Joplin Server is the official sync server for Joplin. Once you host your own instance, your notes can stay on your VPS, NAS, or home server, while your desktop and mobile clients sync without depending on a third-party cloud drive.
The easiest deployment method today is Docker Compose: one PostgreSQL container, one Joplin Server container, and a correctly configured APP_BASE_URL.
This guide is aimed at practical self-hosting on Ubuntu, Debian, CentOS, Synology, Unraid, OpenMediaVault, or any other environment that can run Docker.
Requirements
Before starting, prepare:
- a server or NAS that can stay online;
- Docker and Docker Compose;
- an internal IP if you only need LAN sync;
- a domain name and HTTPS reverse proxy if you need sync from outside your network;
- a real database password. Do not keep the sample password.
If you only sync between devices at home, http://LAN-IP:22300 is enough to get started. If you need external access from a phone or laptop, use Nginx Proxy Manager, Caddy, Traefik, or a similar HTTPS reverse proxy. Avoid exposing a plain HTTP service directly to the public internet.
Create a Joplin working directory
Create a dedicated directory for Joplin Server configuration and database data:
|
|
You can use another path, such as /opt/joplin or /volume1/docker/joplin. The important part is that the database directory must be persistent, so PostgreSQL data is not deleted with the container.
Write docker-compose.yml
Create the Compose file in the working directory:
|
|
Paste this configuration:
|
|
The two values you must change are:
POSTGRES_PASSWORD: the database password. It must be identical in both thedbandappservices;APP_BASE_URL: the fixed address that Joplin clients will use to reach the server.
APP_BASE_URL is critical. It must be the address your clients can actually open:
- LAN only:
http://192.168.1.10:22300 - public IP:
http://your-public-ip:22300 - domain with HTTPS:
https://joplin.example.com
If you later change the access address, update APP_BASE_URL and restart the service. Otherwise client sync, web redirects, or attachment links may behave oddly.
Start Joplin Server
Run this in the directory containing docker-compose.yml:
|
|
Check the containers:
|
|
If the first startup takes a while, watch the logs:
|
|
By default, Joplin Server listens on port 22300. Open your configured APP_BASE_URL in a browser. If the login page appears, the basic deployment is working.
First admin login
The default administrator account is:
|
|
The default password is:
|
|
After the first login, do one thing immediately: change the administrator password. Do not leave the default password on the server, especially if the service is reachable from the internet.
In the admin UI, open the Change Password page and replace admin with a strong password.
Create a daily sync account
Do not use the administrator account for daily note sync. A cleaner setup is to create a normal user and use that account on your desktop and mobile clients.
In the admin panel:
- open
Users; - click
Add user; - enter the email and password you want to use;
- create the user.
There is one common trap: if SMTP is not configured, Joplin Server will say it sent an activation email, but you will not receive it.
The workaround is simple:
- go back to the admin panel;
- open the
Emailsmenu; - find the unsent activation email;
- copy the activation link inside it;
- open the link in a new browser tab to activate the account.
After activation, this normal user can be used for client sync.
Configure Joplin client sync
In the Joplin desktop or mobile app:
- open
Optionsor settings; - go to
Synchronization; - select
Joplin Serveras the synchronization target; - enter your
APP_BASE_URLinJoplin Server URL; - enter the activated normal user’s email in
Email / Username; - enter that user’s password;
- click
Check sync configuration.
If the check passes, save the settings and start syncing.
If it fails, check these first:
- can the client open
APP_BASE_URLin a browser? - does
APP_BASE_URLmatch the Compose file? - has the normal user been activated?
Use HTTPS for external access
HTTP is usually fine for LAN-only use. For public access, use a reverse proxy and HTTPS.
Common options include:
- Nginx Proxy Manager;
- Caddy;
- Traefik;
- manual Nginx configuration.
When using a reverse proxy, APP_BASE_URL must be the final HTTPS address used by clients, for example:
|
|
If you configure Nginx manually, pay attention to at least two things:
- increase the upload limit, for example
client_max_body_size 100M;, otherwise notes with large attachments may fail to sync; - forward
Host,X-Forwarded-For,X-Forwarded-Proto, and related headers correctly, so Joplin Server can infer the right URL and protocol.
A simplified Nginx reverse proxy block:
|
|
With Nginx Proxy Manager, you usually only need to proxy the domain to port 22300 and enable an SSL certificate. Remember to change APP_BASE_URL in Compose to the HTTPS domain.
