
version0.1.0
licenseservice, wilhelm
serviceApache-2.0
wilhelmApache-2.0
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typehosted
categorytools
emoji💘
pixelIcon
............
..KKKKKKKK..
.KWWWWWWWWK.
.KWWWWWWWWK.
.KWKWKWKWWK.
.KWWWWWWWWK.
..KKKKKKKK..
..KKK.......
..KK........
............
............
............
primaryColor#6B7280
tags[ ]
compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
webpublicDir
previewdir, desktop, mobile, capture
captureurl, wait
wait1000
componentsservice, vscode
serviceimage, port, compose, healthCheck
imagewilhelm/wilhe-llm:latest
port3058
healthChecktype, path, interval, timeout, retries
typehttp
path/healthz
interval30s
timeout5s
retries3
vscodeextensions, extension
extensions[ ]
extensionnull
dependenciesrequires, optional, provides
requires[ ]
optional[ ]
provides[ ]
oidcCapabilityasClient, asProvider, fallback
asClientfalse
asProviderfalse
fallbacknone
secretsRefs[ ]
skinslogan, logo, theme
sloganAI chat with character.
themeprimary, mode
primary#6B7280
modesystem
marketplacevisibility, screenshots, pricing, supportUrl
visibilityprivate
pricingfree
supportUrlwilhelm.tech

Standalone compose

Every service app can run on its own: cd apps/wilhe-llm && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.

docker-compose.yml
# WilheLLM - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/wilhe-llm/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
#   cp .env.example .env && docker compose up -d
#   → http://localhost:${WILHE_LLM_PORT:-3058}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
  wilhe-llm:
    image: wilhelm/wilhe-llm:latest
    restart: unless-stopped
    env_file:
      - .env
    ports:
      - "${WILHE_LLM_PORT:-3058}:3058"
    healthcheck:
      test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:3058/healthz"]
      interval: 30s
      timeout: 5s
      retries: 3
      start_period: 20s
    networks:
      - wilhe-llm
    # TODO: persistent volume(s) if this image stores state. e.g.:
    #   volumes: [ "wilhe-llm_data:/data" ]

networks:
  wilhe-llm:
    name: wilhe-llm
.env.example
# ── WilheLLM (consumer Claude alternative, profile: wilhe-llm) ────────────────
# Host port the web UI is published on (container listens on 3058).
WILHELLM_HOST_PORT=5690
# Agent engine: open-claude-code (default, baked into the image, bring-your-own-key)
# or claude (needs a logged-in CLI - not usable headless in the container).
WILHELLM_ENGINE=open-claude-code
# Consumer key for the open-claude-code engine. Required for it to answer.
ANTHROPIC_API_KEY=
# Optional: custom Anthropic-compatible endpoint / model. The image patches occ
# to honour ANTHROPIC_BASE_URL (stock occ ignores it), so this points the occ
# engine at a custom endpoint or the Ollama bridge - same as the claude engine.
# ANTHROPIC_BASE_URL=
# ANTHROPIC_MODEL=claude-sonnet-4-6
# Fun media: die KI darf zwischendurch ein GIF (GIPHY) oder Reddit-Meme schicken.
# Memes brauchen keinen Key; für GIFs einen eigenen GIPHY-Key setzen (sonst Fallback
# auf Reddit-Reaction-GIFs). Komplett abschalten mit WILHELLM_FUNMEDIA=0.
# WILHELLM_FUNMEDIA=1
# GIPHY_API_KEY=

From the README

Add workflows/ for n8n exports, schemas/ for NocoDB tables, service/ for a Docker service, or nextcloud/ for a native NC app - see the canonical apps/_template/ and the root README - Building an App.

Read on: apps/wilhe-llm/README.md

Support  ·  apps/wilhe-llm/

doc/sources.md

wMovie

Cut video in the browser.

Hosted appToolsMITv0.1.0freeprivate

iMovie/CapCut alternative based on OpenCut: a browser-based, privacy-friendly video editor (timeline, multi-track, export) - self-hosted in the Wilhelm stack.

What it does

wMovie is a browser-based, privacy-friendly video editor - timeline, multi-track, export - hosted in the Wilhelm stack as an iMovie and CapCut alternative. Wilhelm does not rebuild the editor: it hosts OpenCut (the stable classic branch), skins it and routes it through the gateway like any other app.

