Wilhelm Techstack
Your company's software, in your own house.
57 apps, one docker compose up, no vendor lock-in. Cloud files, mail, CRM, projects, forms, signatures, shop, analytics, monitoring and AI - self-hosted open-source tools, wired together behind one login, described by one manifest standard. This page is generated from those manifests, the icons, previews and READMEs next to them: the stack as it is in the repository.
What it means for you
- Your data stays with you. Every service runs in your own containers; the compliance notes of every app say plainly what is a certificate, what is a vendor claim and what simply follows from self-hosting.
- One login, one place. Nextcloud is the kernel - single sign-on, files, calendar, contacts, dashboard. 36 apps plug into it as Nextcloud apps or embedded services; TaskHQ shows the whole stack as a desktop, Enter edits it as code.
- Subscriptions become services. The replacement table lists which proprietary product each app stands in for - Google Workspace, Salesforce, Jira, DocuSign, Figma, Zapier and friends.
- Open licences, honestly labelled. Each app carries three licences: the upstream service, the Wilhelm wrapper and the Wilhelm code. Fair-code licences (n8n, NocoDB) are marked as such.
- A standard, not glue. Every app is one folder with one
manifest.json; icons, favicons, OpenGraph cards, standalone compose files, desktop builds and this documentation are derived from it by tools, never hand-maintained. - Runs alone, too. Every service app ships a self-contained
docker-compose.ymlso it can be used outside the stack.
The stack in numbers
Apps by category
| Category | Apps |
|---|---|
| Wilhelm core | 16 |
| Adapters | 1 |
| AI | 1 |
| Analytics | 1 |
| Automation | 2 |
| CAD | 1 |
| Commerce | 1 |
| Core | 1 |
| CRM | 2 |
| Dashboards | 1 |
| Database | 1 |
| Design | 1 |
| Documents | 1 |
| Finance | 1 |
| Forms | 1 |
| Infrastructure | 2 |
| 1 | |
| Medical | 1 |
| Monitoring | 2 |
| Photos | 1 |
| Projects | 1 |
| Scheduling | 1 |
| Security | 2 |
| Services | 4 |
| Storage | 1 |
| Tools | 8 |
| Website | 1 |
as a table
| Category | Apps |
|---|---|
| Wilhelm core | 16 |
| Adapters | 1 |
| AI | 1 |
| Analytics | 1 |
| Automation | 2 |
| CAD | 1 |
| Commerce | 1 |
| Core | 1 |
| CRM | 2 |
| Dashboards | 1 |
| Database | 1 |
| Design | 1 |
| Documents | 1 |
| Finance | 1 |
| Forms | 1 |
| Infrastructure | 2 |
| 1 | |
| Medical | 1 |
| Monitoring | 2 |
| Photos | 1 |
| Projects | 1 |
| Scheduling | 1 |
| Security | 2 |
| Services | 4 |
| Storage | 1 |
| Tools | 8 |
| Website | 1 |
Service licences
| Licence | Apps |
|---|---|
| MIT | 10 |
| AGPL-3.0 | 12 |
| Apache-2.0 | 13 |
| Proprietary | 18 |
| MPL-2.0 | 1 |
| GPL-3.0 | 1 |
| Fair-Code-SUL | 2 |
as a table
| Licence | Apps |
|---|---|
| MIT | 10 |
| AGPL-3.0 | 12 |
| Apache-2.0 | 13 |
| Proprietary | 18 |
| MPL-2.0 | 1 |
| GPL-3.0 | 1 |
| Fair-Code-SUL | 2 |
How to read this page
The sidebar lists every app by category. Each app page has the same shape: at a glance (what it is based on, what it replaces, licence, image, public URL), preview (screenshots and contributed widgets), icon & assets (the derived asset set), configuration (service, embedding, Nextcloud app, Enter, desktop, TaskHQ, resources, dependencies, MCP, SSO, skin, secrets), compliance, the full manifest as a tree, the standalone compose file and the README.
Generated 2026-09-14 by node tools/stack-docs/index.mjs --standalone. Layout and elements: HTML67. Folders in apps/ without a manifest are not documented here: kernel, keycloak, loki, nextcloud, nginx, odoo, penpot, promtail, twenty, uptime-kuma, wilhelm-mcp, wormhole.
All apps
Every app that carries a manifest, with what it is based on, what it replaces and under which licence the service runs. Click a name for the full page.
| App | Based on | Category | Type | Service licence | Replaces |
|---|---|---|---|---|---|
Documents in, formats out. | Wilhelm acid | Dashboards | External service | MIT | |
Web analytics without snooping. | Plausible Analytics | Analytics | External service | AGPL-3.0 | Google Analytics, Hotjar |
| Blackwell | Tools | Embedded app | Apache-2.0 | ||
Full-stack HTML, done. | Bluedune | Tools | Embedded app | Apache-2.0 | |
Appointments that book themselves. | Cal.com | Scheduling | External service | AGPL-3.0 | Calendly, MS Bookings |
One gateway, every model. | Wilhelm-native | AI | Infrastructure | Apache-2.0 | |
Talk where the work happens. | Wilhelm-native | Wilhelm core | Nextcloud app | Proprietary | ChatGPT, Copilot |
Your server in one minute. | Wilhelm-native | Infrastructure | Infrastructure | Proprietary | |
See code instead of reading it. | Wilhelm-native | Tools | Infrastructure | Apache-2.0 | |
Customers in view, not in spreadsheets. | Twenty CRM | CRM | External service | AGPL-3.0 | Salesforce, HubSpot |
| Wilhelm-native | Security | Infrastructure | Apache-2.0 | ||
Design in the browser, as a team. | Penpot | Design | External service | MPL-2.0 | Figma, Adobe XD |
The editor that thinks along. | code-server (Coder) | Tools | External service | MIT | |
Elevators, assets, everything in view. | Evi | Tools | Embedded app | Apache-2.0 | |
Fabi's projects, one board. | Fabi | Tools | Embedded app | Apache-2.0 | |
Your portfolio, clearly. | Ghostfolio | Finance | External service | AGPL-3.0 | Yahoo Finance, Portfolio Performance |
Ask. Answer. Done. | Formbricks | Forms | External service | AGPL-3.0 | Typeform, Google Forms |
Your network - and it remembers. | Wilhelm-native | CRM | Nextcloud app | Apache-2.0 | |
All of Wilhelm, one door. | Wilhelm-native | Wilhelm core | Nextcloud app | Proprietary | |
HTML, thought further. | Wilhelm-native | Wilhelm core | Specification | Proprietary | |
Pictures from words. | Wilhelm-native | Wilhelm core | Nextcloud app | Proprietary | |
Everything talks to everything. | Wilhelm-native | Infrastructure | Infrastructure | Proprietary | |
Models local, answers instant. | Ollama | Services | External service | MIT | OpenAI API, Azure AI |
Mail under your own roof. | mailcow: dockerized | External service | GPL-3.0 | ||
Reach without friction. | Wilhelm-native | Wilhelm core | Nextcloud app | Proprietary | |
Medical knowledge, docked in. | Wilhelm-native | Medical | Infrastructure | Proprietary | |
Green means green. | Uptime Kuma | Monitoring | External service | MIT | Pingdom, UptimeRobot |
Workflows that click. | n8n | Automation | External service | Fair-Code-SUL | Zapier, Make, Power Automate |
Mail that arrives. | listmonk | Services | External service | AGPL-3.0 | Mailchimp, SendGrid |
A database without SQL anxiety. | NocoDB | Database | External service | Fair-Code-SUL | Airtable, Google Sheets |
A heads-up when it counts. | Wilhelm-native | Wilhelm core | Nextcloud app | Proprietary | Firebase FCM, Pushover |
Automation, fair and open. | Wilhelm-native | Automation | Hosted app | Apache-2.0 | |
One gateway, all text recognition. | Wilhelm-native | Wilhelm core | Infrastructure | Apache-2.0 | |
PDFs, done. | Wilhelm-native | Wilhelm core | Nextcloud app | Proprietary | Adobe Acrobat, SmallPDF |
Your pictures, your server. | Immich | Photos | External service | AGPL-3.0 | Google Photos, iCloud Photos |
Projects in flow. | Plane | Projects | External service | AGPL-3.0 | Jira, Linear, Asana |
Every metric, one place. | Prometheus | Monitoring | Infrastructure | Apache-2.0 | |
Knowledge that answers. | Wilhelm-native | Wilhelm core | Nextcloud app | Proprietary | |
Nextcloud speaks S3. | Wilhelm-native | Storage | Integration | AGPL-3.0 | |
SAP in the Wilhelm stack - clean REST instead of RFC pain. | Wilhelm-native | Adapters | Infrastructure | Apache-2.0 | |
Find instead of search. | Wilhelm-native | Wilhelm core | Nextcloud app | Proprietary | Algolia, Elasticsearch |
One place for every setting. | Wilhelm-native | Wilhelm core | Nextcloud app | Proprietary | |
Sell without a landlord. | Medusa | Commerce | External service | MIT | Shopify, WooCommerce |
Signatures, digital and binding. | Documenso | Documents | External service | AGPL-3.0 | DocuSign, Adobe Sign |
Your shop, your look. | Medusa Next.js Starter | Services | External service | MIT | |
APIs you can touch. | Swagger UI | Wilhelm core | Nextcloud app | Proprietary | Postman, ReadMe.io |
The stack in a Task Manager. | Wilhelm taskhq (@wilhelm/taskhq) | Core | External service | MIT | |
A mailbox with brains. | Wilhelm tell-imap | Services | External service | MIT | |
Tools for all the small things. | Wilhelm-native | Wilhelm core | Nextcloud app | Proprietary | |
CAD in the browser, with a pen. | Chili3d | CAD | External service | AGPL-3.0 | |
One standard, every interface. | Wilhelm-native | Wilhelm core | Nextcloud app | Proprietary | |
Passwords, safe at home. | Vaultwarden | Security | External service | AGPL-3.0 | 1Password, LastPass, Bitwarden |
Your site from one folder. | Wilhelm-native | Wilhelm core | Nextcloud app | Proprietary | WordPress, Squarespace |
Build websites like Lego. | Webwow | Website | External service | MIT | |
AI chat with character. | Wilhellm | Tools | Hosted app | Apache-2.0 | |
The stack as a toolbox. | Wilhelm-native | Wilhelm core | Nextcloud app | Proprietary | |
Cut video in the browser. | Wilhelm-native | Tools | Hosted app | MIT |
What it replaces
The ecosystem reference in apps/README.md maps every tool in the stack to the proprietary product it stands in for. Rows link to the app page where one exists; the rest is shared infrastructure (databases, gateway, office, conversion).
| Wilhelm name | Tool | Replaces | Licence | Status |
|---|---|---|---|---|
| Wilhelm Cloud | Nextcloud | Google Workspace, Microsoft 365 | AGPL-3.0 | Live |
| Wilhelm Gateway | Traefik | Cloudflare, nginx Proxy Manager | MIT | Live |
| infrastructure | MariaDB | Managed MySQL | GPL-2.0 | Live |
| infrastructure | PostgreSQL | Managed PostgreSQL | PostgreSQL License | Live |
| infrastructure | Redis | Managed Redis | BSD-3-Clause | Live |
| Wilhelm Automate | n8nn8n | Zapier, Make, Power Automate | Sustainable Use | Live |
| Wilhelm API | Wilhelm API | Custom backend | MIT | Live |
| Wilhelm Docs | Swagger UIswagger | Postman, ReadMe.io | Apache-2.0 | Live |
| Wilhelm Data | NocoDBnocodb | Airtable, Google Sheets | Sustainable Use | Live |
| Wilhelm Graph | Neo4j | AWS Neptune | AGPL-3.0 | Live |
| Wilhelm Search | Meilisearchsearch | Algolia, Elasticsearch | MIT | Planned |
| Wilhelm Brain | Ollamallm | OpenAI API, Azure AI | MIT | Live |
| Wilhelm AI | Open WebUIchat | ChatGPT, Copilot | MIT | Live |
| Wilhelm OCR | Tesseract | Adobe OCR, AWS Textract | Apache-2.0 | Live |
| Wilhelm Vision | NC Recognize | Google Photos AI | AGPL-3.0 | Live |
| Wilhelm Office | Collabora | Google Docs, Office Online | MPL-2.0 | Live |
| Wilhelm Convert | Gotenberg | CloudConvert, Zamzar | MIT | Live |
| Wilhelm PDF | Stirling-PDFpdf | Adobe Acrobat, SmallPDF | MIT | Live |
| Wilhelm Sign | Documensosign | DocuSign, Adobe Sign | AGPL-3.0 | Planned |
| Wilhelm Board | Excalidraw | Miro, FigJam | MIT | Live |
| Wilhelm Shop | Medusashop | Shopify, WooCommerce | MIT | Live |
| Wilhelm CRM | Twentycrm | Salesforce, HubSpot | AGPL-3.0 | Planned |
| Wilhelm Booking | Cal.combooking | Calendly, MS Bookings | AGPL-3.0 | Planned |
| Wilhelm Finance | Ghostfoliofinance | Yahoo Finance, Portfolio Performance | AGPL-3.0 | Planned |
| Wilhelm Mail | Listmonknewsletter | Mailchimp, SendGrid | AGPL-3.0 | Planned |
| Wilhelm Notify | Ntfynotify | Firebase FCM, Pushover | Apache-2.0 / GPL-2.0 | Planned |
| Wilhelm Forms | Formbricksforms | Typeform, Google Forms | AGPL-3.0 | Planned |
| Wilhelm Status | Uptime Kumamonitoring | Pingdom, UptimeRobot | MIT | Live |
| Wilhelm Monitor | Grafana | Datadog, New Relic | AGPL-3.0 | Live |
| Wilhelm Logs | Loki + Promtail | Splunk, Datadog Logs | AGPL-3.0 | Live |
| Wilhelm Analytics | Plausibleanalytics | Google Analytics, Hotjar | AGPL-3.0 | Planned |
| Wilhelm Vault | Vaultwardenvault | 1Password, LastPass, Bitwarden | AGPL-3.0 | Planned |
| Wilhelm Design | Penpotdesign | Figma, Adobe XD | MPL-2.0 | Planned |
| Wilhelm Photos | Immichphotos | Google Photos, iCloud Photos | AGPL-3.0 | Planned |
| Wilhelm Projects | Planeprojects | Jira, Linear, Asana | AGPL-3.0 | Planned |
| Wilhelm Web | Wilhelm Websitewebsite | WordPress, Squarespace | MIT | Live |
Architecture
Nextcloud is the kernel every other app plugs into; n8n orchestrates; NocoDB, Neo4j and Meilisearch hold and index the data; Traefik terminates HTTPS in front of everything.
══════════════════════════════════════════════════════════════════════
WILHELM CLOUD (Nextcloud)
The Kernel - SSO, Files, Calendar,
Contacts, Mail, Dashboard
══════════════════════════════════════════════════════════════════════
│ │ │ │ │
▼ ▼ ▼ ▼ ▼
┌──────────┐ ┌────────┐ ┌──────┐ ┌───────┐ ┌────────┐
│ Office │ │ Board │ │Vision│ │ Vault │ │Booking │
│Collabora │ │Excali- │ │Recog.│ │Vault- │ │Cal.com │
│ │ │draw │ │ │ │warden │ │ │
└──────────┘ └────────┘ └──┬───┘ └───────┘ └───┬────┘
│ │
│ CalDAV Sync ◄─────┘
▼
══════════════════════════════════════════════════════════════════════
WILHELM AUTOMATE (n8n) - Orchestrates everything
══════════════════════════════════════════════════════════════════════
│ │ │ │ │ │ │ │
▼ ▼ ▼ ▼ ▼ ▼ ▼ ▼
┌──────┐┌──────┐┌──────┐┌──────┐┌──────┐┌──────┐┌──────┐┌──────┐
│ Shop ││ CRM ││ Mail ││Forms ││ Sign ││Notify││Finan.││Proj. │
│Medusa││Twenty││List- ││Form- ││Docu- ││Ntfy ││Ghost-││Plane │
│ ││ ││monk ││bricks││menso ││ ││folio ││ │
└──┬───┘└──┬───┘└──┬───┘└──┬───┘└──┬───┘└──┬───┘└──────┘└──────┘
│ │ │ │ │ │
▼ ▼ ▼ ▼ ▼ ▼
══════════════════════════════════════════════════════════════════════
WILHELM DATA (NocoDB) - Central data layer
══════════════════════════════════════════════════════════════════════
│ │
▼ ▼
┌────────────┐ ┌──────────┐
│ Graph │ │ Search │
│ Neo4j │ │ Meili- │
│(Relations) │ │ search │
└────────────┘ └─────┬────┘
│
┌─────────────┼─────────────┐
▼ ▼ ▼
┌──────────┐ ┌──────────┐ ┌──────────┐
│ Brain │ │ OCR │ │ Convert │
│ Ollama │ │Tesseract │ │Gotenberg │
│(Embedd.) │ │(Img→Txt) │ │(Doc→PDF) │
└────┬─────┘ └──────────┘ └──────────┘
│
▼
┌──────────┐
│ AI │
│Open WebUI│
└──────────┘
══════════════════════════════════════════════════════════════════════
Monitoring & Analytics
══════════════════════════════════════════════════════════════════════
┌──────────┐ ┌──────────┐ ┌──────────┐ ┌──────────┐ ┌──────────┐
│ Status │ │ Monitor │ │ Logs │ │Analytics │ │ PDF │
│ Uptime │ │ Grafana │ │ Loki + │ │Plausible │ │Stirling │
│ Kuma │ │ │ │ Promtail │ │ │ │ PDF │
└──────────┘ └──────────┘ └──────────┘ └──────────┘ └──────────┘
══════════════════════════════════════════════════════════════════════
Creative & Media
══════════════════════════════════════════════════════════════════════
┌──────────┐ ┌──────────┐ ┌──────────┐
│ Design │ │ Photos │ │ Web │
│ Penpot │ │ Immich │ │ Wilhelm │
│ │ │ │ │ Website │
└──────────┘ └──────────┘ └──────────┘
══════════════════════════════════════════════════════════════════════
WILHELM GATEWAY (Traefik) - HTTPS, Routing, Certificates
══════════════════════════════════════════════════════════════════════Compliance
What each app can prove, and for whom. Hover a cell for scope and note. A certificate held by the vendor's cloud offering does not carry over to a self-hosted instance - the per-app notes say so where it matters.
certified formal certificate attested audit report compliant demonstrably compliant (DPA, feature set) conformant conforms to the standard vendor claim vendor statement only in progress announced planned announced
| App | 21 CFR Part 11 | CCPA | DPA | EAA / BFSG | eIDAS (SES) | ESIGN / UETA | GDPR | HIPAA | ISO 9241 | ISO/IEC 27001 | SOC 2 Type II | WCAG |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ACID | conformant | |||||||||||
| Analytics | vendor claim | compliant | compliant | |||||||||
| Bluedune | conformant | |||||||||||
| Booking | vendor claim | compliant | vendor claim | attested | ||||||||
| Wilhelm Intelligence | conformant | |||||||||||
| chat | conformant | |||||||||||
| Wilhelm Cloud | conformant | |||||||||||
| Codeflow | conformant | |||||||||||
| CRM | compliant | conformant | in progress | |||||||||
| Data Broker | conformant | |||||||||||
| Design | compliant | conformant | ||||||||||
| Enter | in progress | conformant | in progress | in progress | attested | in progress | ||||||
| evi | conformant | |||||||||||
| Fabi AI | conformant | |||||||||||
| Finance | vendor claim | |||||||||||
| Forms | compliant | vendor claim | vendor claim | vendor claim | ||||||||
| garyn.ai | in progress | conformant | in progress | in progress | in progress | |||||||
| home | conformant | |||||||||||
| HTML67 | conformant | |||||||||||
| imagegen | conformant | |||||||||||
| Integrations | conformant | |||||||||||
| llm | vendor claim | |||||||||||
| compliant | compliant | |||||||||||
| MarketingMachine | conformant | |||||||||||
| Medical | conformant | |||||||||||
| Uptime Kuma | conformant | |||||||||||
| n8n Workflows | compliant | attested | ||||||||||
| newsletter | conformant | |||||||||||
| NocoDB | conformant | |||||||||||
| notify | conformant | |||||||||||
| o14n - open n8n | conformant | |||||||||||
| OCR Gateway | conformant | |||||||||||
| conformant | ||||||||||||
| Photos | conformant | |||||||||||
| Projects | compliant | vendor claim | certified | attested | ||||||||
| Prometheus | conformant | |||||||||||
| rag | in progress | conformant | in progress | in progress | in progress | |||||||
| Wilhelm S3 | conformant | |||||||||||
| SAP Adapter | conformant | |||||||||||
| search | conformant | |||||||||||
| settings | conformant | |||||||||||
| Amazing Shop | compliant | conformant | ||||||||||
| Sign | vendor claim | compliant | compliant | vendor claim | vendor claim | |||||||
| storefront | conformant | |||||||||||
| swagger | conformant | |||||||||||
| TaskHQ | in progress | conformant | in progress | in progress | in progress | |||||||
| tell | conformant | |||||||||||
| tools | conformant | |||||||||||
| Tusch3D | in progress | conformant | in progress | in progress | in progress | |||||||
| Wilhelm UI | conformant | |||||||||||
| Vault | conformant | |||||||||||
| website | conformant | |||||||||||
| Website Builder | in progress | conformant | in progress | in progress | in progress | |||||||
| WilheLLM | conformant | |||||||||||
| Wilhelm MCP Server | conformant | |||||||||||
| wMovie | conformant |
The manifest standard
Every app is one folder under apps/ with one manifest.json validated against schema/app-manifest-v2.json. Tools derive the rest: tools/app-assets the icons, tools/app-preview the screenshots, scripts/generate-standalone.mjs the compose files, scripts/generate-desktop-app.mjs the desktop builds, tools/stack-docs this page.
id · domain · vendor | Folder name, the self-explanatory domain term (booking, photos) and the upstream project name (calcom, immich). |
name · description · version · tags · homepage | What the store, the launcher and this page show. |
license | Three licences: service (the upstream), wrapper (the Wilhelm integration), wilhelm (Wilhelm-authored code). |
type · category | nc-app, external, infrastructure, hosted, embedded, spec … and the category the sidebar groups by. |
icon · emoji · pixelIcon · primaryColor | One brand SVG is the source of every derived asset; the emoji and pixel icon serve the text and retro surfaces (TaskHQ start menu). |
compliance | Certifications with status (certified, attested, compliant, claimed, in progress) and scope (vendor, cloud, software, operator), plus an honest one-line assessment. |
web · preview | Public page (serving copy of the asset set, OpenGraph card) and the preview media slots the App Store and website read. |
components | service (image, port, health check), nextcloudApp, embed (subdomain, container, profile, auth gate), widgets (contributed HTML67 elements), vscode (presence inside Enter). |
desktop · taskhq | Electron desktop build and the TaskHQ desktop window. |
resources · permissions | Memory, CPU, storage; host network, privileged mode, egress domains. |
dependencies · mcp · oidcCapability · secretsRefs | What the app needs and provides, the MCP server it contributes, its SSO role, and where its required secrets are declared. |
marketplace · skin | Visibility, pricing, support URL; slogan, logo, theme and agent persona. |
signature | Optional signature over the canonicalised manifest. |
Folder layout
apps/<id>/ manifest.json the one source of truth icon.svg brand mark (manifest.icon) appinfo/ derived: appicon.svg, favicon.svg, favicon-32.png, apple-touch-icon.png, og-image.png, site.webmanifest preview/ desktop.png, mobile.png, gallery/, widgets/, SOURCES.md README.md standalone header block (generated) + editable body doc/ sources.md, reference notes, upstream docs docker-compose.yml self-contained compose (generated) secrets.spec.yaml required secrets - names and purpose, never values nextcloud/ service/ the Nextcloud app and the service code
New app: node scripts/new-app.mjs <id>. Validate: node scripts/validate-app-manifests.mjs. Rebuild this page: npm run docs:stack.
chat
Talk where the work happens.
Wilhelm chat app
What it does
Chat is Open WebUI, the self-hosted chat interface that gives a team what the ChatGPT web app gives an individual - conversations, model switching, prompt library, documents you can ask questions about, image generation hooks - against whichever backend you choose.
In the Wilhelm stack it is embedded in Nextcloud as a thin app and talks to the stack's own model gateway (Wilhelm Intelligence) or directly to Ollama, so the model choice stays with the operator.
Features
OpenAI-compatible and Ollama backends; switch models per conversation.
Upload documents and ask questions over them.
Accounts, roles and shared prompt library.
Reusable prompts, functions and image generation hooks.
One login - the Nextcloud session is the authentication.
Why it is in the stack
- Talk where the work happens: the chat UI inside the Nextcloud shell, next to files and mail.
- Replaces ChatGPT and Copilot subscriptions with a self-hosted interface and a model choice that is yours.
- Zero backend code of its own to maintain - a pure wrapper around a widely used upstream.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs chat.
At a glance
| Based on | Wilhelm-native - no upstream project |
| Replaces | ChatGPT, Copilot · listed as Wilhelm AI in the ecosystem reference |
| Type · category | Nextcloud app · Wilhelm core |
| Licence | service Proprietary · wrapper Proprietary · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support/chat |
| Public URL | https://ai.<your-domain> |
| Compose profile | open-webui |
| Nextcloud app id | wilhelmopenwebui · Nextcloud 30-32 |
| Folder | apps/chat/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Embedding in Nextcloud
| Registry id · label | open-webui · Open WebUI (AI Chat) |
| Subdomain | ai |
| Container | open-webui:8080 |
| Embed-proxy port (localhost) | 8895 |
| Compose profile | open-webui |
| Nextcloud config key | openwebui_url |
Nextcloud app
| App id | wilhelmopenwebui |
| Path | . |
| Nextcloud versions | 30 - 32 |
Dependencies
| Requires | nextcloud >=30 |
Skin & branding
| Slogan | Talk where the work happens. |
| Theme | primary #0369FF · mode system |
| Logo | ./appinfo/icon.svg |
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idchatdomainchatvendorwilhelmnamechatdescriptionWilhelm chat appversion2.0.0licenseservice, wrapper, wilhelm
serviceProprietarywrapperProprietarywilhelmProprietarymaintainername, email, url
typenc-appcategorywilhelm-coreemoji📦pixelIcon............ .KKKKKKKKKK. .KWWWWWWWWK. .KWKKKKKWWK. .KWKWWWKWWK. .KWKWWWKWWK. .KWKKKKKWWK. .KWWKWWWWWK. .KWWWWWWWWK. .KKKKKKKKKK. ............
primaryColor#0369FFtags[ ]compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.componentsnextcloudApp, embed, vscode
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmopenwebuipath.minNcVersion30maxNcVersion32embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile
idopen-webuilabelOpen WebUI (AI Chat)ncConfigKeyopenwebui_urlsubdomainaicontaineropen-webuicontainerPort8080embedProxyPort8895profileopen-webuivscodeextensions, extension
extensions[ ]extensionnulldependenciesrequires, optional
requires1 item
0id, version
idnextcloudversion>=30optional[ ]skinslogan, logo, theme
marketplacevisibility, pricing, supportUrl
Links & documentation files
home
All of Wilhelm, one door.
Wilhelm home app
What it does
Home is the stack's start screen: a Nextcloud app that turns the dashboard into a widget board - profile, photos, files, office, notes, calendar, quota, and the apps of the stack - configurable per user and per installation, with a 'create new document' flow that opens an office document in one click.
It is native Nextcloud: authentication and data come from the session, the front end aggregates the Activity, DAV, Deck, Calendar and Notes APIs directly, and a failing app leaves only its widget empty.
Features
Per-user visible widgets; sensible defaults.
Admin-wide overrides re-point tiles to Wilhelm apps without patching Nextcloud.
Pick a template, create the office file, land in the editor.
Activity, files, deck, calendar and notes on one screen.
Storage use and group membership at a glance.
Why it is in the stack
- All of Wilhelm, one door - one start screen that pulls the stack together.
- Pure Nextcloud-native: no extra service, no extra login.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs home.
At a glance
| Based on | Wilhelm-native - no upstream project |
| Type · category | Nextcloud app · Wilhelm core |
| Licence | service Proprietary · wrapper Proprietary · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support/home |
| Nextcloud app id | wilhelmhome · Nextcloud 30-32 |
| Folder | apps/home/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Nextcloud app
| App id | wilhelmhome |
| Path | . |
| Nextcloud versions | 30 - 32 |
Dependencies
| Requires | nextcloud >=30 |
Skin & branding
| Slogan | All of Wilhelm, one door. |
| Theme | primary #0369FF · mode system |
| Logo | ./appinfo/icon.svg |
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idhomedomainhomevendorwilhelmnamehomedescriptionWilhelm home appversion2.0.0licenseservice, wrapper, wilhelm
serviceProprietarywrapperProprietarywilhelmProprietarymaintainername, email, url
typenc-appcategorywilhelm-coreemoji📦pixelIcon............ .KKKKKKKKKK. .KWWWKKWWWK. .KWWKWWKWWK. .KWKWWWWKWK. .KWKKKKKKWK. .KWKWWWWKWK. .KWKWGGWKWK. .KWKKKKKKWK. .KKKKKKKKKK. ............
primaryColor#0369FFtags[ ]compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.componentsnextcloudApp, vscode
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmhomepath.minNcVersion30maxNcVersion32vscodeextensions, extension
extensions[ ]extensionnulldependenciesrequires, optional
requires1 item
0id, version
idnextcloudversion>=30optional[ ]skinslogan, logo, theme
marketplacevisibility, pricing, supportUrl
Links & documentation files
HTML67
HTML, thought further.
One base, two leaps. A standard the way C++/C#/TypeScript are (published spec + reference runtime, just not WHATWG-ratified), a superset of HTML5, not a fork, resolved at runtime by the @wilhelm/ui runtime. HTML6 = UI, presentation & text (components, <wl-include> native partials, GlyphUp as <wl-glyph>); HTML7 = living vocabularies (law/science, correctness layer). The umbrella over apps/ui + apps/wilhe-llm/glyphup. Spec: SPEC.md, live demo: apps/ui/index.html at localhost:4321/.
What it does
HTML67 is a published standard plus a reference runtime, not an app: a superset of HTML5 - no fork, no new browser - that adds the two layers HTML never got natively. HTML6 covers UI, presentation and text: cards, charts, maps, tabs, native partials and the GlyphUp text layer as bare tags. HTML7 covers living domain vocabularies - law, science, licences, units, citations - as a correctness layer the page carries itself.
Every HTML67 page is valid HTML5; one script upgrades the bare tags in place. The Wilhelm site, its editors and this documentation are written in it. A standard the way C++, C# or TypeScript are standards: published spec, reference implementation, just not WHATWG-ratified.
Features
Plus 32 web components and short-form aliases, generated and counted from the source.
A single script tag; pages stay valid HTML5 and work in today's browsers.
<wl-include> for partials, <wl-glyph> for the GlyphUp annotation layer.
<norm>, <cite>, <unit>, <license>, <frist> and friends resolve law, sources, units and deadlines.
The whole site bundles into one .html that runs from file://.
Spec, changelog, audit gates and a candidate list under a vocabulary freeze.
Why it is in the stack
- HTML, thought further: a superset, documented candidly, including what it is not.
- No bundler, no framework lock-in; disciplined vocabulary before any new tag ships.
- The umbrella over Wilhelm UI and WilheLLM's GlyphUp.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs html67.
At a glance
| Based on | Wilhelm-native - no upstream project |
| Type · category | Specification · Wilhelm core |
| Licence | service Proprietary · wrapper Proprietary · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Homepage | wilhelm.tech |
| Tags | html67standardspecglyphupuiwilhelm-core |
| Folder | apps/html67/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Dependencies
| Requires | ui >=2 |
| Provides | spec |
Skin & branding
| Slogan | HTML, thought further. |
| Theme | primary #0369FF · mode system |
| Logo | ./icon.svg |
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idhtml67domainhtml67vendorwilhelmnameHTML67descriptionOne base, two leaps. A standard the way C++/C#/TypeScript are (published spec + reference runtime, just not WHATWG-ratified), a superset of HTML5, not a fork, resolved at runtime by the @wilhelm/ui runtime. HTML6 = UI, presentation & text (components, <wl-include> native partials, GlyphUp as <wl-glyph>); HTML7 = living vocabularies (law/science, correctness layer). The umbrella over apps/ui + apps/wilhe-llm/glyphup. Spec: SPEC.md, live demo: apps/ui/index.html at localhost:4321/.version0.1.0licenseservice, wrapper, wilhelm
serviceProprietarywrapperProprietarywilhelmProprietarymaintainername, email, url
typespeccategorywilhelm-coreicon./icon.svgemoji📄pixelIcon............ .KKKKKKKKKK. .KWWWWWWWWK. .KWWKWWKWWK. .KWKWWWWKWK. .KKWWWWWWKK. .KWKWWWWKWK. .KWWKWWKWWK. .KWWWWWWWWK. .KKKKKKKKKK. ............
primaryColor#0369FFhomepagewilhelm.techtagshtml67standardspecglyphupuiwilhelm-corecompliancecertifications, note
certifications1 item
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.dependenciesrequires, optional, provides
requires1 item
0id, version
iduiversion>=2optional[ ]providesspecskinslogan, logo, theme
marketplacevisibility, pricing
visibilitypublicpricingfreecomponentsvscode
vscodeextensions, extension
extensions[ ]extensionnullLinks & documentation files
imagegen
Pictures from words.
Wilhelm imagegen app
What it does
ImageGen is ComfyUI, the node-graph interface for Stable Diffusion and related models, embedded in Nextcloud: text-to-image, image-to-image and whatever workflow you wire on the canvas, on your own GPU - the self-hosted counterpart to Midjourney or DALL·E.
Generation happens in the ComfyUI container; the Nextcloud app is a shell with one route. n8n drives it over the queue API with the generic HTTP node.
Features
Checkpoint loader, prompts, sampler, VAE decode - compose any pipeline visually.
Bring your own models; runs on the GPU box under its own compose profile.
Submit a prompt, poll history, fetch the result - scriptable from n8n.
Clipboard access in the iframe; the session is the login.
Why it is in the stack
- Pictures from words, on your own hardware - no per-image cloud credits.
- Full ComfyUI workflow power, not a locked-down prompt box.
- Appears as a normal app in the Nextcloud sidebar.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs imagegen.
At a glance
| Based on | Wilhelm-native - no upstream project |
| Type · category | Nextcloud app · Wilhelm core |
| Licence | service Proprietary · wrapper Proprietary · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support/imagegen |
| Public URL | https://imagegen.<your-domain> |
| Compose profile | imagegen |
| Nextcloud app id | wilhelmimagegen · Nextcloud 30-32 |
| Folder | apps/imagegen/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Embedding in Nextcloud
| Registry id · label | comfyui · ComfyUI / ImageGen |
| Subdomain | imagegen |
| Container | comfyui:8188 |
| Embed-proxy port (localhost) | 8910 |
| Compose profile | imagegen |
| Nextcloud config key | comfyui_url |
Nextcloud app
| App id | wilhelmimagegen |
| Path | . |
| Nextcloud versions | 30 - 32 |
Dependencies
| Requires | nextcloud >=30 |
Skin & branding
| Slogan | Pictures from words. |
| Theme | primary #0369FF · mode system |
| Logo | ./appinfo/icon.svg |
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idimagegendomainimagegenvendorwilhelmnameimagegendescriptionWilhelm imagegen appversion2.0.0licenseservice, wrapper, wilhelm
serviceProprietarywrapperProprietarywilhelmProprietarymaintainername, email, url
typenc-appcategorywilhelm-coreemoji📦pixelIcon............ .KKKKKKKKKK. .KWKKKKKKWK. .KWKWWGWKWK. .KWKWWWWKWK. .KWKWKWWKWK. .KWKKWKWKWK. .KWKKKKKKWK. .KWWWWWWWWK. .KKKKKKKKKK. ............
primaryColor#0369FFtags[ ]compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.componentsnextcloudApp, embed, vscode
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmimagegenpath.minNcVersion30maxNcVersion32embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile
idcomfyuilabelComfyUI / ImageGenncConfigKeycomfyui_urlsubdomainimagegencontainercomfyuicontainerPort8188embedProxyPort8910profileimagegenvscodeextensions, extension
extensions[ ]extensionnulldependenciesrequires, optional
requires1 item
0id, version
idnextcloudversion>=30optional[ ]skinslogan, logo, theme
marketplacevisibility, pricing, supportUrl
Links & documentation files
MarketingMachine
Reach without friction.
Central company operating system - D-DNA, media, outputs. Radically separates content from design: one source produces websites, flyers, business cards, social posts, legal texts and catalogues.
What it does
MarketingMachine is a central company operating system that separates content from design radically: one database - the D-DNA - holds everything that defines the company, and every output is generated from it: websites, flyers, business cards, social posts, legal texts, catalogues. A website and a flyer are the same thing; only the medium differs.
Today it is a thin UI skeleton with four sections; the logic is specified in seven specs that name the stack roles - n8n for generation, NocoDB as database, Neo4j for relations, Ollama for the AI 'advocates', Gotenberg for PDF, Tesseract for OCR.
Features
The single source of truth for brand, entities and content.
Manage what the company is; generate what it publishes.
Print and web artefacts from one source.
AI agents that draft and adapt content (spec).
API and connectors to the rest of the stack (spec).
Why it is in the stack
- Reach without friction: one source instead of copy-pasting brand content across tools.
- Outputs are generated, not hand-maintained per medium.
- Built entirely on self-hosted stack components; the specs are the roadmap, not the current state.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs marketing.
At a glance
| Based on | Wilhelm-native - no upstream project |
| Type · category | Nextcloud app · Wilhelm core |
| Licence | service Proprietary · wrapper Proprietary · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support/marketing |
| Nextcloud app id | marketingmachine · Nextcloud 30-32 |
| Folder | apps/marketing/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Nextcloud app
| App id | marketingmachine |
| Path | . |
| Nextcloud versions | 30 - 32 |
Dependencies
| Requires | nextcloud >=30 |
Skin & branding
| Slogan | Reach without friction. |
| Theme | primary #0369FF · mode system |
| Logo | ./appinfo/icon.svg |
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idmarketingdomainmarketingvendorwilhelmnameMarketingMachinedescriptionCentral company operating system - D-DNA, media, outputs. Radically separates content from design: one source produces websites, flyers, business cards, social posts, legal texts and catalogues.version2.0.0licenseservice, wrapper, wilhelm
serviceProprietarywrapperProprietarywilhelmProprietarymaintainername, email, url
typenc-appcategorywilhelm-coreemoji🧬pixelIcon............ .KKKKKKKKKK. .KWWKWWWWWK. .KWKKWGWWWK. .KKKKWWGWWK. .KKKKWWGWWK. .KWKKWGWWWK. .KWWKWWWWWK. .KWWWWWWWWK. .KKKKKKKKKK. ............
primaryColor#0369FFtags[ ]compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.componentsnextcloudApp, vscode
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidmarketingmachinepath.minNcVersion30maxNcVersion32vscodeextensions, extension
extensions[ ]extensionnulldependenciesrequires, optional
requires1 item
0id, version
idnextcloudversion>=30optional[ ]skinslogan, logo, theme
marketplacevisibility, pricing, supportUrl
README
The README is not in English - see apps/marketing/README.md.
Links & documentation files
notify
A heads-up when it counts.
Wilhelm notify app
What it does
notify is ntfy, the self-hosted push notification service: publish a message to a topic over HTTP, and every phone, desktop or browser subscribed to that topic gets it - without Firebase, Pushover or any vendor holding the content.
The Kernel API wraps it in one push endpoint that n8n workflows and apps call with the stack token; the Nextcloud app embeds the ntfy web UI for reading and subscribing.
Features
Publish and subscribe by topic name; default topic for the stack.
Android and iOS apps, desktop and web - no account needed on the receiving side.
One authenticated push call for the whole stack; title and message become an ntfy notification.
Upstream features for richer notifications.
Why it is in the stack
- A heads-up when it counts, without a third party reading your notifications.
- One uniform endpoint any workflow can call; no per-message quota.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs notify.
