Securo

Securo

Docker app from junkerderprovinz's Repository

Overview

Securo is a self-hosted personal finance manager: accounts, transactions, budgets, goals, assets and reports, with imports from OFX, QIF, CAMT and CSV and optional bank sync for European, US and Brazilian banks. Upstream runs it as six containers; this image puts the official backend and web app, the Celery worker and the scheduler into one. Getting started: • PostgreSQL already running? Enter its host, user and password. It needs pgvector, which pgvector/pgvector:pg16 and the PostgreSQL image Immich uses both have and the plain postgres image does not. Securo creates its database on the first start if the user may. • Redis already running? Enter its host. If other apps use database 0 on it, give Securo another number under Redis database. • No PostgreSQL or Redis? Set Built-in PostgreSQL and Built-in Redis to true and leave their host fields empty. • Set App address to the address you open Securo on. Bank sync and single sign-on send you back there. • The first start creates the tables, which takes under a minute. Securo is ready when the log says SECURO IS READY. Then open the web app and create your account. Passkeys only work over HTTPS on a domain, not on http://IP:port. Behind a reverse proxy, set Trusted proxies to 2. Source on GitHub: https://github.com/junkerderprovinz/securo This is an independent packaging of Securo and is not affiliated with the Securo project.

Securo

Build  Lint  Docker Pulls  Arch  Securo  Unraid  License: AGPL-3.0


The Securo personal finance manager on Unraid, from a single template. It uses the PostgreSQL and Redis you already run, or brings its own when you have none.


In Unraid's Community Applications soon   Run it with Docker   Download the source archive


A one-knight job: I build it, keep it running, work through the issues and add what people ask for, until nothing is missing. It is free, with no accounts, no telemetry, no ads and no paid tier. No asterisk anywhere. Nothing readable ever leaves your own walls. Forged on evenings and weekends, with heart and stubbornness.

If it has earned a place on your server or computer, toss a coin to your knight: it helps cover the costs and keeps the project alive. It also makes this knight's heart beat a little faster. Three ways below, whichever suits you.

Buy me a coffee   PayPal   Donate with crypto


Table of Contents

  1. What it looks like
  2. What it does
  3. Getting started
  4. Bank sync and single sign-on
  5. How AI is used here
  6. Support this project

1. What it looks like

The accounts and amounts in these pictures are made up.

Securo's dashboard with balances, spending by category and the latest transactions
The dashboard, served by the container on your server.


The transaction list of a checking account, with categories and running balance
Transactions with categories, filters and a running balance.


2. What it does

Securo is a self-hosted finance manager: accounts, transactions, budgets, goals, assets and reports, with imports from OFX, QIF, CAMT and CSV and optional bank sync. Upstream ships it as six containers in a compose file. This image puts them into one, built from the official backend and frontend images:

  • Your own databases first. By default Securo connects to the PostgreSQL and Redis containers you already have on Unraid. On the first start it creates its database and enables pgvector there.
  • Or everything built in. Set Built-in PostgreSQL and Built-in Redis to true, and both run inside the container, listen only on 127.0.0.1 and keep their data in your appdata folder.
  • A secret key on the first start. It is generated and kept in secrets.env, so nobody has to invent one.
  • One port. nginx serves the web app and passes /api/ to the backend. The Celery worker and scheduler run next to it, so bank syncs, recurring transactions and price updates work without extra containers.
  • A clear stop instead of a crash loop. A missing database host, a wrong password or a PostgreSQL without pgvector ends in one line that says what to change.
  • Upstream unchanged. The backend and the web app are the official images of the same version, and the settings from upstream's .env.example work as variables.

3. Getting started

  1. Install Securo from Community Applications.
  2. Pick your databases:
    • PostgreSQL already running? Enter its host, user and password. The server needs pgvector: pgvector/pgvector:pg16 and the PostgreSQL image Immich uses both have it, the plain postgres image does not. If the user may create databases, Securo creates securo on the first start; otherwise create it yourself and run CREATE EXTENSION vector; in it as a superuser.
    • Redis already running? Enter its host, and its password if it has one. If other apps use database 0 on it, give Securo a number of its own under Redis database.
    • Neither? Set Built-in PostgreSQL and Built-in Redis to true and leave the host fields empty.
  3. Set App address to the address you open Securo on, such as http://192.168.1.10:3000 or https://securo.example.com. Bank sync and single sign-on send you back there.
  4. Start the container. The first start creates the tables, which takes under a minute. It is ready when the log says SECURO IS READY.
  5. Open the web app and create your account. To keep strangers from signing up, set Registration to false afterwards.