Projects persist in PostgreSQL with their own accounts; a small shim translates OpenCut's hosted Redis client to the stack's Redis. Nextcloud files and SSO integration are noted as future work.

Features

Timeline editing

Multi-track cutting, trimming, arranging.

Browser-only

Footage is processed in the browser, not uploaded to a vendor.

Export

Render the finished video.

Projects and accounts

Persisted in PostgreSQL.

Four containers

Web, database, Redis and the REST shim, merged via a compose fragment.

Why it is in the stack

  • Cut video in the browser - without CapCut's cloud upload or Apple hardware lock-in.
  • MIT upstream, no subscription; footage and projects stay on your machine.

Screenshots

No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs wmovie.

At a glance

Based onWilhelm-native - no upstream project
Type · categoryHosted app · Tools
Licenceservice MIT  ·  wilhelm Apache-2.0
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Homepagewilhelm.tech/wmovie
Supportwilhelm.tech/support
Docker imagewilhelm/wmovie:latest · port 3101
Resourcesmemory 1Gi  ·  cpu 1.0  ·  storage 5Gi
Tagsvideoeditoropencutmediatimelinecapcutimovie
Folderapps/wmovie/manifest.json

Icon & assets

BrandBrand-SquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 🎬Emoji #EAB308 one brand SVG → tools/app-assetsappinfo/

Configuration

Service

Imagewilhelm/wmovie:latest
Port3101
Compose fragment./service/compose.fragment.yml
Health checkhttp / every 30s · timeout 5s · 3 retries

Resources & permissions

Memory · CPU · storage1Gi · 1.0 · 5Gi
Host networkno
Privilegedno
Egress domainsfreesound.org

Dependencies

Requiresnothing
Optionalnextcloud >=30
Providesui-component

Single sign-on (OIDC)

As clientno
As providerno
Fallbacknone

Skin & branding

SloganCut video in the browser.
Themeprimary #EAB308  ·  mode system
Logo./appinfo/icon.svg

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.

Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idwmovie
domainwmovie
vendorwilhelm
namewMovie
descriptioniMovie/CapCut alternative based on OpenCut: a browser-based, privacy-friendly video editor (timeline, multi-track, export) - self-hosted in the Wilhelm stack.
version0.1.0
licenseservice, wilhelm
serviceMIT
wilhelmApache-2.0
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typehosted
categorytools
emoji🎬
pixelIcon
............
.KKKKKKKKKK.
.KKKWKKWKKK.
.KKKKKKKKKK.
.KKWWWWWWKK.
.KKWWWWWWKK.
.KKWWWWWWKK.
.KKKKKKKKKK.
.KWWWWWWWWK.
.KKKKKKKKKK.
............
primaryColor#EAB308
tagsvideoeditoropencutmediatimelinecapcutimovie
compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
componentsservice, vscode
serviceimage, build, port, compose, healthCheck
imagewilhelm/wmovie:latest
port3101
healthChecktype, path, interval, timeout, retries
typehttp
path/
interval30s
timeout5s
retries3
vscodeextensions, extension
extensions[ ]
extensionnull
resourcesmemory, cpu, storage
memory1Gi
cpu1.0
storage5Gi
permissionsneedsHostNetwork, needsPrivileged, egressDomains
needsHostNetworkfalse
needsPrivilegedfalse
egressDomainsfreesound.org
dependenciesrequires, optional, provides
requires[ ]
optional1 item
0id, version
idnextcloud
version>=30
providesui-component
oidcCapabilityasClient, asProvider, fallback
asClientfalse
asProviderfalse
fallbacknone
secretsRefs[ ]
skinslogan, logo, theme
sloganCut video in the browser.
themeprimary, mode
primary#EAB308
modesystem
marketplacevisibility, screenshots, pricing, supportUrl
visibilityprivate
screenshots[ ]
pricingfree

Standalone compose

Every service app can run on its own: cd apps/wmovie && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.