At a glance
| Based on | Wilhelm-native - no upstream project |
| Replaces | Firebase FCM, Pushover · listed as Wilhelm Notify in the ecosystem reference |
| Type · category | Nextcloud app · Wilhelm core |
| Licence | service Proprietary · wrapper Proprietary · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support/notify |
| Public URL | https://notify.<your-domain> |
| Compose profile | ntfy |
| Nextcloud app id | wilhelmnotify · Nextcloud 30-32 |
| Folder | apps/notify/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Embedding in Nextcloud
| Registry id · label | ntfy · ntfy Notifications |
| Subdomain | notify |
| Container | ntfy:80 |
| Embed-proxy port (localhost) | 8898 |
| Compose profile | ntfy |
| Nextcloud config key | ntfy_url |
Nextcloud app
| App id | wilhelmnotify |
| Path | . |
| Nextcloud versions | 30 - 32 |
Dependencies
| Requires | nextcloud >=30 |
Skin & branding
| Slogan | A heads-up when it counts. |
| Theme | primary #0369FF · mode system |
| Logo | ./appinfo/icon.svg |
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idnotifydomainnotifyvendorwilhelmnamenotifydescriptionWilhelm notify appversion2.0.0licenseservice, wrapper, wilhelm
serviceProprietarywrapperProprietarywilhelmProprietarymaintainername, email, url
typenc-appcategorywilhelm-coreemoji📦pixelIcon............ .KKKKKKKKKK. .KWWWKKWWWK. .KWWKKKKWWK. .KWWKKKKWWK. .KWWKKKKWWK. .KWKKKKKKWK. .KWWWKKWWWK. .KWWWWWWWWK. .KKKKKKKKKK. ............
primaryColor#0369FFtags[ ]compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.componentsnextcloudApp, embed, vscode
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmnotifypath.minNcVersion30maxNcVersion32embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile
idntfylabelntfy NotificationsncConfigKeyntfy_urlsubdomainnotifycontainerntfycontainerPort80embedProxyPort8898profilentfyvscodeextensions, extension
extensions[ ]extensionnulldependenciesrequires, optional
requires1 item
0id, version
idnextcloudversion>=30optional[ ]skinslogan, logo, theme
marketplacevisibility, pricing, supportUrl
Links & documentation files
OCR Gateway
One gateway, all text recognition.
One API gateway in front of all OCR engines (Tesseract, Stirling, PaddleOCR, Unlimited-OCR, Text-Extract) with file-type conversion and an optional Ollama post-processing pass.
What it does
OCR Gateway is one API in front of every text-recognition engine in the stack: Tesseract, Stirling PDF, PaddleOCR, Unlimited-OCR (a vision model) and plain text extraction. The caller picks an engine; the gateway detects the file type, converts Office documents through Gotenberg, renders multipage PDFs, routes to the engine, normalises the result and optionally runs an Ollama post-pass - the self-hosted counterpart to AWS Textract or Google Vision.
It is a dependency-free Node service in the style of the Kernel API; engines are plain URL adapters, so adding one never changes the API.
Features
POST a file with a name, choose an engine, get text, a searchable PDF or full JSON with blocks and confidence.
text, stirling, tesseract, paddle, unlimited - CPU-fast or GPU-vision per request.
Office and HTML inputs become PDF through Gotenberg; multipage PDFs are rendered page by page.
Optional Ollama step attached to the result.
Stack token on every call; an MCP directory for agent access.
Why it is in the stack
- One gateway, all text recognition - swap engines without touching callers.
- Documents never leave the stack; GPU engines run on the GPU box under their own profile.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs ocr.
At a glance
| Based on | Wilhelm-native - no upstream project |
| Type · category | Infrastructure · Wilhelm core |
| Licence | service Apache-2.0 · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support/ocr |
| Tags | ocrtesseractpaddleocrstirlingdocumentextraction |
| Folder | apps/ocr/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Service
| Compose fragment | ./service/compose.fragment.yml |
| Health check | http /healthz every 30s · timeout 5s · 3 retries |
Desktop build (Electron)
| Enabled | no - opted out |
Dependencies
| Requires | nothing |
| Optional | pdf >=2, llm >=1 |
MCP (Model Context Protocol)
| Server | mcp/server.js |
| Transport | stdio |
| Tools | ocr_enginesocr_extract |
| Environment | OCR_URLWILHELM_API_TOKEN |
Skin & branding
| Slogan | One gateway, all text recognition. |
| Theme | primary #0369FF · mode system |
| Logo | ./icon.svg |
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idocrdomainocrvendorwilhelmnameOCR GatewaydescriptionOne API gateway in front of all OCR engines (Tesseract, Stirling, PaddleOCR, Unlimited-OCR, Text-Extract) with file-type conversion and an optional Ollama post-processing pass.version1.0.0licenseservice, wilhelm
serviceApache-2.0wilhelmProprietarymaintainername, email, url
typeinfrastructurecategorywilhelm-coreicon./icon.svgemoji🔍pixelIcon............ .KKKKKKKKKK. .KWWWWWWWWK. .KWWKKKKWWK. .KWKWWWWKWK. .KKWWKKWWKK. .KWKWWWWKWK. .KWWKKKKWWK. .KWWWWWWWWK. .KKKKKKKKKK. ............
primaryColor#0369FFtagsocrtesseractpaddleocrstirlingdocumentextractioncompliancecertifications, note
certifications1 item
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.componentsservice, vscode
servicecompose, container, containerPort, profile, healthCheck
containerocr-gatewaycontainerPort3000profileocrhealthChecktype, path, interval, timeout, retries
typehttppath/healthzinterval30stimeout5sretries3vscodeextensions, extension
extensions[ ]extensionnulldesktopenabled
enabledfalsedependenciesrequires, optional
requires[ ]optional2 items
0id, version
idpdfversion>=21id, version
idllmversion>=1mcpserver, transport, tools, env, grants
servermcp/server.jstransportstdiotoolsocr_enginesocr_extractenvOCR_URL, WILHELM_API_TOKEN
OCR_URL${OCR_URL:-http://ocr-gateway:3000}WILHELM_API_TOKEN${WILHELM_API_TOKEN}grants[ ]skinslogan, logo, theme
marketplacevisibility, pricing, supportUrl
Standalone compose
Every service app can run on its own: cd apps/ocr && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.
docker-compose.yml
# OCR Gateway - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/ocr/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
# cp .env.example .env && docker compose up -d
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
ocr:
build:
context: ./service
restart: unless-stopped
env_file:
- .env
networks:
- ocr
# TODO: persistent volume(s) if this image stores state. e.g.:
# volumes: [ "ocr_data:/data" ]
networks:
ocr:
name: ocr
.env.example
# OCR Gateway - standalone env. Copy to .env and fill in. # GENERATED by scripts/generate-standalone.mjs # No declared secrets. Add image-specific env vars here as needed.
README
The README is not in English - see apps/ocr/README.md.
Links & documentation files
PDFs, done.
Wilhelm pdf app
What it does
pdf is Stirling PDF embedded in Nextcloud - merge, split, compress, rotate, OCR, watermark, protect, extract, convert - plus Gotenberg behind the Kernel API for creating PDFs from URLs, HTML, Markdown and Office documents: what people open Adobe Acrobat or a web PDF tool for, on your own server.
The Nextcloud app is the UI shell; the Kernel API carries the programmable part with two paths - Stirling for manipulation, Gotenberg for generation - both behind the stack token and reachable from n8n.
Features
Merge, split, compress, rotate, reorder, watermark, password-protect.
Searchable PDFs, German by default.
Text, images and metadata.
URL, HTML, Markdown and Office to PDF via Gotenberg.
Base64 in and out for every operation; n8n-ready.
Why it is in the stack
- PDFs, done - without uploading documents to a web tool.
- Manipulation and generation behind one token-authenticated API.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs pdf.
At a glance
| Based on | Wilhelm-native - no upstream project |
| Replaces | Adobe Acrobat, SmallPDF · listed as Wilhelm PDF in the ecosystem reference |
| Type · category | Nextcloud app · Wilhelm core |
| Licence | service Proprietary · wrapper Proprietary · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support/pdf |
| Public URL | https://pdf.<your-domain> · behind AppAPI auth |
| Compose profile | stirling-pdf |
| Nextcloud app id | wilhelmpdf · Nextcloud 30-32 |
| Folder | apps/pdf/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Embedding in Nextcloud
| Registry id · label | stirling-pdf · Stirling PDF |
| Subdomain | pdf |
| Container | stirling-pdf:8080 |
| Embed-proxy port (localhost) | 8894 |
| Compose profile | stirling-pdf |
| Nextcloud config key | pdf_url |
| Auth gate | yes - served as ExApp behind AppAPI auth ({"id":"wilhelmpdf","adapter":"stirling-pdf-exapp","upstream":"http://stirling-pdf:8080","prefix":""}) |
Nextcloud app
| App id | wilhelmpdf |
| Path | . |
| Nextcloud versions | 30 - 32 |
Desktop build (Electron)
| Enabled | yes |
| Start path | /index.php/apps/wilhelmpdf/ |
| Hide Nextcloud chrome | yes |
Dependencies
| Requires | nextcloud >=30 |
Skin & branding
| Slogan | PDFs, done. |
| Theme | primary #0369FF · mode system |
| Logo | ./appinfo/icon.svg |
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idpdfdomainpdfvendorwilhelmnamepdfdescriptionWilhelm pdf appversion2.0.0licenseservice, wrapper, wilhelm
serviceProprietarywrapperProprietarywilhelmProprietarymaintainername, email, url
typenc-appcategorywilhelm-coreemoji📦pixelIcon............ .KKKKKKKKKK. .KWKKKKKWWK. .KWKWWWKKWK. .KWKWWWWKWK. .KWKGGWWKWK. .KWKGGGWKWK. .KWKWWWWKWK. .KWKKKKKKWK. .KKKKKKKKKK. ............
primaryColor#0369FFtags[ ]compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.componentsnextcloudApp, embed, vscode
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmpdfpath.minNcVersion30maxNcVersion32embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile, gate, exapp
idstirling-pdflabelStirling PDFncConfigKeypdf_urlsubdomainpdfcontainerstirling-pdfcontainerPort8080embedProxyPort8894profilestirling-pdfgatetrueexappid, adapter, upstream, prefix
vscodeextensions, extension
extensions[ ]extensionnulldesktopenabled, startPath, hideNextcloudChrome
enabledtruestartPath/index.php/apps/wilhelmpdf/hideNextcloudChrometruedependenciesrequires, optional
requires1 item
0id, version
idnextcloudversion>=30optional[ ]skinslogan, logo, theme
marketplacevisibility, pricing, supportUrl
Links & documentation files
rag
Knowledge that answers.
Wilhelm rag app
What it does
rag is the stack's knowledge base: semantic search and answers with sources over Nextcloud files, NocoDB records, shop products and the Wilhelm app documentation. The Nextcloud app embeds the Qdrant dashboard; the work happens in the Kernel API, which embeds documents with Ollama and stores the vectors in Qdrant - the self-hosted counterpart to Pinecone plus a hosted RAG service.
Agents reach it as an MCP tool; the Enter chat pulls it on demand rather than on every message. Ingest is idempotent and collections size themselves from the first embedding.
Features
Semantic search, or an answer generated with citations.
Embed with a local model, upsert by stable id, collection created on first run.
App docs, Nextcloud files, NocoDB records, shop products.
rag_search for any MCP-capable client, Enter included.
Ollama embeddings, Qdrant vectors, no hosted vector service.
Why it is in the stack
- Knowledge that answers: your own files become answerable, with sources, without leaving the stack.
- On-demand retrieval keeps chats fast; the index trigger endpoint is still a stub and says so.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs rag.
At a glance
| Based on | Wilhelm-native - no upstream project |
| Type · category | Nextcloud app · Wilhelm core |
| Licence | service Proprietary · wrapper Proprietary · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support/rag |
| Public URL | https://vectors.<your-domain> |
| Compose profile | rag |
| Nextcloud app id | wilhelmrag · Nextcloud 30-32 |
| Folder | apps/rag/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Embedding in Nextcloud
| Registry id · label | qdrant · Qdrant Vector DB |
| Subdomain | vectors |
| Container | qdrant:6333 |
| Embed-proxy port (localhost) | 8912 |
| Compose profile | rag |
| Nextcloud config key | qdrant_dash_url |
Nextcloud app
| App id | wilhelmrag |
| Path | . |
| Nextcloud versions | 30 - 32 |
Dependencies
| Requires | nextcloud >=30 |
Skin & branding
| Slogan | Knowledge that answers. |
| Theme | primary #0369FF · mode system |
| Logo | ./appinfo/icon.svg |
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
| ISO/IEC 27001 Information security | in progress | software | Wilhelm certification programme - implementation for all Wilhelm apps in progress. |
| WCAG Accessibility | in progress | software | Wilhelm certification programme - implementation for all Wilhelm apps in progress. |
| ISO 9241 Usability / ergonomics | in progress | software | Wilhelm certification programme - implementation for all Wilhelm apps in progress. |
| EAA / BFSG Accessibility | in progress | software | Wilhelm certification programme - implementation for all Wilhelm apps in progress. |
Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idragdomainragvendorwilhelmnameragdescriptionWilhelm rag appversion2.0.0licenseservice, wrapper, wilhelm
serviceProprietarywrapperProprietarywilhelmProprietarymaintainername, email, url
typenc-appcategorywilhelm-coreemoji📦pixelIcon............ .KKKKKKKKKK. .KWWWWWWWWK. .KKKKWWKKKK. .KKWWKKWWKK. .KKWWKKWWKK. .KKWWKKWWKK. .KKKKKKKKKK. .KWWWWWWWWK. .KKKKKKKKKK. ............
primaryColor#0369FFtags[ ]compliancecertifications, note
certifications5 items
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.1id, status, scope, note
idiso-27001statusin-progressscopesoftwarenoteWilhelm certification programme - implementation for all Wilhelm apps in progress.2id, status, scope, note
idwcagstatusin-progressscopesoftwarenoteWilhelm certification programme - implementation for all Wilhelm apps in progress.3id, status, scope, note
idiso-9241statusin-progressscopesoftwarenoteWilhelm certification programme - implementation for all Wilhelm apps in progress.4id, status, scope, note
ideaastatusin-progressscopesoftwarenoteWilhelm certification programme - implementation for all Wilhelm apps in progress.noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.componentsnextcloudApp, embed, vscode
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmragpath.minNcVersion30maxNcVersion32embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile
idqdrantlabelQdrant Vector DBncConfigKeyqdrant_dash_urlsubdomainvectorscontainerqdrantcontainerPort6333embedProxyPort8912profileragvscodeextensions, extension
extensions[ ]extensionnulldependenciesrequires, optional
requires1 item
0id, version
idnextcloudversion>=30optional[ ]skinslogan, logo, theme
marketplacevisibility, pricing, supportUrl
Links & documentation files
doc/ai-notes.md · doc/api.md · doc/caret-rag.md · doc/n8n.md · doc/sources.md
search
Find instead of search.
Wilhelm search app
What it does
search is Meilisearch wired into Nextcloud's global search bar: a registered search provider runs a federated query over three indexes - Nextcloud files, NocoDB records and shop products - and each hit deep-links into Files, NocoDB or the shop. Typo-tolerant, instant, millisecond-ranked, the self-hosted alternative to Algolia.
Meilisearch has no UI of its own; the app page is a status page. Indexing happens through the Kernel API, typically by n8n jobs.
Features
Results in the search box users already use.
Three indexes, one query, hits tagged with their source.
Upstream search quality.
Search, index, list and delete with the stack token.
Why it is in the stack
- Find instead of search: one box over files, database records and products.
- Self-hosted engine, no SaaS index.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs search.
At a glance
| Based on | Wilhelm-native - no upstream project |
| Replaces | Algolia, Elasticsearch · listed as Wilhelm Search in the ecosystem reference |
| Type · category | Nextcloud app · Wilhelm core |
| Licence | service Proprietary · wrapper Proprietary · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support/search |
| Public URL | https://search.<your-domain> |
| Compose profile | meilisearch |
| Nextcloud app id | wilhelmsearch · Nextcloud 30-32 |
| Folder | apps/search/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Embedding in Nextcloud
| Registry id · label | meilisearch · Meilisearch |
| Subdomain | search |
| Container | meilisearch:7700 |
| Embed-proxy port (localhost) | 7700 |
| Compose profile | meilisearch |
| Nextcloud config key | search_url |
Nextcloud app
| App id | wilhelmsearch |
| Path | . |
| Nextcloud versions | 30 - 32 |
Dependencies
| Requires | nextcloud >=30 |
Skin & branding
| Slogan | Find instead of search. |
| Theme | primary #0369FF · mode system |
| Logo | ./appinfo/icon.svg |
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idsearchdomainsearchvendorwilhelmnamesearchdescriptionWilhelm search appversion2.0.0licenseservice, wrapper, wilhelm
serviceProprietarywrapperProprietarywilhelmProprietarymaintainername, email, url
typenc-appcategorywilhelm-coreemoji📦pixelIcon............ .KKKKKKKKKK. .KWWKKWWWWK. .KWKWWKWWWK. .KWKWWKWWWK. .KWWKKKWWWK. .KWWWWWKWWK. .KWWWWWWKWK. .KWWWWWWWWK. .KKKKKKKKKK. ............
primaryColor#0369FFtags[ ]compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.componentsnextcloudApp, embed, vscode
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmsearchpath.minNcVersion30maxNcVersion32embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile
idmeilisearchlabelMeilisearchncConfigKeysearch_urlsubdomainsearchcontainermeilisearchcontainerPort7700embedProxyPort7700profilemeilisearchvscodeextensions, extension
extensions[ ]extensionnulldependenciesrequires, optional
requires1 item
0id, version
idnextcloudversion>=30optional[ ]skinslogan, logo, theme
marketplacevisibility, pricing, supportUrl
Links & documentation files
settings
One place for every setting.
Wilhelm settings app
What it does
settings is the Wilhelm admin panel inside Nextcloud's settings area: general, services, Nextcloud, branding and credentials sections that forward everything to the Kernel API - edit the central environment, list and restart Docker services, manage the credentials of every stack app - without a shell.
It has no business logic of its own; the Kernel is the single source of truth for configuration and Docker control.
Features
Central .env through the Kernel.
Docker service list and restart control.
n8n, NocoDB, Neo4j, database, Vaultwarden, Medusa, Plausible, Twenty, Immich and more in one place.
Stack-wide branding settings.
Why it is in the stack
- One place for every setting, inside the login you already have.
- No shell access needed for the everyday operations.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs settings.
At a glance
| Based on | Wilhelm-native - no upstream project |
| Type · category | Nextcloud app · Wilhelm core |
| Licence | service Proprietary · wrapper Proprietary · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support/settings |
| Nextcloud app id | wilhelmsettings · Nextcloud 30-32 |
| Folder | apps/settings/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Nextcloud app
| App id | wilhelmsettings |
| Path | . |
| Nextcloud versions | 30 - 32 |
Dependencies
| Requires | nextcloud >=30 |
Skin & branding
| Slogan | One place for every setting. |
| Theme | primary #0369FF · mode system |
| Logo | ./appinfo/icon.svg |
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idsettingsdomainsettingsvendorwilhelmnamesettingsdescriptionWilhelm settings appversion2.0.0licenseservice, wrapper, wilhelm
serviceProprietarywrapperProprietarywilhelmProprietarymaintainername, email, url
typenc-appcategorywilhelm-coreemoji📦pixelIcon............ .KKKKKKKKKK. .KWWKWWKWWK. .KWKKKKKKWK. .KKKKWWKKKK. .KKKWWWWKKK. .KKKKWWKKKK. .KWKKKKKKWK. .KWWKWWKWWK. .KKKKKKKKKK. ............
primaryColor#0369FFtags[ ]compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.componentsnextcloudApp, vscode
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmsettingspath.minNcVersion30maxNcVersion32vscodeextensions, extension
extensions[ ]extensionnulldependenciesrequires, optional
requires1 item
0id, version
idnextcloudversion>=30optional[ ]skinslogan, logo, theme
marketplacevisibility, pricing, supportUrl
Links & documentation files
swagger
APIs you can touch.
Wilhelm swagger app
What it does
swagger is Swagger UI packaged as a Nextcloud app: the stack's own API explorer. It renders the OpenAPI specifications of the Wilhelm apps as interactive pages - browse endpoints, inspect schemas, try requests against the real API - behind the Nextcloud login, with no container or port of its own.
It stands in for hosted API-documentation portals such as SwaggerHub or ReadMe.
Features
OpenAPI 2 and 3; try-it-out against live endpoints.
A dropdown over the specs of every app.
API key, bearer and OAuth2 flows.
Link to a single operation.
Why it is in the stack
- APIs you can touch - one in-house explorer for the whole stack.
- Zero extra infrastructure; rides along in Nextcloud.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs swagger.
At a glance
| Based on | Swagger UI · source · docs |
| Replaces | Postman, ReadMe.io · listed as Wilhelm Docs in the ecosystem reference |
| Type · category | Nextcloud app · Wilhelm core |
| Licence | service Proprietary · wrapper Proprietary · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support/swagger |
| Compose profile | n8n |
| Nextcloud app id | wilhelmswagger · Nextcloud 30-32 |
| Folder | apps/swagger/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Nextcloud app
| App id | wilhelmswagger |
| Path | . |
| Nextcloud versions | 30 - 32 |
Dependencies
| Requires | nextcloud >=30 |
Skin & branding
| Slogan | APIs you can touch. |
| Theme | primary #0369FF · mode system |
| Logo | ./appinfo/icon.svg |
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idswaggerdomainswaggervendorwilhelmnameswaggerdescriptionWilhelm swagger appversion2.0.0licenseservice, wrapper, wilhelm
serviceProprietarywrapperProprietarywilhelmProprietarymaintainername, email, url
typenc-appcategorywilhelm-coreemoji📦pixelIcon............ .KKKKKKKKKK. .KWWKWWKWWK. .KWKWWWWKWK. .KWKWWWWKWK. .KKWWWWWWKK. .KWKWWWWKWK. .KWKWWWWKWK. .KWWKWWKWWK. .KKKKKKKKKK. ............
primaryColor#0369FFtags[ ]compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.componentsnextcloudApp, vscode
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmswaggerpath.minNcVersion30maxNcVersion32vscodeextensions, extension
extensions[ ]extensionnulldependenciesrequires, optional
requires1 item
0id, version
idnextcloudversion>=30optional[ ]skinslogan, logo, theme
marketplacevisibility, pricing, supportUrl
Links & documentation files
Upstream docs · Upstream source · Support · apps/swagger/
doc/ai-notes.md · doc/api.md · doc/n8n.md · doc/sources.md · doc/swagger-reference.md
tools
Tools for all the small things.
Wilhelm tools app
What it does
tools adds document conversion and PDF manipulation as right-click actions on files in Nextcloud: compress, OCR, split, rotate, merge, PDF to image and back via Stirling PDF; HTML, Markdown and Office to PDF and URL screenshots via Gotenberg. What people open Acrobat or a web converter for, where the files already live.
A single controller passes the file to the stack-internal service and returns the result as a download; operations are whitelisted so only the intended endpoints are reachable.
Features
Whitelisted transforms registered as Nextcloud file actions.
Compress, OCR (German), split, rotate, merge, PDF and image conversion.
HTML, Markdown, Office to PDF; URL to PDF.
Sanitised operation names, whitelist, timeouts.
Why it is in the stack
- Tools for all the small things - without uploading files to a third-party web tool.
- No per-document pricing; no Kernel, n8n or database coupling.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs tools.
At a glance
| Based on | Wilhelm-native - no upstream project |
| Type · category | Nextcloud app · Wilhelm core |
| Licence | service Proprietary · wrapper Proprietary · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support/tools |
| Nextcloud app id | wilhelmtools · Nextcloud 30-32 |
| Folder | apps/tools/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Nextcloud app
| App id | wilhelmtools |
| Path | . |
| Nextcloud versions | 30 - 32 |
Dependencies
| Requires | nextcloud >=30 |
Skin & branding
| Slogan | Tools for all the small things. |
| Theme | primary #0369FF · mode system |
| Logo | ./appinfo/icon.svg |
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idtoolsdomaintoolsvendorwilhelmnametoolsdescriptionWilhelm tools appversion2.0.0licenseservice, wrapper, wilhelm
serviceProprietarywrapperProprietarywilhelmProprietarymaintainername, email, url
typenc-appcategorywilhelm-coreemoji📦pixelIcon............ .KKKKKKKKKK. .KWWWWKWKWK. .KWWWWWKKWK. .KWWWWKKWWK. .KWWWKKWWWK. .KWWKKWWWWK. .KWKKWWWWWK. .KKKWWWWWWK. .KKKKKKKKKK. ............
primaryColor#0369FFtags[ ]compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.componentsnextcloudApp, vscode
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmtoolspath.minNcVersion30maxNcVersion32vscodeextensions, extension
extensions[ ]extensionnulldependenciesrequires, optional
requires1 item
0id, version
idnextcloudversion>=30optional[ ]skinslogan, logo, theme
sloganTools for all the small things.themeprimary, mode
primary#0369FFmodesystemmarketplacevisibility, pricing, supportUrl
Links & documentation files
website
Your site from one folder.
Wilhelm website app
What it does
website turns a Nextcloud group folder into the source of the public website: editors publish and unpublish pages by working with normal files - a leading underscore means draft, no underscore means published - and the index file of each folder becomes its start page. Delivery is done by the Webwow backend behind the gateway.
Publishing is file management in a tool the team already uses: no CMS login, and the content keeps Nextcloud's sharing and versioning.
Features
A file rename toggles the state; drafts are unmistakable at a glance.
Sidebar tab and file action in the Files app.
index.md or README.md per folder, rendered to HTML.
One group folder as the site's content.
Why it is in the stack
- Your site from one folder - publishing without a separate CMS.
- Content stays in Nextcloud with sharing and versions.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs website.
At a glance
| Based on | Wilhelm-native - no upstream project |
| Replaces | WordPress, Squarespace · listed as Wilhelm Web in the ecosystem reference |
| Type · category | Nextcloud app · Wilhelm core |
| Licence | service Proprietary · wrapper Proprietary · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support/website |
| Compose profile | nextcloud |
| Nextcloud app id | wilhelmwebsite · Nextcloud 30-32 |
| Folder | apps/website/manifest.json |
Icon & assets
tools/app-assets → appinfo/ · serving copy in ./site
Configuration
Nextcloud app
| App id | wilhelmwebsite |
| Path | . |
| Nextcloud versions | 30 - 32 |
Dependencies
| Requires | nextcloud >=30 |
Skin & branding
| Slogan | Your site from one folder. |
| Theme | primary #0369FF · mode system |
| Logo | ./appinfo/icon.svg |
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idwebsitedomainwebsitevendorwilhelmnamewebsitedescriptionWilhelm website appversion2.0.0licenseservice, wrapper, wilhelm
serviceProprietarywrapperProprietarywilhelmProprietarymaintainername, email, url
typenc-appcategorywilhelm-coreemoji📦pixelIcon............ .KKKKKKKKKK. .KWKWWWWWWK. .KKKKKKKKKK. .KWWWWWWWWK. .KWKKKWWWWK. .KWWWWWWWWK. .KWKKKKKKWK. .KWWWWWWWWK. .KKKKKKKKKK. ............ ............
primaryColor#0369FFtags[ ]compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.webpublicDir
publicDir./sitecomponentsnextcloudApp, vscode
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmwebsitepath.minNcVersion30maxNcVersion32vscodeextensions, extension
extensions[ ]extensionnulldependenciesrequires, optional
requires1 item
0id, version
idnextcloudversion>=30optional[ ]skinslogan, logo, theme
marketplacevisibility, pricing, supportUrl
Links & documentation files
Wilhelm MCP Server
The stack as a toolbox.
Nextcloud wrapper for the Wilhelm MCP server (embeds the MCP dashboard).
What it does
Wilhelm MCP Server exposes the stack to AI clients as Model Context Protocol tools: Nextcloud files and calendar, NocoDB queries, Meilisearch, Ollama generation, ntfy notifications, ComfyUI image generation and optionally Qdrant search - one authenticated door for Claude, Enter or any MCP-capable client. Pure Node, no npm dependencies.
The Nextcloud app embeds its status dashboard; the server itself speaks SSE and streamable HTTP and shares the stack's token scheme with the Wilhelm API.
Features
nextcloud_files, nextcloud_calendar, nocodb_query, meilisearch, ollama_generate, ntfy_send, comfyui_generate, qdrant_search.
SSE and streamable HTTP; JSON-RPC initialize, ping, tools/list, tools/call.
Health and status pages.
Service credentials never reach the model client.
Enabled by setting the stack token.
Why it is in the stack
- The stack as a toolbox - one MCP door into everything.
- Zero dependencies keeps the attack surface and maintenance small.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs wilhelmmcp.
At a glance
| Based on | Wilhelm-native - no upstream project |
| Type · category | Nextcloud app · Wilhelm core |
| Licence | service Proprietary · wrapper Proprietary · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support/mcp |
| Public URL | https://mcp.<your-domain> |
| Compose profile | mcp |
| Nextcloud app id | wilhelmmcp · Nextcloud 30-32 |
| Tags | mcpai |
| Folder | apps/wilhelmmcp/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Embedding in Nextcloud
| Registry id · label | mcp · Wilhelm MCP Server |
| Subdomain | mcp |
| Container | wilhelm-mcp:3040 |
| Embed-proxy port (localhost) | 8911 |
| Compose profile | mcp |
| Nextcloud config key | mcp_url |
Nextcloud app
| App id | wilhelmmcp |
| Path | . |
| Nextcloud versions | 30 - 32 |
Dependencies
| Requires | nextcloud >=30 |
Skin & branding
| Slogan | The stack as a toolbox. |
| Theme | primary #6366F1 · mode system |
| Logo | ./app/img/app.svg |
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idwilhelmmcpdomainmcpvendorwilhelmnameWilhelm MCP ServerdescriptionNextcloud wrapper for the Wilhelm MCP server (embeds the MCP dashboard).version2.0.0licenseservice, wrapper, wilhelm
serviceProprietarywrapperProprietarywilhelmProprietarymaintainername, email, url
typenc-appcategorywilhelm-coreemoji🤖pixelIcon............ .KKKKKKKKKK. .KWGWKWGWWK. .KGWWKWWGWK. .KWWWKWWWWK. .KWWKKKWWWK. .KWWKKKWWWK. .KWKKKKKWWK. .KWWWWWWWWK. .KKKKKKKKKK. ............
primaryColor#6366F1tagsmcpaicompliancecertifications, note
certifications1 item
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.componentsnextcloudApp, embed, vscode
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmmcppath.minNcVersion30maxNcVersion32embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile
idmcplabelWilhelm MCP ServerncConfigKeymcp_urlsubdomainmcpcontainerwilhelm-mcpcontainerPort3040embedProxyPort8911profilemcpvscodeextensions, extension
extensions[ ]extensionnulldependenciesrequires, optional
requires1 item
0id, version
idnextcloudversion>=30optional[ ]skinslogan, logo, theme
marketplacevisibility, pricing, supportUrl
Links & documentation files
Wilhelm UI
One standard, every interface.
Wilhelm design system: Lit web components + Open Props design tokens, no bundler. Ships the shared <wl-*> elements, the --wl-* tokens and a zero-dependency dev environment with live reload (npm run dev). The front-end foundation for new Wilhelm apps instead of React.
What it does
Wilhelm UI is the shared front-end layer of every Wilhelm app: Lit web components and Open Props design tokens, served without a bundler. Every app gets the same <wl-*> elements and the same --wl-* tokens without inheriting a build step - deliberately React-free, and the foundation new Wilhelm apps are built on.
Its second face is HTML67: the same components as bare tags, one script, no build step. A Nextcloud app restyles the Nextcloud interface itself, and the runtime is vendored into apps such as WilheLLM so chat output shares the same markup and tokens.
Features
App shell, cards, panels, buttons, charts, maps, editors - per-component imports for lean apps.
A thin Wilhelm semantic layer over Open Props; dark mode by preference; components reference tokens only.
Live reload; the index page doubles as playground and gallery.
Stylesheet, import map, module.
App-grid dropdown and slimmer header via the wilhelmui app.
Why it is in the stack
- One standard, every interface - one visual language across the stack.
- No bundler, no node_modules monster: browsers do import maps and custom properties natively.
- Theming is central because components never hard-code values.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs ui.
At a glance
| Based on | Wilhelm-native - no upstream project |
| Type · category | Nextcloud app · Wilhelm core |
| Licence | service Proprietary · wrapper Proprietary · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Homepage | wilhelm.tech |
| Support | wilhelm.tech/support/ui |
| Nextcloud app id | wilhelmui · Nextcloud 30-32 |
| Tags | frontenddesign-systemlitopenpropswilhelm-core |
| Folder | apps/ui/manifest.json |
Icon & assets
tools/app-assets → appinfo/ · serving copy in .
Configuration
Nextcloud app
| App id | wilhelmui |
| Path | . |
| Nextcloud versions | 30 - 32 |
Dependencies
| Requires | nextcloud >=30 |
| Provides | nc-appui-component |
| Required by | html67 |
Skin & branding
| Slogan | One standard, every interface. |
| Theme | primary #0369FF · mode system |
| Logo | ./favicon.svg |
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
iduidomainuivendorwilhelmnameWilhelm UIdescriptionWilhelm design system: Lit web components + Open Props design tokens, no bundler. Ships the shared <wl-*> elements, the --wl-* tokens and a zero-dependency dev environment with live reload (npm run dev). The front-end foundation for new Wilhelm apps instead of React.version2.0.0licenseservice, wrapper, wilhelm
serviceProprietarywrapperProprietarywilhelmProprietarymaintainername, email, url
typenc-appcategorywilhelm-coreicon./favicon.svgemoji🎨pixelIcon............ .KKKKKKKKK.. .KWWWWWWWK.. .KWKKKKKWK.. .KWWWWWWWK.. .KKKKKKKKK.. ......K..... ......KK.... ......KKK... ......KKKK.. ......K.K... ............
primaryColor#0369FFhomepagewilhelm.techtagsfrontenddesign-systemlitopenpropswilhelm-corecompliancecertifications, note
certifications1 item
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.webpublicDir
publicDir.componentsnextcloudApp, vscode
nextcloudAppappid, path, minNcVersion, maxNcVersion
appidwilhelmuipath.minNcVersion30maxNcVersion32vscodeextensions, extension
extensions[ ]extensionnulldependenciesrequires, optional, provides
requires1 item
0id, version
idnextcloudversion>=30optional[ ]providesnc-appui-componentskinslogan, logo, theme
marketplacevisibility, pricing, supportUrl
README
The README is not in English - see apps/ui/README.md.
Links & documentation files
doc/ai-notes.md · doc/api.md · doc/sources.md · doc/using-the-design-system.md
SAP Adapter
SAP in the Wilhelm stack - clean REST instead of RFC pain.
Adapter that fronts a SAP / HANA system behind clean REST + MCP so the Wilhelm stack (Enter, n8n, Gary) can read and write it. Reusable 'adapter' pattern for proprietary systems.
What it does
SAP Adapter fronts an existing SAP / HANA system with clean REST and MCP so that Enter, n8n, Gary and the Kernel can read and write SAP without RFC, BAPI or the raw HANA SQL port. It is the canonical adapter pattern for proprietary systems - the same shape is meant to be reused for Dynamics, Salesforce or Lexware.
It ships a generic 'ERP' n8n node with a provider dropdown (SAP active, Odoo and Lexoffice planned), two workflows, an MCP server with query and read tools, a complete secrets specification, and an optional local HANA Express profile for development.
Features
/healthz and /query; OData read path works, HANA-SQL path is a stub.
sap_query and sap_read for agents.
One node, many providers - never renamed as providers are added.
Scheduled HANA query into Wilhelm; inbound webhook into SAP.
Reachable through the Kernel API and the Nextcloud proxy.
HANA Express under a separate profile, off by default.
Why it is in the stack
- SAP in the Wilhelm stack - clean REST instead of RFC pain; the rest of the stack only ever talks to the adapter.
- Connects to your existing SAP; no vendor cloud middleware.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs sap.
At a glance
| Based on | Wilhelm-native - no upstream project |
| Type · category | Infrastructure · Adapters |
| Licence | service Apache-2.0 · wilhelm Apache-2.0 |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support |
| Docker image | wilhelm/sap-adapter:0.1.0 |
| Nextcloud app id | wilhelmsap · Nextcloud 30-32 |
| Resources | memory 256Mi · cpu 0.25 · storage 1Gi |
| Tags | saperpadapterhanan8n-node |
| Folder | apps/sap/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Service
| Image | wilhelm/sap-adapter:0.1.0 |
| Compose fragment | ./service/compose.fragment.yml |
| Init script | ./service/init.sh |
| Health check | http /healthz every 30s · timeout 5s · 3 retries |
Nextcloud app
| App id | wilhelmsap |
| Path | ./nextcloud |
| Nextcloud versions | 30 - 32 |
Desktop build (Electron)
| Enabled | no - opted out |
Resources & permissions
| Memory · CPU · storage | 256Mi · 0.25 · 1Gi |
| Host network | no |
| Privileged | no |
| Egress domains | none - no outbound connections declared |
Dependencies
| Requires | nextcloud >=30 |
| Optional | n8n |
| Provides | nc-appn8n-workflowsn8n-erp-nodemcp |
MCP (Model Context Protocol)
| Server | mcp/server.js |
| Transport | stdio |
| Tools | sap_querysap_read |
Single sign-on (OIDC)
| As client | no |
| As provider | no |
| Fallback | none |
Skin & branding
| Slogan | SAP in the Wilhelm stack - clean REST instead of RFC pain. |
| Theme | primary #0FAAFF · mode system |
| Logo | ./skin/logo.svg |
| Agent persona | SAP-Adapter - “Ask me about HANA data.” |
Secrets
Declared in apps/sap/secrets.spec.yaml - names and purpose only, values live in .env / the secret store.
| Name | Required | Purpose |
|---|---|---|
SAP_HOST | yes | Hostname/IP of the SAP HANA server the adapter connects to. Defaults to the local sap-hana container in dev. e.g. hana.example.com |
SAP_PORT | yes | HANA SQL port (SQL/MDX). 39017 for HXE SYSTEMDB, 3<inst>15 for tenant DBs on standard SAP. e.g. 39017 |
SAP_USER | yes | HANA/SAP technical user the adapter authenticates as. Give it read-only rights unless write-back is needed. e.g. WILHELM_RO |
SAP_PASSWORD 🔒 | yes | Password for SAP_USER. Store in the secret vault, never commit. |
HANA_DB | yes | Target HANA database/tenant name. HXE for HANA Express. e.g. HXE |
SAP_ODATA_BASE | no | Base URL of the SAP OData (gateway) service, if OData reads are used. Enables the /query op=odata path. e.g. https://sap.example.com/sap/opu/odata/sap |
HANA_ENCRYPT | no | Enable TLS for the HANA SQL connection (encrypt=true). Required by HANA Cloud, usually off for local HANA Express. Set to true/1/yes. e.g. true |
HANA_CONNECT_TIMEOUT | no | HANA connect timeout in milliseconds for the @sap/hana-client driver. e.g. 15000 |
HANA_POOL_SIZE | no | Max size of the reused HANA connection pool. e.g. 5 |
SAP_ADAPTER_PORT | no | Host loopback port the adapter is published on (127.0.0.1 only). e.g. 8897 |
WILHELM_API_TOKEN 🔒 | no | Shared stack token. If set, the adapter requires it as Bearer on all non-health routes. Shared with the MCP server. |
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idsapdomainsapvendorwilhelmnameSAP AdapterdescriptionAdapter that fronts a SAP / HANA system behind clean REST + MCP so the Wilhelm stack (Enter, n8n, Gary) can read and write it. Reusable 'adapter' pattern for proprietary systems.version0.1.0licenseservice, wilhelm
serviceApache-2.0wilhelmApache-2.0maintainername, email, url
typeinfrastructurecategoryadaptericon./icon.svgemoji🧩pixelIcon............ .KKKKKKKKKK. .KWWWKKWWWK. .KWKKWWKKWK. .KKWWWWWWKK. .KKWWWWWWKK. .KWKKWWKKWK. .KWWWKKWWWK. .KWWWWWWWWK. .KKKKKKKKKK. ............
primaryColor#0FAAFFtagssaperpadapterhanan8n-nodecompliancecertifications, note
certifications1 item
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.componentsservice, nextcloudApp, vscode
serviceimage, compose, init, healthCheck
imagewilhelm/sap-adapter:0.1.0healthChecktype, path, interval, timeout, retries
typehttppath/healthzinterval30stimeout5sretries3nextcloudAppappid, path, minNcVersion, maxNcVersion
vscodeextensions, extension
extensions[ ]extensionnulldesktopenabled
enabledfalseresourcesmemory, cpu, storage
memory256Micpu0.25storage1GipermissionsneedsHostNetwork, needsPrivileged, egressDomains
needsHostNetworkfalseneedsPrivilegedfalseegressDomains[ ]dependenciesrequires, optional, provides
requires1 item
0id, version
idnextcloudversion>=30optional1 item
0id
idn8nprovidesnc-appn8n-workflowsn8n-erp-nodemcpmcpserver, transport, tools, grants
servermcp/server.jstransportstdiotoolssap_querysap_readgrants[ ]oidcCapabilityasClient, asProvider, fallback
asClientfalseasProviderfalsefallbacknonesecretsRefs./secrets.spec.yamlskinslogan, logo, theme, agent
sloganSAP in the Wilhelm stack - clean REST instead of RFC pain.logo./skin/logo.svgthemeprimary, mode
primary#0FAAFFmodesystemagentname, greeting, persona
marketplacevisibility, screenshots, pricing, supportUrl
From the README
Adapter that fronts a SAP / HANA system behind clean REST + MCP so the rest of the Wilhelm stack (Enter, n8n, Gary, Kernel-API) can read and write it without touching RFC/BAPI or the raw HANA SQL port.
