Enterprise self-host
Deploy Sessionly AI with Docker Compose (MySQL + API). Suitable for private cloud, VPC, or air-gapped environments.
Quick start
git clone https://github.com/DevHassanR/aio-frontend.git sessionly-ai
cd sessionly-ai
cp server/.env.example .env
# Edit the root .env: uncomment and set MYSQL_ROOT_PASSWORD; change SEED_EMAIL, SEED_PASSWORD,
# SEED_SITE_TOKEN, and unique JWT_SECRET (32+ characters),
# AUTOMATION_SECRET_KEY (16+) and IP_HASH_SALT (16+).
# Set TRUST_PROXY=0 for direct localhost; use 1 behind one trusted TLS proxy.
docker compose up --build -d
docker compose exec app sh -c "cd server && npm run seed:auth"
Docker Compose reads the root .env, not server/.env. Open http://localhost:3000/admin and sign in with your SEED_EMAIL and SEED_PASSWORD. Change both before internet exposure. Only set TRUST_PROXY=1 if exactly one trusted proxy is in front.
What’s included
- Session replay ingest + dashboard
- Client-side WAF policy
- Automation Studio (Slack, Jira, Datadog, PagerDuty, etc.)
- Organization admin + OIDC SSO (Okta, Azure AD, Google)
- Per-site integration marketplace
Production checklist
- Set a strong
JWT_SECRET(32+ chars),AUTOMATION_SECRET_KEY(16+), andIP_HASH_SALT(16+) - Keep JWT/API keys private and assign each user only to the sites they may access; admin access is not bound to source IP
- Set
TRUST_PROXY=1when behind nginx/Caddy/cloud load balancer so HTTPS snippets work - Configure
REPLAY_BASE_URLto your public HTTPS URL (e.g.https://your-host/replay) - Add allowed domains per site in the setup wizard before expecting ingest/WAF
- Enable OIDC SSO via
OIDC_ISSUER,OIDC_CLIENT_ID,OIDC_CLIENT_SECRET - Put TLS termination in front (nginx, Caddy, cloud load balancer)
Compare to LogRocket
LogRocket offers mature hosted SaaS and enterprise contracts. Sessionly AI self-host gives you data residency, WAF + replay in one stack, and built-in automations without a separate integration marketplace subscription.