docker-compose.yml
# wMovie - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/wmovie/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
#   cp .env.example .env && docker compose up -d
#   → http://localhost:${WMOVIE_PORT:-3101}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
  wmovie:
    image: wilhelm/wmovie:latest
    restart: unless-stopped
    env_file:
      - .env
    ports:
      - "${WMOVIE_PORT:-3101}:3101"
    healthcheck:
      test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:3101/"]
      interval: 30s
      timeout: 5s
      retries: 3
      start_period: 20s
    networks:
      - wmovie
    # TODO: persistent volume(s) if this image stores state. e.g.:
    #   volumes: [ "wmovie_data:/data" ]

networks:
  wmovie:
    name: wmovie
.env.example
# wMovie - standalone env. Copy to .env and fill in.
# GENERATED by scripts/generate-standalone.mjs

# Host port the app is published on.
WMOVIE_PORT=3101

# No declared secrets. Add image-specific env vars here as needed.

README

The README is not in English - see apps/wmovie/README.md.

Homepage  ·  Support  ·  apps/wmovie/

doc/ai-notes.md  ·  doc/proposal.md  ·  doc/sources.md

Wilhelm Techstack / Website / Website Builder

Website Builder

Build websites like Lego.

External serviceWebsiteMITv2.0.0free

Webwow visual website builder in Nextcloud

What it does

Website Builder is Webwow, the visual site builder embedded in Nextcloud and the delivery backend of the website app: build pages visually like Lego, and serve the content of the website folder - including Markdown rendered to HTML - through the gateway. It stands in for Wix and Webflow.

The reference notes are candid: the upstream image origin could not be verified at the time of writing, so concrete builder features are documented as unconfirmed until that is settled.

Features

Visual editing

Build pages in the browser (manifest tags: website, builder, CMS).

Delivery backend

Serves the public site from the website folder; Markdown to HTML.

Gated embed

Served behind AppAPI auth through an ExApp adapter.

n8n node package

Vendored in the stack; API not yet documented.

Why it is in the stack

  • Build websites like Lego, inside the same self-hosted session as the content.
  • The docs say what is verified and what is not.

Screenshots

Welcome screen
Welcome screen

The builder's start screen after login: 'Welcome to Webwow' and a Get started button - the shot tools/app-preview took from the running container.

desktop.png
Mobile layout
Mobile layout

The same start screen on a phone-sized viewport.

mobile.png
Seitenübersicht im Editor: alle Seiten, Ordner und Fehlerseiten
Seitenübersicht im Editor: alle Seiten, Ordner und Fehlerseiten01-pages-overview.png
Editor im Phone-Breakpoint mit Style-Panel
Editor im Phone-Breakpoint mit Style-Panel02-editor-phone-breakpoint.png
CMS: Collection Projekte mit KI-Agent-Panel (Claude, OpenAI, Gemini, Grok)
CMS: Collection Projekte mit KI-Agent-Panel (Claude, OpenAI, Gemini, Grok)03-cms-collections-agent.png
Webflow-Importer: ZIP + CMS-CSV
Webflow-Importer: ZIP + CMS-CSV04-webflow-importer.png
Einstellungen: Website, SEO, Custom Code, Agent, Nutzer, Security
Einstellungen: Website, SEO, Custom Code, Agent, Nutzer, Security05-settings.png
Integrationen: MCP-URL und OAuth für KI-Assistenten
Integrationen: MCP-URL und OAuth für KI-Assistenten06-integrations-mcp.png
Sites-Dashboard unter /webwow
Sites-Dashboard unter /webwow07-sites-dashboard.png
Login mit lokaler Nutzerverwaltung
Login mit lokaler Nutzerverwaltung08-login.png
Beispielsite Lichtwerk Studio: Startseite
Beispielsite Lichtwerk Studio: Startseite09-site-home.png
Beispielsite: Leistungen
Beispielsite: Leistungen10-site-leistungen.png
Beispielsite: Preise
Beispielsite: Preise11-site-preise.png
Beispielsite: Über uns / Team
Beispielsite: Über uns / Team12-site-team.png
Beispielsite: Blog-Übersicht
Beispielsite: Blog-Übersicht13-site-blog.png
Beispielsite auf dem Phone
Beispielsite auf dem Phone14-site-blog-mobile.png

Screenshots are the upstream project's official product shots (see preview/SOURCES.md) until the stack runs with demo data and tools/app-preview shoots real Wilhelm screens. Images © their respective projects.