With docker run:

docker run -d --name securo \
  -p 3000:8080 \
  -v /mnt/user/appdata/securo:/data \
  -e FRONTEND_URL=http://192.168.1.10:3000 \
  -e BUILTIN_POSTGRES=true \
  -e BUILTIN_REDIS=true \
  junkerderprovinz/securo:latest

A few things worth knowing:

  • Passkeys need HTTPS on a domain. Browsers refuse them on http://192.168.1.10:3000. Put Securo behind your reverse proxy with a certificate, or skip passkeys and use a password with two-factor codes.
  • Behind a reverse proxy, set Trusted proxies to 2, so the login rate limit counts each visitor on its own instead of all of them as your proxy.
  • Backups: with the built-in database, stop the container and copy the appdata folder. With your own PostgreSQL, back up the securo database the way you back up the others.

4. Bank sync and single sign-on

All of this stays off until you fill in the fields. Each provider switches itself on once its credentials are present.

Feature What to set Where you get it
European banks (PSD2) Enable Banking app ID, and the private key as enable_banking_private.pem in the secrets folder of your appdata Create a production application at enablebanking.com. Its redirect URL is your App address followed by /oauth/callback, which needs https
US and other banks SimpleFIN set to true A setup token from the SimpleFIN Bridge, pasted into Securo under Accounts
Brazilian banks Pluggy client ID and Pluggy client secret dashboard.pluggy.ai
Single sign-on OIDC set to true, plus discovery URL, client ID and secret Your provider, such as Authentik or Pocket ID. The redirect URI is your App address followed by /api/auth/oidc/callback

Every other setting from upstream's .env.example works as a container variable with the same name. The optional AI agents are not part of this image yet.


5. How AI is used here

One knight builds this, and AI is one of the tools I work with, the same way I work with an editor or a compiler. It helps me write code and documentation and it checks my work, and that saves me a good many evenings. It does not make the decisions, though. I read and understand everything before it ships, and if something here breaks, that is on me and not on the tool.

You do not have to take my word for it. The code is open and every release note is written by hand. The issue tracker shows how problems actually get handled, including the ones I got wrong the first time. If you find something that is not right, open an issue and I will look at it.


6. Support this project

Questions, bugs, ideas or feature requests? Please open a GitHub issue. Problems with Securo itself, the app rather than the container, are best reported upstream.

A one-knight job: I build it, keep it running, work through the issues and add what people ask for, until nothing is missing. It is free, with no accounts, no telemetry, no ads and no paid tier. No asterisk anywhere. Nothing readable ever leaves your own walls. Forged on evenings and weekends, with heart and stubbornness.

If it has earned a place on your server or computer, toss a coin to your knight: it helps cover the costs and keeps the project alive. It also makes this knight's heart beat a little faster. Three ways below, whichever suits you.

Buy me a coffee   PayPal   Donate with crypto


Securo is developed by the Securo project and released under AGPL-3.0. This is an independent packaging for Unraid and is not affiliated with the Securo project.

Requirements

A PostgreSQL server with pgvector and a Redis server, or Built-in PostgreSQL and Built-in Redis set to true.

Download Statistics

168
Total Downloads

Related apps

Details

Repository
junkerderprovinz/securo:latest
Last Updated2026-10-09
First Seen2026-10-11

Runtime arguments

Web UI
http://[IP]:[PORT:8080]/
Network
bridge
Shell
bash
Privileged
false
Extra Params
--restart=unless-stopped

Template configuration

WebUI PortPorttcp

Port of the Securo web app.

Target
8080
Default
3000
Value
3000
DataPathrw

Attachments, secrets.env with the generated secret key, the secrets folder for an Enable Banking key and, with Built-in PostgreSQL and Redis, their data.

Target
/data
Default
/mnt/user/appdata/securo
Value
/mnt/user/appdata/securo
App addressVariable

The address you open Securo on, such as http://192.168.1.10:3000 or https://securo.example.com. Bank sync and single sign-on send you back there.

Target
FRONTEND_URL
Built-in PostgreSQLVariable

true runs PostgreSQL 16 with pgvector inside this container, with its data in the Data folder. Leave it false to use your own PostgreSQL.