This is the canonical "adapter" pattern (category: "adapter"): a small always-on service that speaks a proprietary protocol on one side and clean Wilhelm REST/MCP on the other. Reuse it for Dynamics/Salesforce/etc.
Read on: apps/sap/README.md
Links & documentation files
Wilhelm Intelligence
One gateway, every model.
OpenAI-compatible LLM gateway: OCR + RAG + pre-prompts in front of Claude
What it does
Wilhelm Intelligence is the stack's one door to language models: an OpenAI-compatible gateway with a pipeline behind it - OCR pre-processing for scans, retrieval from the knowledge base, a versioned Wilhelm persona as system prompt - in front of Claude, an n8n-routed backend, or a local Ollama model.
The value is the pipeline and the persona, not a model of its own. Every AI consumer in the stack (Open WebUI, n8n, WilheLLM, o14n) points its OpenAI base URL at the gateway and gets the same context, the same rules and the same switchable backend.
Features
/v1/models and /v1/chat/completions with streaming - existing clients work unchanged.
Anthropic Claude (streaming, adaptive thinking, prompt caching), n8n routing, or Ollama for an offline, data-sovereign path.
Opt-in RAG against the Qdrant knowledge base through the Wilhelm API.
Opt-in Tesseract for poor scans before the model sees them.
The Wilhelm system prompt lives in prompts/system.md and is versioned like code.
Ships a routing workflow so credentials and routing can be managed in the n8n editor.
Why it is in the stack
- One gateway, every model: one API surface for all AI consumers, one place to switch providers.
- A better pipeline around a best-in-class model instead of a weak model of one's own; honest about the terms it runs under.
- The Ollama path keeps everything inside the house when it has to.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs brain.
At a glance
| Based on | Wilhelm-native - no upstream project |
| Type · category | Infrastructure · AI |
| Licence | service Apache-2.0 · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support/brain |
| Docker image | wilhelm/brain:latest · port 3000 |
| Tags | aillmgatewayragclaude |
| Folder | apps/brain/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Service
| Image | wilhelm/brain:latest |
| Port | 3000 |
| Health check | http /healthz every 30s · timeout 5s · 3 retries |
Dependencies
| Requires | nothing |
| Optional | n8n, rag, llm, tools |
| Provides | api |
Skin & branding
| Slogan | One gateway, every model. |
| Theme | primary #7C3AED · mode system |
| Logo | ./appinfo/icon.svg |
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idbraindomainbrainvendorwilhelmnameWilhelm IntelligencedescriptionOpenAI-compatible LLM gateway: OCR + RAG + pre-prompts in front of Claudeversion1.0.0licenseservice, wilhelm
serviceApache-2.0wilhelmProprietarymaintainername, email, url
typeinfrastructurecategoryaiemoji🧠pixelIcon............ .KKKKKKKKKK. .KWWWWWWWWK. .KWWKKKKWWK. .KWKKWKWKWK. .KWKWKKWKWK. .KWKKWKKKWK. .KWKWKWKWWK. .KWWKKKKWWK. .KKKKKKKKKK. ............
primaryColor#7C3AEDtagsaillmgatewayragclaudecompliancecertifications, note
certifications1 item
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.skinslogan, logo, theme
componentsservice
serviceimage, port, healthCheck
imagewilhelm/brain:latestport3000healthChecktype, path, interval, timeout, retries
typehttppath/healthzinterval30stimeout5sretries3dependenciesrequires, optional, provides
requires[ ]optional4 items
0id
idn8n1id
idrag2id
idllm3id
idtoolsprovidesapimarketplacevisibility, pricing, supportUrl
Standalone compose
Every service app can run on its own: cd apps/brain && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.
.env.example
# ── Wilhelm Intelligence (brain) ───────────────────────────────────────────── # Gateway settings. The ANTHROPIC_API_KEY secret belongs in the root .env. # Which model backend handles inference: # anthropic - call Claude directly (real streaming, adaptive thinking, caching) # n8n - route through the n8n workflow (flexible: swap models/prompts in the editor) # ollama - local Ollama (offline / data-sovereign) BRAIN_BACKEND=anthropic # Default model id used when callers ask for "wilhelm-intelligence". BRAIN_MODEL=claude-opus-4-8 BRAIN_MAX_TOKENS=64000 # REQUIRED for the anthropic backend - set this in the ROOT .env, not here. ANTHROPIC_API_KEY= # Optional bearer key to protect the gateway. Empty = open inside the Docker net. BRAIN_API_KEY= # Host port (bound to 127.0.0.1). BRAIN_PORT=3032 # RAG retrieval (Wilhelm RAG / Qdrant). Off by default; flip to true to enable. BRAIN_RAG_ENABLED=false BRAIN_RAG_COLLECTION=wilhelm BRAIN_RAG_TOP_K=5 BRAIN_WILHELM_API_URL=http://wilhelm-api:3000 # WILHELM_API_TOKEN is inherited from the root .env. # OCR pre-processing (Tesseract). Off by default; Claude reads images natively. BRAIN_OCR_ENABLED=false # TESSERACT_URL inherited from root .env (default http://tesseract:3000) # n8n routing backend. BRAIN_INFER_WEBHOOK=http://n8n:5678/webhook/brain-infer # Ollama fallback backend. BRAIN_OLLAMA_URL=http://ollama:11434 OLLAMA_MODEL=
README
The README is not in English - see apps/brain/README.md.
Links & documentation files
Analytics
Web analytics without snooping.
Plausible Analytics in Nextcloud
What it does
Analytics is Plausible Community Edition: privacy-friendly, cookie-less web analytics that shows what matters on one screen - visitors, sources, pages, countries, devices, goals - instead of the report maze of Google Analytics. A lightweight script records page views and events; no personal data, no cookie banner.
The Wilhelm website and shop are its tracking sources. The Kernel holds the API key, so n8n can build weekly reports or mirror key figures into NocoDB.
Features
A script under 1 KB, no cookies, no personal data - GDPR, CCPA and PECR friendly by design.
Visitors, visits, page views, bounce rate, visit duration, top pages, sources, locations and devices.
Custom events, conversions and funnels; revenue attribution.
Query metrics, dimensions and filters programmatically; real-time, aggregate, time-series and breakdown endpoints.
Share a dashboard openly or by secret link.
Registration is invite-only by default.
Why it is in the stack
- Web analytics without snooping: the data stays in your stack, and there is nothing to consent to.
- Replaces Google Analytics and Hotjar for the questions a company actually asks.
- Embedded in Nextcloud with single sign-on; reachable for n8n and the Kernel through the stats API.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs analytics.
At a glance
| Based on | Plausible Analytics · source · docs · API |
| Replaces | Google Analytics, Hotjar · listed as Wilhelm Analytics in the ecosystem reference |
| Type · category | External service · Analytics |
| Licence | service AGPL-3.0 · wrapper Proprietary · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support/analytics |
| Docker image | plausible/community:latest · port 8000 |
| Public URL | https://analytics.<your-domain> |
| Compose profile | plausible |
| Nextcloud app id | wilhelmanalytics · Nextcloud 30-32 |
| Tags | analyticsprivacy |
| Folder | apps/analytics/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Service
| Image | plausible/community:latest |
| Port | 8000 |
| Init script | ./service/init-plausible.sh |
| Health check | http /api/health every 30s · timeout 5s · 3 retries |
Embedding in Nextcloud
| Registry id · label | plausible · Plausible Analytics |
| Subdomain | analytics |
| Container | plausible:8000 |
| Embed-proxy port (localhost) | 8899 |
| Compose profile | plausible |
| Nextcloud config key | plausible_url |
Nextcloud app
| App id | wilhelmanalytics |
| Path | ./nextcloud |
| Nextcloud versions | 30 - 32 |
Dependencies
| Requires | nextcloud >=30 |
| Optional | vault |
Single sign-on (OIDC)
| As client | yes |
| As provider | no |
| Fallback | vaultwarden |
Skin & branding
| Slogan | Web analytics without snooping. |
| Theme | primary #5850EC · mode system |
| Logo | ./nextcloud/appinfo/icon.svg |
Secrets
Declared in secretsRefs but apps/analytics/secrets.spec.yaml does not exist in the repository.
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | compliant | cloud offering | Privacy-first without cookies or personal data (legally reviewed); hosting exclusively in the EU (Germany). source |
| DPA Privacy | compliant | cloud offering | Public DPA, automatically valid for all cloud customers. source |
| CCPA Privacy | vendor claim | cloud offering | CCPA compliance according to the vendor, since no personal data is collected. source |
Strong privacy story by design; formal audits such as SOC 2 or ISO 27001 do not exist.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idanalyticsdomainanalyticsvendorplausiblenameAnalyticsdescriptionPlausible Analytics in Nextcloudversion2.0.0licenseservice, wrapper, wilhelm
serviceAGPL-3.0wrapperProprietarywilhelmProprietarymaintainername, email, url
typeexternalcategoryanalyticsemoji📊pixelIcon............ .KKKKKKKKKK. .KWWWWWWWWK. .KWWWWWWKWK. .KWWWWWWKWK. .KWWWWKWKWK. .KWWWWKWKWK. .KWWKWKWKWK. .KWWKWKWKWK. .KKKKKKKKKK. ............
primaryColor#5850ECtagsanalyticsprivacycompliancecertifications, note
certifications3 items
0id, status, scope, source, note
idgdprstatuscompliantscopecloudsourceplausible.io/compliancenotePrivacy-first without cookies or personal data (legally reviewed); hosting exclusively in the EU (Germany).1id, status, scope, source, note
idgdpr-avvstatuscompliantscopecloudsourceplausible.io/dpanotePublic DPA, automatically valid for all cloud customers.2id, status, scope, source, note
idccpastatusclaimedscopecloudsourceplausible.io/data-policynoteCCPA compliance according to the vendor, since no personal data is collected.noteStrong privacy story by design; formal audits such as SOC 2 or ISO 27001 do not exist.componentsservice, nextcloudApp, embed, vscode
serviceimage, port, healthCheck, init
imageplausible/community:latestport8000healthChecktype, path, interval, timeout, retries
typehttppath/api/healthinterval30stimeout5sretries3nextcloudAppappid, path, minNcVersion, maxNcVersion
embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile
idplausiblelabelPlausible AnalyticsncConfigKeyplausible_urlsubdomainanalyticscontainerplausiblecontainerPort8000embedProxyPort8899profileplausiblevscodeextensions, extension
extensions[ ]extensionnulldependenciesrequires, optional
requires1 item
0id, version
idnextcloudversion>=30optional1 item
0id
idvaultoidcCapabilityasClient, asProvider, fallback
asClienttrueasProviderfalsefallbackvaultwardensecretsRefs./secrets.spec.yamlskinslogan, logo, theme
sloganWeb analytics without snooping.themeprimary, mode
primary#5850ECmodesystemmarketplacevisibility, screenshots, pricing, supportUrl
Standalone compose
Every service app can run on its own: cd apps/analytics && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.
docker-compose.yml
# Analytics - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/analytics/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
# cp .env.example .env && docker compose up -d
# → http://localhost:${ANALYTICS_PORT:-8000}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
analytics:
image: plausible/community:latest
restart: unless-stopped
env_file:
- .env
ports:
- "${ANALYTICS_PORT:-8000}:8000"
healthcheck:
test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:8000/api/health"]
interval: 30s
timeout: 5s
retries: 3
start_period: 20s
networks:
- analytics
# TODO: persistent volume(s) if this image stores state. e.g.:
# volumes: [ "analytics_data:/data" ]
networks:
analytics:
name: analytics
.env.example
# Analytics - standalone env. Copy to .env and fill in. # GENERATED by scripts/generate-standalone.mjs # Host port the app is published on. ANALYTICS_PORT=8000 # Required secrets are specified in: # ./secrets.spec.yaml # Add the matching KEY=VALUE lines here.
README
The README is not in English - see apps/analytics/README.md.
Links & documentation files
Upstream docs · Upstream API · Upstream source · Support · apps/analytics/
doc/ai-notes.md · doc/analytics-reference.md · doc/api.md · doc/n8n.md · doc/sources.md
n8n Workflows
Workflows that click.
n8n workflow builder in Nextcloud
What it does
n8n is the workflow automation platform the Wilhelm stack uses where others use Zapier, Make or Power Automate: a visual editor in which triggers (a webhook, a schedule, a new mail, a form submission) are wired to nodes that call APIs, transform data, branch, loop and write results back - with several hundred integrations built in and a code node for everything else.
Its AI nodes make it an agent builder as well: an AI Agent node with a chat model, memory, tools and a structured output parser can classify mails, answer questions over your data or drive multi-step tasks, using the stack's own model gateway or any provider.
Features
Drag nodes onto a canvas, connect them, run them step by step and inspect the data flowing through every edge.
Webhooks, schedules, manual runs, chat messages, app events (mail received, record created, form submitted).
Native nodes for the apps in this stack (Nextcloud, NocoDB, Twenty, Plane, Documenso, Cal.com …) and for external services.
If, switch, merge, loop, wait; JavaScript or Python code nodes; expressions everywhere.
AI Agent node with chat model, memory, tools and structured output; chat trigger for conversational workflows.
Execution history with the data of every node, retries, error workflows.
Centrally stored, encrypted credentials; environment variables per instance.
A library of ready-made workflows to start from.
Why it is in the stack
- Wilhelm Automate: n8n orchestrates the whole stack - shop, CRM, mail, forms, signatures, notifications, finance and projects all connect through it.
- Self-hosted under n8n's sustainable-use licence: no per-task pricing, your credentials and data stay on your server.
- Embedded in Nextcloud with single sign-on; the Wilhelm API and every app's n8n notes (doc/n8n.md) document the available triggers and actions.
Screenshots
A chat trigger feeds an AI Agent node; the agent is wired to a chat model, a window buffer memory, a search tool and a sub-workflow tool. An If node routes the result to a success or failure message. The Chat button at the bottom runs the workflow interactively.
01-workflow-editor.jpgManual trigger, a Twitter node that creates a tweet, an If node that branches on the result, and a NoOp - the shape every automation has: trigger, action, decision.
02-example-workflow.jpgA webhook receives a message; an AI Agent with a chat model and a structured output parser calculates its category and priority, returning JSON the following nodes can act on.
03-ai-workflow.jpgThe n8n AI assistant turns a prose description (fetch AI news every morning, summarise, generate an image, send to Telegram, keep a chat history) into nodes, connections and parameters, with setup instructions for the credentials it needs.
04-ai-builder.jpgScreenshots are the upstream project's official product shots (see preview/SOURCES.md) until the stack runs with demo data and tools/app-preview shoots real Wilhelm screens. Images © their respective projects.
At a glance
| Based on | n8n · source · docs · API |
| Replaces | Zapier, Make, Power Automate · listed as Wilhelm Automate in the ecosystem reference |
| Type · category | External service · Automation |
| Licence | service Fair-Code-SUL · wrapper Proprietary · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support/n8n |
| Docker image | n8nio/n8n:latest · port 5678 |
| Public URL | https://n8n.<your-domain> |
| Compose profile | n8n |
| Nextcloud app id | wilhelmn8n · Nextcloud 30-32 |
| Tags | automationworkflows |
| Folder | apps/n8n/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Service
| Image | n8nio/n8n:latest |
| Port | 5678 |
| Health check | http /healthz every 30s · timeout 5s · 3 retries |
Embedding in Nextcloud
| Registry id · label | n8n · n8n Workflow Engine |
| Subdomain | n8n |
| Container | n8n:5678 |
| Embed-proxy port (localhost) | 8891 |
| Compose profile | n8n |
| Nextcloud config key | n8n_url |
Nextcloud app
| App id | wilhelmn8n |
| Path | ./nextcloud |
| Nextcloud versions | 30 - 32 |
Desktop build (Electron)
| Enabled | yes |
| Start path | /index.php/apps/wilhelmn8n/ |
| Hide Nextcloud chrome | yes |
Dependencies
| Requires | nextcloud >=30 |
| Optional | vault |
Single sign-on (OIDC)
| As client | yes |
| As provider | no |
| Fallback | vaultwarden |
Skin & branding
| Slogan | Workflows that click. |
| Theme | primary #EA4B71 · mode system |
| Logo | ./nextcloud/appinfo/icon.svg |
Secrets
Declared in secretsRefs but apps/n8n/secrets.spec.yaml does not exist in the repository.
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| SOC 2 Type II Information security | attested | cloud offering | Annual SOC 2 Type II audit for n8n Cloud (SOC 3 report public, report via trust.n8n.io); does not apply to self-hosted instances. source |
| GDPR Privacy | compliant | cloud offering | DPA published for n8n Cloud; for self-hosting n8n publishes a CAIQ self-assessment questionnaire. source |
Certificates apply to n8n Cloud - the self-hosted instance does not inherit them but benefits from the same software controls.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idn8ndomainn8nvendorn8nnamen8n Workflowsdescriptionn8n workflow builder in Nextcloudversion2.0.0licenseservice, wrapper, wilhelm
serviceFair-Code-SULwrapperProprietarywilhelmProprietarymaintainername, email, url
typeexternalcategoryautomationemoji🔗pixelIcon............ .KKK........ .KWK.KKK.... .KKKKKWK.... ...KKKKKKK.. ......KKKWK. ........KKK. ............
primaryColor#EA4B71tagsautomationworkflowscompliancecertifications, note
certifications2 items
0id, status, scope, source, note
idsoc2-type2statusattestedscopecloudsourcen8n.io/legal/securitynoteAnnual SOC 2 Type II audit for n8n Cloud (SOC 3 report public, report via trust.n8n.io); does not apply to self-hosted instances.1id, status, scope, source, note
idgdprstatuscompliantscopecloudsourcetrust.n8n.ionoteDPA published for n8n Cloud; for self-hosting n8n publishes a CAIQ self-assessment questionnaire.noteCertificates apply to n8n Cloud - the self-hosted instance does not inherit them but benefits from the same software controls.componentsservice, nextcloudApp, embed, vscode
serviceimage, port, healthCheck
imagen8nio/n8n:latestport5678healthChecktype, path, interval, timeout, retries
typehttppath/healthzinterval30stimeout5sretries3nextcloudAppappid, path, minNcVersion, maxNcVersion
embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile
idn8nlabeln8n Workflow EnginencConfigKeyn8n_urlsubdomainn8ncontainern8ncontainerPort5678embedProxyPort8891profilen8nvscodeextensions, extension
extensions[ ]extensionnulldesktopenabled, startPath, hideNextcloudChrome
enabledtruestartPath/index.php/apps/wilhelmn8n/hideNextcloudChrometruedependenciesrequires, optional
requires1 item
0id, version
idnextcloudversion>=30optional1 item
0id
idvaultoidcCapabilityasClient, asProvider, fallback
asClienttrueasProviderfalsefallbackvaultwardensecretsRefs./secrets.spec.yamlskinslogan, logo, theme
sloganWorkflows that click.themeprimary, mode
primary#EA4B71modesystempreviewdir, gallery
dir./previewgallery4 items
0src, caption, kind
1src, caption, kind
2src, caption, kind
3src, caption, kind
marketplacevisibility, screenshots, pricing, supportUrl
visibilitypublicscreenshots./preview/gallery/01-workflow-editor.jpg./preview/gallery/02-example-workflow.jpg./preview/gallery/03-ai-workflow.jpg./preview/gallery/04-ai-builder.jpgpricingfreesupportUrlwilhelm.tech/support/n8nStandalone compose
Every service app can run on its own: cd apps/n8n && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.
docker-compose.yml
# n8n Workflows - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/n8n/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
# cp .env.example .env && docker compose up -d
# → http://localhost:${N8N_PORT:-5678}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
n8n:
image: n8nio/n8n:latest
restart: unless-stopped
env_file:
- .env
ports:
- "${N8N_PORT:-5678}:5678"
healthcheck:
test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:5678/healthz"]
interval: 30s
timeout: 5s
retries: 3
start_period: 20s
networks:
- n8n
# TODO: persistent volume(s) if this image stores state. e.g.:
# volumes: [ "n8n_data:/data" ]
networks:
n8n:
name: n8n
.env.example
# n8n Workflows - standalone env. Copy to .env and fill in. # GENERATED by scripts/generate-standalone.mjs # Host port the app is published on. N8N_PORT=5678 # Required secrets are specified in: # ./secrets.spec.yaml # Add the matching KEY=VALUE lines here.
README
The README is not in English - see apps/n8n/README.md.
Links & documentation files
Upstream docs · Upstream API · Upstream source · Support · apps/n8n/
doc/ai-notes.md · doc/api.md · doc/n8n-reference.md · doc/n8n.md · doc/restart-runbook.md · doc/sources.md
o14n - open n8n
Automation, fair and open.
Fair-code-free n8n alternative: a React-Flow node editor that visualises APIs Swagger-UI-style, driving a headless Node-RED engine (Apache-2.0) over its Admin API.
What it does
o14n - open n8n - is the licence-clean alternative to n8n for the cases where n8n's sustainable-use licence is a problem: Node-RED's battle-tested editor and engine, Wilhelm-skinned, with a node pack that turns any API into nodes from its OpenAPI spec, speaks to the stack's model gateway, and can hand off to n8n when an n8n integration is the shortest path.
The value is deliberately in the node pack, not in a reimplemented editor: an earlier custom front end was lossy and was removed. Node-RED stays unforked, so upstream improvements arrive for free.
Features
Load a spec by URL or inline, pick an operation, map path, query and body parameters.
Talk to the Wilhelm Intelligence gateway with templated system prompts, tool calling and RAG sources.
Trigger an n8n workflow by webhook instead of rebuilding its integrations.
Bearer, API key or basic credentials once, reused across nodes.
Every node-red-contrib package works.
Editor theme and CSS overlay; no fork.
Why it is in the stack
- Automation, fair and open: Apache-2.0 end to end, commercially unrestricted.
- APIs become nodes automatically from their spec.
- Roadmap stated: full dark theme, OIDC in front of the editor, OpenAPI import as subflow.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs o14n.
At a glance
| Based on | Wilhelm-native - no upstream project |
| Type · category | Hosted app · Automation |
| Licence | service Apache-2.0 · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Homepage | wilhelm.tech/o14n |
| Support | wilhelm.tech/support/o14n |
| Docker image | wilhelm/o14n:latest · port 5680 |
| Resources | memory 256Mi · cpu 0.25 · storage 1Gi |
| Tags | automationworkflowsnode-editoropenapireact-flownode-red |
| Folder | apps/o14n/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Service
| Image | wilhelm/o14n:latest |
| Port | 5680 |
| Compose fragment | ./service/compose.fragment.yml |
| Health check | http /healthz every 30s · timeout 5s · 3 retries |
Resources & permissions
| Memory · CPU · storage | 256Mi · 0.25 · 1Gi |
| Host network | no |
| Privileged | no |
| Egress domains | none - no outbound connections declared |
Dependencies
| Requires | nothing |
| Optional | n8n, swagger, nocodb |
| Provides | n8n-workflowsapiui-component |
Single sign-on (OIDC)
| As client | yes |
| As provider | no |
| Fallback | none |
Skin & branding
| Slogan | Automation, fair and open. |
| Theme | primary #00B8A9 · mode system |
| Logo | ./appinfo/icon.svg |
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
ido14ndomaino14nvendorwilhelmnameo14n - open n8ndescriptionFair-code-free n8n alternative: a React-Flow node editor that visualises APIs Swagger-UI-style, driving a headless Node-RED engine (Apache-2.0) over its Admin API.version0.1.0licenseservice, wilhelm
serviceApache-2.0wilhelmProprietarymaintainername, email, url
typehostedcategoryautomationemoji🪢pixelIcon............ .KKKKKKKKKK. .KKKWWWWWWK. .KKKKWWWWWK. .KWWWKKWWWK. .KWWWKKKWWK. .KWWWWWWKKK. .KWWWWWWKKK. .KWWWWWWWWK. .KKKKKKKKKK. ............
primaryColor#00B8A9tagsautomationworkflowsnode-editoropenapireact-flownode-redcompliancecertifications, note
certifications1 item
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.homepagewilhelm.tech/o14npreviewdir, desktop, mobile, capture
dir./previewdesktop./preview/desktop.pngmobile./preview/mobile.pngcaptureurl, wait
wait1500componentsservice, vscode
serviceimage, port, compose, healthCheck
imagewilhelm/o14n:latestport5680healthChecktype, path, interval, timeout, retries
typehttppath/healthzinterval30stimeout5sretries3vscodeextensions, extension
extensions[ ]extensionnullresourcesmemory, cpu, storage
memory256Micpu0.25storage1GipermissionsneedsHostNetwork, needsPrivileged, egressDomains
needsHostNetworkfalseneedsPrivilegedfalseegressDomains[ ]dependenciesrequires, optional, provides
requires[ ]optional3 items
0id
idn8n1id
idswagger2id
idnocodbprovidesn8n-workflowsapiui-componentoidcCapabilityasClient, asProvider, fallback
asClienttrueasProviderfalsefallbacknoneskinslogan, logo, theme
marketplacevisibility, screenshots, pricing, supportUrl
Standalone compose
Every service app can run on its own: cd apps/o14n && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.
docker-compose.yml
# o14n - open n8n - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/o14n/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
# cp .env.example .env && docker compose up -d
# → http://localhost:${O14N_PORT:-5680}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
o14n:
image: wilhelm/o14n:latest
restart: unless-stopped
env_file:
- .env
ports:
- "${O14N_PORT:-5680}:5680"
healthcheck:
test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:5680/healthz"]
interval: 30s
timeout: 5s
retries: 3
start_period: 20s
networks:
- o14n
# TODO: persistent volume(s) if this image stores state. e.g.:
# volumes: [ "o14n_data:/data" ]
networks:
o14n:
name: o14n
.env.example
# o14n - open n8n - standalone env. Copy to .env and fill in. # GENERATED by scripts/generate-standalone.mjs # Host port the app is published on. O14N_PORT=5680 # No declared secrets. Add image-specific env vars here as needed.
README
The README is not in English - see apps/o14n/README.md.
Links & documentation files
Homepage · Support · apps/o14n/
doc/ai-notes.md · doc/api.md · doc/n8n-licensing.md · doc/proposal.md · doc/sources.md
Tusch3D
CAD in the browser, with a pen.
Browser-based CAD with touch and pencil support, in the tradition of German precision tools. Based on Chili3D (AGPL-3.0) - the Tusch3D bridge is a separate sidecar with a clearly separated licence boundary.
What it does
Tusch3D is browser-based CAD with touch and pencil support - the self-hostable alternative to Shapr3D, named after Tusche, the black drafting ink of classical technical drawing. Underneath runs the unmodified Chili3D engine: the OpenCascade kernel compiled to WebAssembly with a three.js renderer, entirely client-side.
Wilhelm adds a slim sidecar bridge for touch gestures and pencil pressure behind a deliberate licence boundary: the AGPL upstream image stays untouched, the MIT bridge talks to it only over HTTP, WebSocket and postMessage.
Features
Box, cylinder, cone, sphere, pyramid; lines, arcs, circles, curves.
Union, difference, intersection; extrude, revolve, sweep, loft; chamfer, fillet, trim.
No install; documents, undo and redo in the browser; import and export.
Bridge endpoints for touch events and pencil pressure.
Why it is in the stack
- CAD in the browser, with a pen - no per-seat iPad CAD licences, no proprietary cloud.
- Runs on any tablet browser; models never leave your stack; upstream stays unpatched.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs tusch3d.
At a glance
| Based on | Chili3d · source · docs |
| Type · category | External service · CAD |
| Licence | service AGPL-3.0 · wrapper MIT · wilhelm MIT |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Homepage | wilhelm.tech |
| Support | wilhelm.tech/support |
| Docker image | ghcr.io/xiangechen/chili3d:latest · port 8910 |
| Resources | memory 1Gi · cpu 1.0 · storage 5Gi |
| Tags | cad3dtouchpencilshapr3d-alternativechili3dopencascade |
| Folder | apps/tusch3d/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Service
| Image | ghcr.io/xiangechen/chili3d:latest |
| Port | 8910 |
| Compose fragment | ./docker-compose.yml |
| Health check | http / every 30s · timeout 5s · 3 retries |
Resources & permissions
| Memory · CPU · storage | 1Gi · 1.0 · 5Gi |
| Host network | no |
| Privileged | no |
| Egress domains | none - no outbound connections declared |
Dependencies
| Requires | nothing |
| Optional | nextcloud, traefik |
| Provides | embedded-app |
Single sign-on (OIDC)
| As client | no |
| As provider | no |
| Fallback | none |
Skin & branding
| Slogan | CAD in the browser, with a pen. |
| Theme | primary #1F4E79 · mode system |
| Logo | ./appinfo/icon.svg |
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
| ISO/IEC 27001 Information security | in progress | software | Wilhelm certification programme - implementation for all Wilhelm apps in progress. |
| WCAG Accessibility | in progress | software | Wilhelm certification programme - implementation for all Wilhelm apps in progress. |
| ISO 9241 Usability / ergonomics | in progress | software | Wilhelm certification programme - implementation for all Wilhelm apps in progress. |
| EAA / BFSG Accessibility | in progress | software | Wilhelm certification programme - implementation for all Wilhelm apps in progress. |
Community project without formal certifications - GDPR compliance follows from self-hosting and rests with the operator.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idtusch3ddomaincadvendortusch3dnameTusch3DdescriptionBrowser-based CAD with touch and pencil support, in the tradition of German precision tools. Based on Chili3D (AGPL-3.0) - the Tusch3D bridge is a separate sidecar with a clearly separated licence boundary.version0.1.0homepagewilhelm.techlicenseservice, wrapper, wilhelm
serviceAGPL-3.0wrapperMITwilhelmMITmaintainername, email, url
typeexternalcategorycademoji📐pixelIcon............ .KKKKKKKKKK. .KWWWKKWWWK. .KWKKWWKKWK. .KKWWWWWWKK. .KKWWKKWWKK. .KKWWKKWWKK. .KWKKKKKKWK. .KWWWKKWWWK. .KKKKKKKKKK. ............
primaryColor#1F4E79tagscad3dtouchpencilshapr3d-alternativechili3dopencascadecompliancecertifications, note
certifications5 items
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.1id, status, scope, note
idiso-27001statusin-progressscopesoftwarenoteWilhelm certification programme - implementation for all Wilhelm apps in progress.2id, status, scope, note
idwcagstatusin-progressscopesoftwarenoteWilhelm certification programme - implementation for all Wilhelm apps in progress.3id, status, scope, note
idiso-9241statusin-progressscopesoftwarenoteWilhelm certification programme - implementation for all Wilhelm apps in progress.4id, status, scope, note
ideaastatusin-progressscopesoftwarenoteWilhelm certification programme - implementation for all Wilhelm apps in progress.noteCommunity project without formal certifications - GDPR compliance follows from self-hosting and rests with the operator.componentsservice, vscode
serviceimage, port, compose, healthCheck
imageghcr.io/xiangechen/chili3d:latestport8910compose./docker-compose.ymlhealthChecktype, path, interval, timeout, retries
typehttppath/interval30stimeout5sretries3vscodeextensions, extension
extensions[ ]extensionnullresourcesmemory, cpu, storage
memory1Gicpu1.0storage5GipermissionsneedsHostNetwork, needsPrivileged, egressDomains
needsHostNetworkfalseneedsPrivilegedfalseegressDomains[ ]dependenciesrequires, optional, provides
requires[ ]optional2 items
0id
idnextcloud1id
idtraefikprovidesembedded-appoidcCapabilityasClient, asProvider, fallback
asClientfalseasProviderfalsefallbacknoneskinslogan, logo, theme
sloganCAD in the browser, with a pen.themeprimary, mode
primary#1F4E79modesystemmarketplacevisibility, screenshots, pricing, supportUrl
Standalone compose
Every service app can run on its own: cd apps/tusch3d && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.
docker-compose.yml
# ============================================================================
# Tusch3D - Browser-CAD (profile: tusch3d)
# ============================================================================
# Zwei-Schichten-Architektur:
#
# Layer 1: chili3d - unmodifiziertes Upstream-Image (AGPL-3.0)
# OpenCascade (WASM) + Three.js sind enthalten.
# KEINE Patches, KEIN Code-Mount in diesen
# Container - sonst greift AGPL-Copyleft
# auf Tusch3D-Eigenleistung über.
#
# Layer 2: tusch3d-bridge - eigener Node.js-Sidecar (MIT).
# Sprache zu Chili3D ausschliesslich über
# öffentliche Wege: HTTP-API, WebSocket,
# postMessage. KEINE shared processes,
# KEINE shared volumes mit ausführbarem Code.
#
# Aktivieren: COMPOSE_PROFILES=tusch3d (oder im .env COMPOSE_PROFILES anhängen)
# ============================================================================
services:
# --------------------------------------------------------------------------
# Layer 1: Chili3D - Upstream Browser-CAD (AGPL-3.0, unmodifiziert)
# --------------------------------------------------------------------------
# Hinweis: Falls xiangechen/chili3d kein offizielles Image veröffentlicht,
# ersetzen durch ein Build-Recipe gegen den Upstream-Master OHNE Patches.
# In diesem Fall: nur Build-Args setzen, NIEMALS Source-Patches einbauen.
chili3d:
image: ghcr.io/xiangechen/chili3d:latest
restart: unless-stopped
ports:
- "127.0.0.1:${TUSCH3D_PORT:-8910}:80"
volumes:
# Persistente Modelle/Projekte. Nur Daten - kein Code-Mount in den
# Container, damit die AGPL-Schicht "unmodified" bleibt.
- tusch3d_models:/data
networks:
- proxy
healthcheck:
test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost/"]
interval: 30s
timeout: 5s
retries: 3
start_period: 20s
labels:
- "traefik.enable=true"
- "traefik.http.routers.tusch3d.rule=Host(`cad.${WILHELM_DOMAIN:-localhost}`)"
- "traefik.http.routers.tusch3d.entrypoints=websecure"
- "traefik.http.routers.tusch3d.tls.certresolver=letsencrypt"
- "traefik.http.services.tusch3d.loadbalancer.server.port=80"
- "traefik.http.routers.tusch3d.middlewares=embed-headers@docker"
profiles: ["tusch3d"]
# --------------------------------------------------------------------------
# Layer 2: Tusch3D-Bridge - Touch/Pencil-Sidecar (MIT, Wilhelm-Eigenleistung)
# --------------------------------------------------------------------------
# Spricht mit chili3d ausschliesslich über HTTP/WebSocket/postMessage.
# Liest/schreibt KEINE Dateien im chili3d-Container, läuft NICHT im selben
# JS-Kontext. Lizenzgrenze: siehe README.md → "Lizenz-Architektur".
tusch3d-bridge:
build:
context: ./bridge
dockerfile: Dockerfile
restart: unless-stopped
environment:
- NODE_ENV=production
- PORT=8911
- LOG_LEVEL=${TUSCH3D_BRIDGE_LOG_LEVEL:-info}
# Nur die öffentliche URL - keine Internals.
- CHILI3D_PUBLIC_URI=http://chili3d:80
ports:
- "127.0.0.1:${TUSCH3D_BRIDGE_PORT:-8911}:8911"
networks:
- proxy
depends_on:
chili3d:
condition: service_healthy
healthcheck:
test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:8911/healthz"]
interval: 30s
timeout: 5s
retries: 3
start_period: 15s
labels:
- "traefik.enable=true"
- "traefik.http.routers.tusch3d-bridge.rule=Host(`cad-bridge.${WILHELM_DOMAIN:-localhost}`)"
- "traefik.http.routers.tusch3d-bridge.entrypoints=websecure"
- "traefik.http.routers.tusch3d-bridge.tls.certresolver=letsencrypt"
- "traefik.http.services.tusch3d-bridge.loadbalancer.server.port=8911"
profiles: ["tusch3d"]
volumes:
tusch3d_models:
name: tusch3d_models
networks:
proxy:
external: true
name: wilhelm-techstack_proxy
.env.example
# ── Tusch3D (Browser-CAD mit Touch + Pencil) ──────────────────────────────── # Chili3D Upstream-UI (unmodifiziert, AGPL-3.0) TUSCH3D_PORT=8910 TUSCH3D_PUBLIC_URI=http://localhost:8910 # Tusch3D-Bridge (eigener Sidecar, MIT) - Touch-/Pencil-Mapping TUSCH3D_BRIDGE_PORT=8911 TUSCH3D_BRIDGE_LOG_LEVEL=info # Embed-Proxy-Port (für iframe-Einbettung in Nextcloud, optional) EMBED_TUSCH3D_PORT=8912
README
The README is not in English - see apps/tusch3d/README.md.
Links & documentation files
Homepage · Upstream docs · Upstream source · Support · apps/tusch3d/
doc/ai-notes.md · doc/api.md · doc/n8n.md · doc/sources.md · doc/tusch3d-reference.md
Amazing Shop
Sell without a landlord.
Amazing Shop: headless commerce (Medusa v2) with storefront, Nextcloud dashboard and stack branding
What it does
Wilhelm Shop is Medusa, the open-source headless commerce engine: products, variants, prices, inventory, regions and currencies, carts, checkout, orders, promotions, payments and fulfilment, with separate Store and Admin APIs and its own admin panel - what Shopify or commercetools provide, on your own PostgreSQL, under MIT.
The storefront is a separate app. In the Wilhelm stack Medusa signs in through the Kernel, its events flow to n8n (invoice to finance and sign, customer to the newsletter), and its products feed the search index and the Wilhelm Cloud product.
Features
Products, variants, price lists, inventory, categories and collections.
Multi-region, multi-currency, taxes and shipping rules.
Cart, checkout, order workflows, promotions, returns.
A React admin for the back office.
Modules, workflows, subscribers, OpenAPI spec.
Why it is in the stack
- Sell without a landlord: no per-order or per-seat platform fee.
- Headless - the storefront is yours; order data is reachable by the rest of the stack.