At a glance

Based onWebwow
Type · categoryExternal service · Website
Licenceservice MIT  ·  wrapper Proprietary  ·  wilhelm Proprietary
MaintainerWilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech
Supportwilhelm.tech/support/webwow
Docker imagewebwow/webwow:latest · port 3002
Public URLhttps://site.<your-domain>/webwow · behind AppAPI auth
Compose profilewebsite-webwow
Nextcloud app idwilhelmwebwow · Nextcloud 30-32
Tagswebsitebuildercms
Folderapps/webwow/manifest.json

Icon & assets

BrandBrandSquircleSquircleFaviconFavicon32 px32 pxTouchTouchOpenGraphOpenGraph{ }Manifest Pixel 💻Emoji #0369FF one brand SVG → tools/app-assetsappinfo/

Configuration

Service

Imagewebwow/webwow:latest
Port3002
Health checkhttp / every 30s · timeout 5s · 3 retries

Embedding in Nextcloud

Registry id · labelwebwow · Webwow Site Builder
Subdomainsite
Containerwebwow:3002
Embed-proxy port (localhost)8913
Compose profilewebsite-webwow
Nextcloud config keywebwow_editor_url
iframe path/webwow
Auth gateyes - served as ExApp behind AppAPI auth ({"id":"wilhelmwebwow","adapter":"webwow-exapp","upstream":"http://webwow:3002","prefix":"/webwow"})

Nextcloud app

App idwilhelmwebwow
Path./nextcloud
Nextcloud versions30 - 32

Dependencies

Requiresnextcloud >=30
Optionalvault

MCP (Model Context Protocol)

Transporthttp
URLhttp://host.docker.internal:3002/webwow/mcp/${WEBWOW_MCP_TOKEN}
Toolspageslayerslayoutscollectionscomponentsstylescolor-variablesfontslocalesformsassetsasset-folderspage-folderssettingspublishingbatch

Single sign-on (OIDC)

As clientyes
As providerno
Fallbackvaultwarden

Skin & branding

SloganBuild websites like Lego.
Themeprimary #0369FF  ·  mode system
Logo./nextcloud/appinfo/icon.svg

Secrets

Declared in secretsRefs but apps/webwow/secrets.spec.yaml does not exist in the repository.

Compliance

StandardStatusScopeNote
GDPR
Privacy
conformantsoftwareFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
ISO/IEC 27001
Information security
in progresssoftwareWilhelm certification programme - implementation for all Wilhelm apps in progress.
WCAG
Accessibility
in progresssoftwareWilhelm certification programme - implementation for all Wilhelm apps in progress.
ISO 9241
Usability / ergonomics
in progresssoftwareWilhelm certification programme - implementation for all Wilhelm apps in progress.
EAA / BFSG
Accessibility
in progresssoftwareWilhelm certification programme - implementation for all Wilhelm apps in progress.

Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.

Manifest

The complete manifest.json (schema v2), German strings rendered in English.