Target
BUILTIN_POSTGRES
Default
false|true
Value
false
Database hostVariable

IP or name of your PostgreSQL server. It needs pgvector. Leave it empty with Built-in PostgreSQL.

Target
POSTGRES_HOST
Database userVariable

A user that may create databases, or the owner of a database you created for Securo. Not used with Built-in PostgreSQL.

Target
POSTGRES_USER
Default
postgres
Value
postgres
Database passwordVariable

Password of the database user. It must not contain @ or %. Not used with Built-in PostgreSQL.

Target
POSTGRES_PASSWORD
Built-in RedisVariable

true runs Redis inside this container. Leave it false to use your own Redis.

Target
BUILTIN_REDIS
Default
false|true
Value
false
Redis hostVariable

IP or name of your Redis server. Leave it empty with Built-in Redis.

Target
REDIS_HOST
RegistrationVariable

Whether new people can sign up. Set it to false once your own account exists.

Target
REGISTRATION_ENABLED
Default
true|false
Value
true
Database portVariable

Port of your PostgreSQL server.

Target
POSTGRES_PORT
Default
5432
Value
5432
Database nameVariable

Created on the first start if it does not exist and the user may create databases.

Target
POSTGRES_DB
Default
securo
Value
securo
Redis portVariable

Port of your Redis server.

Target
REDIS_PORT
Default
6379
Value
6379
Redis passwordVariable

Only when your Redis server asks for one.

Target
REDIS_PASSWORD
Redis databaseVariable

Database number on your Redis server. Give Securo one no other app uses, since its task queue shares the name every Celery app uses.

Target
REDIS_DB
Default
0
Value
0
Trusted proxiesVariable

How many proxies stand in front of Securo, counting the one inside this container. 1 without a reverse proxy, 2 behind one. The login rate limit counts visitors by the address this finds.

Target
TRUSTED_PROXY_HOPS
Default
1
Value
1
Secret keyVariable

Signs the login tokens. Leave it empty to get a generated one, kept in secrets.env. Changing it signs everyone out.

Target
SECRET_KEY
Enable Banking app IDVariable

Bank sync for about 2500 European banks. Put the application's private key into the secrets folder of the Data folder as enable_banking_private.pem. The redirect URL to register is your App address followed by /oauth/callback, over https.

Target
ENABLE_BANKING_APP_ID
SimpleFINVariable

Bank sync for US and other banks through the SimpleFIN Bridge. You paste a setup token into Securo under Accounts.

Target
SIMPLEFIN_ENABLED
Default
false|true
Value
false
SimpleFIN bridgeVariable

The beta bridge hands out demo tokens for trying it. For real banks use https://bridge.simplefin.org.

Target
SIMPLEFIN_API_URL
Default
https://beta-bridge.simplefin.org
Value
https://beta-bridge.simplefin.org
Pluggy client IDVariable

Bank sync for Brazilian banks, from dashboard.pluggy.ai.

Target
PLUGGY_CLIENT_ID
Pluggy client secretVariable

The client secret that belongs to the Pluggy client ID.

Target
PLUGGY_CLIENT_SECRET
OIDCVariable

Sign-in through Authentik, Pocket ID or another OIDC provider. The redirect URI to register is your App address followed by /api/auth/oidc/callback.

Target
OIDC_ENABLED
Default
false|true
Value
false
OIDC provider nameVariable

Shown on the sign-in button.

Target
OIDC_PROVIDER_NAME
Default
OIDC
Value
OIDC
OIDC discovery URLVariable

Ends in /.well-known/openid-configuration.

Target
OIDC_DISCOVERY_URL
OIDC client IDVariable

From the application you created at your provider.

Target
OIDC_CLIENT_ID
OIDC client secretVariable

From the application you created at your provider.

Target
OIDC_CLIENT_SECRET
Password sign-inVariable

false allows only OIDC sign-in. Securo refuses to start that way until OIDC is fully set up.

Target
LOCAL_AUTH_ENABLED
Default
true|false
Value
true
Open Exchange Rates app IDVariable

Optional key for exchange rates between your currencies, from openexchangerates.org.

Target
OPENEXCHANGERATES_APP_ID
PUIDVariable

User that owns the files in the Data folder. 99 is nobody on Unraid.

Default
99
Value
99
PGIDVariable

Group that owns the files in the Data folder. 100 is users on Unraid.

Default
100
Value
100