Screenshots
At a glance
| Based on | Medusa · source · docs · API |
| Replaces | Shopify, WooCommerce · listed as Wilhelm Shop in the ecosystem reference |
| Type · category | External service · Commerce |
| Licence | service MIT · wrapper Proprietary · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support/shop |
| Docker image | ghcr.io/the-wilhelm-project/wilhelm-medusa:latest · port 9000 |
| Compose profile | medusa |
| Nextcloud app id | wilhelmshop · Nextcloud 30-32 |
| Tags | amazingcommerceecommerceshop |
| Folder | apps/shop/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Service
| Image | ghcr.io/the-wilhelm-project/wilhelm-medusa:latest |
| Port | 9000 |
| Health check | http /health every 30s · timeout 5s · 3 retries |
Nextcloud app
| App id | wilhelmshop |
| Path | ./nextcloud |
| Nextcloud versions | 30 - 32 |
Dependencies
| Requires | nextcloud >=30 |
| Optional | vault, storefront, search, n8n |
Single sign-on (OIDC)
| As client | yes |
| As provider | no |
| Fallback | vaultwarden |
Skin & branding
| Slogan | Sell without a landlord. |
| Theme | primary #1C1C1C · mode system |
| Logo | ./nextcloud/appinfo/icon.svg |
Secrets
Declared in apps/shop/secrets.spec.yaml - names and purpose only, values live in .env / the secret store.
| Name | Required | Purpose |
|---|---|---|
MEDUSA_DB_PASSWORD 🔒 | yes | Password of the medusa Postgres user (medusa-db container). |
MEDUSA_JWT_SECRET 🔒 | yes | Signs admin/customer JWTs. Rotating it logs everyone out. |
MEDUSA_COOKIE_SECRET 🔒 | yes | Signs the admin session cookie. |
MEDUSA_ADMIN_EMAIL | yes | First admin user, created on every start if missing. e.g. admin@wilhelm.local |
MEDUSA_ADMIN_PASSWORD 🔒 | yes | Password of the first admin user. Also handed to the Nextcloud app (wilhelmshop) for the admin proxy. |
MEDUSA_PUBLISHABLE_KEY | yes | Store API key of the public sales channel. Generated by the seed; read it from the admin (Settings → Publishable API Keys) and put it here, then restart storefront + nextcloud bootstrap. e.g. pk_... |
MEDUSA_B2B_PUBLISHABLE_KEY | no | Store API key of the internal B2B sales channel used by the Nextcloud app's "Interner Shop" tab. e.g. pk_... |
MEDUSA_STRIPE_KEY | no | Stripe publishable key for the storefront checkout (NEXT_PUBLIC_STRIPE_KEY). e.g. pk_test_... |
STRIPE_API_KEY 🔒 | no | Stripe secret key for the backend payment provider. |
STRIPE_WEBHOOK_SECRET 🔒 | no | Signing secret of the Stripe webhook pointed at /hooks/payment/stripe. |
MOLLIE_API_KEY 🔒 | no | Mollie API key (test_… or live_…). Provider stays inert without it. |
PAYPAL_CLIENT_ID | no | PayPal REST client id. |
PAYPAL_CLIENT_SECRET 🔒 | no | PayPal REST client secret. |
SENDCLOUD_PUBLIC_KEY | no | Sendcloud API public key. The Sendcloud fulfillment provider is only registered when set. |
SENDCLOUD_SECRET_KEY 🔒 | no | Sendcloud API secret key. |
RESEND_API_KEY 🔒 | no | Resend API key for transactional e-mail (order confirmations). Alternative to SENDGRID_API_KEY. |
SLACK_WEBHOOK_URL 🔒 | no | Incoming webhook for the "alerts" notification channel. |
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
| DPA Privacy | compliant | cloud offering | DPA under Art. 28 GDPR for Medusa Cloud customers. source |
Framework without certificates of its own - PCI DSS / GDPR in the finished shop is established by the implementer.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idshopdomainshopvendormedusanameAmazing ShopdescriptionAmazing Shop: headless commerce (Medusa v2) with storefront, Nextcloud dashboard and stack brandingversion2.0.0licenseservice, wrapper, wilhelm
serviceMITwrapperProprietarywilhelmProprietarymaintainername, email, url
typeexternalcategorycommerceemoji🎁pixelIcon............ .K.......... .KK......... ..KKKKKKKK.. ..KWWWWWWK.. ..KWWWWWWK.. ..KKKKKKKK.. ...K....K... ..KKK..KKK.. ..KKK..KKK.. ............
primaryColor#1C1C1Ctagsamazingcommerceecommerceshopcompliancecertifications, note
certifications2 items
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.1id, status, scope, source, note
idgdpr-avvstatuscompliantscopecloudnoteDPA under Art. 28 GDPR for Medusa Cloud customers.noteFramework without certificates of its own - PCI DSS / GDPR in the finished shop is established by the implementer.previewdir, desktop, gallery
dir./previewdesktop./preview/desktop.pnggallery5 items
0src, caption, kind
1src, caption, kind
2src, caption, kind
3src, caption, kind
4src, caption, kind
componentsservice, nextcloudApp, vscode
serviceimage, port, healthCheck
imageghcr.io/the-wilhelm-project/wilhelm-medusa:latestport9000healthChecktype, path, interval, timeout, retries
typehttppath/healthinterval30stimeout5sretries3nextcloudAppappid, path, minNcVersion, maxNcVersion
vscodeextensions, extension
extensions[ ]extensionnulldependenciesrequires, optional
requires1 item
0id, version
idnextcloudversion>=30optional4 items
0id
idvault1id
idstorefront2id
idsearch3id
idn8noidcCapabilityasClient, asProvider, fallback
asClienttrueasProviderfalsefallbackvaultwardensecretsRefs./secrets.spec.yamlskinslogan, logo, theme
sloganSell without a landlord.themeprimary, mode
primary#1C1C1Cmodesystemmarketplacevisibility, screenshots, pricing, supportUrl
Standalone compose
Every service app can run on its own: cd apps/shop && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.
docker-compose.yml
# Wilhelm Shop - standalone Docker compose (hand-authored)
#
# Medusa needs Postgres + Redis, so the generic standalone generator
# (scripts/generate-standalone.mjs) is NOT used for this app - it only knows
# single-container images. This file is left alone by the generator.
#
# Quickstart:
# cp .env.example .env && docker compose up -d
# → API http://localhost:${MEDUSA_BACKEND_PORT:-9000} (admin: /app)
# → Shop http://localhost:${MEDUSA_STOREFRONT_PORT:-8000}
#
# Inside the Wilhelm monorepo the same services live in the root
# docker-compose.yml (profile "medusa", shared traefik + Nextcloud app).
services:
medusa:
image: ghcr.io/the-wilhelm-project/wilhelm-medusa:latest
build: ./service/app
restart: unless-stopped
env_file:
- .env
environment:
- NODE_ENV=production
- PORT=9000
- DATABASE_URL=postgres://medusa:${MEDUSA_DB_PASSWORD:-change_me}@medusa-db:5432/medusa
- REDIS_URL=redis://medusa-redis:6379
- JWT_SECRET=${MEDUSA_JWT_SECRET:-change_me_jwt}
- COOKIE_SECRET=${MEDUSA_COOKIE_SECRET:-change_me_cookie}
- STORE_CORS=${MEDUSA_STORE_CORS:-http://localhost:8000}
- ADMIN_CORS=${MEDUSA_ADMIN_CORS:-http://localhost:9000}
- AUTH_CORS=${MEDUSA_AUTH_CORS:-http://localhost:9000}
- DISABLE_MEDUSA_ADMIN=${MEDUSA_DISABLE_ADMIN:-false}
- MEDUSA_BACKEND_URL=${NEXT_PUBLIC_MEDUSA_BACKEND_URL:-http://localhost:9000}
- STOREFRONT_URL=${MEDUSA_STOREFRONT_URL:-http://localhost:8000}
depends_on:
medusa-db:
condition: service_healthy
medusa-redis:
condition: service_started
ports:
- "${MEDUSA_BACKEND_PORT:-9000}:9000"
volumes:
- medusa_uploads:/server/uploads
healthcheck:
test: ["CMD-SHELL", "wget -qO- http://127.0.0.1:9000/health || exit 1"]
interval: 15s
timeout: 10s
retries: 20
start_period: 120s
networks:
- shop
medusa-db:
image: postgres:16-alpine
restart: unless-stopped
environment:
- POSTGRES_DB=medusa
- POSTGRES_USER=medusa
- POSTGRES_PASSWORD=${MEDUSA_DB_PASSWORD:-change_me}
volumes:
- medusa_db:/var/lib/postgresql/data
healthcheck:
test: ["CMD-SHELL", "pg_isready -U medusa"]
interval: 10s
timeout: 5s
retries: 5
networks:
- shop
medusa-redis:
image: redis:7-alpine
restart: unless-stopped
command: redis-server --appendonly yes
volumes:
- medusa_redis:/data
networks:
- shop
medusa-storefront:
image: ghcr.io/the-wilhelm-project/wilhelm-medusa-storefront:latest
build:
context: ../storefront/app
args:
NEXT_PUBLIC_MEDUSA_BACKEND_URL: ${NEXT_PUBLIC_MEDUSA_BACKEND_URL:-http://localhost:9000}
NEXT_PUBLIC_BASE_URL: ${MEDUSA_STOREFRONT_URL:-http://localhost:8000}
NEXT_PUBLIC_MEDUSA_PUBLISHABLE_KEY: ${MEDUSA_PUBLISHABLE_KEY:-pk_build_placeholder}
restart: unless-stopped
env_file:
- .env
environment:
- MEDUSA_BACKEND_URL=http://medusa:9000
- NEXT_PUBLIC_MEDUSA_BACKEND_URL=${NEXT_PUBLIC_MEDUSA_BACKEND_URL:-http://localhost:9000}
- NEXT_PUBLIC_BASE_URL=${MEDUSA_STOREFRONT_URL:-http://localhost:8000}
- NEXT_PUBLIC_MEDUSA_PUBLISHABLE_KEY=${MEDUSA_PUBLISHABLE_KEY:-}
- NEXT_PUBLIC_STRIPE_KEY=${MEDUSA_STRIPE_KEY:-}
depends_on:
medusa:
condition: service_healthy
ports:
- "${MEDUSA_STOREFRONT_PORT:-8000}:8000"
networks:
- shop
volumes:
medusa_db:
medusa_redis:
medusa_uploads:
networks:
shop:
name: shop
.env.example
# ── Wilhelm Shop (Medusa v2, Headless Commerce) ───────────────────────────── # Inside the Wilhelm stack these live in the root .env (see secrets.spec.yaml). # Standalone (this folder's docker-compose.yml) reads this file directly. # Postgres / secrets MEDUSA_DB_PASSWORD=change_me MEDUSA_JWT_SECRET=change_me_jwt MEDUSA_COOKIE_SECRET=change_me_cookie # First admin (created on start if missing) MEDUSA_ADMIN_EMAIL=admin@wilhelm.local MEDUSA_ADMIN_PASSWORD=change_me # Public URLs (CORS + links in mails/redirects) MEDUSA_BACKEND_PORT=9000 NEXT_PUBLIC_MEDUSA_BACKEND_URL=http://localhost:9000 MEDUSA_STOREFRONT_PORT=8000 MEDUSA_STOREFRONT_URL=http://localhost:8000 MEDUSA_STORE_CORS=http://localhost:8000 MEDUSA_ADMIN_CORS=http://localhost:9000 MEDUSA_AUTH_CORS=http://localhost:9000 # Store API keys (from the admin after the first start / seed) MEDUSA_PUBLISHABLE_KEY= MEDUSA_B2B_PUBLISHABLE_KEY= MEDUSA_B2B_GROUP=InternalShop # Payments (all optional - providers stay visible in the admin but inert) MEDUSA_STRIPE_KEY= STRIPE_API_KEY= STRIPE_WEBHOOK_SECRET= MOLLIE_API_KEY= PAYPAL_CLIENT_ID= PAYPAL_CLIENT_SECRET= PAYPAL_ENVIRONMENT=sandbox # Fulfillment / notifications / search (optional) SENDCLOUD_PUBLIC_KEY= SENDCLOUD_SECRET_KEY= RESEND_API_KEY= RESEND_FROM= SLACK_WEBHOOK_URL= MEILI_HTTP_ADDR= MEILI_MASTER_KEY= MEDUSA_DISABLE_ADMIN=false # ── Brand (inherited from the stack: config/stack.defaults.env) ───────────── # Served by GET /store/brand → storefront + Nextcloud app. The admin theme # editor layers overrides on top of these. WILHELM_BRAND_NAME=Wilhelm WILHELM_BRAND_SHORT_NAME=Wilhelm WILHELM_BRAND_SLOGAN= WILHELM_BRAND_PRIMARY_COLOR=#0369FF WILHELM_BRAND_ACCENT_COLOR=#FFCC00 WILHELM_BRAND_BACKGROUND_COLOR=#FFFFFF WILHELM_BRAND_FOREGROUND_COLOR=#111111 WILHELM_BRAND_MUTED_COLOR=#6B7280 WILHELM_BRAND_BORDER_COLOR=#E5E7EB WILHELM_BRAND_SURFACE_COLOR=#F9FAFB WILHELM_BRAND_FONT_FAMILY=Inter, -apple-system, BlinkMacSystemFont, sans-serif WILHELM_BRAND_FONT_DISPLAY=Inter, -apple-system, BlinkMacSystemFont, sans-serif WILHELM_BRAND_RADIUS=12px WILHELM_BRAND_LOGO_URL= WILHELM_BRAND_LOGO_DARK_URL= WILHELM_BRAND_FAVICON_URL= WILHELM_BRAND_URL= WILHELM_BRAND_IMPRINT_URL= WILHELM_BRAND_PRIVACY_URL= WILHELM_BRAND_TERMS_URL= WILHELM_BRAND_SUPPORT_EMAIL= WILHELM_BRAND_LUCID_NUMBER= WILHELM_BRAND_VAT_ID= WILHELM_BRAND_TRUST_SEAL_ID=
README
The README is not in English - see apps/shop/README.md.
Links & documentation files
Upstream docs · Upstream API · Upstream source · Support · apps/shop/
doc/ai-notes.md · doc/api.md · doc/n8n.md · doc/shop-reference.md · doc/sources.md
TaskHQ
The stack in a Task Manager.
Windows 95 desktop (react95) for Docker: program windows with a window manager, start menu and taskbar. A Task-Manager-style Docker manager (Apps/Kernel/Performance/Info), the Wilhelm graph as an embedded node-canvas window, Setup/Configs/Terminal/My Computer as programs of their own; the raw canvas stays reachable via ?view=canvas.
What it does
TaskHQ is the stack's control plane, styled as a Windows 95 desktop: a window manager, start menu and taskbar in which every Wilhelm app opens as a program window. A Task-Manager-style Docker manager shows apps, kernel, performance and info; Boot, Setup, Configs, Terminal and Workplace are programs of their own; the Wilhelm graph is a node canvas window. It replaces Portainer and Docker Desktop for this stack.
The rule across the repository is that nobody runs docker compose by hand - the stack is started, restarted, stopped and shut down through TaskHQ (or the ARM Wilhelm CLI), with a traffic light, a boot-order plan, diagnostics and a gate doctor that tells you which services are exposed unintentionally.
Features
Start, restart, stop, shut down the whole stack with a progress line and a stack traffic light.
Edit compose profiles with live image and RAM estimates.
Boot-order plan, ports and stack doctor findings, history, backup, installer.
Per-service log streams, error and event tabs.
Traefik routers, firewall, gate classification: gated, open by design, sealed, internal.
Every app becomes a desktop program with no front-end code; window geometry from the manifest.
Host mode works before the stack is up; container mode mounts the Docker socket.
Everything the desktop does is an authenticated API call.
Why it is in the stack
- The stack in a Task Manager - one real desktop to operate a self-hosted company stack.
- A safe operations vocabulary instead of raw compose commands; new apps appear automatically.
- The gate doctor makes unintended exposure visible.
Screenshots
The Task Manager window with CPU and memory history and container counters, the Workplace window listing disks and network drives, a Wilhelm root terminal and an Enter terminal running the coding agent. Desktop icons for Enter, processes, settings, setup, the Wilhelm graph and the terminals; the taskbar at the bottom lists the open windows.
desktop.pngThe desktop on a phone-sized viewport.
mobile.pngScreenshots are the upstream project's official product shots (see preview/SOURCES.md) until the stack runs with demo data and tools/app-preview shoots real Wilhelm screens. Images © their respective projects.
At a glance
| Based on | Wilhelm taskhq (@wilhelm/taskhq) |
| Type · category | External service · Core |
| Licence | service MIT · wrapper Proprietary · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support/tasks |
| Docker image | taskhq/taskhq:latest · port 3060 |
| Public URL | https://admin.<your-domain> |
| Compose profile | taskhq |
| Nextcloud app id | wilhelmtaskhq · Nextcloud 30-32 |
| Tags | admindockercore |
| Folder | apps/tasks/manifest.json |
Icon & assets
tools/app-assets → appinfo/ · serving copy in ./service/app/public
Configuration
Service
| Image | taskhq/taskhq:latest |
| Port | 3060 |
| Health check | http / every 30s · timeout 5s · 3 retries |
Embedding in Nextcloud
| Registry id · label | taskhq · Wilhelm TaskHQ |
| Subdomain | admin · gateway mode taskhq |
| Container | taskhq:3060 |
| Embed-proxy port (localhost) | 8975 |
| Compose profile | taskhq |
| Nextcloud config key | taskhq_url |
Nextcloud app
| App id | wilhelmtaskhq |
| Path | ./nextcloud |
| Nextcloud versions | 30 - 32 |
Dependencies
| Requires | nextcloud >=30 |
| Optional | vault |
Single sign-on (OIDC)
| As client | yes |
| As provider | no |
| Fallback | vaultwarden |
Skin & branding
| Slogan | The stack in a Task Manager. |
| Theme | primary #0369FF · mode system |
| Logo | ./service/appinfo/icon.svg |
Secrets
Declared in secretsRefs but apps/tasks/secrets.spec.yaml does not exist in the repository.
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
| ISO/IEC 27001 Information security | in progress | software | Wilhelm certification programme - implementation for all Wilhelm apps in progress. |
| WCAG Accessibility | in progress | software | Wilhelm certification programme - implementation for all Wilhelm apps in progress. |
| ISO 9241 Usability / ergonomics | in progress | software | Wilhelm certification programme - implementation for all Wilhelm apps in progress. |
| EAA / BFSG Accessibility | in progress | software | Wilhelm certification programme - implementation for all Wilhelm apps in progress. |
Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idtasksdomaintasksvendortaskhqnameTaskHQdescriptionWindows 95 desktop (react95) for Docker: program windows with a window manager, start menu and taskbar. A Task-Manager-style Docker manager (Apps/Kernel/Performance/Info), the Wilhelm graph as an embedded node-canvas window, Setup/Configs/Terminal/My Computer as programs of their own; the raw canvas stays reachable via ?view=canvas.version2.0.0licenseservice, wrapper, wilhelm
serviceMITwrapperProprietarywilhelmProprietarymaintainername, email, url
typeexternalcategorycoreemoji✅pixelIcon............ .KKKKKKKKKK. .KWWWWWWWWK. .KWWWWWWKWK. .KWWWWWKKWK. .KWKWWKKWWK. .KWKKKKWWWK. .KWWKKWWWWK. .KWWWWWWWWK. .KKKKKKKKKK. ............
primaryColor#0369FFtagsadmindockercorecompliancecertifications, note
certifications5 items
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.1id, status, scope, note
idiso-27001statusin-progressscopesoftwarenoteWilhelm certification programme - implementation for all Wilhelm apps in progress.2id, status, scope, note
idwcagstatusin-progressscopesoftwarenoteWilhelm certification programme - implementation for all Wilhelm apps in progress.3id, status, scope, note
idiso-9241statusin-progressscopesoftwarenoteWilhelm certification programme - implementation for all Wilhelm apps in progress.4id, status, scope, note
ideaastatusin-progressscopesoftwarenoteWilhelm certification programme - implementation for all Wilhelm apps in progress.noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.previewdir, desktop, mobile, gallery, capture
dir./previewdesktop./preview/desktop.pngmobile./preview/mobile.pnggallery2 items
0src, caption, kind
1src, caption, kind
captureurl, wait
urltaskhq:3060wait1200componentsservice, nextcloudApp, embed, vscode
serviceimage, port, healthCheck
imagetaskhq/taskhq:latestport3060healthChecktype, path, interval, timeout, retries
typehttppath/interval30stimeout5sretries3nextcloudAppappid, path, minNcVersion, maxNcVersion
embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile, gatewaySubdomain
idtaskhqlabelWilhelm TaskHQncConfigKeytaskhq_urlsubdomainadmincontainertaskhqcontainerPort3060embedProxyPort8975profiletaskhqgatewaySubdomaintaskhqvscodeextensions, extension
extensions[ ]extensionnulldependenciesrequires, optional
requires1 item
0id, version
idnextcloudversion>=30optional1 item
0id
idvaultoidcCapabilityasClient, asProvider, fallback
asClienttrueasProviderfalsefallbackvaultwardensecretsRefs./secrets.spec.yamlskinslogan, logo, theme
sloganThe stack in a Task Manager.themeprimary, mode
primary#0369FFmodesystemmarketplacevisibility, screenshots, pricing, supportUrl
visibilitypublicscreenshots./preview/desktop.png./preview/mobile.png./preview/gallery/01-stack-canvas.jpg./preview/gallery/02-wilhelm-boot.jpgpricingfreesupportUrlwilhelm.tech/support/taskswebpublicDir
publicDir./service/app/publicStandalone compose
Every service app can run on its own: cd apps/tasks && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.
docker-compose.yml
# TaskHQ - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/tasks/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
# cp .env.example .env && docker compose up -d
# → http://localhost:${TASKS_PORT:-3060}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
tasks:
image: taskhq/taskhq:latest
restart: unless-stopped
env_file:
- .env
ports:
- "${TASKS_PORT:-3060}:3060"
healthcheck:
test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:3060/"]
interval: 30s
timeout: 5s
retries: 3
start_period: 20s
networks:
- tasks
# TODO: persistent volume(s) if this image stores state. e.g.:
# volumes: [ "tasks_data:/data" ]
networks:
tasks:
name: tasks
.env.example
# TaskHQ - standalone env. Copy to .env and fill in. # GENERATED by scripts/generate-standalone.mjs # Host port the app is published on. TASKS_PORT=3060 # Required secrets are specified in: # ./secrets.spec.yaml # Add the matching KEY=VALUE lines here.
README
The README is not in English - see apps/tasks/README.md.
Links & documentation files
doc/ai-notes.md · doc/api.md · doc/sources.md · doc/tasks-reference.md
CRM
Customers in view, not in spreadsheets.
Twenty CRM embedded in Nextcloud
What it does
CRM is Twenty, the open-source CRM that sets out to be what Salesforce and HubSpot are for sales teams - people, companies, opportunities, pipelines, notes, tasks and e-mail in one place - without the licence model that makes every additional seat and every additional object a negotiation.
Twenty's data model is fully customisable: standard objects such as companies and opportunities can be extended with fields, and entirely new objects can be added, all of them available in table and kanban views with sorting, filtering and grouping. Workflows, an API, webhooks and, in newer versions, AI agents that answer questions across your records make it a platform rather than a contact list.
Features
Standard objects (companies, people, opportunities) plus your own objects and fields, with relations between them.
Every object in a spreadsheet-like table or a kanban board, with saved sorts and filters.
Connect mailboxes and calendars so conversations and meetings appear on the record they belong to.
Trigger-action automation inside the CRM - when a person is created, search records and send an e-mail.
Charts over pipeline, revenue and activity that update with the data.
Natural-language questions over your CRM data and agents that draft e-mails or act on records, using the model of your choice.
Custom objects, tools, serverless functions, widgets, layout pages and commands - build the CRM you need on top of Twenty.
Everything in the UI is reachable from code and from n8n.
Why it is in the stack
- Replaces Salesforce and HubSpot for the everyday work of a sales team, under an AGPL licence, on your own server.
- The Wilhelm skin turns Twenty into garyn.ai, the emotional contact manager - same data, a different face.
- Data lives in your Wilhelm stack next to mail, calendar and files; SSO, n8n workflows and the Wilhelm API connect it to everything else.
Screenshots
Custom data model, kanban views, custom workflows, sorts and filters, e-mail and calendar sync, live dashboards and a command palette - the standard CRM feature set, all of it in the open-source core.
01-crm-tools.jpgChoose the model behind your agents, let an agent write an e-mail as a workflow step, or ask the CRM directly what deals you have in the pipeline. Model access can be routed through the stack's own gateway.
02-ai-agents.jpgFront-end components and code live in a normal repository: a coding agent creates a component to display your close rate, commits it, and the CRM picks it up.
03-build-apps.jpgThe three extension layers: custom objects and fields (data model), tools, serverless functions and skills (logic), and views, widgets, layout pages and commands (layout).
04-all-tools.jpgScreenshots are the upstream project's official product shots (see preview/SOURCES.md) until the stack runs with demo data and tools/app-preview shoots real Wilhelm screens. Images © their respective projects.
At a glance
| Based on | Twenty CRM · source · docs · API |
| Replaces | Salesforce, HubSpot · listed as Wilhelm CRM in the ecosystem reference |
| Type · category | External service · CRM |
| Licence | service AGPL-3.0 · wrapper Proprietary · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support/crm |
| Docker image | twentycrm/twenty:latest · port 3000 |
| Compose profile | crm |
| Nextcloud app id | wilhelmcrm · Nextcloud 30-32 |
| Tags | crmcontacts |
| Folder | apps/crm/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Service
| Image | twentycrm/twenty:latest |
| Port | 3000 |
| Init script | ./service/init-twenty.sh |
| Health check | http /healthz every 30s · timeout 5s · 3 retries |
Nextcloud app
| App id | wilhelmcrm |
| Path | ./nextcloud |
| Nextcloud versions | 30 - 32 |
Dependencies
| Requires | nextcloud >=30 |
| Optional | vault |
| Required by | garyn |
Single sign-on (OIDC)
| As client | yes |
| As provider | no |
| Fallback | vaultwarden |
Skin & branding
| Slogan | Customers in view, not in spreadsheets. |
| Theme | primary #1C1C1C · mode system |
| Logo | ./nextcloud/appinfo/icon.svg |
Secrets
Declared in secretsRefs but apps/crm/secrets.spec.yaml does not exist in the repository.
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
| DPA Privacy | compliant | cloud offering | Published DPA with SCC safeguards for EEA/UK/CH data transfers. source |
| SOC 2 Type II Information security | in progress | cloud offering | SOC 2 Type II in progress according to the trust center, no completed audit report yet. source |
Young project: DPA available, SOC 2 in progress; no ISO/WCAG evidence.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idcrmdomaincrmvendortwentynameCRMdescriptionTwenty CRM embedded in Nextcloudversion2.0.0licenseservice, wrapper, wilhelm
serviceAGPL-3.0wrapperProprietarywilhelmProprietarymaintainername, email, url
typeexternalcategorycrmemoji🤝pixelIcon............ .KKKKKKKKKK. .KWWWWWWWWK. .KWWKKWWWWK. .KWWKKWKKWK. .KWWWWWWWWK. .KWKKKKWWWK. .KWKKKKKKWK. .KWWWWWWWWK. .KKKKKKKKKK. ............ ............
primaryColor#1C1C1Ctagscrmcontactscompliancecertifications, note
certifications3 items
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.1id, status, scope, source, note
idgdpr-avvstatuscompliantscopecloudsourcetwenty.com/legal/dpanotePublished DPA with SCC safeguards for EEA/UK/CH data transfers.2id, status, scope, source, note
idsoc2-type2statusin-progressscopecloudnoteSOC 2 Type II in progress according to the trust center, no completed audit report yet.noteYoung project: DPA available, SOC 2 in progress; no ISO/WCAG evidence.componentsservice, nextcloudApp, vscode
serviceimage, port, healthCheck, init
imagetwentycrm/twenty:latestport3000healthChecktype, path, interval, timeout, retries
typehttppath/healthzinterval30stimeout5sretries3nextcloudAppappid, path, minNcVersion, maxNcVersion
vscodeextensions, extension
extensions[ ]extensionnulldependenciesrequires, optional
requires1 item
0id, version
idnextcloudversion>=30optional1 item
0id
idvaultoidcCapabilityasClient, asProvider, fallback
asClienttrueasProviderfalsefallbackvaultwardensecretsRefs./secrets.spec.yamlskinslogan, logo, theme
sloganCustomers in view, not in spreadsheets.themeprimary, mode
primary#1C1C1Cmodesystempreviewdir, gallery
dir./previewgallery4 items
0src, caption, kind
1src, caption, kind
2src, caption, kind
3src, caption, kind
marketplacevisibility, screenshots, pricing, supportUrl
visibilitypublicscreenshots./preview/gallery/01-crm-tools.jpg./preview/gallery/02-ai-agents.jpg./preview/gallery/03-build-apps.jpg./preview/gallery/04-all-tools.jpgpricingfreesupportUrlwilhelm.tech/support/crmStandalone compose
Every service app can run on its own: cd apps/crm && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.
docker-compose.yml
# CRM - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/crm/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
# cp .env.example .env && docker compose up -d
# → http://localhost:${CRM_PORT:-3000}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
crm:
image: twentycrm/twenty:latest
restart: unless-stopped
env_file:
- .env
ports:
- "${CRM_PORT:-3000}:3000"
healthcheck:
test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:3000/healthz"]
interval: 30s
timeout: 5s
retries: 3
start_period: 20s
networks:
- crm
# TODO: persistent volume(s) if this image stores state. e.g.:
# volumes: [ "crm_data:/data" ]
networks:
crm:
name: crm
.env.example
# CRM - standalone env. Copy to .env and fill in. # GENERATED by scripts/generate-standalone.mjs # Host port the app is published on. CRM_PORT=3000 # Required secrets are specified in: # ./secrets.spec.yaml # Add the matching KEY=VALUE lines here.
README
The README is not in English - see apps/crm/README.md.
Links & documentation files
Upstream docs · Upstream API · Upstream source · Support · apps/crm/
doc/ai-notes.md · doc/api.md · doc/crm-reference.md · doc/n8n.md · doc/sources.md
garyn.ai
Your network - and it remembers.
Emotional contact manager on top of Twenty: Excel sync, Nextcloud contacts, Gary chatbot. Looks like WhatsApp x LinkedIn x Instagram.
What it does
garyn.ai is the emotional contact manager: it looks like WhatsApp × LinkedIn × Instagram, thinks like a CRM and talks like WilheLLM. Contacts come from an Excel file on Nextcloud, land in Twenty as the data hub, and are then usable in sync from Nextcloud Contacts, Nextcloud Mail and the Gary chat.
Twenty stays unforked and headless underneath; garyn adds three clean layers - a Twenty SDK app that brings the WilheLLM engine in as an agent tool, a Gary app with personality and sync logic, and the social-style front end wrapped in Nextcloud. Status: phase 0, scaffold and documentation.
Features
A spreadsheet on Nextcloud is the source; star topology with documented conflict rules.
Ask questions over your own contact graph; Gary remembers.
Feed, profiles and chat instead of tables.
The same people everywhere.
Schemas and a phased plan ship with the app.
Why it is in the stack
- Your network - and it remembers: consumer-grade UX on top of CRM data.
- No fork of Twenty, so upgrades stay possible.
- The relationship graph and the AI on top of it stay on your own server.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs garyn.
At a glance
| Based on | Wilhelm-native - no upstream project |
| Type · category | Nextcloud app · CRM |
| Licence | service Apache-2.0 · wilhelm Apache-2.0 |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support |
| Nextcloud app id | garyn · Nextcloud 30-32 |
| Resources | memory 256Mi · cpu 0.25 · storage 1Gi |
| Tags | crmcontactschatbotrelationshipstwentywilhe-llm |
| Folder | apps/garyn/manifest.json |
Icon & assets
tools/app-assets → appinfo/ · serving copy in ./service/app/public
Configuration
Service
| Compose fragment | ./service/compose.fragment.yml |
| Init script | ./service/init.sh |
| Health check | http /healthz every 30s · timeout 5s · 3 retries |
Nextcloud app
| App id | garyn |
| Path | ./nextcloud |
| Nextcloud versions | 30 - 32 |
Desktop build (Electron)
| Enabled | no - opted out |
| Start path | /index.php/apps/garyn/ |
| Hide Nextcloud chrome | yes |
Resources & permissions
| Memory · CPU · storage | 256Mi · 0.25 · 1Gi |
| Host network | no |
| Privileged | no |
| Egress domains | none - no outbound connections declared |
Dependencies
| Requires | nextcloud >=30, crm |
| Optional | n8n, wilhe-llm, vault |
| Provides | nc-appn8n-workflowsapi |
Single sign-on (OIDC)
| As client | no |
| As provider | no |
| Fallback | none |
Skin & branding
| Slogan | Your network - and it remembers. |
| Theme | primary #FF6B5C · accent #1A1A2E · mode system |
| Logo | ./brand/gary-mascot.svg |
| Agent persona | Gary - “Hi, I'm Gary!” |
| Whitelabel target | crm |
Secrets
Declared in secretsRefs but apps/garyn/secrets.spec.yaml does not exist in the repository.
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
| ISO/IEC 27001 Information security | in progress | software | Wilhelm certification programme - implementation for all Wilhelm apps in progress. |
| WCAG Accessibility | in progress | software | Wilhelm certification programme - implementation for all Wilhelm apps in progress. |
| ISO 9241 Usability / ergonomics | in progress | software | Wilhelm certification programme - implementation for all Wilhelm apps in progress. |
| EAA / BFSG Accessibility | in progress | software | Wilhelm certification programme - implementation for all Wilhelm apps in progress. |
Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idgaryndomaincontactsvendorwilhelmnamegaryn.aidescriptionEmotional contact manager on top of Twenty: Excel sync, Nextcloud contacts, Gary chatbot. Looks like WhatsApp x LinkedIn x Instagram.version2.0.0licenseservice, wilhelm
serviceApache-2.0wilhelmApache-2.0maintainername, email, url
typenc-appcategorycrmicon./icon.svgemoji🫂pixelIcon............ ..KK...KK... .KWWK.KWWK.. .KWWWKWWWK.. .KWWWWWWWK.. ..KWWWWWK... ...KWWWK.... ....KWK..... .....K...... ............ ............ ............
primaryColor#FF6B5Ctagscrmcontactschatbotrelationshipstwentywilhe-llmcompliancecertifications, note
certifications5 items
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.1id, status, scope, note
idiso-27001statusin-progressscopesoftwarenoteWilhelm certification programme - implementation for all Wilhelm apps in progress.2id, status, scope, note
idwcagstatusin-progressscopesoftwarenoteWilhelm certification programme - implementation for all Wilhelm apps in progress.3id, status, scope, note
idiso-9241statusin-progressscopesoftwarenoteWilhelm certification programme - implementation for all Wilhelm apps in progress.4id, status, scope, note
ideaastatusin-progressscopesoftwarenoteWilhelm certification programme - implementation for all Wilhelm apps in progress.noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.webpublicDir
publicDir./service/app/publicpreviewdir, desktop, mobile, capture
dir./previewdesktop./preview/desktop.pngmobile./preview/mobile.pngcaptureurl, wait
urlgaryn:8910wait1000componentsservice, nextcloudApp, vscode
serviceimage, compose, init, healthCheck
imagehealthChecktype, path, interval, timeout, retries
typehttppath/healthzinterval30stimeout5sretries3nextcloudAppappid, path, minNcVersion, maxNcVersion
vscodeextensions, extension
extensions[ ]extensionnulldesktopenabled, startPath, hideNextcloudChrome
enabledfalsestartPath/index.php/apps/garyn/hideNextcloudChrometrueresourcesmemory, cpu, storage
memory256Micpu0.25storage1GipermissionsneedsHostNetwork, needsPrivileged, egressDomains
needsHostNetworkfalseneedsPrivilegedfalseegressDomains[ ]dependenciesrequires, optional, provides
requires2 items
0id, version
idnextcloudversion>=301id
idcrmoptional3 items
0id
idn8n1id
idwilhe-llm2id
idvaultprovidesnc-appn8n-workflowsapioidcCapabilityasClient, asProvider, fallback
asClientfalseasProviderfalsefallbacknonesecretsRefs./secrets.spec.yamlskinslogan, logo, wordmark, signet, icon, favicon, theme, agent, overlay, whitelabel, env
sloganYour network - and it remembers.wordmark./brand/gary-wortmarke.svgsignet./brand/gary-signet.svgthemeprimary, accent, mode
primary#FF6B5Caccent#1A1A2Emodesystemagentname, greeting, persona
overlayjs, css, assets
whitelabeltarget, applyWith
targetcrmapplyWith./branding/twenty/deploy.shenvPWA_NAME
PWA_NAMEGaryNmarketplacevisibility, screenshots, pricing, supportUrl
Standalone compose
Every service app can run on its own: cd apps/garyn && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.
docker-compose.yml
# garyn.ai - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/garyn/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
# cp .env.example .env && docker compose up -d
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
garyn:
build:
context: ./service
restart: unless-stopped
env_file:
- .env
networks:
- garyn
# TODO: persistent volume(s) if this image stores state. e.g.:
# volumes: [ "garyn_data:/data" ]
networks:
garyn:
name: garyn
.env.example
# garyn.ai - standalone env. Copy to .env and fill in. # GENERATED by scripts/generate-standalone.mjs # Required secrets are specified in: # ./secrets.spec.yaml # Add the matching KEY=VALUE lines here.
README
The README is not in English - see apps/garyn/README.md.
Links & documentation files
doc/ai-notes.md · doc/api.md · doc/datamodel.md · doc/sources.md · doc/sync.md
ACID
Documents in, formats out.
ACID dashboard embedded in Nextcloud
What it does
ACID - the Augmented Content Identifier - is the Wilhelm document pipeline's dashboard: drop files in, name the JSON schema you want them extracted against, and watch them become structured records with a confidence score. It is the visible front of what document-capture products such as ABBYY or the cloud OCR/IDP services do behind a form.
ACID itself is a React single-page app with no backend of its own. It talks to the converter API in the Kernel, and n8n orchestrates the pipeline behind it; the extracted results are filed into NocoDB as ordinary records the rest of the stack can query.
Features
Send files with a target JSON schema; the pipeline extracts fields, not just text.
See what is in the queue, what is processing and what is done, with the extracted data and confidence per file.
Online check and a live feed of the pipeline while it runs.
Flow graph, map, globe and charts over the extracted entities and their relations.
Schemas are kept locally and reused across uploads.
Send a file from Nextcloud straight into the pipeline.
Simulates a processing cycle without a backend, for evaluation and screenshots.
Why it is in the stack
- Documents in, formats out: a PDF pile becomes structured business data in NocoDB, ready for the CRM, finance or search.
- The whole pipeline (OCR gateway, n8n, NocoDB) runs in your own stack; nothing is uploaded to an IDP vendor.
- A dashboard-first view on a batch process that is otherwise invisible.
Screenshots
Entities extracted from eight documents - companies, documents, persons, locations - placed on a map with their relations (document reference, ownership, location) drawn between them. The header shows the pipeline counters (in, processing, done) and the live feed; the left rail switches between dashboard, files, schema templates and map.
desktop.pngThe same dashboard on a phone-sized viewport.
mobile.pngAt a glance
| Based on | Wilhelm acid |
| Type · category | External service · Dashboards |
| Licence | service MIT · wrapper Proprietary · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support/acid |
| Docker image | acid/acid:latest · port 3050 |
| Public URL | https://acid.<your-domain> |
| Compose profile | acid |
| Nextcloud app id | wilhelmacid · Nextcloud 30-32 |
| Tags | dashboardadmin |
| Folder | apps/acid/manifest.json |
Icon & assets
tools/app-assets → appinfo/ · serving copy in ./service/app/public
Configuration
Service
| Image | acid/acid:latest |
| Port | 3050 |
| Health check | http /healthz every 30s · timeout 5s · 3 retries |
Embedding in Nextcloud
| Registry id · label | acid · ACID Document Pipeline |
| Subdomain | acid |
| Container | acid:3050 |
| Embed-proxy port (localhost) | 8914 |
| Compose profile | acid |
| Nextcloud config key | acid_app_url |
Nextcloud app
| App id | wilhelmacid |
| Path | ./nextcloud |
| Nextcloud versions | 30 - 32 |
Dependencies
| Requires | nextcloud >=30 |
| Optional | vault |
Single sign-on (OIDC)
| As client | yes |
| As provider | no |
| Fallback | vaultwarden |
Skin & branding
| Slogan | Documents in, formats out. |
| Theme | primary #FFCC00 · mode system |
| Logo | ./nextcloud/appinfo/icon.svg |
Secrets
Declared in secretsRefs but apps/acid/secrets.spec.yaml does not exist in the repository.
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idaciddomainacidvendoracidnameACIDdescriptionACID dashboard embedded in Nextcloudversion2.0.0licenseservice, wrapper, wilhelm
serviceMITwrapperProprietarywilhelmProprietarymaintainername, email, url
typeexternalcategorydashboardemoji🧪pixelIcon............ .KKKKKKKKKK. .KWWWKKWWWK. .KWWWKKWWWK. .KWWKWWKWWK. .KWKWWWWKWK. .KWKGGGGKWK. .KWKGGGGKWK. .KWWKKKKWWK. .KKKKKKKKKK. ............
primaryColor#FFCC00tagsdashboardadmincompliancecertifications, note
certifications1 item
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.webpublicDir
publicDir./service/app/publicpreviewdir, desktop, mobile, capture
dir./previewdesktop./preview/desktop.pngmobile./preview/mobile.pngcaptureurl, wait
urlacid:3050wait800componentsservice, nextcloudApp, embed, vscode
serviceimage, port, healthCheck
imageacid/acid:latestport3050healthChecktype, path, interval, timeout, retries
typehttppath/healthzinterval30stimeout5sretries3nextcloudAppappid, path, minNcVersion, maxNcVersion
embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile
idacidlabelACID Document PipelinencConfigKeyacid_app_urlsubdomainacidcontaineracidcontainerPort3050embedProxyPort8914profileacidvscodeextensions, extension
extensions[ ]extensionnulldependenciesrequires, optional
requires1 item
0id, version
idnextcloudversion>=30optional1 item
0id
idvaultoidcCapabilityasClient, asProvider, fallback
asClienttrueasProviderfalsefallbackvaultwardensecretsRefs./secrets.spec.yamlskinslogan, logo, theme
sloganDocuments in, formats out.themeprimary, mode
primary#FFCC00modesystemmarketplacevisibility, screenshots, pricing, supportUrl
visibilitypublicscreenshots./preview/desktop.png./preview/mobile.pngpricingfreesupportUrlwilhelm.tech/support/acidStandalone compose
Every service app can run on its own: cd apps/acid && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.
docker-compose.yml
# ACID - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/acid/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
# cp .env.example .env && docker compose up -d
# → http://localhost:${ACID_PORT:-3050}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
acid:
image: acid/acid:latest
restart: unless-stopped
env_file:
- .env
ports:
- "${ACID_PORT:-3050}:3050"
healthcheck:
test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:3050/healthz"]
interval: 30s
timeout: 5s
retries: 3
start_period: 20s
networks:
- acid
# TODO: persistent volume(s) if this image stores state. e.g.:
# volumes: [ "acid_data:/data" ]
networks:
acid:
name: acid
.env.example
# ACID - standalone env. Copy to .env and fill in. # GENERATED by scripts/generate-standalone.mjs # Host port the app is published on. ACID_PORT=3050 # Required secrets are specified in: # ./secrets.spec.yaml # Add the matching KEY=VALUE lines here.