Common issues
APP_BASE_URL changes do not take effect
After editing docker-compose.yml, recreate the containers:
|
|
If it still behaves incorrectly, verify that the container environment variables have really changed. Editing the file alone is not enough if the service was not restarted.
Client sync reports a network error
Check these first:
- can your phone or computer open Joplin Server in a browser?
- is the reverse proxy certificate valid?
- is
APP_BASE_URLthe actual client-facing address? - does the firewall allow
22300or the HTTPS port? - has the normal user been activated?
Large attachments fail to sync
If you access Joplin Server through Nginx or another reverse proxy, check the upload size limit first. Nginx defaults may be too small, so set:
|
|
Increase it further if your note attachments are larger.
Can I use it without SMTP?
Yes. For personal or family use, SMTP is not required. After creating a user, open the Emails page in the admin panel and copy the activation link manually.
For long-term team use, configure SMTP so registration, password resets, and notifications work properly.
Backup advice
The most important Joplin Server data is in PostgreSQL. In the example above, it is stored under:
|
|
Back up this directory regularly, or use PostgreSQL pg_dump for database backups. Backing up only the Joplin Server container is not useful; the container can be pulled again, but the database contains your sync data.
The local clients also keep copies of your notes, but do not treat them as your only backup. A more robust setup is server database backup + local client copies + occasional JEX exports.
Deploy Joplin Server on Synology DSM 7.x
On Synology DSM 7.x, the easiest way to deploy Joplin Server is to use the “Project” feature in Container Manager. Under the hood, it is Docker Compose: one PostgreSQL database container, one Joplin Server container, and Synology handles image pulls, container creation, and day-to-day startup management.
This is the Synology-specific version of the setup. It focuses on File Station directories, Container Manager projects, LAN access, remote sync, and reverse proxy details. If you already write docker-compose.yml by hand on Linux servers, the flow will look familiar. If you mostly use Synology’s GUI, you can follow along directly.
When this setup makes sense
Joplin Server is useful if you want to keep note sync data on your own device. It lets Windows, macOS, iOS, Android, and other Joplin clients sync through your own server instead of relying on a third-party cloud drive.
Deploying it on Synology is a good fit when:
- your NAS stays online and can act as a home or personal sync server;
- you only need to sync computers and phones on the LAN;
- you want remote sync through Tailscale, WireGuard, or a reverse proxy;
- you prefer managing containers through Container Manager instead of SSH all the way.
If you are only trying Joplin temporarily, you do not necessarily need Joplin Server. Joplin also supports WebDAV, S3, Dropbox, and other sync methods. For long-term self-hosting, however, Joplin Server is the more complete option.
Step 1: Prepare directories in File Station
Open Synology File Station and go to the docker shared folder.
Create a directory:
|
|
Inside joplin, create another directory:
|
|
The final structure should look like this:
|
|
postgres_data stores the PostgreSQL database. Joplin Server’s sync data mainly lives in the database, so this directory must be persistent. When you update or recreate containers later, the data will remain as long as this directory still exists.
Step 2: Create a project in Container Manager
Open Container Manager on Synology:
- click
Projecton the left; - click
Create; - set the project name to
joplin-server; - choose the
/docker/joplinpath you created; - choose
Create docker-compose.ymlas the source.
Paste this Compose configuration:
|
|
Two values must be changed:
POSTGRES_PASSWORD: the database password. It must be identical in both places;APP_BASE_URL: the actual address Joplin clients will use to reach the server.
If you only use it on the LAN, set APP_BASE_URL to your Synology LAN IP:
|
|
If you already have an HTTPS reverse proxy, use the public domain directly:
|
|
Do not fill in APP_BASE_URL casually. Joplin client sync, web redirects, and attachment links all depend on it. The address you actually use to access the service is the address you should put here.
After confirming the configuration, continue through the wizard until it finishes. Container Manager will download postgres:16 and joplin/server:latest, then start both containers.
Step 3: Check container status
After the project is created, open the joplin-server project page in Container Manager.
You should normally see two containers:
joplin-dbjoplin-server
If both are green and running, continue to the next step.
If they do not start correctly, check the project logs first. Common causes are:
- the two database passwords do not match;
- the
postgres_datadirectory has permission issues; - port
22300on Synology is already used by another service; - YAML indentation was broken.
Step 4: First login to Joplin Server
Open this in a browser:
|
|
For example:
|
|
The default administrator account is:
|
|
The default password is:
|
|
After the first login, change the administrator password immediately. Do not skip this step, especially if you plan to expose the service through remote access.