idwebwow
domainwebwow
vendorwebwow
nameWebsite Builder
descriptionWebwow visual website builder in Nextcloud
version2.0.0
licenseservice, wrapper, wilhelm
serviceMIT
wrapperProprietary
wilhelmProprietary
maintainername, email, url
nameWilhelm Verlag
emailkernel@wilhelm.tech
typeexternal
categorywebsite
emoji💻
pixelIcon
............
.KKKKKKKKKK.
.KWKKKKKKWK.
.KWKKKKKKWK.
.KWKWWWWKWK.
.KWKWKWWKWK.
.KWKWKKWKWK.
.KWKKKKKKWK.
.KWWWWWWWWK.
.KKKKKKKKKK.
............
primaryColor#0369FF
tagswebsitebuildercms
compliancecertifications, note
certifications5 items
0id, status, scope, note
idgdpr
statusconformant
scopesoftware
noteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.
1id, status, scope, note
idiso-27001
statusin-progress
scopesoftware
noteWilhelm certification programme - implementation for all Wilhelm apps in progress.
2id, status, scope, note
idwcag
statusin-progress
scopesoftware
noteWilhelm certification programme - implementation for all Wilhelm apps in progress.
3id, status, scope, note
idiso-9241
statusin-progress
scopesoftware
noteWilhelm certification programme - implementation for all Wilhelm apps in progress.
4id, status, scope, note
ideaa
statusin-progress
scopesoftware
noteWilhelm certification programme - implementation for all Wilhelm apps in progress.
noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
previewdir, desktop, mobile, gallery, capture
gallery14 items
0src, caption, kind
captionSeitenübersicht im Editor: alle Seiten, Ordner und Fehlerseiten
kinddesktop
1src, caption, kind
captionEditor im Phone-Breakpoint mit Style-Panel
kinddesktop
2src, caption, kind
captionCMS: Collection Projekte mit KI-Agent-Panel (Claude, OpenAI, Gemini, Grok)
kinddesktop
3src, caption, kind
captionWebflow-Importer: ZIP + CMS-CSV
kinddesktop
4src, caption, kind
captionEinstellungen: Website, SEO, Custom Code, Agent, Nutzer, Security
kinddesktop
5src, caption, kind
captionIntegrationen: MCP-URL und OAuth für KI-Assistenten
kinddesktop
6src, caption, kind
captionSites-Dashboard unter /webwow
kinddesktop
7src, caption, kind
captionLogin mit lokaler Nutzerverwaltung
kinddesktop
8src, caption, kind
captionBeispielsite Lichtwerk Studio: Startseite
kinddesktop
9src, caption, kind
captionBeispielsite: Leistungen
kinddesktop
10src, caption, kind
captionBeispielsite: Preise
kinddesktop
11src, caption, kind
captionBeispielsite: Über uns / Team
kinddesktop
12src, caption, kind
captionBeispielsite: Blog-Übersicht
kinddesktop
13src, caption, kind
captionBeispielsite auf dem Phone
kindmobile
captureurl, mobileUrl, wait
mobileUrlwebwow:3002
wait8000
componentsservice, nextcloudApp, embed, vscode
serviceimage, port, healthCheck
imagewebwow/webwow:latest
port3002
healthChecktype, path, interval, timeout, retries
typehttp
path/
interval30s
timeout5s
retries3
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmwebwow
minNcVersion30
maxNcVersion32
embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile, iframePath, gate, exapp
idwebwow
labelWebwow Site Builder
ncConfigKeywebwow_editor_url
subdomainsite
containerwebwow
containerPort3002
embedProxyPort8913
profilewebsite-webwow
iframePath/webwow
gatetrue
exappid, adapter, upstream, prefix
idwilhelmwebwow
adapterwebwow-exapp
upstreamwebwow:3002
prefix/webwow
vscodeextensions, extension
extensions[ ]
extensionnull
mcptransport, url, tools
transporthttp
toolspageslayerslayoutscollectionscomponentsstylescolor-variablesfontslocalesformsassetsasset-folderspage-folderssettingspublishingbatch
dependenciesrequires, optional
requires1 item
0id, version
idnextcloud
version>=30
optional1 item
0id
idvault
oidcCapabilityasClient, asProvider, fallback
asClienttrue
asProviderfalse
fallbackvaultwarden
secretsRefs./secrets.spec.yaml
skinslogan, logo, theme
sloganBuild websites like Lego.
themeprimary, mode
primary#0369FF
modesystem
marketplacevisibility, screenshots, pricing, supportUrl

Standalone compose

Every service app can run on its own: cd apps/webwow && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.

docker-compose.yml
# Website Builder - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/webwow/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
#   cp .env.example .env && docker compose up -d
#   → http://localhost:${WEBWOW_PORT:-3002}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
  webwow:
    image: webwow/webwow:latest
    restart: unless-stopped
    env_file:
      - .env
    ports:
      - "${WEBWOW_PORT:-3002}:3002"
    healthcheck:
      test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:3002/"]
      interval: 30s
      timeout: 5s
      retries: 3
      start_period: 20s
    networks:
      - webwow
    # TODO: persistent volume(s) if this image stores state. e.g.:
    #   volumes: [ "webwow_data:/data" ]

networks:
  webwow:
    name: webwow
.env.example
# Website Builder - standalone env. Copy to .env and fill in.
# GENERATED by scripts/generate-standalone.mjs

# Host port the app is published on.
WEBWOW_PORT=3002

# Required secrets are specified in:
#   ./secrets.spec.yaml
# Add the matching KEY=VALUE lines here.

README

The README is not in English - see apps/webwow/README.md.

Support  ·  apps/webwow/

doc/ai-notes.md  ·  doc/api.md  ·  doc/embed-reference.md  ·  doc/n8n.md  ·  doc/sources.md