README
The README is not in English - see apps/acid/README.md.
Links & documentation files
doc/acid-reference.md · doc/ai-notes.md · doc/api.md · doc/n8n.md · doc/sources.md
NocoDB
A database without SQL anxiety.
NocoDB database interface in Nextcloud
What it does
NocoDB turns any database into a smart spreadsheet - the open-source alternative to Airtable and to the Google Sheets that quietly became a company's database. Tables, relations, views, forms, automations and an API on top of PostgreSQL, MySQL or SQLite, with an interface that anyone who has used a spreadsheet already knows.
In the Wilhelm stack NocoDB is the central data layer: the place where n8n workflows write their results, where forms land, and where the other apps' data is joined, curated and shared as grids, galleries, kanban boards and forms.
Features
A spreadsheet-like table with typed columns: text, numbers, dates, single and multi select, attachments, links to other tables, formulas, lookups and rollups.
The same table as a card gallery, a board grouped by a select field, a public form for data entry, or a calendar.
Per-view configuration of visible fields, filters, groupings and sorts, shared with the team or kept private.
Drag-and-drop form builder on any table; share a public link and collect records without giving database access.
Link records across tables and pull fields through, the way a relational database is meant to be used.
Every base gets a documented API and webhooks on record events - the glue for n8n.
Connect an existing PostgreSQL or MySQL database and get the spreadsheet interface on top of it.
Workspace and base roles from viewer to owner; shared views and public forms.
Why it is in the stack
- Replaces Airtable and spreadsheet-as-database with a fair-code tool that runs on your own PostgreSQL.
- The stack's central data layer: n8n workflows, forms and the Wilhelm API read and write the same tables.
- Embedded in Nextcloud with the stack's single sign-on; a database interface without SQL anxiety for the whole team.
Screenshots
A media project table as a spreadsheet: album, thumbnail attachment, platform and status as coloured select fields, release date, linked staff records and budget. Fields, filter, group-by and sort sit in the toolbar; the views of this table are listed on the right.
01-grid-view.jpgThe same records as cards with the attachment field as cover image and the platform underneath - a view configuration, not a copy of the data.
02-gallery-view.jpgRecords stacked by the platform field into columns; drag a card to another column and the field changes. Each column shows its record count and an add button.
03-kanban-view.jpgA form built from the table's fields by drag and drop - title, description, which fields to show - shared as a public link so records can be collected without database access.
04-form-view.jpgScreenshots are the upstream project's official product shots (see preview/SOURCES.md) until the stack runs with demo data and tools/app-preview shoots real Wilhelm screens. Images © their respective projects.
At a glance
| Based on | NocoDB · source · docs · API |
| Replaces | Airtable, Google Sheets · listed as Wilhelm Data in the ecosystem reference |
| Type · category | External service · Database |
| Licence | service Fair-Code-SUL · wrapper Proprietary · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support/nocodb |
| Docker image | nocodb/nocodb:latest · port 8080 |
| Public URL | https://db.<your-domain> · behind AppAPI auth |
| Compose profile | nocodb |
| Nextcloud app id | wilhelmnocodb · Nextcloud 30-32 |
| Tags | databasenocode |
| Folder | apps/nocodb/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Service
| Image | nocodb/nocodb:latest |
| Port | 8080 |
| Init script | ./service/init-nocodb.sh |
| Health check | http /api/v1/health every 30s · timeout 5s · 3 retries |
Embedding in Nextcloud
| Registry id · label | nocodb · NocoDB |
| Subdomain | db |
| Container | nocodb:8080 |
| Embed-proxy port (localhost) | 8892 |
| Compose profile | nocodb |
| Nextcloud config key | nocodb_url |
| Auth gate | yes - served as ExApp behind AppAPI auth ({"id":"wilhelmnocodb","adapter":"nocodb-exapp","upstream":"http://nocodb:8080","prefix":""}) |
Nextcloud app
| App id | wilhelmnocodb |
| Path | ./nextcloud |
| Nextcloud versions | 30 - 32 |
Desktop build (Electron)
| Enabled | yes |
| Start path | /index.php/apps/wilhelmnocodb/ |
| Hide Nextcloud chrome | yes |
Dependencies
| Requires | nextcloud >=30 |
| Optional | vault |
Single sign-on (OIDC)
| As client | yes |
| As provider | no |
| Fallback | vaultwarden |
Skin & branding
| Slogan | A database without SQL anxiety. |
| Theme | primary #7f4e8a · mode system |
| Logo | ./nextcloud/appinfo/icon.svg |
Secrets
Declared in secretsRefs but apps/nocodb/secrets.spec.yaml does not exist in the repository.
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
No formal certifications found (no SOC 2, ISO 27001 or DPA). GDPR compliance follows from self-hosting and rests with the operator.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idnocodbdomainnocodbvendornocodbnameNocoDBdescriptionNocoDB database interface in Nextcloudversion2.0.0licenseservice, wrapper, wilhelm
serviceFair-Code-SULwrapperProprietarywilhelmProprietarymaintainername, email, url
typeexternalcategorydatabaseemoji🗄️pixelIcon............ .KKKKKKKKKK. .KWKKKKKKWK. .KWKWWKWKWK. .KWKKKKKKWK. .KWKWWKWKWK. .KWKKKKKKWK. .KWKWWKWKWK. .KWKKKKKKWK. .KKKKKKKKKK. ............
primaryColor#7f4e8atagsdatabasenocodecompliancecertifications, note
certifications1 item
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.noteNo formal certifications found (no SOC 2, ISO 27001 or DPA). GDPR compliance follows from self-hosting and rests with the operator.componentsservice, nextcloudApp, embed, vscode
serviceimage, port, healthCheck, init
imagenocodb/nocodb:latestport8080healthChecktype, path, interval, timeout, retries
typehttppath/api/v1/healthinterval30stimeout5sretries3nextcloudAppappid, path, minNcVersion, maxNcVersion
embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile, gate, exapp
idnocodblabelNocoDBncConfigKeynocodb_urlsubdomaindbcontainernocodbcontainerPort8080embedProxyPort8892profilenocodbgatetrueexappid, adapter, upstream, prefix
vscodeextensions, extension
extensions[ ]extensionnulldesktopenabled, startPath, hideNextcloudChrome
enabledtruestartPath/index.php/apps/wilhelmnocodb/hideNextcloudChrometruedependenciesrequires, optional
requires1 item
0id, version
idnextcloudversion>=30optional1 item
0id
idvaultoidcCapabilityasClient, asProvider, fallback
asClienttrueasProviderfalsefallbackvaultwardensecretsRefs./secrets.spec.yamlskinslogan, logo, theme
sloganA database without SQL anxiety.themeprimary, mode
primary#7f4e8amodesystempreviewdir, gallery
dir./previewgallery4 items
0src, caption, kind
1src, caption, kind
2src, caption, kind
3src, caption, kind
marketplacevisibility, screenshots, pricing, supportUrl
visibilitypublicscreenshots./preview/gallery/01-grid-view.jpg./preview/gallery/02-gallery-view.jpg./preview/gallery/03-kanban-view.jpg./preview/gallery/04-form-view.jpgpricingfreesupportUrlwilhelm.tech/support/nocodbStandalone compose
Every service app can run on its own: cd apps/nocodb && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.
docker-compose.yml
# NocoDB - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/nocodb/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
# cp .env.example .env && docker compose up -d
# → http://localhost:${NOCODB_PORT:-8080}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
nocodb:
image: nocodb/nocodb:latest
restart: unless-stopped
env_file:
- .env
ports:
- "${NOCODB_PORT:-8080}:8080"
healthcheck:
test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:8080/api/v1/health"]
interval: 30s
timeout: 5s
retries: 3
start_period: 20s
networks:
- nocodb
# TODO: persistent volume(s) if this image stores state. e.g.:
# volumes: [ "nocodb_data:/data" ]
networks:
nocodb:
name: nocodb
.env.example
# NocoDB - standalone env. Copy to .env and fill in. # GENERATED by scripts/generate-standalone.mjs # Host port the app is published on. NOCODB_PORT=8080 # Required secrets are specified in: # ./secrets.spec.yaml # Add the matching KEY=VALUE lines here.
README
The README is not in English - see apps/nocodb/README.md.
Links & documentation files
Upstream docs · Upstream API · Upstream source · Support · apps/nocodb/
doc/ai-notes.md · doc/api.md · doc/n8n.md · doc/nocodb-reference.md · doc/sources.md
Design
Design in the browser, as a team.
Penpot design tool in Nextcloud
What it does
Design is Penpot, the open-source design and prototyping platform that does what Figma and Adobe XD do - design, prototype and hand off to developers, together, in the browser - on an open SVG-based format and on your own server.
In the Wilhelm stack login runs exclusively through the Kernel (password login and registration are disabled), so the design team shares the stack's identity, and Penpot's webhooks let n8n react to design changes.
Features
Vector design, components, flex and grid layouts, interactive prototypes.
Inspect mode with measurements, CSS and assets; open SVG format, no proprietary lock-in.
Teams, projects, files and shared component libraries.
Comment threads on files for review.
Team-level webhooks; personal access tokens with expiry; RPC API.
Why it is in the stack
- Design in the browser, as a team - Figma-class tooling without per-editor pricing.
- Design files stay in your PostgreSQL and object store; SSO through the stack.
- MPL-2.0 lets you run it as a service without opening the Wilhelm wrapper.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs design.
At a glance
| Based on | Penpot · source · docs · API |
| Replaces | Figma, Adobe XD · listed as Wilhelm Design in the ecosystem reference |
| Type · category | External service · Design |
| Licence | service MPL-2.0 · wrapper Proprietary · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support/design |
| Docker image | penpotapp/frontend:latest · port 8080 |
| Public URL | https://design.<your-domain> |
| Compose profile | penpot |
| Nextcloud app id | wilhelmdesign · Nextcloud 30-32 |
| Tags | designui |
| Folder | apps/design/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Service
| Image | penpotapp/frontend:latest |
| Port | 8080 |
| Init script | ./service/init-penpot.sh |
| Health check | http / every 30s · timeout 5s · 3 retries |
Embedding in Nextcloud
| Registry id · label | penpot · Penpot Design |
| Subdomain | design |
| Container | penpot-frontend:80 |
| Embed-proxy port (localhost) | 8907 |
| Compose profile | penpot |
| Nextcloud config key | penpot_url |
Nextcloud app
| App id | wilhelmdesign |
| Path | ./nextcloud |
| Nextcloud versions | 30 - 32 |
Dependencies
| Requires | nextcloud >=30 |
| Optional | vault |
Single sign-on (OIDC)
| As client | yes |
| As provider | no |
| Fallback | vaultwarden |
Skin & branding
| Slogan | Design in the browser, as a team. |
| Theme | primary #7238B2 · mode system |
| Logo | ./nextcloud/appinfo/icon.svg |
Secrets
Declared in secretsRefs but apps/design/secrets.spec.yaml does not exist in the repository.
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
| DPA Privacy | compliant | cloud offering | Public DPA with Kaleidos (EU hosting in Spain, no third-country transfers planned). source |
Only GDPR/DPA documented for the Penpot SaaS; despite accessibility design features there is no WCAG conformance statement for the product.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
iddesigndomaindesignvendorpenpotnameDesigndescriptionPenpot design tool in Nextcloudversion2.0.0licenseservice, wrapper, wilhelm
serviceMPL-2.0wrapperProprietarywilhelmProprietarymaintainername, email, url
typeexternalcategorydesignemoji🎨pixelIcon............ .KKKKKKKKKK. .KWWWKKWWWK. .KWWKWWKWWK. .KWWKWWKWWK. .KWWKGGKWWK. .KWWWKKWWWK. .KWWWKKWWWK. .KWWWWWWWWK. .KKKKKKKKKK. ............
primaryColor#7238B2tagsdesignuicompliancecertifications, note
certifications2 items
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.1id, status, scope, source, note
idgdpr-avvstatuscompliantscopecloudsourcepenpot.app/dpanotePublic DPA with Kaleidos (EU hosting in Spain, no third-country transfers planned).noteOnly GDPR/DPA documented for the Penpot SaaS; despite accessibility design features there is no WCAG conformance statement for the product.componentsservice, nextcloudApp, embed, vscode
serviceimage, port, healthCheck, init
imagepenpotapp/frontend:latestport8080healthChecktype, path, interval, timeout, retries
typehttppath/interval30stimeout5sretries3nextcloudAppappid, path, minNcVersion, maxNcVersion
embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile
idpenpotlabelPenpot DesignncConfigKeypenpot_urlsubdomaindesigncontainerpenpot-frontendcontainerPort80embedProxyPort8907profilepenpotvscodeextensions, extension
extensions[ ]extensionnulldependenciesrequires, optional
requires1 item
0id, version
idnextcloudversion>=30optional1 item
0id
idvaultoidcCapabilityasClient, asProvider, fallback
asClienttrueasProviderfalsefallbackvaultwardensecretsRefs./secrets.spec.yamlskinslogan, logo, theme
sloganDesign in the browser, as a team.themeprimary, mode
primary#7238B2modesystemmarketplacevisibility, screenshots, pricing, supportUrl
Standalone compose
Every service app can run on its own: cd apps/design && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.
docker-compose.yml
# Design - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/design/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
# cp .env.example .env && docker compose up -d
# → http://localhost:${DESIGN_PORT:-8080}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
design:
image: penpotapp/frontend:latest
restart: unless-stopped
env_file:
- .env
ports:
- "${DESIGN_PORT:-8080}:8080"
healthcheck:
test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:8080/"]
interval: 30s
timeout: 5s
retries: 3
start_period: 20s
networks:
- design
# TODO: persistent volume(s) if this image stores state. e.g.:
# volumes: [ "design_data:/data" ]
networks:
design:
name: design
.env.example
# Design - standalone env. Copy to .env and fill in. # GENERATED by scripts/generate-standalone.mjs # Host port the app is published on. DESIGN_PORT=8080 # Required secrets are specified in: # ./secrets.spec.yaml # Add the matching KEY=VALUE lines here.
README
The README is not in English - see apps/design/README.md.
Links & documentation files
Upstream docs · Upstream API · Upstream source · Support · apps/design/
doc/ai-notes.md · doc/api.md · doc/design-reference.md · doc/n8n.md · doc/sources.md
Sign
Signatures, digital and binding.
Documenso document signing in Nextcloud
What it does
Sign is Documenso, the open-source alternative to DocuSign and Adobe Sign: upload a PDF, place signature and form fields, add recipients in order, send - and get back a cryptographically signed PDF with an audit trail. Templates, teams, embedding and an API make it part of a process rather than a one-off.
In the Wilhelm stack it signs in through the Kernel, takes PDFs from Nextcloud Files, and n8n creates envelopes from templates and receives status webhooks. Today it provides simple electronic signatures; qualified signatures (eIDAS AES/QES) are announced upstream.
Features
Drag signature, text, date and checkbox fields; signing order.
Reusable documents with pre-placed fields.
Certificate-based signing with an audit trail.
Shared documents and templates.
Sign inside your own apps; envelope-based API v2.
Why it is in the stack
- Signatures, digital and binding - without per-envelope pricing.
- Documents and signing certificates stay on your server; same SSO and file storage as the rest of the office.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs sign.
At a glance
| Based on | Documenso · source · docs · API |
| Replaces | DocuSign, Adobe Sign · listed as Wilhelm Sign in the ecosystem reference |
| Type · category | External service · Documents |
| Licence | service AGPL-3.0 · wrapper Proprietary · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support/sign |
| Docker image | documenso/documenso:latest · port 3000 |
| Public URL | https://sign.<your-domain> |
| Compose profile | documenso |
| Nextcloud app id | wilhelmsign · Nextcloud 30-32 |
| Tags | signingdocuments |
| Folder | apps/sign/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Service
| Image | documenso/documenso:latest |
| Port | 3000 |
| Init script | ./service/init-documenso.sh |
| Health check | http /api/health every 30s · timeout 5s · 3 retries |
Embedding in Nextcloud
| Registry id · label | documenso · Documenso E-Signing |
| Subdomain | sign |
| Container | documenso:3000 |
| Embed-proxy port (localhost) | 8903 |
| Compose profile | documenso |
| Nextcloud config key | documenso_url |
Nextcloud app
| App id | wilhelmsign |
| Path | ./nextcloud |
| Nextcloud versions | 30 - 32 |
Dependencies
| Requires | nextcloud >=30 |
| Optional | vault |
Single sign-on (OIDC)
| As client | yes |
| As provider | no |
| Fallback | vaultwarden |
Skin & branding
| Slogan | Signatures, digital and binding. |
| Theme | primary #1E7980 · mode system |
| Logo | ./nextcloud/appinfo/icon.svg |
Secrets
Declared in secretsRefs but apps/sign/secrets.spec.yaml does not exist in the repository.
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| eIDAS (SES) Electronic signature | compliant | software | Simple electronic signature (SES) under eIDAS; AES/QES announced for H2 2026. source |
| ESIGN / UETA Electronic signature | compliant | software | Compliant with the US ESIGN Act and UETA. source |
| SOC 2 Type II Information security | vendor claim | cloud offering | Listed as "compliant", without public auditor details. source |
| 21 CFR Part 11 Healthcare | vendor claim | cloud offering | Listed as "compliant"; Part 11 suitability depends heavily on the processes of the organisation using it. source |
| GDPR Privacy | vendor claim | cloud offering | GDPR handling documented for the hosted service; self-hosters are their own controller. source |
Honest compliance matrix: today SES level plus ESIGN/UETA; ISO 27001, ZertES and eIDAS AES/QES are announced for 2026. Not yet suitable for qualified signatures (QES).
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idsigndomainsignvendordocumensonameSigndescriptionDocumenso document signing in Nextcloudversion2.0.0licenseservice, wrapper, wilhelm
serviceAGPL-3.0wrapperProprietarywilhelmProprietarymaintainername, email, url
typeexternalcategorydocumentsemoji✍️pixelIcon............ .KKKKKKKKKK. .KWWWWWKKWK. .KWWWWKKKWK. .KWWWKKKWWK. .KWWKKKWWWK. .KWKKWWWWWK. .KWWWWWWWWK. .KGGWGGWGGK. .KKKKKKKKKK. ............
primaryColor#1E7980tagssigningdocumentscompliancecertifications, note
certifications5 items
0id, status, scope, source, note
ideidas-sesstatuscompliantscopesoftwaresourcedocumenso.com/compliancenoteSimple electronic signature (SES) under eIDAS; AES/QES announced for H2 2026.1id, status, scope, source, note
idesign-uetastatuscompliantscopesoftwaresourcedocumenso.com/compliancenoteCompliant with the US ESIGN Act and UETA.2id, status, scope, source, note
idsoc2-type2statusclaimedscopecloudsourcedocumenso.com/compliancenoteListed as "compliant", without public auditor details.3id, status, scope, source, note
id21-cfr-part-11statusclaimedscopecloudsourcedocumenso.com/compliancenoteListed as "compliant"; Part 11 suitability depends heavily on the processes of the organisation using it.4id, status, scope, source, note
idgdprstatusclaimedscopecloudnoteGDPR handling documented for the hosted service; self-hosters are their own controller.noteHonest compliance matrix: today SES level plus ESIGN/UETA; ISO 27001, ZertES and eIDAS AES/QES are announced for 2026. Not yet suitable for qualified signatures (QES).componentsservice, nextcloudApp, embed, vscode
serviceimage, port, healthCheck, init
imagedocumenso/documenso:latestport3000healthChecktype, path, interval, timeout, retries
typehttppath/api/healthinterval30stimeout5sretries3nextcloudAppappid, path, minNcVersion, maxNcVersion
embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile
iddocumensolabelDocumenso E-SigningncConfigKeydocumenso_urlsubdomainsigncontainerdocumensocontainerPort3000embedProxyPort8903profiledocumensovscodeextensions, extension
extensions[ ]extensionnulldependenciesrequires, optional
requires1 item
0id, version
idnextcloudversion>=30optional1 item
0id
idvaultoidcCapabilityasClient, asProvider, fallback
asClienttrueasProviderfalsefallbackvaultwardensecretsRefs./secrets.spec.yamlskinslogan, logo, theme
sloganSignatures, digital and binding.themeprimary, mode
primary#1E7980modesystemmarketplacevisibility, screenshots, pricing, supportUrl
Standalone compose
Every service app can run on its own: cd apps/sign && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.
docker-compose.yml
# Sign - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/sign/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
# cp .env.example .env && docker compose up -d
# → http://localhost:${SIGN_PORT:-3000}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
sign:
image: documenso/documenso:latest
restart: unless-stopped
env_file:
- .env
ports:
- "${SIGN_PORT:-3000}:3000"
healthcheck:
test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:3000/api/health"]
interval: 30s
timeout: 5s
retries: 3
start_period: 20s
networks:
- sign
# TODO: persistent volume(s) if this image stores state. e.g.:
# volumes: [ "sign_data:/data" ]
networks:
sign:
name: sign
.env.example
# Sign - standalone env. Copy to .env and fill in. # GENERATED by scripts/generate-standalone.mjs # Host port the app is published on. SIGN_PORT=3000 # Required secrets are specified in: # ./secrets.spec.yaml # Add the matching KEY=VALUE lines here.
README
The README is not in English - see apps/sign/README.md.
Links & documentation files
Upstream docs · Upstream API · Upstream source · Support · apps/sign/
doc/ai-notes.md · doc/api.md · doc/n8n.md · doc/sign-reference.md · doc/sources.md
Finance
Your portfolio, clearly.
Ghostfolio portfolio tracker in Nextcloud
What it does
Finance is Ghostfolio, the open-source wealth-management software that tracks a portfolio across accounts and asset classes - stocks, ETFs, crypto - and delivers performance and risk analysis, the way Portfolio Performance or a broker's dashboard would, on your own server.
Transactions can be imported from any source, so n8n can feed it from bank exports or shop orders and pull snapshots back out for reports and notifications.
Features
Stocks, ETFs, crypto and cash across any number of accounts and currencies.
Returns over today, year-to-date, up to five years and all time.
Diversification by asset class, sector, region and currency; risk indicators.
Buy, sell, dividend, fee, interest and liability activities via API or CSV.
A read-only share of your portfolio without giving away account access.
Configurable data sources for prices.
Why it is in the stack
- Your portfolio, clearly - financial data on your own server instead of a broker's cloud.
- No subscription; feed it from any source through the API.
- Embedded in Nextcloud with single sign-on; reports via n8n.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs finance.
At a glance
| Based on | Ghostfolio · source · docs · API |
| Replaces | Yahoo Finance, Portfolio Performance · listed as Wilhelm Finance in the ecosystem reference |
| Type · category | External service · Finance |
| Licence | service AGPL-3.0 · wrapper Proprietary · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support/finance |
| Docker image | ghostfolio/ghostfolio:latest · port 3333 |
| Public URL | https://finance.<your-domain> |
| Compose profile | ghostfolio |
| Nextcloud app id | wilhelmfinance · Nextcloud 30-32 |
| Tags | financeportfolio |
| Folder | apps/finance/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Service
| Image | ghostfolio/ghostfolio:latest |
| Port | 3333 |
| Init script | ./service/init-ghostfolio.sh |
| Health check | http /api/v1/health every 30s · timeout 5s · 3 retries |
Embedding in Nextcloud
| Registry id · label | ghostfolio · Ghostfolio Finance |
| Subdomain | finance |
| Container | ghostfolio:3333 |
| Embed-proxy port (localhost) | 8909 |
| Compose profile | ghostfolio |
| Nextcloud config key | ghostfolio_url |
Nextcloud app
| App id | wilhelmfinance |
| Path | ./nextcloud |
| Nextcloud versions | 30 - 32 |
Dependencies
| Requires | nextcloud >=30 |
| Optional | vault |
Single sign-on (OIDC)
| As client | yes |
| As provider | no |
| Fallback | vaultwarden |
Skin & branding
| Slogan | Your portfolio, clearly. |
| Theme | primary #F97316 · mode system |
| Logo | ./nextcloud/appinfo/icon.svg |
Secrets
Declared in secretsRefs but apps/finance/secrets.spec.yaml does not exist in the repository.
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | vendor claim | cloud offering | Privacy policy of the SaaS (operated from Zurich under Swiss data protection law); no audited certification. source |
Swiss community project without formal certifications - privacy via self-hosting.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idfinancedomainfinancevendorghostfolionameFinancedescriptionGhostfolio portfolio tracker in Nextcloudversion2.0.0licenseservice, wrapper, wilhelm
serviceAGPL-3.0wrapperProprietarywilhelmProprietarymaintainername, email, url
typeexternalcategoryfinanceemoji💰pixelIcon............ .KKKKKKKKKK. .KWWWWWKKWK. .KWWWWWWKWK. .KWWWWWKWWK. .KWWWWKWWWK. .KWWWKWWWWK. .KWWKWWWWWK. .KWKWWWWWWK. .KKKKKKKKKK. ............
primaryColor#F97316tagsfinanceportfoliocompliancecertifications, note
certifications1 item
0id, status, scope, source, note
idgdprstatusclaimedscopecloudnotePrivacy policy of the SaaS (operated from Zurich under Swiss data protection law); no audited certification.noteSwiss community project without formal certifications - privacy via self-hosting.componentsservice, nextcloudApp, embed, vscode
serviceimage, port, healthCheck, init
imageghostfolio/ghostfolio:latestport3333healthChecktype, path, interval, timeout, retries
typehttppath/api/v1/healthinterval30stimeout5sretries3nextcloudAppappid, path, minNcVersion, maxNcVersion
embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile
idghostfoliolabelGhostfolio FinancencConfigKeyghostfolio_urlsubdomainfinancecontainerghostfoliocontainerPort3333embedProxyPort8909profileghostfoliovscodeextensions, extension
extensions[ ]extensionnulldependenciesrequires, optional
requires1 item
0id, version
idnextcloudversion>=30optional1 item
0id
idvaultoidcCapabilityasClient, asProvider, fallback
asClienttrueasProviderfalsefallbackvaultwardensecretsRefs./secrets.spec.yamlskinslogan, logo, theme
sloganYour portfolio, clearly.themeprimary, mode
primary#F97316modesystemmarketplacevisibility, screenshots, pricing, supportUrl
Standalone compose
Every service app can run on its own: cd apps/finance && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.
docker-compose.yml
# Finance - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/finance/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
# cp .env.example .env && docker compose up -d
# → http://localhost:${FINANCE_PORT:-3333}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
finance:
image: ghostfolio/ghostfolio:latest
restart: unless-stopped
env_file:
- .env
ports:
- "${FINANCE_PORT:-3333}:3333"
healthcheck:
test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:3333/api/v1/health"]
interval: 30s
timeout: 5s
retries: 3
start_period: 20s
networks:
- finance
# TODO: persistent volume(s) if this image stores state. e.g.:
# volumes: [ "finance_data:/data" ]
networks:
finance:
name: finance
.env.example
# Finance - standalone env. Copy to .env and fill in. # GENERATED by scripts/generate-standalone.mjs # Host port the app is published on. FINANCE_PORT=3333 # Required secrets are specified in: # ./secrets.spec.yaml # Add the matching KEY=VALUE lines here.
README
The README is not in English - see apps/finance/README.md.
Links & documentation files
Upstream docs · Upstream API · Upstream source · Support · apps/finance/
doc/ai-notes.md · doc/api.md · doc/finance-reference.md · doc/n8n.md · doc/sources.md
Forms
Ask. Answer. Done.
Formbricks forms in Nextcloud
What it does
Forms is Formbricks, the open-source experience-management platform for surveys and forms: in-app surveys triggered by what users do, link surveys for everyone else, and evaluation of the answers - what Typeform, Qualtrics and Google Forms do, with the responses in your own database.
In the Wilhelm stack it signs in through the Kernel, and its webhooks push every response into n8n, where it can become a NocoDB record, a CRM note or a notification.
Features
Share a link or trigger a survey on user actions in your product.
NPS, onboarding, product feedback, churn and classic forms to start from.
Conditional logic; contacts with attributes for targeting.
Summaries, filters and response exports.
Surveys, responses, contacts and webhooks via API; a public client API for the web SDK.
Single sign-on built in.
Why it is in the stack
- Ask. Answer. Done. - survey responses stay in your own database, which matters for customer and employee feedback.
- No per-response pricing; unmodified upstream image behind the Wilhelm wrapper.
- Every response is an automation trigger via n8n.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs forms.
At a glance
| Based on | Formbricks · source · docs · API |
| Replaces | Typeform, Google Forms · listed as Wilhelm Forms in the ecosystem reference |
| Type · category | External service · Forms |
| Licence | service AGPL-3.0 · wrapper Proprietary · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support/forms |
| Docker image | formbricks/formbricks:latest · port 3000 |
| Public URL | https://forms.<your-domain> |
| Compose profile | formbricks |
| Nextcloud app id | wilhelmforms · Nextcloud 30-32 |
| Tags | formssurveys |
| Folder | apps/forms/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Service
| Image | formbricks/formbricks:latest |
| Port | 3000 |
| Init script | ./service/init-formbricks.sh |
| Health check | http /health every 30s · timeout 5s · 3 retries |
Embedding in Nextcloud
| Registry id · label | formbricks · Formbricks Forms |
| Subdomain | forms |
| Container | formbricks:3000 |
| Embed-proxy port (localhost) | 8902 |
| Compose profile | formbricks |
| Nextcloud config key | formbricks_url |
Nextcloud app
| App id | wilhelmforms |
| Path | ./nextcloud |
| Nextcloud versions | 30 - 32 |
Dependencies
| Requires | nextcloud >=30 |
| Optional | vault |
Single sign-on (OIDC)
| As client | yes |
| As provider | no |
| Fallback | vaultwarden |
Skin & branding
| Slogan | Ask. Answer. Done. |
| Theme | primary #5349D3 · mode system |
| Logo | ./nextcloud/appinfo/icon.svg |
Secrets
Declared in secretsRefs but apps/forms/secrets.spec.yaml does not exist in the repository.
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | compliant | cloud offering | German vendor, cloud hosting in Germany, DPA linked - GDPR by design. source |
| SOC 2 Type II Information security | vendor claim | cloud offering | SOC 2 Type II according to the privacy page; no publicly linked audit report. source |
| ISO/IEC 27001 Information security | vendor claim | cloud offering | ISO 27001 according to the privacy page; sources disagree on whether the certification is complete. source |
| HIPAA Healthcare | vendor claim | software | HIPAA use promoted primarily via self-hosting (the customer controls PHI); no BAA programme documented. source |
Strong GDPR story (German company, hosting in Germany); SOC 2 / ISO 27001 are vendor claims without a public trust center.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idformsdomainformsvendorformbricksnameFormsdescriptionFormbricks forms in Nextcloudversion2.0.0licenseservice, wrapper, wilhelm
serviceAGPL-3.0wrapperProprietarywilhelmProprietarymaintainername, email, url
typeexternalcategoryformsemoji📝pixelIcon............ .KKKKKKKKKK. .KWGWKKKWWK. .KWWWWWWWWK. .KWGWKKKWWK. .KWWWWWWWWK. .KWGWKKKWWK. .KWWWWWWWWK. .KWWWWWWWWK. .KKKKKKKKKK. ............
primaryColor#5349D3tagsformssurveyscompliancecertifications, note
certifications4 items
0id, status, scope, source, note
idgdprstatuscompliantscopecloudsourceformbricks.com/privacynoteGerman vendor, cloud hosting in Germany, DPA linked - GDPR by design.1id, status, scope, source, note
idsoc2-type2statusclaimedscopecloudsourceformbricks.com/privacynoteSOC 2 Type II according to the privacy page; no publicly linked audit report.2id, status, scope, source, note
idiso-27001statusclaimedscopecloudsourceformbricks.com/privacynoteISO 27001 according to the privacy page; sources disagree on whether the certification is complete.3id, status, scope, source, note
idhipaastatusclaimedscopesoftwarenoteHIPAA use promoted primarily via self-hosting (the customer controls PHI); no BAA programme documented.noteStrong GDPR story (German company, hosting in Germany); SOC 2 / ISO 27001 are vendor claims without a public trust center.componentsservice, nextcloudApp, embed, vscode
serviceimage, port, healthCheck, init
imageformbricks/formbricks:latestport3000healthChecktype, path, interval, timeout, retries
typehttppath/healthinterval30stimeout5sretries3nextcloudAppappid, path, minNcVersion, maxNcVersion
embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile
idformbrickslabelFormbricks FormsncConfigKeyformbricks_urlsubdomainformscontainerformbrickscontainerPort3000embedProxyPort8902profileformbricksvscodeextensions, extension
extensions[ ]extensionnulldependenciesrequires, optional
requires1 item
0id, version
idnextcloudversion>=30optional1 item
0id
idvaultoidcCapabilityasClient, asProvider, fallback
asClienttrueasProviderfalsefallbackvaultwardensecretsRefs./secrets.spec.yamlskinslogan, logo, theme
marketplacevisibility, screenshots, pricing, supportUrl
Standalone compose
Every service app can run on its own: cd apps/forms && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.
docker-compose.yml
# Forms - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/forms/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
# cp .env.example .env && docker compose up -d
# → http://localhost:${FORMS_PORT:-3000}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
forms:
image: formbricks/formbricks:latest
restart: unless-stopped
env_file:
- .env
ports:
- "${FORMS_PORT:-3000}:3000"
healthcheck:
test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:3000/health"]
interval: 30s
timeout: 5s
retries: 3
start_period: 20s
networks:
- forms
# TODO: persistent volume(s) if this image stores state. e.g.:
# volumes: [ "forms_data:/data" ]
networks:
forms:
name: forms
.env.example
# Forms - standalone env. Copy to .env and fill in. # GENERATED by scripts/generate-standalone.mjs # Host port the app is published on. FORMS_PORT=3000 # Required secrets are specified in: # ./secrets.spec.yaml # Add the matching KEY=VALUE lines here.
README
The README is not in English - see apps/forms/README.md.
Links & documentation files
Upstream docs · Upstream API · Upstream source · Support · apps/forms/
doc/ai-notes.md · doc/api.md · doc/forms-reference.md · doc/n8n.md · doc/sources.md
Integrations
Everything talks to everything.
integrations infrastructure (Wilhelm-managed)
What it does
Integrations is a reserved namespace for Wilhelm-managed integration infrastructure - the place where cross-app connectors will live. Today it ships nothing executable: manifest and icon only.
It is listed so that the catalogue and the graph already know the slot; the notes say plainly that it is currently without function.
Features
Reserved infrastructure namespace
No service container, no API surface, no Nextcloud app yet
Why it is in the stack
- Everything talks to everything - the intent; status: placeholder.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs integrations.
At a glance
| Based on | Wilhelm-native - no upstream project |
| Type · category | Infrastructure · Infrastructure |
| Licence | service Proprietary · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Tags | infrastructure |
| Folder | apps/integrations/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Skin & branding
| Slogan | Everything talks to everything. |
| Theme | primary #6B7280 · mode system |
| Logo | ./appinfo/icon.svg |
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idintegrationsdomainintegrationsvendorwilhelmnameIntegrationsdescriptionintegrations infrastructure (Wilhelm-managed)version2.0.0licenseservice, wilhelm
serviceProprietarywilhelmProprietarymaintainername, email, url
typeinfrastructurecategoryinfrastructureemoji🔧pixelIcon............ .KKKKKKKKKK. .KWWKWKWWWK. .KWWKWKWWWK. .KWKKKKKWWK. .KWKKKKKWWK. .KWWWKWWWWK. .KWWWKWWWWK. .KWWWWKKWWK. .KKKKKKKKKK. ............
primaryColor#6B7280tagsinfrastructurecompliancecertifications, note
certifications1 item
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.skinslogan, logo, theme
sloganEverything talks to everything.themeprimary, mode
primary#6B7280modesystemcomponentsvscode
vscodeextensions, extension
extensions[ ]extensionnullLinks & documentation files
Wilhelm Cloud
Your server in one minute.
Managed Wilhelm server: bought in the shop (Medusa/PayPal), provisioned automatically through the Hetzner Cloud API (white-label), delivered as a fully installed stack.
What it does
Wilhelm Cloud turns the stack into a product you can sell: a customer buys a Wilhelm server in your Medusa shop, pays by PayPal, and receives a fully installed stack under their own subdomain - provisioned automatically through the Hetzner Cloud API, white-label, so the infrastructure provider never appears in the UI, the mails or the invoices.
It is wiring of existing stack pieces rather than new software: the shop, an n8n order workflow, a dependency-free provisioner with cloud-init, the mail server for the welcome mail, and TaskHQ for operating the provisioned servers afterwards.
Features
A 'Wilhelm Server' product with plan and subdomain metadata in Medusa; PayPal as payment provider - no own payment code.
n8n assigns the subdomain, calls the provisioner, sets the DNS record and sends the welcome mail.
Zero-dependency Node script with dry-run, webhook mode for n8n and a manual CLI; server self-installs via cloud-init.
Server type, location and image are parameters.
Provisioned servers appear in TaskHQ under 'Connect to server' over hardened SSH.
Why it is in the stack
- Your server in one minute: sell managed Wilhelm servers under your own brand, end to end automated.
- Reuses the stack instead of adding bespoke code; the provider is named as processor where GDPR requires it.
- Status is stated plainly: provisioner done, shop and workflow wiring in progress.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs cloud.
At a glance
| Based on | Wilhelm-native - no upstream project |
| Type · category | Infrastructure · Infrastructure |
| Licence | service Proprietary · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Tags | cloudprovisioninghosting |
| Folder | apps/cloud/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Skin & branding
| Slogan | Your server in one minute. |
| Theme | primary #0369FF · mode system |
| Logo | ./icon.svg |
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idclouddomaincloudvendorwilhelmnameWilhelm ClouddescriptionManaged Wilhelm server: bought in the shop (Medusa/PayPal), provisioned automatically through the Hetzner Cloud API (white-label), delivered as a fully installed stack.version0.1.0licenseservice, wilhelm
serviceProprietarywilhelmProprietarymaintainername, email, url
typeinfrastructurecategoryinfrastructureemoji☁️primaryColor#0369FFicon./icon.svgpixelIcon............ ............ ....KKKK.... ...KWWWWK... ..KWWWWWWK.. .KWWWWWWWWK. .KWWWWWWWWK. ..KKKKKKKK.. ............ ............
tagscloudprovisioninghostingcompliancecertifications, note
certifications1 item
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.skinslogan, logo, theme
README
The README is not in English - see apps/cloud/README.md.
Links & documentation files
Mail under your own roof.
E-mail integration in Nextcloud
What it does
Mail is mailcow, the dockerised mail server suite: Postfix, Dovecot, Rspamd, SOGo webmail with calendar and contacts, ActiveSync for phones, and an admin interface that makes running your own mail server a matter of adding domains and mailboxes. It stands in for Google Workspace mail and Microsoft 365 Exchange.
Everything a mailbox owner would expect from a hosted provider is there - spam filtering with adjustable thresholds, aliases and temporary addresses, plus-address tagging into folders, whitelists and blacklists, sync jobs to pull in old accounts - under your own domain, on your own server.
Features
SMTP, IMAP, POP3, Sieve filters, DKIM, DMARC, SPF, TLS out of the box.
Rspamd with per-mailbox low and high score thresholds, learning from junk moves, whitelists and blacklists.