If the admin UI allows changing the administrator email, it is also a good idea to replace it with your own email for easier account identification later.
Step 5: Should you create a normal user?
If you are the only user, syncing with the updated administrator account works. A cleaner setup is to create a normal user and use that account for note sync, while keeping the administrator account for management only.
In the admin UI:
- open
Users; - click
Add user; - enter an email and password;
- save.
If SMTP is not configured, the system will say it sent an activation email, but you will not receive it. In that case, open the Emails page in the admin UI, find the unsent activation email, copy the activation link, and open it in a browser to activate the account.
For personal use, running without SMTP is fine. For multiple long-term users, configure SMTP later so registration, activation, and password reset are less painful.
Step 6: Configure Joplin client sync
Open the Joplin client on your computer or phone:
- go to
Options / Settings; - open
Synchronization; - choose
Joplin Serveras the sync target; - enter the
APP_BASE_URLyou configured earlier inJoplin Server URL; - enter the administrator email or normal user email;
- enter the corresponding password;
- click
Check synchronization configuration.
If the check succeeds, save the settings and start syncing.
If it fails, first confirm whether the client can open Joplin Server in a browser. Many sync issues are not Joplin problems, but wrong APP_BASE_URL, an inactive account, a broken reverse proxy certificate, or a phone that is not on the same network.
Remote sync option 1: Tailscale or WireGuard
The safest and simplest way to sync remotely is to connect your phone and computer back to your home network through a VPN.
Common choices:
- Tailscale;
- WireGuard;
- ZeroTier.
The benefit is that Joplin Server does not need to be exposed directly to the public internet. The URL in the Joplin client can still be your Synology LAN address, for example:
|
|
When your phone is outside, connect Tailscale or WireGuard first, then open Joplin and sync.
If you do not want to deal with public IPs, DDNS, certificates, and port forwarding, this is the most stable route. The downside is that every external device must join the VPN first.
Remote sync option 2: Synology reverse proxy and HTTPS
If you want Joplin to sync directly from any network, configure an HTTPS domain for it.
The rough process is:
- prepare a domain or DDNS;
- forward port
443on your router to Synology; - in Synology
Control Panel -> Login Portal -> Advanced -> Reverse Proxy, create a new rule; - set the source to
https://joplin.example.com:443; - set the destination to
http://127.0.0.1:22300orhttp://Synology-LAN-IP:22300; - request and bind an HTTPS certificate for the domain;
- change
APP_BASE_URLin Compose tohttps://joplin.example.com; - redeploy the project in Container Manager.
For reverse proxy headers, add common forwarded headers such as:
|
|
If you use Synology’s built-in reverse proxy UI, field names may vary slightly between DSM minor versions. Add them through the “custom header” or “WebSocket” related options in the interface.
Joplin may also hit upload size limits when syncing large attachments. If you use Nginx Proxy Manager or a manual Nginx setup, set:
|
|
If Synology’s built-in reverse proxy does not expose that option, test normal attachment sync first. If you often sync large files, Nginx Proxy Manager or Caddy will be more flexible.
Redeploy after changing APP_BASE_URL
Many people start with a LAN IP for testing and later switch to an HTTPS domain. That is fine, but do not only change the client.
You must also update the Compose configuration in the Container Manager project:
|
|
Then redeploy the project so the container environment variables take effect.
If APP_BASE_URL still points to the old address, you may see:
- client sync check failures;
- login redirects to the wrong address;
- broken attachment links;
- wrong protocol behavior behind the reverse proxy.
Backup priorities
On Synology, the most important directory is:
|
|
It stores the PostgreSQL database, which is the core sync data for Joplin Server. Add it to Hyper Backup or another backup plan.
A more robust setup is:
- back up
docker/joplin/postgres_dataregularly; - keep a local copy of notes in Joplin clients;
- export important notes as JEX from time to time;
- confirm backups before updating containers.
Do not only back up the Joplin Server image or container configuration. Images can be downloaded again; the database is your data.
Summary
Joplin Server is not hard to deploy with Docker Compose. The real pitfalls are mostly these:
APP_BASE_URLmust be the real address used by clients;- the default administrator password
adminmust be changed immediately; - without SMTP, new users need to be activated from the
Emailspage in the admin panel.
For LAN use, http://IP:22300 is enough. For public access, use an HTTPS reverse proxy and increase the upload size limit. Once those details are handled, Joplin Server is a stable private note sync solution.