SOGo groupware with CalDAV and CardDAV; ActiveSync for mobile mail, calendar and contacts.
Domain and mailbox aliases, temporary random aliases with a lifetime, plus-address tags that sort into subfolders.
Domains, mailboxes, quotas, resources, domain admins, per-user settings - no config files.
Pull mail from an existing external account on a schedule during migration.
Enforce TLS for specific domains or peers.
Scripted backup and restore; the update script keeps the suite current.
Why it is in the stack
- Your mail under your own domain and roof - no provider reads, mines or rate-limits it; the best German GDPR story in the stack.
- Embedded in Nextcloud alongside Nextcloud Mail, calendar and contacts, with the stack's single sign-on.
- Newsletter (listmonk) and Tell (IMAP intelligence) build on it for bulk sending and smart inbox handling.
Screenshots
Two sliders set the low and high spam score: below the first is not spam, between them mail is tagged and moved to junk, above the second the server rejects it. Whitelist and blacklist entries with wildcards sit underneath.
01-spam-filter.jpgGenerate a random alias with a lifetime of a few hours, extend or remove it - a throwaway address for sign-ups that never exposes the real mailbox.
02-spam-alias.jpgMail to you+Facebook@example.org lands in the subfolder INBOX/Facebook or gets the tag prepended to the subject - a filing system without filter rules. The mailbox quota and the ActiveSync device cache reset live on the same page.
03-tagging.jpgAddresses or wildcard patterns that are never classified as spam, and ones that are always rejected - per mailbox, in addition to the domain-wide rules.
04-blacklist-whitelist.jpgScreenshots are the upstream project's official product shots (see preview/SOURCES.md) until the stack runs with demo data and tools/app-preview shoots real Wilhelm screens. Images © their respective projects.
At a glance
| Based on | mailcow: dockerized · source · docs · API |
| Type · category | External service · Mail |
| Licence | service GPL-3.0 · wrapper Proprietary · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support/mailcow |
| Docker image | mailcow/mailcow:latest · port 8080 |
| Public URL | https://mail.<your-domain> |
| Compose profile | listmonk |
| Nextcloud app id | wilhelmmail · Nextcloud 30-32 |
| Tags | mailemailserver |
| Folder | apps/mailcow/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Service
| Image | mailcow/mailcow:latest |
| Port | 8080 |
| Init script | ./service/setup-mailcow.sh |
| Health check | http / every 30s · timeout 5s · 3 retries |
Embedding in Nextcloud
| Registry id · label | listmonk · Listmonk Newsletter |
| Subdomain | mail |
| Container | listmonk:9000 |
| Embed-proxy port (localhost) | 8900 |
| Compose profile | listmonk |
| Nextcloud config key | listmonk_url |
Nextcloud app
| App id | wilhelmmail |
| Path | ./nextcloud |
| Nextcloud versions | 30 - 32 |
Dependencies
| Requires | nextcloud >=30 |
| Optional | vault |
Single sign-on (OIDC)
| As client | yes |
| As provider | no |
| Fallback | vaultwarden |
Skin & branding
| Slogan | Mail under your own roof. |
| Theme | primary #0369FF · mode system |
| Logo | ./nextcloud/appinfo/icon.svg |
Secrets
Declared in secretsRefs but apps/mailcow/secrets.spec.yaml does not exist in the repository.
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | compliant | vendor | German vendor (tinc GmbH, Willich) with GDPR privacy policies for all offerings. source |
| DPA Privacy | compliant | cloud offering | DPA under Art. 28 GDPR can be concluded directly in the Servercow customer profile; hosted mailcow runs in Frankfurt. source |
The best German GDPR story in the stack (German GmbH, German data centre, self-service DPA); no ISO 27001 / SOC 2 certificates.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idmailcowdomainmailcowvendormailcownameMaildescriptionE-mail integration in Nextcloudversion2.0.0licenseservice, wrapper, wilhelm
serviceGPL-3.0wrapperProprietarywilhelmProprietarymaintainername, email, url
typeexternalcategorymailemoji📧pixelIcon............ .KKKKKKKKKK. .KWKKKKKKWK. .KWKKWWKKWK. .KWKWKKWKWK. .KWKWWWWKWK. .KWKWWWWKWK. .KWKKKKKKWK. .KWWWWWWWWK. .KKKKKKKKKK. ............
primaryColor#0369FFtagsmailemailservercompliancecertifications, note
certifications2 items
0id, status, scope, source, note
idgdprstatuscompliantscopevendorsourcetinc.gmbh/datenschutznoteGerman vendor (tinc GmbH, Willich) with GDPR privacy policies for all offerings.1id, status, scope, source, note
idgdpr-avvstatuscompliantscopecloudnoteDPA under Art. 28 GDPR can be concluded directly in the Servercow customer profile; hosted mailcow runs in Frankfurt.noteThe best German GDPR story in the stack (German GmbH, German data centre, self-service DPA); no ISO 27001 / SOC 2 certificates.componentsservice, nextcloudApp, embed, vscode
serviceimage, port, healthCheck, init
imagemailcow/mailcow:latestport8080healthChecktype, path, interval, timeout, retries
typehttppath/interval30stimeout5sretries3nextcloudAppappid, path, minNcVersion, maxNcVersion
embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile
idlistmonklabelListmonk NewsletterncConfigKeylistmonk_urlsubdomainmailcontainerlistmonkcontainerPort9000embedProxyPort8900profilelistmonkvscodeextensions, extension
extensions[ ]extensionnulldependenciesrequires, optional
requires1 item
0id, version
idnextcloudversion>=30optional1 item
0id
idvaultoidcCapabilityasClient, asProvider, fallback
asClienttrueasProviderfalsefallbackvaultwardensecretsRefs./secrets.spec.yamlskinslogan, logo, theme
sloganMail under your own roof.themeprimary, mode
primary#0369FFmodesystempreviewdir, gallery
dir./previewgallery4 items
0src, caption, kind
1src, caption, kind
2src, caption, kind
3src, caption, kind
marketplacevisibility, screenshots, pricing, supportUrl
visibilitypublicscreenshots./preview/gallery/01-spam-filter.jpg./preview/gallery/02-spam-alias.jpg./preview/gallery/03-tagging.jpg./preview/gallery/04-blacklist-whitelist.jpgpricingfreesupportUrlwilhelm.tech/support/mailcowStandalone compose
Every service app can run on its own: cd apps/mailcow && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.
docker-compose.yml
# Mail - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/mailcow/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
# cp .env.example .env && docker compose up -d
# → http://localhost:${MAILCOW_PORT:-8080}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
mailcow:
image: mailcow/mailcow:latest
restart: unless-stopped
env_file:
- .env
ports:
- "${MAILCOW_PORT:-8080}:8080"
healthcheck:
test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:8080/"]
interval: 30s
timeout: 5s
retries: 3
start_period: 20s
networks:
- mailcow
# TODO: persistent volume(s) if this image stores state. e.g.:
# volumes: [ "mailcow_data:/data" ]
networks:
mailcow:
name: mailcow
.env.example
# Mail - standalone env. Copy to .env and fill in. # GENERATED by scripts/generate-standalone.mjs # Host port the app is published on. MAILCOW_PORT=8080 # Required secrets are specified in: # ./secrets.spec.yaml # Add the matching KEY=VALUE lines here.
README
The README is not in English - see apps/mailcow/README.md.
Links & documentation files
Upstream docs · Upstream API · Upstream source · Support · apps/mailcow/
doc/ai-notes.md · doc/api.md · doc/mailcow-reference.md · doc/n8n.md · doc/sources.md
Medical
Medical knowledge, docked in.
Medical knowledge via the AMBOSS integration (TODO: API wrapper)
What it does
Medical is the planned door to medical knowledge through an AMBOSS integration: licence-compliant queries of AMBOSS endpoints with a key from the vault, results normalised into NocoDB records, and optionally fed into the Wilhelm knowledge base - no scraping, by policy.
It is documented as blocked: AMBOSS is a commercial platform, its free APIs may not be used commercially, and a licence agreement has to come first. The code currently under the app folder is unrelated - a 3D embossing-stamp generator that exports STL files.
Features
Planned: AMBOSS GraphQL queries with a vault-held API key
Planned: normalisation into NocoDB, selective caching
Planned: licence-permitted content into the RAG index
Policy: no scraping of the web platform
Why it is in the stack
- Medical knowledge, docked in - once the licence question is settled.
- The documentation states the blocker instead of hiding it.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs medical.
At a glance
| Based on | Wilhelm-native - no upstream project |
| Type · category | Infrastructure · Medical |
| Licence | service Proprietary · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Tags | medicalambosswip |
| Folder | apps/medical/manifest.json |
Icon & assets
tools/app-assets → appinfo/ · serving copy in ./app/public
Configuration
Skin & branding
| Slogan | Medical knowledge, docked in. |
| Theme | primary #0EA5E9 · mode system |
| Logo | ./icon.svg |
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idmedicaldomainmedicalvendorwilhelmnameMedicaldescriptionMedical knowledge via the AMBOSS integration (TODO: API wrapper)version0.1.0licenseservice, wilhelm
serviceProprietarywilhelmProprietarymaintainername, email, url
typeinfrastructurecategorymedicalicon./icon.svgemoji🏥pixelIcon............ .KKKKKKKKKK. .KWWWKKWWWK. .KWWWKKWWWK. .KWKKKKKKWK. .KWKKKKKKWK. .KWWWKKWWWK. .KWWWKKWWWK. .KWWWWWWWWK. .KKKKKKKKKK. ............
primaryColor#0EA5E9tagsmedicalambosswipcompliancecertifications, note
certifications1 item
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.webpublicDir
publicDir./app/publicpreviewdir, desktop, mobile, capture
dir./previewdesktop./preview/desktop.pngmobile./preview/mobile.pngcaptureurl, wait
urlmedical:5173wait800skinslogan, logo, theme
marketplacevisibility
visibilityprivatecomponentsvscode
vscodeextensions, extension
extensions[ ]extensionnullStandalone compose
Every service app can run on its own: cd apps/medical && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.
.env.example
# Amboss - keine serverseitigen Env-Variablen nötig (reine Client-App)
Links & documentation files
doc/ai-notes.md · doc/api.md · doc/medical-reference.md · doc/sources.md
Prometheus
Every metric, one place.
Metrics-collection config (alertmanager + alerts + scrape config). Mounted into the prometheus container by docker-compose.
What it does
Prometheus is the stack's metrics layer, shipped as configuration: scrape jobs, alert rules and Alertmanager routing that docker-compose mounts into the Prometheus container. It pulls metrics from the gateway, the shop, identity and the databases and provides the data behind Grafana dashboards and alerts - the metrics half of what Datadog sells.
Logs are Loki's job; the two are correlated in Grafana, not here.
Features
Traefik, Medusa, Keycloak and the PostgreSQL instances every 15 seconds.
ServiceDown, HighErrorRate, PaymentWebhookFailure as code in the repo.
Routing configuration; receivers to be pointed at real webhooks.
Live stack state for dashboards, workflows and agents.
Configuration reloads on signal.
Why it is in the stack
- Every metric, one place - full ownership without a per-host observability subscription.
- Alert rules are versioned with the stack.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs prometheus.
At a glance
| Based on | Prometheus · source · docs · API |
| Type · category | Infrastructure · Monitoring |
| Licence | service Apache-2.0 · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Tags | monitoringmetrics |
| Folder | apps/prometheus/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Skin & branding
| Slogan | Every metric, one place. |
| Theme | primary #E6522C · mode system |
| Logo | ./icon.svg |
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
CNCF project without certifications; security audits by cure53 (CNCF-funded). Compliance rests entirely with the operator.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idprometheusdomainprometheusvendorprometheusnamePrometheusdescriptionMetrics-collection config (alertmanager + alerts + scrape config). Mounted into the prometheus container by docker-compose.version1.0.0licenseservice, wilhelm
serviceApache-2.0wilhelmProprietarymaintainername, email, url
typeinfrastructurecategorymonitoringicon./icon.svgemoji📈pixelIcon............ .KKKKKKKKKK. .KWWWWKWWWK. .KWWWKKWWWK. .KWWKKKKWWK. .KWKKGGKKWK. .KWKKGGKKWK. .KWWKKKKWWK. .KWWWWWWWWK. .KKKKKKKKKK. ............
primaryColor#E6522Ctagsmonitoringmetricscompliancecertifications, note
certifications1 item
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.noteCNCF project without certifications; security audits by cure53 (CNCF-funded). Compliance rests entirely with the operator.skinslogan, logo, theme
componentsvscode
vscodeextensions, extension
extensions[ ]extensionnullLinks & documentation files
Upstream docs · Upstream API · Upstream source · apps/prometheus/
doc/ai-notes.md · doc/api.md · doc/n8n.md · doc/prometheus-reference.md · doc/sources.md
Uptime Kuma
Green means green.
Uptime Kuma monitoring in Nextcloud
What it does
Uptime Kuma watches every service in the stack and speaks up before your users do: HTTP, keyword, JSON, TCP, ping, DNS, Docker container and push monitors on intervals from twenty seconds, a live dashboard with response-time charts, public status pages on your own domain, and notifications through ninety-plus channels - the self-hosted alternative to Pingdom and UptimeRobot.
In the Wilhelm stack it is embedded in Nextcloud and initialised with an admin user by script; Prometheus deliberately does not scrape it - it is the standalone status tool.
Features
HTTP(s), keyword, JSON query, TCP, ping, DNS, WebSocket, push, Steam, Docker container.
Multiple public status pages, optionally on their own domain; status badges.
Telegram, Slack, Discord, e-mail, ntfy and dozens more.
TLS expiry information per monitor.
Jobs report in; silence becomes an alert.
Why it is in the stack
- Green means green - one dashboard for every service, no per-monitor subscription.
- Status pages hosted on your own domain.
- Integration is via Socket.io rather than REST; the notes say so.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs monitoring.
At a glance
| Based on | Uptime Kuma · source · docs |
| Replaces | Pingdom, UptimeRobot · listed as Wilhelm Status in the ecosystem reference |
| Type · category | External service · Monitoring |
| Licence | service MIT · wrapper Proprietary · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support/monitoring |
| Docker image | louislam/uptime-kuma:latest · port 3001 |
| Public URL | https://status.<your-domain> |
| Compose profile | uptime-kuma |
| Nextcloud app id | wilhelmkuma · Nextcloud 30-32 |
| Tags | monitoringstatus |
| Folder | apps/monitoring/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Service
| Image | louislam/uptime-kuma:latest |
| Port | 3001 |
| Init script | ./service/init-uptime-kuma.sh |
| Health check | http / every 30s · timeout 5s · 3 retries |
Embedding in Nextcloud
| Registry id · label | uptime-kuma · Uptime Kuma |
| Subdomain | status |
| Container | uptime-kuma:3001 |
| Embed-proxy port (localhost) | 8893 |
| Compose profile | uptime-kuma |
| Nextcloud config key | kuma_url |
Nextcloud app
| App id | wilhelmkuma |
| Path | ./nextcloud |
| Nextcloud versions | 30 - 32 |
Dependencies
| Requires | nextcloud >=30 |
| Optional | vault |
Single sign-on (OIDC)
| As client | yes |
| As provider | no |
| Fallback | vaultwarden |
Skin & branding
| Slogan | Green means green. |
| Theme | primary #5CDD8B · mode system |
| Logo | ./nextcloud/appinfo/icon.svg |
Secrets
Declared in secretsRefs but apps/monitoring/secrets.spec.yaml does not exist in the repository.
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
Pure community project without a legal entity and without certifications; a GitHub label tracks accessibility work, but there is no WCAG conformance statement.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idmonitoringdomainmonitoringvendoruptime-kumanameUptime KumadescriptionUptime Kuma monitoring in Nextcloudversion2.0.0licenseservice, wrapper, wilhelm
serviceMITwrapperProprietarywilhelmProprietarymaintainername, email, url
typeexternalcategorymonitoringemoji💓pixelIcon............ .KKKKKKKKKK. .KWWWWWWWWK. .KWWWKWWWWK. .KWWKWKWWWK. .KKKWWWKKKK. .KWWWWWWWWK. .KWWWWWWWWK. .KWWWWWWWWK. .KKKKKKKKKK. ............
primaryColor#5CDD8Btagsmonitoringstatuscompliancecertifications, note
certifications1 item
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.notePure community project without a legal entity and without certifications; a GitHub label tracks accessibility work, but there is no WCAG conformance statement.componentsservice, nextcloudApp, embed, vscode
serviceimage, port, healthCheck, init
imagelouislam/uptime-kuma:latestport3001healthChecktype, path, interval, timeout, retries
typehttppath/interval30stimeout5sretries3nextcloudAppappid, path, minNcVersion, maxNcVersion
embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile
iduptime-kumalabelUptime KumancConfigKeykuma_urlsubdomainstatuscontaineruptime-kumacontainerPort3001embedProxyPort8893profileuptime-kumavscodeextensions, extension
extensions[ ]extensionnulldependenciesrequires, optional
requires1 item
0id, version
idnextcloudversion>=30optional1 item
0id
idvaultoidcCapabilityasClient, asProvider, fallback
asClienttrueasProviderfalsefallbackvaultwardensecretsRefs./secrets.spec.yamlskinslogan, logo, theme
marketplacevisibility, screenshots, pricing, supportUrl
Standalone compose
Every service app can run on its own: cd apps/monitoring && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.
docker-compose.yml
# Uptime Kuma - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/monitoring/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
# cp .env.example .env && docker compose up -d
# → http://localhost:${MONITORING_PORT:-3001}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
monitoring:
image: louislam/uptime-kuma:latest
restart: unless-stopped
env_file:
- .env
ports:
- "${MONITORING_PORT:-3001}:3001"
healthcheck:
test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:3001/"]
interval: 30s
timeout: 5s
retries: 3
start_period: 20s
networks:
- monitoring
# TODO: persistent volume(s) if this image stores state. e.g.:
# volumes: [ "monitoring_data:/data" ]
networks:
monitoring:
name: monitoring
.env.example
# Uptime Kuma - standalone env. Copy to .env and fill in. # GENERATED by scripts/generate-standalone.mjs # Host port the app is published on. MONITORING_PORT=3001 # Required secrets are specified in: # ./secrets.spec.yaml # Add the matching KEY=VALUE lines here.
README
The README is not in English - see apps/monitoring/README.md.
Links & documentation files
Upstream docs · Upstream source · Support · apps/monitoring/
doc/ai-notes.md · doc/api.md · doc/monitoring-reference.md · doc/n8n.md · doc/sources.md
Photos
Your pictures, your server.
Immich photo gallery in Nextcloud
What it does
Photos is Immich, the self-hosted photo and video platform built to give you back what Google Photos and iCloud Photos do - automatic backup from your phone, a timeline, albums, sharing, a map, people, and a search that understands what is in a picture - with the originals on your own server.
Machine learning runs locally: face recognition, object and scene detection and CLIP-based context search work on your hardware, so a query like 'sunrise on the beach' finds the picture without any image ever leaving the house.
Features
iOS and Android apps upload photos and videos automatically, in the background, with per-album selection.
The library organised by date, with albums, favourites, archive and trash.
Faces grouped into people you can name; photos on a map from their GPS data.
Search by what is in the image, by file name, description or recognised text (OCR), by people, tags, place, camera, date and media type.
Shared albums with other users, public links, partner sharing for a second person's library.
Rotate, flip, crop to any aspect ratio in the web app.
Full-resolution originals with thumbnails and transcoding for the web.
Users with quotas; index existing folders on disk as external libraries.
Why it is in the stack
- Replaces Google Photos and iCloud Photos with an AGPL tool; the originals stay on your server, the ML stays on your hardware.
- Embedded in Nextcloud with single sign-on next to the files, so the photo library is part of the cloud instead of a second cloud.
- No end-to-end encryption - the protection is the self-hosted deployment, which the compliance note says plainly.
Screenshots
The web timeline and map on the left, the mobile app on the right: search with people and places, albums, the detail view of a single photo with EXIF data and location, and the backup screen that shows what is uploaded and what is left.
01-overview.jpgAn album shared with two users and via link: every photo shows who added it, viewers can like and comment, and the toolbar offers adding photos, sharing, map, slideshow and download.
02-shared-album.jpgOrientation (rotate, flip) and crop with free or fixed aspect ratios, straight in the browser, non-destructively with a reset.
03-web-editor.jpgSearch by people, by context ('sunrise on the beach'), file name, description or OCR text, by tags, place (country, state, city), camera make, model and lens, date range, media type and album membership - all computed locally.
04-search-filters.jpgScreenshots are the upstream project's official product shots (see preview/SOURCES.md) until the stack runs with demo data and tools/app-preview shoots real Wilhelm screens. Images © their respective projects.
At a glance
| Based on | Immich · source · docs · API |
| Replaces | Google Photos, iCloud Photos · listed as Wilhelm Photos in the ecosystem reference |
| Type · category | External service · Photos |
| Licence | service AGPL-3.0 · wrapper Proprietary · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support/photos |
| Docker image | ghcr.io/immich-app/immich-server · port 3001 |
| Public URL | https://photos.<your-domain> |
| Compose profile | immich |
| Nextcloud app id | wilhelmphotos · Nextcloud 30-32 |
| Tags | photosbackup |
| Folder | apps/photos/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Service
| Image | ghcr.io/immich-app/immich-server |
| Port | 3001 |
| Init script | ./service/init-immich.sh |
| Health check | http /api/server-info/ping every 30s · timeout 5s · 3 retries |
Embedding in Nextcloud
| Registry id · label | immich · Immich Photos |
| Subdomain | photos |
| Container | immich-server:2283 |
| Embed-proxy port (localhost) | 8908 |
| Compose profile | immich |
| Nextcloud config key | immich_url |
Nextcloud app
| App id | wilhelmphotos |
| Path | ./nextcloud |
| Nextcloud versions | 30 - 32 |
Dependencies
| Requires | nextcloud >=30 |
| Optional | vault |
Single sign-on (OIDC)
| As client | yes |
| As provider | no |
| Fallback | vaultwarden |
Skin & branding
| Slogan | Your pictures, your server. |
| Theme | primary #4250AF · mode system |
| Logo | ./nextcloud/appinfo/icon.svg |
Secrets
Declared in secretsRefs but apps/photos/secrets.spec.yaml does not exist in the repository.
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
FUTO-backed project without a cloud offering and without certificates - data stays entirely with the operator. Note: no end-to-end encryption; protection at rest rests with the host.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idphotosdomainphotosvendorimmichnamePhotosdescriptionImmich photo gallery in Nextcloudversion2.0.0licenseservice, wrapper, wilhelm
serviceAGPL-3.0wrapperProprietarywilhelmProprietarymaintainername, email, url
typeexternalcategoryphotosemoji📷pixelIcon............ .KKKKKKKKKK. .KWWKKWWWWK. .KWKKKKKKWK. .KWKWGGWKWK. .KWKWGGWKWK. .KWKWWWWKWK. .KWKKKKKKWK. .KWWWWWWWWK. .KKKKKKKKKK. ............
primaryColor#4250AFtagsphotosbackupcompliancecertifications, note
certifications1 item
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.noteFUTO-backed project without a cloud offering and without certificates - data stays entirely with the operator. Note: no end-to-end encryption; protection at rest rests with the host.componentsservice, nextcloudApp, embed, vscode
serviceimage, port, healthCheck, init
imageghcr.io/immich-app/immich-serverport3001healthChecktype, path, interval, timeout, retries
typehttppath/api/server-info/pinginterval30stimeout5sretries3nextcloudAppappid, path, minNcVersion, maxNcVersion
embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile
idimmichlabelImmich PhotosncConfigKeyimmich_urlsubdomainphotoscontainerimmich-servercontainerPort2283embedProxyPort8908profileimmichvscodeextensions, extension
extensions[ ]extensionnulldependenciesrequires, optional
requires1 item
0id, version
idnextcloudversion>=30optional1 item
0id
idvaultoidcCapabilityasClient, asProvider, fallback
asClienttrueasProviderfalsefallbackvaultwardensecretsRefs./secrets.spec.yamlskinslogan, logo, theme
sloganYour pictures, your server.themeprimary, mode
primary#4250AFmodesystempreviewdir, gallery
dir./previewgallery4 items
0src, caption, kind
1src, caption, kind
2src, caption, kind
3src, caption, kind
marketplacevisibility, screenshots, pricing, supportUrl
visibilitypublicscreenshots./preview/gallery/01-overview.jpg./preview/gallery/02-shared-album.jpg./preview/gallery/03-web-editor.jpg./preview/gallery/04-search-filters.jpgpricingfreesupportUrlwilhelm.tech/support/photosStandalone compose
Every service app can run on its own: cd apps/photos && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.
docker-compose.yml
# Photos - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/photos/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
# cp .env.example .env && docker compose up -d
# → http://localhost:${PHOTOS_PORT:-3001}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
photos:
image: ghcr.io/immich-app/immich-server
restart: unless-stopped
env_file:
- .env
ports:
- "${PHOTOS_PORT:-3001}:3001"
healthcheck:
test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:3001/api/server-info/ping"]
interval: 30s
timeout: 5s
retries: 3
start_period: 20s
networks:
- photos
# TODO: persistent volume(s) if this image stores state. e.g.:
# volumes: [ "photos_data:/data" ]
networks:
photos:
name: photos
.env.example
# Photos - standalone env. Copy to .env and fill in. # GENERATED by scripts/generate-standalone.mjs # Host port the app is published on. PHOTOS_PORT=3001 # Required secrets are specified in: # ./secrets.spec.yaml # Add the matching KEY=VALUE lines here.
README
The README is not in English - see apps/photos/README.md.
Links & documentation files
Upstream docs · Upstream API · Upstream source · Support · apps/photos/
doc/ai-notes.md · doc/api.md · doc/n8n.md · doc/photos-reference.md · doc/sources.md
Projects
Projects in flow.
Plane project management in Nextcloud
What it does
Projects is Plane, the open-source project and product management tool that covers the ground Jira, Linear and Asana share: work items with states, priorities, labels and assignees; cycles for time-boxed sprints; modules for larger pieces of work; pages for specs and notes; and analytics across all of it. It runs on your own server inside the Wilhelm stack.
Where Jira grows into a configuration project of its own, Plane stays opinionated: a small set of well-designed concepts (work items, cycles, modules, views, pages, intake) that map onto how software and product teams actually work, with a clean interface that does not need training.
Features
Issues with states, priorities, labels, estimates, sub-items, relations and attachments; list, board, calendar, spreadsheet and Gantt views on the same data.
Time-boxed iterations with progress, burndown and scope-change tracking - the sprint, without the ceremony.
Group work items into features or epics with their own lead, members, dates and progress chart.
Save any filtered, grouped and sorted combination as a shared or private view.
Rich-text documents for specs, meeting notes and decisions, living next to the work they describe.
A triage queue for requests that are not yet work items - accept, decline, snooze.
Workspace and project dashboards: throughput, states, priorities, assignees, custom insights.
Organise projects by team and roll several projects up into a strategic initiative.
Why it is in the stack
- Replaces Jira, Linear and Asana with one AGPL-licensed tool - no per-seat pricing, no data outside your infrastructure.
- Embedded in Nextcloud with the stack's single sign-on; project links open inside the Wilhelm cloud, not in another SaaS tab.
- A REST API and n8n nodes let workflows create and update work items automatically - from forms, mails, support tickets or the CRM.
Screenshots
Work items grouped by state (Backlog, Todo, In progress) as a kanban board. Every card carries its identifier, priority, state, due date and assignees; the left rail switches between epics, work items, cycles, modules, views, pages and intake of the selected project.
01-overview.jpgThe same work items as a Gantt-style timeline with dependencies drawn between them, and as a board with custom states such as Blocked, Planning and Permits awaited. Views are layouts, not copies - a change in one is a change everywhere.
02-work-items.jpgA running cycle shows completed, started, unstarted and backlog items, the burndown against the ideal line, pending work and the priority items still open - per team, at a glance.
03-cycles.jpgModules group work items into a feature or epic. The detail panel shows dates, lead, members and a progress chart in which scope creep (+29 %) is visible instead of hidden.
04-modules.jpgTotals for users, projects and work items with month-on-month change, a radar of project activity over the last 30 days and per-project custom insights, for example open items by priority.
05-analytics.jpgScreenshots are the upstream project's official product shots (see preview/SOURCES.md) until the stack runs with demo data and tools/app-preview shoots real Wilhelm screens. Images © their respective projects.
At a glance
| Based on | Plane · source · docs · API |
| Replaces | Jira, Linear, Asana · listed as Wilhelm Projects in the ecosystem reference |
| Type · category | External service · Projects |
| Licence | service AGPL-3.0 · wrapper Proprietary · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support/projects |
| Docker image | makeplane/plane-frontend:latest · port 3000 |
| Public URL | https://projects.<your-domain> |
| Compose profile | plane |
| Nextcloud app id | wilhelmprojects · Nextcloud 30-32 |
| Tags | projectsmanagement |
| Folder | apps/projects/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Service
| Image | makeplane/plane-frontend:latest |
| Port | 3000 |
| Init script | ./service/init-plane.sh |
| Health check | http / every 30s · timeout 5s · 3 retries |
Embedding in Nextcloud
| Registry id · label | plane · Plane Project Mgmt |
| Subdomain | projects |
| Container | plane-web:3000 |
| Embed-proxy port (localhost) | 8906 |
| Compose profile | plane |
| Nextcloud config key | plane_url |
Nextcloud app
| App id | wilhelmprojects |
| Path | ./nextcloud |
| Nextcloud versions | 30 - 32 |
Dependencies
| Requires | nextcloud >=30 |
| Optional | vault |
Single sign-on (OIDC)
| As client | yes |
| As provider | no |
| Fallback | vaultwarden |
Skin & branding
| Slogan | Projects in flow. |
| Theme | primary #3A61D8 · mode system |
| Logo | ./nextcloud/appinfo/icon.svg |
Secrets
Declared in secretsRefs but apps/projects/secrets.spec.yaml does not exist in the repository.
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| ISO/IEC 27001 Information security | certified 2025-01 | vendor | ISO 27001:2022 certification of Plane's ISMS. source |
| SOC 2 Type II Information security | attested 2025-01 | cloud offering | SOC 2 Type II via independent audit; attestation of the vendor's controls, not of your own instance. source |
| GDPR Privacy | compliant | cloud offering | GDPR compliance statement for Plane's data processing. source |
| HIPAA Healthcare | vendor claim | cloud offering | HIPAA-compliant PHI processing claimed for Plane Cloud. source |
Unusually strong compliance package for an open-source PM tool (January 2025) - applies to vendor/cloud; self-hosting inherits the controls, not the certificates.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idprojectsdomainprojectsvendorplanenameProjectsdescriptionPlane project management in Nextcloudversion2.0.0licenseservice, wrapper, wilhelm
serviceAGPL-3.0wrapperProprietarywilhelmProprietarymaintainername, email, url
typeexternalcategoryprojectsemoji✈️pixelIcon............ .KKKKKKKKKK. .KKKWKKWKKK. .KKKWKKWKKK. .KWWWKKWWWK. .KKKWWWWKKK. .KKKWWWWKKK. .KWWWWWWWWK. .KWWWWWWWWK. .KKKKKKKKKK. ............
primaryColor#3A61D8tagsprojectsmanagementcompliancecertifications, note
certifications4 items
0id, status, scope, since, source, note
idiso-27001statuscertifiedscopevendorsince2025-01noteISO 27001:2022 certification of Plane's ISMS.1id, status, scope, since, source, note
idsoc2-type2statusattestedscopecloudsince2025-01noteSOC 2 Type II via independent audit; attestation of the vendor's controls, not of your own instance.2id, status, scope, source, note
idgdprstatuscompliantscopecloudnoteGDPR compliance statement for Plane's data processing.3id, status, scope, source, note
idhipaastatusclaimedscopecloudnoteHIPAA-compliant PHI processing claimed for Plane Cloud.noteUnusually strong compliance package for an open-source PM tool (January 2025) - applies to vendor/cloud; self-hosting inherits the controls, not the certificates.componentsservice, nextcloudApp, embed, vscode
serviceimage, port, healthCheck, init
imagemakeplane/plane-frontend:latestport3000healthChecktype, path, interval, timeout, retries
typehttppath/interval30stimeout5sretries3nextcloudAppappid, path, minNcVersion, maxNcVersion
embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile
idplanelabelPlane Project MgmtncConfigKeyplane_urlsubdomainprojectscontainerplane-webcontainerPort3000embedProxyPort8906profileplanevscodeextensions, extension
extensions[ ]extensionnulldependenciesrequires, optional
requires1 item
0id, version
idnextcloudversion>=30optional1 item
0id
idvaultoidcCapabilityasClient, asProvider, fallback
asClienttrueasProviderfalsefallbackvaultwardensecretsRefs./secrets.spec.yamlskinslogan, logo, theme
previewdir, gallery
dir./previewgallery5 items
0src, caption, kind
1src, caption, kind
2src, caption, kind
3src, caption, kind
4src, caption, kind
marketplacevisibility, screenshots, pricing, supportUrl
Standalone compose
Every service app can run on its own: cd apps/projects && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.
docker-compose.yml
# Projects - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/projects/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
# cp .env.example .env && docker compose up -d
# → http://localhost:${PROJECTS_PORT:-3000}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
projects:
image: makeplane/plane-frontend:latest
restart: unless-stopped
env_file:
- .env
ports:
- "${PROJECTS_PORT:-3000}:3000"
healthcheck:
test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:3000/"]
interval: 30s
timeout: 5s
retries: 3
start_period: 20s
networks:
- projects
# TODO: persistent volume(s) if this image stores state. e.g.:
# volumes: [ "projects_data:/data" ]
networks:
projects:
name: projects
.env.example
# Projects - standalone env. Copy to .env and fill in. # GENERATED by scripts/generate-standalone.mjs # Host port the app is published on. PROJECTS_PORT=3000 # Required secrets are specified in: # ./secrets.spec.yaml # Add the matching KEY=VALUE lines here.
README
The README is not in English - see apps/projects/README.md.
Links & documentation files
Upstream docs · Upstream API · Upstream source · Support · apps/projects/
doc/ai-notes.md · doc/api.md · doc/n8n.md · doc/projects-reference.md · doc/sources.md
Booking
Appointments that book themselves.
Cal.com bookings in Nextcloud
What it does
Booking is Cal.com, the open-source scheduling platform built as the alternative to Calendly and Microsoft Bookings: define event types and availability, share a link, and guests book free slots that land in everyone's calendar with reminders, video links and confirmations.
In the Wilhelm stack it syncs with the Nextcloud calendar over CalDAV, and every booking is an event other apps react to: a confirmation mail, a contact in the CRM, a task in the project tool.
Features
Durations, buffers, limits, schedules per event type; team and round-robin events.
Public pages per user, team or event type; embeddable booking widgets.
Google, Outlook and CalDAV - the Nextcloud calendar included.
Conferencing links and e-mail/SMS reminders on every booking.
Shared event types, managed users, OAuth platform clients.
Create, read, cancel and reschedule bookings; webhooks on created, cancelled and rescheduled.
Why it is in the stack
- Appointments that book themselves - Calendly features without per-seat subscription, on your own server.
- Booking data and calendar credentials stay in your PostgreSQL; CalDAV keeps the Nextcloud calendar in sync.
- Booking events are automation triggers for the whole stack via n8n.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs booking.
At a glance
| Based on | Cal.com · source · docs · API |
| Replaces | Calendly, MS Bookings · listed as Wilhelm Booking in the ecosystem reference |
| Type · category | External service · Scheduling |
| Licence | service AGPL-3.0 · wrapper Proprietary · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support/booking |
| Docker image | calcom/cal.com:latest · port 3000 |
| Public URL | https://booking.<your-domain> |
| Compose profile | calcom |
| Nextcloud app id | wilhelmbooking · Nextcloud 30-32 |
| Tags | bookingcalendarscheduling |
| Folder | apps/booking/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Service
| Image | calcom/cal.com:latest |
| Port | 3000 |
| Init script | ./service/init-calcom.sh |
| Health check | http /api/health every 30s · timeout 5s · 3 retries |
Embedding in Nextcloud
| Registry id · label | calcom · Cal.com Booking |
| Subdomain | booking |
| Container | calcom:3000 |
| Embed-proxy port (localhost) | 8904 |
| Compose profile | calcom |
| Nextcloud config key | calcom_url |
Nextcloud app
| App id | wilhelmbooking |
| Path | ./nextcloud |
| Nextcloud versions | 30 - 32 |
Dependencies
| Requires | nextcloud >=30 |
| Optional | vault |
Single sign-on (OIDC)
| As client | yes |
| As provider | no |
| Fallback | vaultwarden |
Skin & branding
| Slogan | Appointments that book themselves. |
| Theme | primary #292929 · mode system |
| Logo | ./nextcloud/appinfo/icon.svg |
Secrets
Declared in secretsRefs but apps/booking/secrets.spec.yaml does not exist in the repository.
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| SOC 2 Type II Information security | attested | cloud offering | SOC 2 Type II with annual independent audits; report via trust.cal.com. source |
| ISO/IEC 27001 Information security | vendor claim | cloud offering | ISO/IEC 27001 listed on the compliance page; certificate details only via the trust center. source |
| HIPAA Healthcare | compliant | cloud offering | HIPAA via encryption, access controls and BAAs (attestation, not certification). source |
| GDPR Privacy | vendor claim | cloud offering | GDPR compliance according to the compliance page, for the cloud offering. source |
The broadest compliance portfolio in the stack - all evidence applies to Cal.com Cloud, not to the self-hosted instance.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idbookingdomainbookingvendorcalcomnameBookingdescriptionCal.com bookings in Nextcloudversion2.0.0licenseservice, wrapper, wilhelm
serviceAGPL-3.0wrapperProprietarywilhelmProprietarymaintainername, email, url
typeexternalcategoryschedulingemoji📅pixelIcon............ .KKKKKKKKKK. .KWWKWWKWWK. .KWKKKKKKWK. .KWKWWWWKWK. .KWKKKKKKWK. .KWKWGWWKWK. .KWKWWWWKWK. .KWKKKKKKWK. .KKKKKKKKKK. ............
primaryColor#292929tagsbookingcalendarschedulingcompliancecertifications, note
certifications4 items
0id, status, scope, source, note
idsoc2-type2statusattestedscopecloudsourcecal.com/compliance/soc-2noteSOC 2 Type II with annual independent audits; report via trust.cal.com.1id, status, scope, source, note
idiso-27001statusclaimedscopecloudsourcecal.com/compliancenoteISO/IEC 27001 listed on the compliance page; certificate details only via the trust center.2id, status, scope, source, note
idhipaastatuscompliantscopecloudsourcecal.com/compliance/hipaanoteHIPAA via encryption, access controls and BAAs (attestation, not certification).3id, status, scope, source, note
idgdprstatusclaimedscopecloudsourcecal.com/compliancenoteGDPR compliance according to the compliance page, for the cloud offering.noteThe broadest compliance portfolio in the stack - all evidence applies to Cal.com Cloud, not to the self-hosted instance.componentsservice, nextcloudApp, embed, vscode
serviceimage, port, healthCheck, init
imagecalcom/cal.com:latestport3000healthChecktype, path, interval, timeout, retries
typehttppath/api/healthinterval30stimeout5sretries3nextcloudAppappid, path, minNcVersion, maxNcVersion
embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile
idcalcomlabelCal.com BookingncConfigKeycalcom_urlsubdomainbookingcontainercalcomcontainerPort3000embedProxyPort8904profilecalcomvscodeextensions, extension
extensions[ ]extensionnulldependenciesrequires, optional
requires1 item
0id, version
idnextcloudversion>=30optional1 item
0id
idvaultoidcCapabilityasClient, asProvider, fallback
asClienttrueasProviderfalsefallbackvaultwardensecretsRefs./secrets.spec.yamlskinslogan, logo, theme
sloganAppointments that book themselves.themeprimary, mode
primary#292929modesystemmarketplacevisibility, screenshots, pricing, supportUrl
Standalone compose
Every service app can run on its own: cd apps/booking && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.
docker-compose.yml
# Booking - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/booking/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
# cp .env.example .env && docker compose up -d
# → http://localhost:${BOOKING_PORT:-3000}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
booking:
image: calcom/cal.com:latest
restart: unless-stopped
env_file:
- .env
ports:
- "${BOOKING_PORT:-3000}:3000"
healthcheck:
test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:3000/api/health"]
interval: 30s
timeout: 5s
retries: 3
start_period: 20s
networks:
- booking
# TODO: persistent volume(s) if this image stores state. e.g.:
# volumes: [ "booking_data:/data" ]
networks:
booking:
name: booking
.env.example
# Booking - standalone env. Copy to .env and fill in. # GENERATED by scripts/generate-standalone.mjs # Host port the app is published on. BOOKING_PORT=3000 # Required secrets are specified in: # ./secrets.spec.yaml # Add the matching KEY=VALUE lines here.
README
The README is not in English - see apps/booking/README.md.
Links & documentation files
Upstream docs · Upstream API · Upstream source · Support · apps/booking/
doc/ai-notes.md · doc/api.md · doc/booking-reference.md · doc/n8n.md · doc/sources.md
Data Broker
API-key gateway in front of the Wilhelm API: one endpoint tree per key (allow/block/empty/broker); broker mode substitutes sensitive data based on a case file
What it does
Data Broker is the bouncer with a memory: an API-key gateway in front of the Wilhelm API, the MCP servers and the native app APIs. Every key carries an endpoint tree that decides what the caller may reach - and in broker mode the answer is not just allow or deny: sensitive content is substituted with placeholders according to a case file before it leaves the house.
It exists so that data can be shared with third parties and AI agents without sharing secrets. The policy engine and the redaction rules are implemented and tested; the reverse-proxy service around them is roadmap.
Features
Three namespaces (Wilhelm API, MCP, apps) with inheritance and deny-by-default at the root.
allow, block (403), empty (a type-correct empty body so the client sees 'no data', not 'blocked'), broker.
Rules by literal, JSON property (any depth), file-name glob or regex, applied to requests and responses.
Keys and trees are edited in a settings window; the plaintext token is shown once.
JSON schemas for keys and case files; pure, tested reference implementation.
Why it is in the stack
- Share data with agents and partners without sharing secrets; deny by default, fine-grained per key.
- 'Empty' as a stealth deny keeps client apps working while revealing nothing.
- One policy over API, MCP and app endpoints alike.
Screenshots
Contributed HTML67 widgets
At a glance
| Based on | Wilhelm-native - no upstream project |
| Type · category | Infrastructure · Security |
| Licence | service Apache-2.0 · wilhelm Apache-2.0 |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support |
| Resources | memory 256Mi · cpu 0.25 · storage 1Gi |
| Tags | securitygatewayapi-keysprivacybroker |
| Folder | apps/databroker/manifest.json |
Icon & assets
tools/app-assets → appinfo/ · serving copy in ./service/app/public
Configuration
Service
| Compose fragment | ./service/compose.fragment.yml |
| Init script | ./service/init.sh |
| Health check | http /healthz every 30s · timeout 5s · 3 retries |
Desktop build (Electron)
| Enabled | no - opted out |
| Start path | /index.php/apps/example/ |
| Hide Nextcloud chrome | yes |
TaskHQ desktop window
| Shown | yes |
| Window | 760 × 520 px |
Resources & permissions
| Memory · CPU · storage | 256Mi · 0.25 · 1Gi |
| Host network | no |
| Privileged | no |
| Egress domains | none - no outbound connections declared |
Dependencies
| Requires | nextcloud >=30 |
| Optional | n8n, nocodb |
| Provides | nc-appn8n-workflowsnocodb-schema |
MCP (Model Context Protocol)
| Server | mcp/server.js |
| Transport | stdio |
Single sign-on (OIDC)
| As client | no |
| As provider | no |
| Fallback | none |
Skin & branding
| Theme | primary #6B7280 · mode system |
| Logo | ./skin/logo.svg |
| Agent persona | Agent - “Hi!” |
Secrets
Declared in secretsRefs but apps/databroker/secrets.spec.yaml does not exist in the repository.
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
iddatabrokerdomaindatabrokervendorwilhelmnameData BrokerdescriptionAPI-key gateway in front of the Wilhelm API: one endpoint tree per key (allow/block/empty/broker); broker mode substitutes sensitive data based on a case fileversion2.0.0licenseservice, wilhelm
serviceApache-2.0wilhelmApache-2.0maintainername, email, url
typeinfrastructurecategorysecurityicon./icon.svgemoji🗝️pixelIcon............ ....KKKK.... ...KWWWWK... ...KWKKWK... ...KWWWWK... ....KWWK.... ....KWWK.... ....KWWKK... ....KWWK.... ....KWWKK... ....KKKK.... ............
primaryColor#8B0000tagssecuritygatewayapi-keysprivacybrokercompliancecertifications, note
certifications1 item
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.webpublicDir
publicDir./service/app/publicpreviewdir, desktop, mobile, gallery, video, capture
dir./previewdesktop./preview/desktop.pngmobile./preview/mobile.pnggallery1 item
0src, caption, kind
src./preview/gallery/example.pngcaptionExample screenshotkindflowvideosrc, poster
src./preview/demo.webmposter./preview/demo-poster.pngcaptureurl, wait, widgetsUrl
componentsservice, widgets
serviceimage, compose, init, healthCheck
imagehealthChecktype, path, interval, timeout, retries
typehttppath/healthzinterval30stimeout5sretries3widgets1 item
0tag, description, since, preview
tagwl-carddescriptionExample: a wl-* component this app contributes - the tag must exist in apps/ui/wl-html-data.json (tools/doctor warns otherwise).since0.1.0preview./preview/widgets/wl-card.pngdesktopenabled, startPath, hideNextcloudChrome
enabledfalsestartPath/index.php/apps/example/hideNextcloudChrometrueresourcesmemory, cpu, storage
memory256Micpu0.25storage1GipermissionsneedsHostNetwork, needsPrivileged, egressDomains
needsHostNetworkfalseneedsPrivilegedfalseegressDomains[ ]dependenciesrequires, optional, provides
requires1 item
0id, version
idnextcloudversion>=30optional2 items
0id
idn8n1id
idnocodbprovidesnc-appn8n-workflowsnocodb-schemamcpserver, transport, grants
servermcp/server.jstransportstdiogrants[ ]oidcCapabilityasClient, asProvider, fallback
asClientfalseasProviderfalsefallbacknonesecretsRefs./secrets.spec.yamlskinslogan, logo, icon, theme, agent, dashboards
sloganlogo./skin/logo.svgicon./skin/icon/512.pngthemeprimary, mode
primary#6B7280modesystemagentname, greeting, persona
dashboards./skin/dashboards/*.jsonmarketplacevisibility, screenshots, pricing, supportUrl
taskhqenabled, width, height
enabledtruewidth760height520README
The README is not in English - see apps/databroker/README.md.
Links & documentation files
Vault
Passwords, safe at home.
Vaultwarden password manager in Nextcloud
What it does
Vault is Vaultwarden, the lightweight, unofficial server implementation of the Bitwarden API: the official Bitwarden apps and browser extensions connect to it, so you get a full password manager - vaults, organisations, sharing, two-step login, passkeys, secure notes, cards and identities - on your own server, replacing 1Password, LastPass and the Bitwarden cloud.
Because the clients are Bitwarden's own, the experience is the polished one users know; because the server is yours, the encrypted vault never leaves your infrastructure. Bitwarden's certificates (ISO 27001, SOC 2) do not carry over to Vaultwarden, which the compliance note states rather than glosses over.
Features
Works with the official browser extensions, desktop and mobile apps, CLI and web vault.
Logins, cards, identities and secure notes with folders, favourites, attachments and a trash.
Share items with teams via organisations, collections and groups; admin console.
E-mail codes, authenticator apps, passkeys / FIDO2 security keys, YubiKey OTP, Duo.
Generate strong passwords and passphrases; exposed, weak and reused password reports.
Share text or files securely with expiry and access limits.
Trusted contacts can request access to a vault after a waiting period.
Import from other password managers; encrypted exports.
Why it is in the stack
- Replaces 1Password, LastPass and Bitwarden cloud with an AGPL server that needs a fraction of the resources.
- Passwords, safe at home: the encrypted vault is stored in your Wilhelm stack, embedded in Nextcloud with single sign-on.
- The official clients on every platform - nothing to teach, nothing to switch.
Screenshots
Personal vault and organisation vault in one list: a company credit card owned by the organisation, a mailing address identity, logins and a secure note. Filters by vault, item type, folder and collection on the left; generator, import and export under tools.
01-all-vaults.jpgSecurity settings with master password, two-step login and keys. A recovery code protects against lock-out; providers can be enabled side by side.
02-security-2fa.jpgE-mail, authenticator app, passkey (biometrics or a FIDO2 key), Yubico OTP and Duo - the same choice the Bitwarden cloud offers, served by your own instance.
03-2fa-providers.jpgScreenshots are the upstream project's official product shots (see preview/SOURCES.md) until the stack runs with demo data and tools/app-preview shoots real Wilhelm screens. Images © their respective projects.
At a glance
| Based on | Vaultwarden · source · docs · API |
| Replaces | 1Password, LastPass, Bitwarden · listed as Wilhelm Vault in the ecosystem reference |
| Type · category | External service · Security |
| Licence | service AGPL-3.0 · wrapper Proprietary · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support/vault |
| Docker image | vaultwarden/server:latest · port 80 |
| Public URL | https://vault.<your-domain> |
| Compose profile | vaultwarden |
| Nextcloud app id | wilhelmvault · Nextcloud 30-32 |
| Tags | passwordssecurity |
| Folder | apps/vault/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Service
| Image | vaultwarden/server:latest |
| Port | 80 |
| Health check | http /alive every 30s · timeout 5s · 3 retries |
Embedding in Nextcloud
| Registry id · label | vaultwarden · Vaultwarden Passwords |
| Subdomain | vault |
| Container | vaultwarden:80 |
| Embed-proxy port (localhost) | 8901 |
| Compose profile | vaultwarden |
| Nextcloud config key | vault_url |
Nextcloud app
| App id | wilhelmvault |
| Path | ./nextcloud |
| Nextcloud versions | 30 - 32 |
Dependencies
| Requires | nextcloud >=30 |
| Optional | vault |
Single sign-on (OIDC)
| As client | yes |
| As provider | no |
| Fallback | vaultwarden |
Skin & branding
| Slogan | Passwords, safe at home. |
| Theme | primary #175DDC · mode system |
| Logo | ./nextcloud/appinfo/icon.svg |
Secrets
Declared in secretsRefs but apps/vault/secrets.spec.yaml does not exist in the repository.
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
Unofficial community reimplementation of the Bitwarden server: Bitwarden's certificates (ISO 27001, SOC 2/3, HIPAA audits) do NOT apply to Vaultwarden. No audit, no vendor - unsuitable where vendor-backed attestation is contractually required. The Bitwarden client apps themselves are audited.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idvaultdomainvaultvendorvaultwardennameVaultdescriptionVaultwarden password manager in Nextcloudversion2.0.0licenseservice, wrapper, wilhelm
serviceAGPL-3.0wrapperProprietarywilhelmProprietarymaintainername, email, url
typeexternalcategorysecurityemoji🔐pixelIcon............ .KKKKKKKKKK. .KWWKKKKWWK. .KWWKWWKWWK. .KWKKKKKKWK. .KWKWWWWKWK. .KWKWGGWKWK. .KWKWWWWKWK. .KWKKKKKKWK. .KKKKKKKKKK. ............
primaryColor#175DDCtagspasswordssecuritycompliancecertifications, note
certifications1 item
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.noteUnofficial community reimplementation of the Bitwarden server: Bitwarden's certificates (ISO 27001, SOC 2/3, HIPAA audits) do NOT apply to Vaultwarden. No audit, no vendor - unsuitable where vendor-backed attestation is contractually required. The Bitwarden client apps themselves are audited.componentsservice, nextcloudApp, embed, vscode
serviceimage, port, volumes, environment, healthCheck
imagevaultwarden/server:latestport80volumesvault_data:/dataenvironmentSIGNUPS_ALLOWED, DOMAIN, ADMIN_TOKEN
healthChecktype, path, interval, timeout, retries
typehttppath/aliveinterval30stimeout5sretries3nextcloudAppappid, path, minNcVersion, maxNcVersion
embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile
idvaultwardenlabelVaultwarden PasswordsncConfigKeyvault_urlsubdomainvaultcontainervaultwardencontainerPort80embedProxyPort8901profilevaultwardenvscodeextensions, extension
extensions[ ]extensionnulldependenciesrequires, optional
requires1 item
0id, version
idnextcloudversion>=30optional1 item
0id
idvaultoidcCapabilityasClient, asProvider, fallback
asClienttrueasProviderfalsefallbackvaultwardensecretsRefs./secrets.spec.yamlskinslogan, logo, theme
sloganPasswords, safe at home.themeprimary, mode
primary#175DDCmodesystempreviewdir, gallery
dir./previewgallery3 items
0src, caption, kind
1src, caption, kind
2src, caption, kind
marketplacevisibility, screenshots, pricing, supportUrl
visibilitypublicscreenshots./preview/gallery/01-all-vaults.jpg./preview/gallery/02-security-2fa.jpg./preview/gallery/03-2fa-providers.jpgpricingfreesupportUrlwilhelm.tech/support/vaultStandalone compose
Every service app can run on its own: cd apps/vault && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.
docker-compose.yml
# Vault - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/vault/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
# cp .env.example .env && docker compose up -d
# → http://localhost:${VAULT_PORT:-80}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
vault:
image: vaultwarden/server:latest
restart: unless-stopped
env_file:
- .env
ports:
- "${VAULT_PORT:-80}:80"
environment:
SIGNUPS_ALLOWED: ${SIGNUPS_ALLOWED:-false}
DOMAIN: ${DOMAIN:-http://localhost:80}
ADMIN_TOKEN: ${ADMIN_TOKEN:-}
healthcheck:
test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:80/alive"]
interval: 30s
timeout: 5s
retries: 3
start_period: 20s
networks:
- vault
volumes:
- "vault_data:/data"
networks:
vault:
name: vault
volumes:
vault_data:
.env.example
# Vault - standalone env. Copy to .env and fill in. # GENERATED by scripts/generate-standalone.mjs # Host port the app is published on. VAULT_PORT=80 # Service configuration (compose falls back to these defaults if unset). SIGNUPS_ALLOWED=false DOMAIN=http://localhost:80 ADMIN_TOKEN= # Required secrets are specified in: # ./secrets.spec.yaml # Add the matching KEY=VALUE lines here.
README
The README is not in English - see apps/vault/README.md.
Links & documentation files
Upstream docs · Upstream API · Upstream source · Support · apps/vault/
doc/ai-notes.md · doc/api.md · doc/n8n.md · doc/sources.md · doc/vault-reference.md
llm
Models local, answers instant.
ollama integration for the Wilhelm stack
What it does
llm is Ollama, the local inference engine of the stack: it downloads open-weight models (Llama, Mistral, Gemma, Qwen, Phi and more), keeps them warm and serves them over a slim HTTP API - completion, chat with tool calling, embeddings, model management - with no cloud dependency at all.
Its OpenAI-compatible endpoints mean existing clients work unchanged; the RAG pipeline uses it for embeddings, Wilhelm Intelligence can route to it as the offline backend, and Open WebUI chats against it.
Features
Pull, create, copy and delete models from a Modelfile, GGUF or Safetensors.
Native API plus /v1/chat/completions, /v1/embeddings, /v1/models.
Streamed responses; JSON and JSON-schema constrained output.
Image input for vision models.
NVIDIA acceleration where available; models persist in a volume.
A model is pulled at startup by configuration.
Why it is in the stack
- Models local, answers instant - no token ever leaves the house, no per-token billing.
- Drop-in for OpenAI-compatible clients.
- Protection is at the network level; the notes say so.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs llm.
At a glance
| Based on | Ollama · source · docs · API |
| Replaces | OpenAI API, Azure AI · listed as Wilhelm Brain in the ecosystem reference |
| Type · category | External service · Services |
| Licence | service MIT · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support/llm |
| Docker image | ollama/ollama:latest · port 11434 |
| Compose profile | ollama |
| Folder | apps/llm/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Service
| Image | ollama/ollama:latest |
| Port | 11434 |
| Health check | http / every 30s · timeout 5s · 3 retries |
Dependencies
| Requires | nothing |
Skin & branding
| Slogan | Models local, answers instant. |
| Theme | primary #6B7280 · mode system |
| Logo | ./appinfo/icon.svg |
Secrets
Declared in secretsRefs but apps/llm/secrets.spec.yaml does not exist in the repository.
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | vendor claim | cloud offering | The privacy policy addresses GDPR data-subject rights for ollama.com; no DPA, no EU data residency. source |
The local runtime processes everything inside your own stack - an architectural property, not a certification. No formal audits.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idllmdomainllmvendorollamanamellmdescriptionollama integration for the Wilhelm stackversion2.0.0licenseservice, wilhelm
serviceMITwilhelmProprietarymaintainername, email, url
typeexternalcategoryserviceemoji📦pixelIcon............ .KKKKKKKKKK. .KWWWKWWWWK. .KWWKKKWWWK. .KWKKKKKWWK. .KWWKKKWWWK. .KWWWKWWWWK. .KWWWWWWGWK. .KWWWWWWWWK. .KKKKKKKKKK. ............
primaryColor#6B7280tags[ ]compliancecertifications, note
certifications1 item
0id, status, scope, source, note
idgdprstatusclaimedscopecloudsourceollama.com/privacynoteThe privacy policy addresses GDPR data-subject rights for ollama.com; no DPA, no EU data residency.noteThe local runtime processes everything inside your own stack - an architectural property, not a certification. No formal audits.componentsservice, vscode
serviceimage, port, healthCheck
imageollama/ollama:latestport11434healthChecktype, path, interval, timeout, retries
typehttppath/interval30stimeout5sretries3vscodeextensions, extension
extensions[ ]extensionnulldependenciesrequires, optional
requires[ ]optional[ ]secretsRefs./secrets.spec.yamlskinslogan, logo, theme
sloganModels local, answers instant.themeprimary, mode
primary#6B7280modesystemmarketplacevisibility, pricing, supportUrl
Standalone compose
Every service app can run on its own: cd apps/llm && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.
docker-compose.yml
# llm - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/llm/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
# cp .env.example .env && docker compose up -d
# → http://localhost:${LLM_PORT:-11434}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
llm:
image: ollama/ollama:latest
restart: unless-stopped
env_file:
- .env
ports:
- "${LLM_PORT:-11434}:11434"
healthcheck:
test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:11434/"]
interval: 30s
timeout: 5s
retries: 3
start_period: 20s
networks:
- llm
# TODO: persistent volume(s) if this image stores state. e.g.:
# volumes: [ "llm_data:/data" ]
networks:
llm:
name: llm
.env.example
# ── Ollama (Local LLM) ─────────────────────────────────────────────────────── OLLAMA_PORT=11434 # Optional: Auto-pull model on startup (e.g. llama3.2:latest) # OLLAMA_PULL_MODEL=llama3.2:latest # Optional: Model storage path (default in container: /root/.ollama) # OLLAMA_MODELS=/path/to/models # Optional: How long model stays in RAM after use (default 5m) # OLLAMA_DEFAULT_KEEPALIVE=30m OLLAMA_EMBED_MODEL=nomic-embed-text
README
The README is not in English - see apps/llm/README.md.
Links & documentation files
Upstream docs · Upstream API · Upstream source · Support · apps/llm/
doc/ai-notes.md · doc/api.md · doc/llm-reference.md · doc/n8n.md · doc/sources.md
newsletter
Mail that arrives.
listmonk integration for the Wilhelm stack
What it does
newsletter is listmonk, the self-hosted newsletter and mailing-list manager: subscribers, lists, campaigns, templates and transactional mail in a single Go binary on PostgreSQL that handles lists in the millions - the alternative to Mailchimp and SendGrid marketing.
In the Wilhelm stack the lists 'All contacts', 'Customers' and 'Buyers' are created at initialisation, and n8n keeps them in sync with the shop: new customers and orders flow into the right list automatically.
Features
Attributes, list memberships, public double-opt-in lists, bulk operations by query.
Templates, test sends, scheduling, a public archive.
Send templated single mails through the API.
Views, clicks, bounces per campaign.
Complete HTTP API with per-user API permissions; Swagger docs on the instance.
Why it is in the stack
- Mail that arrives: newsletters without a middleman and without subscription fees.
- Subscriber data stays in your PostgreSQL; sending goes through your own mail server.
- Pre-wired to the shop so lists maintain themselves.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs newsletter.
At a glance
| Based on | listmonk · source · docs · API |
| Replaces | Mailchimp, SendGrid · listed as Wilhelm Mail in the ecosystem reference |
| Type · category | External service · Services |
| Licence | service AGPL-3.0 · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support/newsletter |
| Docker image | listmonk/listmonk:latest · port 9000 |
| Compose profile | listmonk |
| Folder | apps/newsletter/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Service
| Image | listmonk/listmonk:latest |
| Port | 9000 |
| Init script | ./init-listmonk.sh |
| Health check | http /health every 30s · timeout 5s · 3 retries |
Dependencies
| Requires | nothing |
Skin & branding
| Slogan | Mail that arrives. |
| Theme | primary #6B7280 · mode system |
| Logo | ./appinfo/icon.svg |
Secrets
Declared in secretsRefs but apps/newsletter/secrets.spec.yaml does not exist in the repository.
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | GDPR-supporting features (self-service data export, one-click deletion, self-service blocklist, anonymous tracking) - compliance is established by the operator. source |
Zerodha-backed FOSS project without certifications and without its own hosting offering.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idnewsletterdomainnewslettervendorlistmonknamenewsletterdescriptionlistmonk integration for the Wilhelm stackversion2.0.0licenseservice, wilhelm
serviceAGPL-3.0wilhelmProprietarymaintainername, email, url
typeexternalcategoryserviceemoji📦pixelIcon............ .KKKKKKKKKK. .KWWWWWWWWK. .KWWWWWKKWK. .KWWWKKKKWK. .KWKKKKKWWK. .KWWWKKWWWK. .KWWWKWWWWK. .KWWWWWWWWK. .KKKKKKKKKK. ............
primaryColor#6B7280tags[ ]compliancecertifications, note
certifications1 item
0id, status, scope, source, note
idgdprstatusconformantscopesoftwaresourcelistmonk.appnoteGDPR-supporting features (self-service data export, one-click deletion, self-service blocklist, anonymous tracking) - compliance is established by the operator.noteZerodha-backed FOSS project without certifications and without its own hosting offering.componentsservice, vscode
serviceimage, port, healthCheck, init
imagelistmonk/listmonk:latestport9000healthChecktype, path, interval, timeout, retries
typehttppath/healthinterval30stimeout5sretries3vscodeextensions, extension
extensions[ ]extensionnulldependenciesrequires, optional
requires[ ]optional[ ]secretsRefs./secrets.spec.yamlskinslogan, logo, theme
marketplacevisibility, pricing, supportUrl
Standalone compose
Every service app can run on its own: cd apps/newsletter && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.
docker-compose.yml
# newsletter - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/newsletter/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
# cp .env.example .env && docker compose up -d
# → http://localhost:${NEWSLETTER_PORT:-9000}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
newsletter:
image: listmonk/listmonk:latest
restart: unless-stopped
env_file:
- .env
ports:
- "${NEWSLETTER_PORT:-9000}:9000"
healthcheck:
test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:9000/health"]
interval: 30s
timeout: 5s
retries: 3
start_period: 20s
networks:
- newsletter
# TODO: persistent volume(s) if this image stores state. e.g.:
# volumes: [ "newsletter_data:/data" ]
networks:
newsletter:
name: newsletter
.env.example
# ── Listmonk (Newsletter & Mailing Lists) ──────────────────────────────────── LISTMONK_PORT=9001 EMBED_LISTMONK_PORT=8900 LISTMONK_ADMIN_USER=admin LISTMONK_ADMIN_PASSWORD=change_me LISTMONK_DB_PASSWORD=change_me
README
The README is not in English - see apps/newsletter/README.md.
Links & documentation files
Upstream docs · Upstream API · Upstream source · Support · apps/newsletter/
doc/ai-notes.md · doc/api.md · doc/n8n.md · doc/newsletter-reference.md · doc/sources.md
storefront
Your shop, your look.
medusa-storefront integration for the Wilhelm stack
What it does
storefront is the Medusa Next.js starter - the customer-facing shop: product listings, product pages, cart, multi-step checkout and customer accounts, as a pure client of the Store API with no database of its own.
It ships with Stripe and PayPal, mirrors the backend's regions and currencies, and can be restyled or replaced freely because it only speaks the public API.
Features
Search, filters, variants, images.
Multi-step checkout with shipping and payment.
Registration, login, order history, addresses.
Stripe and PayPal out of the box.
App Router, TypeScript, server and client rendering.
Why it is in the stack
- Your shop, your look - a production-shaped storefront whose source you own.
- No hosted-storefront subscription; customer analytics can go to Plausible.
Screenshots
At a glance
| Based on | Medusa Next.js Starter · source · docs |
| Type · category | External service · Services |
| Licence | service MIT · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support/storefront |
| Docker image | medusajs/nextjs-starter-medusa · port 9000 |
| Folder | apps/storefront/manifest.json |
Icon & assets
tools/app-assets → appinfo/ · serving copy in ./app/public
Configuration
Service
| Image | medusajs/nextjs-starter-medusa |
| Port | 9000 |
| Health check | http / every 30s · timeout 5s · 3 retries |
Dependencies
| Requires | nothing |
Skin & branding
| Slogan | Your shop, your look. |
| Theme | primary #6B7280 · mode system |
| Logo | ./appinfo/icon.svg |
Secrets
Declared in secretsRefs but apps/storefront/secrets.spec.yaml does not exist in the repository.
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
Next.js starter frontend - compliance follows the shop instance (see app "shop").
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idstorefrontdomainstorefrontvendormedusa-storefrontnamestorefrontdescriptionmedusa-storefront integration for the Wilhelm stackversion2.0.0licenseservice, wilhelm
serviceMITwilhelmProprietarymaintainername, email, url
typeexternalcategoryserviceemoji📦pixelIcon............ .KKKKKKKKKK. .KKKKKKKKKK. .KKWKWKWKWK. .KWWWWWWWWK. .KWKWWWWKWK. .KWKWKKWKWK. .KWKWKKWKWK. .KWKKKKKKWK. .KKKKKKKKKK. ............
primaryColor#6B7280tags[ ]compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.noteNext.js starter frontend - compliance follows the shop instance (see app "shop").webpublicDir
publicDir./app/publicpreviewdir, desktop, mobile, gallery
dir./previewdesktop./preview/desktop.pngmobile./preview/mobile.pnggallery4 items
0src, caption, kind
1src, caption, kind
2src, caption, kind
3src, caption, kind
componentsservice, vscode
serviceimage, port, healthCheck
imagemedusajs/nextjs-starter-medusaport9000healthChecktype, path, interval, timeout, retries
typehttppath/interval30stimeout5sretries3vscodeextensions, extension
extensions[ ]extensionnulldependenciesrequires, optional
requires[ ]optional[ ]secretsRefs./secrets.spec.yamlskinslogan, logo, theme
marketplacevisibility, pricing, supportUrl, screenshots
Standalone compose
Every service app can run on its own: cd apps/storefront && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.
docker-compose.yml
# storefront - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/storefront/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
# cp .env.example .env && docker compose up -d
# → http://localhost:${STOREFRONT_PORT:-9000}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
storefront:
image: medusajs/nextjs-starter-medusa
restart: unless-stopped
env_file:
- .env
ports:
- "${STOREFRONT_PORT:-9000}:9000"
healthcheck:
test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:9000/"]
interval: 30s
timeout: 5s
retries: 3
start_period: 20s
networks:
- storefront
# TODO: persistent volume(s) if this image stores state. e.g.:
# volumes: [ "storefront_data:/data" ]
networks:
storefront:
name: storefront
.env.example
# ── Medusa Storefront ──────────────────────────────────────────────────────── # Inherits MEDUSA_* from medusa/.env or root .env MEDUSA_STOREFRONT_PORT=8000 MEDUSA_STOREFRONT_URL=http://localhost:8000 # ── Wilhelm Brand (zentrale Single Source of Truth) ──────────────────────── # Setze diese Werte in der Root-.env (siehe config/stack.defaults.env). # docker-compose mappt sie auf NEXT_PUBLIC_BRAND_* - im Storefront verfügbar # über getBrand() aus @lib/brand. # # WILHELM_BRAND_NAME="Wilhelm" # WILHELM_BRAND_PRIMARY_COLOR="#0369FF" # WILHELM_BRAND_ACCENT_COLOR="#FFCC00" # WILHELM_BRAND_LOGO_URL=
README
The README is not in English - see apps/storefront/README.md.
Links & documentation files
Upstream docs · Upstream source · Support · apps/storefront/
doc/ai-notes.md · doc/api.md · doc/n8n.md · doc/sources.md · doc/storefront-reference.md
tell
A mailbox with brains.
tell-imap integration for the Wilhelm stack
What it does
tell is a mailbox with brains: a very lean IMAP-to-webhook bridge that watches a mailbox over IMAP IDLE and pushes every new mail as JSON to n8n - the entry trigger for all mail-based workflows, without a cloud automation service ever seeing the mail.
One file, one dependency, a reconnect loop and a health endpoint. The usual source is the stack's own mail server.
Features
Live watching, no polling.
Each mail becomes a JSON POST, optionally with the body.
Robust loop with configurable delay.
A health endpoint; restartable from the settings app.
Why it is in the stack
- Event-driven mail automation with a tiny footprint and no state.
- Mail credentials never leave the stack.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs tell.
At a glance
| Based on | Wilhelm tell-imap |
| Type · category | External service · Services |
| Licence | service MIT · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support/tell |
| Docker image | wilhelm/tell-imap:latest · port 3000 |
| Folder | apps/tell/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Service
| Image | wilhelm/tell-imap:latest |
| Port | 3000 |
| Health check | http / every 30s · timeout 5s · 3 retries |
Dependencies
| Requires | nothing |
Skin & branding
| Slogan | A mailbox with brains. |
| Theme | primary #6B7280 · mode system |
| Logo | ./appinfo/icon.svg |
Secrets
Declared in secretsRefs but apps/tell/secrets.spec.yaml does not exist in the repository.
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idtelldomaintellvendortell-imapnametelldescriptiontell-imap integration for the Wilhelm stackversion2.0.0licenseservice, wilhelm
serviceMITwilhelmProprietarymaintainername, email, url
typeexternalcategoryserviceemoji📦pixelIcon............ .KKKKKKKKKK. .KWKKKKKKWK. .KWKWWWGKWK. .KWKWWWWKWK. .KWKGGWWKWK. .KWKGGGWKWK. .KWKKKKKKWK. .KWWWWWWWWK. .KKKKKKKKKK. ............
primaryColor#6B7280tags[ ]compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.componentsservice, vscode
serviceimage, port, healthCheck
imagewilhelm/tell-imap:latestport3000healthChecktype, path, interval, timeout, retries
typehttppath/interval30stimeout5sretries3vscodeextensions, extension
extensions[ ]extensionnulldependenciesrequires, optional
requires[ ]optional[ ]secretsRefs./secrets.spec.yamlskinslogan, logo, theme
marketplacevisibility, pricing, supportUrl
Standalone compose
Every service app can run on its own: cd apps/tell && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.
docker-compose.yml
# tell - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/tell/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
# cp .env.example .env && docker compose up -d
# → http://localhost:${TELL_PORT:-3000}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
tell:
image: wilhelm/tell-imap:latest
restart: unless-stopped
env_file:
- .env
ports:
- "${TELL_PORT:-3000}:3000"
healthcheck:
test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:3000/"]
interval: 30s
timeout: 5s
retries: 3
start_period: 20s
networks:
- tell
# TODO: persistent volume(s) if this image stores state. e.g.:
# volumes: [ "tell_data:/data" ]
networks:
tell:
name: tell
.env.example
# ── Tell IMAP (IMAP → n8n Bridge) ──────────────────────────────────────────── # Inherits IMAP_* from root .env or set here IMAP_HOST=mailcow IMAP_PORT=993 IMAP_USER= IMAP_PASS= IMAP_TLS=true IMAP_MAILBOX=INBOX TELL_IMAP_WEBHOOK_URL=http://n8n:5678/webhook/tell-imap IMAP_FETCH_BODY=false IMAP_RECONNECT_DELAY_MS=5000
README
The README is not in English - see apps/tell/README.md.
Links & documentation files
Wilhelm S3
Nextcloud speaks S3.
Native Nextcloud app that turns Nextcloud into an S3 server. Buckets are real Nextcloud folders, objects are real files (with sharing, versions, quota). Other apps such as Twenty CRM speak S3 while the files sit right in the Nextcloud file browser. No second object store.
What it does
Wilhelm S3 turns Nextcloud into an S3 server: a native Nextcloud app that maps S3 buckets to top-level folders and object keys to file paths. An S3 PUT from Twenty CRM or any AWS-SDK client lands as a real file in a user's Nextcloud Files - with sharing, versions and quota - instead of in a second object store such as MinIO.
Requests are verified with AWS Signature V4; access keys map to a Nextcloud user whose Files hold the buckets. Deployment is a script with health check and rollback, and a smoke test does a put-head-get round trip.
Features
Buckets are folders, objects are files.
The AWS SDK default; no Nextcloud session or CSRF needed.
Access key to secret and user, managed with occ.
Point any client at the app path with forcePathStyle.
Why it is in the stack
- Nextcloud speaks S3: one storage system instead of two.
- Objects stay visible and manageable in the normal Nextcloud UI.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs s3proxy.
At a glance
| Based on | Wilhelm-native - no upstream project |
| Type · category | Integration · Storage |
| Licence | service AGPL-3.0 · wilhelm Apache-2.0 |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support |
| Nextcloud app id | wilhelms3 |
| Resources | memory 128Mi · cpu 0.25 · storage 1Gi |
| Tags | s3storagenextcloudapi |
| Folder | apps/s3proxy/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Nextcloud app
| App id | wilhelms3 |
| Path | . |
Desktop build (Electron)
| Enabled | no - opted out |
Resources & permissions
| Memory · CPU · storage | 128Mi · 0.25 · 1Gi |
| Host network | no |
| Privileged | no |
| Egress domains | none - no outbound connections declared |
Dependencies
| Requires | nextcloud >=30 |
| Optional | twenty |
| Provides | s3-endpoint |
Single sign-on (OIDC)
| As client | no |
| As provider | no |
| Fallback | none |
Skin & branding
| Slogan | Nextcloud speaks S3. |
| Theme | primary #3B82F6 · mode system |
| Logo | ./icon.svg |
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
ids3proxydomains3proxyvendorwilhelmnameWilhelm S3descriptionNative Nextcloud app that turns Nextcloud into an S3 server. Buckets are real Nextcloud folders, objects are real files (with sharing, versions, quota). Other apps such as Twenty CRM speak S3 while the files sit right in the Nextcloud file browser. No second object store.version0.1.0licenseservice, wilhelm
serviceAGPL-3.0wilhelmApache-2.0maintainername, email, url
typeintegrationcategorystorageicon./icon.svgemoji🪣pixelIcon............ .KKKKKKKKKK. .KWKKKKKKWK. .KWKWWWWKWK. .KWWKWWKWWK. .KWWKGGKWWK. .KWWWKKWWWK. .KWWWWWWWWK. .KWWWWWWWWK. .KKKKKKKKKK. ............
primaryColor#3B82F6tagss3storagenextcloudapicompliancecertifications, note
certifications1 item
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.componentsnextcloudApp, vscode
nextcloudAppappid, path
appidwilhelms3path.vscodeextensions, extension
extensions[ ]extensionnulldesktopenabled
enabledfalseresourcesmemory, cpu, storage
memory128Micpu0.25storage1GipermissionsneedsHostNetwork, needsPrivileged, egressDomains
needsHostNetworkfalseneedsPrivilegedfalseegressDomains[ ]dependenciesrequires, optional, provides
requires1 item
0id, version
idnextcloudversion>=30optional1 item
0id
idtwentyprovidess3-endpointoidcCapabilityasClient, asProvider, fallback
asClientfalseasProviderfalsefallbacknoneskinslogan, logo, theme
marketplacevisibility, pricing, supportUrl
Links & documentation files
Blackwell
A news letterpress
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs blackwell.
At a glance
| Based on | Blackwell |
| Type · category | Embedded app · Tools |
| Licence | service Apache-2.0 · wilhelm Apache-2.0 |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Docker image | nginx:alpine · port 80 |
| Tags | newsverlagrssbundestagthemen |
| Folder | apps/blackwell/manifest.json |
Icon & assets
tools/app-assets → appinfo/ · serving copy in ./service/app/public
Configuration
Service
| Image | nginx:alpine |
| Port | 80 |
| Compose fragment | ./service/compose.fragment.yml |
| Health check | http /healthz every 30s · timeout 5s · 3 retries |
Dependencies
| Requires | nextcloud >=30 |
Single sign-on (OIDC)
| As client | no |
| As provider | no |
| Fallback | none |
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idblackwelldomainblackwellvendorblackwellnameBlackwelldescriptionA news letterpress version0.1.0licenseservice, wilhelm
serviceApache-2.0wilhelmApache-2.0maintainername, email, url
typeembeddedcategorytoolsicon./icon.svgemoji📰primaryColor#1A1A1AtagsnewsverlagrssbundestagthemenwebpublicDir
publicDir./service/app/publiccomponentsservice, vscode
serviceimage, compose, port, healthCheck
imagenginx:alpineport80healthChecktype, path, interval, timeout, retries
typehttppath/healthzinterval30stimeout5sretries3vscodeextensions, extension
extensions[ ]extensionnulldependenciesrequires, optional, provides
requires1 item
0id, version
idnextcloudversion>=30optional[ ]provides[ ]oidcCapabilityasClient, asProvider, fallback
asClientfalseasProviderfalsefallbacknonesecretsRefs[ ]marketplacevisibility, screenshots, pricing, supportUrl
visibilityprivatescreenshots[ ]pricingfreesupportUrlFrom the README
Add workflows/ for n8n exports, schemas/ for NocoDB tables, service/ for a Docker service, or nextcloud/ for a native NC app - see the canonical apps/_template/ and the root README - Building an App.
Read on: apps/blackwell/README.md
Links & documentation files
Bluedune
Full-stack HTML, done.
Fullstack HTML Framework
What it does
Bluedune is a full-stack HTML framework in the Wilhelm family - the idea that a page, its data and its behaviour can be written as HTML, in the spirit of HTML67, without a separate frontend and backend project.
The app is scaffolded from the Wilhelm template: manifest, icon and README exist, the service image and port are still to be defined. This page documents the contract, not yet a running product.
Features
Embedded app type - runs inside the Nextcloud shell once a service exists
Apache-2.0 licensed, unusually permissive for the stack
Template slots for n8n workflows, NocoDB schemas, a service and a Nextcloud app
Why it is in the stack
- Full-stack HTML, done: one language for the whole page.
- Status is honest - scaffold only; the manifest is the specification to build against.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs bluedune.
At a glance
| Based on | Bluedune |
| Type · category | Embedded app · Tools |
| Licence | service Apache-2.0 · wilhelm Apache-2.0 |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Docker image | TODO/replace-me:latest |
| Folder | apps/bluedune/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Service
| Image | TODO/replace-me:latest |
| Health check | http /healthz every 30s · timeout 5s · 3 retries |
Dependencies
| Requires | nextcloud >=30 |
Single sign-on (OIDC)
| As client | no |
| As provider | no |
| Fallback | none |
Skin & branding
| Slogan | Full-stack HTML, done. |
| Theme | primary #6B7280 · mode system |
| Logo | ./icon.svg |
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idbluedunedomainbluedunevendorbluedunenameBluedunedescriptionFullstack HTML Frameworkversion0.1.0licenseservice, wilhelm
serviceApache-2.0wilhelmApache-2.0maintainername, email, url
typeembeddedcategorytoolsicon./icon.svgemoji🏜️pixelIcon............ .KKKKKKKKKK. .KWWWWWWWWK. .KWWWWWWWWK. .KWWWKKWWWK. .KWWKWWKWWK. .KWKWWWWKWK. .KKWWWWWWKK. .KGGGGGGGGK. .KKKKKKKKKK. ............
primaryColor#6B7280tags[ ]compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.componentsservice, vscode
serviceimage, port, healthCheck
imageTODO/replace-me:latestport0healthChecktype, path, interval, timeout, retries
typehttppath/healthzinterval30stimeout5sretries3vscodeextensions, extension
extensions[ ]extensionnulldependenciesrequires, optional, provides
requires1 item
0id, version
idnextcloudversion>=30optional[ ]provides[ ]oidcCapabilityasClient, asProvider, fallback
asClientfalseasProviderfalsefallbacknonesecretsRefs[ ]skinslogan, logo, theme
marketplacevisibility, screenshots, pricing, supportUrl
visibilityprivatescreenshots[ ]pricingfreesupportUrlFrom the README
Add workflows/ for n8n exports, schemas/ for NocoDB tables, service/ for a Docker service, or nextcloud/ for a native NC app - see the canonical apps/_template/ and the root README - Building an App.
Read on: apps/bluedune/README.md
Links & documentation files
Codeflow
See code instead of reading it.
ReactFlow-based code visualizer + editor - bundled into Enter as a VS Code extension
What it does
Codeflow shows code instead of making you read it: a visualiser and editor for the real symbol graph of a repository - functions, components, classes, methods and their call, render and import edges - plus the stack-level artefacts around them: app manifests, n8n workflows, compose dependencies, JSON schemas.
It is bundled into Enter as a VS Code extension. The graph is extracted by a tool into the repo, and the view refreshes whenever the graph changes - including when a coding agent rewrites it.
Features
Force (animated physics), Layer (call direction left to right), Bundle (hierarchical edge bundling) and Circles (zoomable circle packing of directories, files and symbols).
Pan, zoom, hover to highlight callers and callees, click to jump to file and line.
Toggle utility symbols and file-level import edges.
Manifest dependencies, n8n node graphs, docker-compose depends_on and schemas in the same picture.
Every app carries a graph.codeflow file with its own custom editor.
The renderer is vanilla; the d3-style layouts are ports.
Why it is in the stack
- See the architecture as it is, extracted from the code, not as it was drawn once.
- Lives in the editor the team already uses; the agent can open it from a chat answer.
- Replaces commercial code-map tools without sending the source anywhere.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs codeflow.
At a glance
| Based on | Wilhelm-native - no upstream project |
| Type · category | Infrastructure · Tools |
| Licence | service Apache-2.0 · wilhelm Apache-2.0 |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support/codeflow |
| Tags | editorvisualizationreactflowgraph |
| Folder | apps/codeflow/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Inside Enter (code-server)
| Bundled extension | ./extension |
Dependencies
| Requires | nothing |
| Provides | ui-component |
Single sign-on (OIDC)
| As client | no |
| As provider | no |
| Fallback | none |
Skin & branding
| Slogan | See code instead of reading it. |
| Theme | primary #A855F7 · mode system |
| Logo | ./icon.svg |
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idcodeflowdomaincodeflowvendorwilhelmnameCodeflowdescriptionReactFlow-based code visualizer + editor - bundled into Enter as a VS Code extensionversion0.1.0licenseservice, wilhelm
serviceApache-2.0wilhelmApache-2.0maintainername, email, url
typeinfrastructurecategorytoolsicon./icon.svgemoji🪢pixelIcon............ .KKKKKKKKKK. .KWKKWWWWWK. .KWKKWWWWWK. .KWWWKWWWWK. .KWWWWKWWWK. .KWWWWWWWWK. .KWWWWWKKWK. .KWWWWWKKWK. .KKKKKKKKKK. ............
primaryColor#A855F7tagseditorvisualizationreactflowgraphcompliancecertifications, note
certifications1 item
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.dependenciesrequires, optional, provides
requires[ ]optional[ ]providesui-componentoidcCapabilityasClient, asProvider, fallback
asClientfalseasProviderfalsefallbacknonesecretsRefs[ ]skinslogan, logo, theme
marketplacevisibility, screenshots, pricing, supportUrl
componentsvscode
vscodeextensions, extension
extensions[ ]extension./extensionFrom the README
Status: functional. Renders the real symbol graph (functions, React components, classes, methods) with call / render / import edges - plus the app-level artifacts: app manifests (requires dependencies between apps), n8n workflows (node-to-node flow), docker-compose services (depends_on), JSON schemas. The graph is produced by tools/codeflow-extract (ts-morph + artifact scan) and written to .wilhelm/codeflow/graph.json; the webview picks it up automatically.
A file watcher on .wilhelm/codeflow/*.json opens/refreshes the webview whenever a graph is (re)written - including when the Caret agent runs the extractor. Caret can also open it explicitly by emitting <CODEFLOW src="…" /> in a chat answer (parsed in apps/enter/.../plan-render.ts).
Read on: apps/codeflow/README.md
Links & documentation files
Enter
The editor that thinks along.
Cursor-style AI code editor (code-server + Enter Chat extension) - Plan / Inspect / Agent modes powered by Anthropic Claude
What it does
Enter is Wilhelm's Cursor alternative: browser-based VS Code (code-server) with a bundled chat extension that gives you Cursor's three ways of working - Plan, Inspect and Agent - powered by Anthropic Claude. The chat is a pinned pane in the first editor column; files open next to it; Ctrl/Cmd+L focuses the chat.
The decisive difference to Cursor is how it talks to the model: the extension shells out to the local Claude Code CLI, so the existing Anthropic subscription does the work - no API key, no per-token bill, no SaaS backend in between. Every tool call streams into the chat as it happens.
Features
Read-only planning - the agent reads and reasons, no edits, no shell.
Conversational questions about the codebase, read-only.
Full agent with edits and shell inside the sandboxed workspace mount.
Terminal, extensions, settings sync, a built-in port proxy for the apps you run.
The code graph extension ships in the same image; the agent can open graphs from a chat answer.
System prompts live in the extension source and are appended to every run.
Every app's memory and notes are loaded into the chat when you work on that app.
Why it is in the stack
- The editor that thinks along - Cursor's workflow, fully open-source and self-hosted.
- No API key and no token cost: it reuses the subscription session you already have.
- Runs in the existing Docker stack, embedded in Nextcloud, with the whole repository as the workspace.
Screenshots
Screenshots are the upstream project's official product shots (see preview/SOURCES.md) until the stack runs with demo data and tools/app-preview shoots real Wilhelm screens. Images © their respective projects.
At a glance
| Based on | code-server (Coder) · source · docs |
| Type · category | External service · Tools |
| Licence | service MIT · wrapper Apache-2.0 · wilhelm Apache-2.0 |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support/enter |
| Docker image | codercom/code-server:4.96.4 · port 8443 |
| Public URL | https://enter.<your-domain>/?folder=/workspace/wilhelm-techstack |
| Compose profile | enter |
| Nextcloud app id | wilhelmenter · Nextcloud 30-32 |
| Resources | memory 1Gi · cpu 1.0 · storage 5Gi |
| Tags | editoraiidecodingclaude |
| Folder | apps/enter/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Service
| Image | codercom/code-server:4.96.4 |
| Port | 8443 |
| Health check | http /healthz every 30s · timeout 5s · 5 retries |
Embedding in Nextcloud
| Registry id · label | enter · Enter - AI Code Editor |
| Subdomain | enter |
| Container | enter:8443 |
| Embed-proxy port (localhost) | 8976 |
| Compose profile | enter |
| Nextcloud config key | enter_app_url |
| iframe path | /?folder=/workspace/wilhelm-techstack |
Nextcloud app
| App id | wilhelmenter |
| Path | ./nextcloud |
| Nextcloud versions | 30 - 32 |
Inside Enter (code-server)
| Bundled extension | ./service/extension |
Desktop build (Electron)
| Enabled | yes |
| Reader path | /proxy/8765/ |
Resources & permissions
| Memory · CPU · storage | 1Gi · 1.0 · 5Gi |
| Host network | no |
| Privileged | no |
| Egress domains | none - no outbound connections declared |
Dependencies
| Requires | nextcloud >=30 |
| Optional | vault |
| Provides | embedded-appnc-app |
MCP (Model Context Protocol)
| Grants | the agent additionally gets the MCP of webwow |
Single sign-on (OIDC)
| As client | no |
| As provider | no |
| Fallback | none |
Skin & branding
| Slogan | The editor that thinks along. |
| Theme | primary #0F172A · mode system |
| Logo | ./icon.svg |
Secrets
Declared in secretsRefs but apps/enter/secrets.spec.yaml does not exist in the repository.
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| SOC 2 Type II Information security | attested | vendor | SOC 2 Type II of the company Coder; does not carry over to self-hosted code-server. source |
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
| ISO/IEC 27001 Information security | in progress | software | Wilhelm certification programme - implementation for all Wilhelm apps in progress. |
| WCAG Accessibility | in progress | software | Wilhelm certification programme - implementation for all Wilhelm apps in progress. |
| ISO 9241 Usability / ergonomics | in progress | software | Wilhelm certification programme - implementation for all Wilhelm apps in progress. |
| EAA / BFSG Accessibility | in progress | software | Wilhelm certification programme - implementation for all Wilhelm apps in progress. |
code-server itself is uncertified open-source software; the Coder attestation applies to the company.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
identerdomainentervendorwilhelmnameEnterdescriptionCursor-style AI code editor (code-server + Enter Chat extension) - Plan / Inspect / Agent modes powered by Anthropic Claudeversion0.1.0licenseservice, wrapper, wilhelm
serviceMITwrapperApache-2.0wilhelmApache-2.0maintainername, email, url
typeexternalcategorytoolsicon./icon.svgemoji⌨️pixelIcon............ ..........K. ..........K. ..........K. ...K......K. ..KK......K. .KKKKKKKKKK. ..KK........ ...K........ ............
primaryColor#0F172Atagseditoraiidecodingclaudecompliancecertifications, note
certifications6 items
0id, status, scope, source, note
idsoc2-type2statusattestedscopevendorsourcetrust.coder.comnoteSOC 2 Type II of the company Coder; does not carry over to self-hosted code-server.1id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.2id, status, scope, note
idiso-27001statusin-progressscopesoftwarenoteWilhelm certification programme - implementation for all Wilhelm apps in progress.3id, status, scope, note
idwcagstatusin-progressscopesoftwarenoteWilhelm certification programme - implementation for all Wilhelm apps in progress.4id, status, scope, note
idiso-9241statusin-progressscopesoftwarenoteWilhelm certification programme - implementation for all Wilhelm apps in progress.5id, status, scope, note
ideaastatusin-progressscopesoftwarenoteWilhelm certification programme - implementation for all Wilhelm apps in progress.notecode-server itself is uncertified open-source software; the Coder attestation applies to the company.desktopreaderPath
readerPath/proxy/8765/componentsservice, nextcloudApp, embed, vscode
serviceimage, port, healthCheck
imagecodercom/code-server:4.96.4port8443healthChecktype, path, interval, timeout, retries
typehttppath/healthzinterval30stimeout5sretries5nextcloudAppappid, path, minNcVersion, maxNcVersion
embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile, iframePath
identerlabelEnter - AI Code EditorncConfigKeyenter_app_urlsubdomainentercontainerentercontainerPort8443embedProxyPort8976profileenteriframePath/?folder=/workspace/wilhelm-techstackvscodeextensions, extension
extensions[ ]extension./service/extensionresourcesmemory, cpu, storage
memory1Gicpu1.0storage5GipermissionsneedsHostNetwork, needsPrivileged, egressDomains
needsHostNetworkfalseneedsPrivilegedfalseegressDomains[ ]mcpgrants
grantswebwowdependenciesrequires, optional, provides
requires1 item
0id, version
idnextcloudversion>=30optional1 item
0id
idvaultprovidesembedded-appnc-appoidcCapabilityasClient, asProvider, fallback
asClientfalseasProviderfalsefallbacknonesecretsRefs./secrets.spec.yamlskinslogan, logo, theme
previewdir, desktop, gallery
marketplacevisibility, screenshots, pricing, supportUrl
visibilitypublicscreenshots./preview/desktop.png./preview/gallery/01-chat-and-editor.jpg./preview/gallery/02-wilhelm-apps.jpgpricingfreesupportUrlwilhelm.tech/support/enterStandalone compose
Every service app can run on its own: cd apps/enter && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.
docker-compose.yml
# Enter - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/enter/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
# cp .env.example .env && docker compose up -d
# → http://localhost:${ENTER_PORT:-8443}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
enter:
image: codercom/code-server:4.96.4
restart: unless-stopped
env_file:
- .env
ports:
- "${ENTER_PORT:-8443}:8443"
healthcheck:
test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:8443/healthz"]
interval: 30s
timeout: 5s
retries: 5
start_period: 20s
networks:
- enter
# TODO: persistent volume(s) if this image stores state. e.g.:
# volumes: [ "enter_data:/data" ]
networks:
enter:
name: enter
.env.example
# Enter - standalone env. Copy to .env and fill in. # GENERATED by scripts/generate-standalone.mjs # Host port the app is published on. ENTER_PORT=8443 # Required secrets are specified in: # ./secrets.spec.yaml # Add the matching KEY=VALUE lines here.
From the README
Cursor-style AI code editor, fully open-source, self-hosted in Wilhelm. Browser-based VS Code (code-server) plus the bundled Caret chat extension with three Cursor-style modes - Plan, Inspect, Agent - that shell out to your local Claude Code CLI. No API key. No token cost. Your existing Anthropic Pro/Max subscription does all the work.
Cursor is closed-source and bills per-token via its own backend. Wilhelm needed a 1:1 replacement that:
Read on: apps/enter/README.md
Links & documentation files
Upstream docs · Upstream source · Support · apps/enter/
doc/ai-notes.md · doc/api.md · doc/enter-reference.md · doc/n8n.md · doc/sources.md
evi
Elevators, assets, everything in view.
elevator intelligence, property management and asset lifecycle platform
What it does
evi is an elevator-intelligence, property-management and asset-lifecycle platform by elevator intelligence GmbH, positioned as an embedded partner app in the Wilhelm catalogue: lifts, assets and their lifecycle in one view, next to the company's files, mail and projects.
Only the app contract exists in this repository so far - manifest, icon and README. The service image and port follow with the partner's delivery.
Features
Declared domain: elevator intelligence, property management, asset lifecycle
Embedded app type - runs inside the Nextcloud shell
Apache-2.0 licensed; requires Nextcloud 30 or newer
Why it is in the stack
- Elevators, assets, everything in view - a vertical application on the same self-hosted foundation as the rest of the stack.
- Status is honest: scaffold and contract; no data flows anywhere yet.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs evi.
At a glance
| Based on | Evi |
| Type · category | Embedded app · Tools |
| Licence | service Apache-2.0 · wilhelm Apache-2.0 |
| Maintainer | elevator intelligence GmbH · tobias@ev-i.de · www.elevatorintelligence.com |
| Docker image | TODO/replace-me:latest |
| Folder | apps/evi/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Service
| Image | TODO/replace-me:latest |
| Health check | http /healthz every 30s · timeout 5s · 3 retries |
Dependencies
| Requires | nextcloud >=30 |
Single sign-on (OIDC)
| As client | no |
| As provider | no |
| Fallback | none |
Skin & branding
| Slogan | Elevators, assets, everything in view. |
| Theme | primary #6B7280 · mode system |
| Logo | ./icon.svg |
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idevidomainevivendorevinameevidescriptionelevator intelligence, property management and asset lifecycle platformversion0.1.0licenseservice, wilhelm
serviceApache-2.0wilhelmApache-2.0maintainername, email, url
typeembeddedcategorytoolsicon./icon.svgemoji🏢pixelIcon............ .KKKKKKKKKK. .KWWWKWWWWK. .KWWWKWWWWK. .KWKKKKKWWK. .KWWWKWWWWK. .KWWWKWWWWK. .KWWWWWWGWK. .KWWWWWWWWK. .KKKKKKKKKK. ............
primaryColor#6B7280tags[ ]compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.componentsservice, vscode
serviceimage, port, healthCheck
imageTODO/replace-me:latestport0healthChecktype, path, interval, timeout, retries
typehttppath/healthzinterval30stimeout5sretries3vscodeextensions, extension
extensions[ ]extensionnulldependenciesrequires, optional, provides
requires1 item
0id, version
idnextcloudversion>=30optional[ ]provides[ ]oidcCapabilityasClient, asProvider, fallback
asClientfalseasProviderfalsefallbacknonesecretsRefs[ ]skinslogan, logo, theme
sloganElevators, assets, everything in view.logo./icon.svgthemeprimary, mode
primary#6B7280modesystemmarketplacevisibility, screenshots, pricing, supportUrl
visibilityprivatescreenshots[ ]pricingfreesupportUrlFrom the README
elevator intelligence, property management and asset lifecycle platform
Add workflows/ for n8n exports, schemas/ for NocoDB tables, service/ for a Docker service, or nextcloud/ for a native NC app - see the canonical apps/_template/ and the root README - Building an App.
Read on: apps/evi/README.md
Links & documentation files
Fabi AI
Fabi's projects, one board.
Fabi's app
What it does
Fabi AI is a personal project board - Fabi's projects, one board - shipped as a static page straight from the app folder, with a letter template and an n8n workflow that sends a physical letter through Deutsche Post.
It shows the smallest possible Wilhelm app: a web directory published through the manifest, branded assets, and automation attached through n8n instead of a backend of its own.
Features
Static single-page project board served from the app folder
Letter template for printed correspondence
n8n workflow: send a physical letter via Deutsche Post
Branded asset set: favicons, touch icon, OpenGraph card
Why it is in the stack
- Paper output from a web app via n8n - without an extra SaaS.
- Everything an app needs to exist in the stack, in a handful of files.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs fabi.
At a glance
| Based on | Fabi |
| Type · category | Embedded app · Tools |
| Licence | service Apache-2.0 · wilhelm Apache-2.0 |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Docker image | TODO/replace-me:latest |
| Folder | apps/fabi/manifest.json |
Icon & assets
tools/app-assets → appinfo/ · serving copy in .
Configuration
Service
| Image | TODO/replace-me:latest |
| Health check | http /healthz every 30s · timeout 5s · 3 retries |
Dependencies
| Requires | nextcloud >=30 |
Single sign-on (OIDC)
| As client | no |
| As provider | no |
| Fallback | none |
Skin & branding
| Slogan | Fabi's projects, one board. |
| Theme | primary #6B7280 · mode system |
| Logo | ./icon.svg |
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idfabidomainfabivendorfabinameFabi AIdescriptionFabi's appversion0.1.0licenseservice, wilhelm
serviceApache-2.0wilhelmApache-2.0maintainername, email, url
typeembeddedcategorytoolsicon./icon.svgemoji💕pixelIcon............ .KKKKKKKKKK. .KWWWWWWWWK. .KWKKWWKKWK. .KKWWKKWWKK. .KKWWWWWWKK. .KWKWWWWKWK. .KWWKWWKWWK. .KWWWKKWWWK. .KKKKKKKKKK. ............
primaryColor#6B7280tags[ ]compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.webpublicDir
publicDir.componentsservice, vscode
serviceimage, port, healthCheck
imageTODO/replace-me:latestport0healthChecktype, path, interval, timeout, retries
typehttppath/healthzinterval30stimeout5sretries3vscodeextensions, extension
extensions[ ]extensionnulldependenciesrequires, optional, provides
requires1 item
0id, version
idnextcloudversion>=30optional[ ]provides[ ]oidcCapabilityasClient, asProvider, fallback
asClientfalseasProviderfalsefallbacknonesecretsRefs[ ]skinslogan, logo, theme
marketplacevisibility, screenshots, pricing, supportUrl
visibilityprivatescreenshots[ ]pricingfreesupportUrlFrom the README
Add workflows/ for n8n exports, schemas/ for NocoDB tables, service/ for a Docker service, or nextcloud/ for a native NC app - see the canonical apps/_template/ and the root README - Building an App.
Read on: apps/fabi/README.md
Links & documentation files
WilheLLM
AI chat with character.
Wilhelm
What it does
WilheLLM is the consumer-style AI assistant you host yourself - built to match the claude.ai and Claude Desktop experience: streaming answers with a stop button, rich rendering, an animated avatar with voice and face, characters with personality. It runs an agent engine in the container with your own key and can be pointed at any Anthropic-compatible endpoint, including a fully local Ollama route.
Two things no hosted client offers: GlyphUp, a text annotation markup that is a strict superset of Markdown and travels as plain text through any chat API, and HTML67 rich messages rendered and sanitised in the chat. A feature matrix tracks the gaps against claude.ai honestly - no model picker, no history sidebar, no file upload yet.
Features
Interrupt and stop; light and dark themes synced to the Wilhelm tokens.
Marked, uncertain, emphasised and emotional text as plain UTF-8; renderer, patch applier, tests.
Cards, charts, tables and maps in answers, sanitised.
A 3D dot avatar and synthesised speech.
Personas such as the Clause family with their own greeting and voice.
Built-in Wilhelm context in the system prompt, switchable.
GIFs and memes on request, switchable off.
Twin builds kept in parity by a sync tool.
Why it is in the stack
- AI chat with character - a Claude-style surface you host, with your own key and endpoint.
- Conversations and context stay in your stack; no per-seat SaaS subscription.
- Expressive output (GlyphUp, HTML67) no hosted client has.
Screenshots
The Clause character family - Santa greets with the persona's own introduction; the sidebar keeps the conversation history, the composer at the bottom takes text and attachments. The whole interface is rendered with the Wilhelm UI tokens.
desktop.pngThe same chat on a phone-sized viewport.
mobile.pngAt a glance
| Based on | Wilhellm |
| Type · category | Hosted app · Tools |
| Licence | service Apache-2.0 · wilhelm Apache-2.0 |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech |
| Docker image | wilhelm/wilhe-llm:latest · port 3058 |
| Folder | apps/wilhe-llm/manifest.json |
Icon & assets
tools/app-assets → appinfo/ · serving copy in ./service/app/public
Configuration
Service
| Image | wilhelm/wilhe-llm:latest |
| Port | 3058 |
| Compose fragment | ./service/compose.fragment.yml |
| Health check | http /healthz every 30s · timeout 5s · 3 retries |
Dependencies
| Requires | nothing |
Single sign-on (OIDC)
| As client | no |
| As provider | no |
| Fallback | none |
Skin & branding
| Slogan | AI chat with character. |
| Theme | primary #6B7280 · mode system |
| Logo | ./icon.svg |
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idwilhe-llmdomainwilhe-llmvendorwilhellmnameWilheLLMdescriptionWilhelmversion0.1.0licenseservice, wilhelm
serviceApache-2.0wilhelmApache-2.0maintainername, email, url
typehostedcategorytoolsicon./icon.svgemoji💘pixelIcon............ ..KKKKKKKK.. .KWWWWWWWWK. .KWWWWWWWWK. .KWKWKWKWWK. .KWWWWWWWWK. ..KKKKKKKK.. ..KKK....... ..KK........ ............ ............ ............
primaryColor#6B7280tags[ ]compliancecertifications, note
certifications1 item
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.webpublicDir
publicDir./service/app/publicpreviewdir, desktop, mobile, capture
componentsservice, vscode
serviceimage, port, compose, healthCheck
imagewilhelm/wilhe-llm:latestport3058healthChecktype, path, interval, timeout, retries
typehttppath/healthzinterval30stimeout5sretries3vscodeextensions, extension
extensions[ ]extensionnulldependenciesrequires, optional, provides
requires[ ]optional[ ]provides[ ]oidcCapabilityasClient, asProvider, fallback
asClientfalseasProviderfalsefallbacknonesecretsRefs[ ]skinslogan, logo, theme
marketplacevisibility, screenshots, pricing, supportUrl
visibilityprivatescreenshots./preview/desktop.png./preview/mobile.pngpricingfreesupportUrlwilhelm.techStandalone compose
Every service app can run on its own: cd apps/wilhe-llm && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.
docker-compose.yml
# WilheLLM - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/wilhe-llm/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
# cp .env.example .env && docker compose up -d
# → http://localhost:${WILHE_LLM_PORT:-3058}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
wilhe-llm:
image: wilhelm/wilhe-llm:latest
restart: unless-stopped
env_file:
- .env
ports:
- "${WILHE_LLM_PORT:-3058}:3058"
healthcheck:
test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:3058/healthz"]
interval: 30s
timeout: 5s
retries: 3
start_period: 20s
networks:
- wilhe-llm
# TODO: persistent volume(s) if this image stores state. e.g.:
# volumes: [ "wilhe-llm_data:/data" ]
networks:
wilhe-llm:
name: wilhe-llm
.env.example
# ── WilheLLM (consumer Claude alternative, profile: wilhe-llm) ──────────────── # Host port the web UI is published on (container listens on 3058). WILHELLM_HOST_PORT=5690 # Agent engine: open-claude-code (default, baked into the image, bring-your-own-key) # or claude (needs a logged-in CLI - not usable headless in the container). WILHELLM_ENGINE=open-claude-code # Consumer key for the open-claude-code engine. Required for it to answer. ANTHROPIC_API_KEY= # Optional: custom Anthropic-compatible endpoint / model. The image patches occ # to honour ANTHROPIC_BASE_URL (stock occ ignores it), so this points the occ # engine at a custom endpoint or the Ollama bridge - same as the claude engine. # ANTHROPIC_BASE_URL= # ANTHROPIC_MODEL=claude-sonnet-4-6 # Fun media: die KI darf zwischendurch ein GIF (GIPHY) oder Reddit-Meme schicken. # Memes brauchen keinen Key; für GIFs einen eigenen GIPHY-Key setzen (sonst Fallback # auf Reddit-Reaction-GIFs). Komplett abschalten mit WILHELLM_FUNMEDIA=0. # WILHELLM_FUNMEDIA=1 # GIPHY_API_KEY=
From the README
Add workflows/ for n8n exports, schemas/ for NocoDB tables, service/ for a Docker service, or nextcloud/ for a native NC app - see the canonical apps/_template/ and the root README - Building an App.
Read on: apps/wilhe-llm/README.md
Links & documentation files
wMovie
Cut video in the browser.
iMovie/CapCut alternative based on OpenCut: a browser-based, privacy-friendly video editor (timeline, multi-track, export) - self-hosted in the Wilhelm stack.
What it does
wMovie is a browser-based, privacy-friendly video editor - timeline, multi-track, export - hosted in the Wilhelm stack as an iMovie and CapCut alternative. Wilhelm does not rebuild the editor: it hosts OpenCut (the stable classic branch), skins it and routes it through the gateway like any other app.
Projects persist in PostgreSQL with their own accounts; a small shim translates OpenCut's hosted Redis client to the stack's Redis. Nextcloud files and SSO integration are noted as future work.
Features
Multi-track cutting, trimming, arranging.
Footage is processed in the browser, not uploaded to a vendor.
Render the finished video.
Persisted in PostgreSQL.
Web, database, Redis and the REST shim, merged via a compose fragment.
Why it is in the stack
- Cut video in the browser - without CapCut's cloud upload or Apple hardware lock-in.
- MIT upstream, no subscription; footage and projects stay on your machine.
Screenshots
No screenshots yet - add a preview block to the manifest and run node tools/app-preview/index.mjs wmovie.
At a glance
| Based on | Wilhelm-native - no upstream project |
| Type · category | Hosted app · Tools |
| Licence | service MIT · wilhelm Apache-2.0 |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Homepage | wilhelm.tech/wmovie |
| Support | wilhelm.tech/support |
| Docker image | wilhelm/wmovie:latest · port 3101 |
| Resources | memory 1Gi · cpu 1.0 · storage 5Gi |
| Tags | videoeditoropencutmediatimelinecapcutimovie |
| Folder | apps/wmovie/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Service
| Image | wilhelm/wmovie:latest |
| Port | 3101 |
| Compose fragment | ./service/compose.fragment.yml |
| Health check | http / every 30s · timeout 5s · 3 retries |
Resources & permissions
| Memory · CPU · storage | 1Gi · 1.0 · 5Gi |
| Host network | no |
| Privileged | no |
| Egress domains | freesound.org |
Dependencies
| Requires | nothing |
| Optional | nextcloud >=30 |
| Provides | ui-component |
Single sign-on (OIDC)
| As client | no |
| As provider | no |
| Fallback | none |
Skin & branding
| Slogan | Cut video in the browser. |
| Theme | primary #EAB308 · mode system |
| Logo | ./appinfo/icon.svg |
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idwmoviedomainwmovievendorwilhelmnamewMoviedescriptioniMovie/CapCut alternative based on OpenCut: a browser-based, privacy-friendly video editor (timeline, multi-track, export) - self-hosted in the Wilhelm stack.version0.1.0licenseservice, wilhelm
serviceMITwilhelmApache-2.0maintainername, email, url
typehostedcategorytoolsemoji🎬pixelIcon............ .KKKKKKKKKK. .KKKWKKWKKK. .KKKKKKKKKK. .KKWWWWWWKK. .KKWWWWWWKK. .KKWWWWWWKK. .KKKKKKKKKK. .KWWWWWWWWK. .KKKKKKKKKK. ............
primaryColor#EAB308tagsvideoeditoropencutmediatimelinecapcutimoviecompliancecertifications, note
certifications1 item
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.homepagewilhelm.tech/wmoviecomponentsservice, vscode
serviceimage, build, port, compose, healthCheck
imagewilhelm/wmovie:latestbuild./serviceport3101healthChecktype, path, interval, timeout, retries
typehttppath/interval30stimeout5sretries3vscodeextensions, extension
extensions[ ]extensionnullresourcesmemory, cpu, storage
memory1Gicpu1.0storage5GipermissionsneedsHostNetwork, needsPrivileged, egressDomains
needsHostNetworkfalseneedsPrivilegedfalseegressDomainsfreesound.orgdependenciesrequires, optional, provides
requires[ ]optional1 item
0id, version
idnextcloudversion>=30providesui-componentoidcCapabilityasClient, asProvider, fallback
asClientfalseasProviderfalsefallbacknonesecretsRefs[ ]skinslogan, logo, theme
marketplacevisibility, screenshots, pricing, supportUrl
Standalone compose
Every service app can run on its own: cd apps/wmovie && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.
docker-compose.yml
# wMovie - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/wmovie/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
# cp .env.example .env && docker compose up -d
# → http://localhost:${WMOVIE_PORT:-3101}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
wmovie:
image: wilhelm/wmovie:latest
restart: unless-stopped
env_file:
- .env
ports:
- "${WMOVIE_PORT:-3101}:3101"
healthcheck:
test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:3101/"]
interval: 30s
timeout: 5s
retries: 3
start_period: 20s
networks:
- wmovie
# TODO: persistent volume(s) if this image stores state. e.g.:
# volumes: [ "wmovie_data:/data" ]
networks:
wmovie:
name: wmovie
.env.example
# wMovie - standalone env. Copy to .env and fill in. # GENERATED by scripts/generate-standalone.mjs # Host port the app is published on. WMOVIE_PORT=3101 # No declared secrets. Add image-specific env vars here as needed.
README
The README is not in English - see apps/wmovie/README.md.
Links & documentation files
Website Builder
Build websites like Lego.
Webwow visual website builder in Nextcloud
What it does
Website Builder is Webwow, the visual site builder embedded in Nextcloud and the delivery backend of the website app: build pages visually like Lego, and serve the content of the website folder - including Markdown rendered to HTML - through the gateway. It stands in for Wix and Webflow.
The reference notes are candid: the upstream image origin could not be verified at the time of writing, so concrete builder features are documented as unconfirmed until that is settled.
Features
Build pages in the browser (manifest tags: website, builder, CMS).
Serves the public site from the website folder; Markdown to HTML.
Served behind AppAPI auth through an ExApp adapter.
Vendored in the stack; API not yet documented.
Why it is in the stack
- Build websites like Lego, inside the same self-hosted session as the content.
- The docs say what is verified and what is not.
Screenshots
The builder's start screen after login: 'Welcome to Webwow' and a Get started button - the shot tools/app-preview took from the running container.
desktop.pngThe same start screen on a phone-sized viewport.
mobile.pngScreenshots are the upstream project's official product shots (see preview/SOURCES.md) until the stack runs with demo data and tools/app-preview shoots real Wilhelm screens. Images © their respective projects.
At a glance
| Based on | Webwow |
| Type · category | External service · Website |
| Licence | service MIT · wrapper Proprietary · wilhelm Proprietary |
| Maintainer | Wilhelm Verlag · kernel@wilhelm.tech · wilhelm.tech |
| Support | wilhelm.tech/support/webwow |
| Docker image | webwow/webwow:latest · port 3002 |
| Public URL | https://site.<your-domain>/webwow · behind AppAPI auth |
| Compose profile | website-webwow |
| Nextcloud app id | wilhelmwebwow · Nextcloud 30-32 |
| Tags | websitebuildercms |
| Folder | apps/webwow/manifest.json |
Icon & assets
tools/app-assets → appinfo/
Configuration
Service
| Image | webwow/webwow:latest |
| Port | 3002 |
| Health check | http / every 30s · timeout 5s · 3 retries |
Embedding in Nextcloud
| Registry id · label | webwow · Webwow Site Builder |
| Subdomain | site |
| Container | webwow:3002 |
| Embed-proxy port (localhost) | 8913 |
| Compose profile | website-webwow |
| Nextcloud config key | webwow_editor_url |
| iframe path | /webwow |
| Auth gate | yes - served as ExApp behind AppAPI auth ({"id":"wilhelmwebwow","adapter":"webwow-exapp","upstream":"http://webwow:3002","prefix":"/webwow"}) |
Nextcloud app
| App id | wilhelmwebwow |
| Path | ./nextcloud |
| Nextcloud versions | 30 - 32 |
Dependencies
| Requires | nextcloud >=30 |
| Optional | vault |
MCP (Model Context Protocol)
| Transport | http |
| URL | http://host.docker.internal:3002/webwow/mcp/${WEBWOW_MCP_TOKEN} |
| Tools | pageslayerslayoutscollectionscomponentsstylescolor-variablesfontslocalesformsassetsasset-folderspage-folderssettingspublishingbatch |
Single sign-on (OIDC)
| As client | yes |
| As provider | no |
| Fallback | vaultwarden |
Skin & branding
| Slogan | Build websites like Lego. |
| Theme | primary #0369FF · mode system |
| Logo | ./nextcloud/appinfo/icon.svg |
Secrets
Declared in secretsRefs but apps/webwow/secrets.spec.yaml does not exist in the repository.
Compliance
| Standard | Status | Scope | Note |
|---|---|---|---|
| GDPR Privacy | conformant | software | Fully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator. |
| ISO/IEC 27001 Information security | in progress | software | Wilhelm certification programme - implementation for all Wilhelm apps in progress. |
| WCAG Accessibility | in progress | software | Wilhelm certification programme - implementation for all Wilhelm apps in progress. |
| ISO 9241 Usability / ergonomics | in progress | software | Wilhelm certification programme - implementation for all Wilhelm apps in progress. |
| EAA / BFSG Accessibility | in progress | software | Wilhelm certification programme - implementation for all Wilhelm apps in progress. |
Wilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.
Manifest
The complete manifest.json (schema v2), German strings rendered in English.
idwebwowdomainwebwowvendorwebwownameWebsite BuilderdescriptionWebwow visual website builder in Nextcloudversion2.0.0licenseservice, wrapper, wilhelm
serviceMITwrapperProprietarywilhelmProprietarymaintainername, email, url
typeexternalcategorywebsiteemoji💻pixelIcon............ .KKKKKKKKKK. .KWKKKKKKWK. .KWKKKKKKWK. .KWKWWWWKWK. .KWKWKWWKWK. .KWKWKKWKWK. .KWKKKKKKWK. .KWWWWWWWWK. .KKKKKKKKKK. ............
primaryColor#0369FFtagswebsitebuildercmscompliancecertifications, note
certifications5 items
0id, status, scope, note
idgdprstatusconformantscopesoftwarenoteFully self-hosted - all data stays in your own stack; GDPR compliance of the operation is established by the operator.1id, status, scope, note
idiso-27001statusin-progressscopesoftwarenoteWilhelm certification programme - implementation for all Wilhelm apps in progress.2id, status, scope, note
idwcagstatusin-progressscopesoftwarenoteWilhelm certification programme - implementation for all Wilhelm apps in progress.3id, status, scope, note
idiso-9241statusin-progressscopesoftwarenoteWilhelm certification programme - implementation for all Wilhelm apps in progress.4id, status, scope, note
ideaastatusin-progressscopesoftwarenoteWilhelm certification programme - implementation for all Wilhelm apps in progress.noteWilhelm component - runs fully self-hosted in your own stack, no data flows to third parties. Formal certifications (e.g. ISO 27001) rest with the operator of the installation.previewdir, desktop, mobile, gallery, capture
dir./previewdesktop./preview/desktop.pngmobile./preview/mobile.pnggallery14 items
0src, caption, kind
captionSeitenübersicht im Editor: alle Seiten, Ordner und Fehlerseitenkinddesktop1src, caption, kind
captionEditor im Phone-Breakpoint mit Style-Panelkinddesktop2src, caption, kind
captionCMS: Collection Projekte mit KI-Agent-Panel (Claude, OpenAI, Gemini, Grok)kinddesktop3src, caption, kind
4src, caption, kind
captionEinstellungen: Website, SEO, Custom Code, Agent, Nutzer, Securitykinddesktop5src, caption, kind
captionIntegrationen: MCP-URL und OAuth für KI-Assistentenkinddesktop6src, caption, kind
7src, caption, kind
8src, caption, kind
9src, caption, kind
10src, caption, kind
11src, caption, kind
12src, caption, kind
13src, caption, kind
captureurl, mobileUrl, wait
componentsservice, nextcloudApp, embed, vscode
serviceimage, port, healthCheck
imagewebwow/webwow:latestport3002healthChecktype, path, interval, timeout, retries
typehttppath/interval30stimeout5sretries3nextcloudAppappid, path, minNcVersion, maxNcVersion
embedid, label, ncConfigKey, subdomain, container, containerPort, embedProxyPort, profile, iframePath, gate, exapp
idwebwowlabelWebwow Site BuilderncConfigKeywebwow_editor_urlsubdomainsitecontainerwebwowcontainerPort3002embedProxyPort8913profilewebsite-webwowiframePath/webwowgatetrueexappid, adapter, upstream, prefix
vscodeextensions, extension
extensions[ ]extensionnullmcptransport, url, tools
transporthttptoolspageslayerslayoutscollectionscomponentsstylescolor-variablesfontslocalesformsassetsasset-folderspage-folderssettingspublishingbatchdependenciesrequires, optional
requires1 item
0id, version
idnextcloudversion>=30optional1 item
0id
idvaultoidcCapabilityasClient, asProvider, fallback
asClienttrueasProviderfalsefallbackvaultwardensecretsRefs./secrets.spec.yamlskinslogan, logo, theme
sloganBuild websites like Lego.themeprimary, mode
primary#0369FFmodesystemmarketplacevisibility, screenshots, pricing, supportUrl
visibilitypublicscreenshots./preview/desktop.png./preview/mobile.png./preview/gallery/01-pages-overview.png./preview/gallery/02-editor-phone-breakpoint.png./preview/gallery/03-cms-collections-agent.png./preview/gallery/04-webflow-importer.png./preview/gallery/05-settings.png./preview/gallery/06-integrations-mcp.png./preview/gallery/07-sites-dashboard.png./preview/gallery/08-login.png./preview/gallery/09-site-home.png./preview/gallery/10-site-leistungen.png./preview/gallery/11-site-preise.png./preview/gallery/12-site-team.png./preview/gallery/13-site-blog.png./preview/gallery/14-site-blog-mobile.pngpricingfreesupportUrlwilhelm.tech/support/webwowStandalone compose
Every service app can run on its own: cd apps/webwow && cp .env.example .env && docker compose up -d. Generated from the manifest by scripts/generate-standalone.mjs.
docker-compose.yml
# Website Builder - standalone Docker compose
# GENERATED by scripts/generate-standalone.mjs from apps/webwow/manifest.json
# Edit the manifest and re-run `npm run standalone:gen`, not this file.
#
# Quickstart:
# cp .env.example .env && docker compose up -d
# → http://localhost:${WEBWOW_PORT:-3002}
#
# Self-contained: own bridge network, published port, no shared proxy net.
# Inside the Wilhelm monorepo the app is wired differently (shared traefik
# + AppAPI auth) - that lives in the root docker-compose.yml, not here.
services:
webwow:
image: webwow/webwow:latest
restart: unless-stopped
env_file:
- .env
ports:
- "${WEBWOW_PORT:-3002}:3002"
healthcheck:
test: ["CMD", "wget", "--quiet", "--tries=1", "--spider", "http://localhost:3002/"]
interval: 30s
timeout: 5s
retries: 3
start_period: 20s
networks:
- webwow
# TODO: persistent volume(s) if this image stores state. e.g.:
# volumes: [ "webwow_data:/data" ]
networks:
webwow:
name: webwow
.env.example
# Website Builder - standalone env. Copy to .env and fill in. # GENERATED by scripts/generate-standalone.mjs # Host port the app is published on. WEBWOW_PORT=3002 # Required secrets are specified in: # ./secrets.spec.yaml # Add the matching KEY=VALUE lines here.
README
The README is not in English - see apps/webwow/README.md.
Links & documentation files
doc/ai-notes.md · doc/api.md · doc/embed-reference.md · doc/n8n.md · doc/sources.md