# Trove KB

> Self-hosted, open-source structured IT documentation for internal IT teams and MSPs. A lightweight alternative to Hudu and IT Glue: companies, locations, and documents built from typed templates; inline editing of templates from inside a document; a knowledge base imported from vendor help sites; credentials brokered from your own Bitwarden, Vaultwarden, 1Password, or HashiCorp vault and never stored; a REST API, signed webhooks, and an MCP endpoint. AGPL-3.0. One `docker compose up`, or a Cloudflare Worker.

- Source: https://github.com/joshhearne/trove-kb
- Issues: https://github.com/joshhearne/trove-kb/issues
- License: AGPL-3.0 (https://trove-kb.com/license/)
- Made by Hearne Technologies (https://hearnetech.com), support@hearnetech.com
- Every page on this site is also available as Markdown: send `Accept: text/markdown`.

## Features

- [Documents + inline editing](https://trove-kb.com/documents/): company > location > document hierarchy, doc types with typed fields (text, url, ip, markdown, richtext, number, date, boolean, dropdown, multi_dropdown, doc_link, secret_ref), add a field or a dropdown option from inside the document, promote a local field to the template, drag to reorder, revisions on every save, backlinks, full-text search, per-company export.
- [Knowledge base](https://trove-kb.com/kb/): collections of articles from vendor help centers, crawled sites, zips, folders, PDFs and Word documents; imports upsert on a stable id and are tidied to read as the source did; runbooks with stable step ids a ticketing system can track; a public site on its own hostname with keyword rules, favorites, and votes.
- [Credentials](https://trove-kb.com/vault/): never stored. Modes link (deep links), bw_serve (official Bitwarden CLI sidecar, no published port), op_connect (1Password Connect), hashicorp_kv. Reveals are permission-checked, audited, no-store.
- [API, webhooks + MCP](https://trove-kb.com/integrations/): /api/v1 with bearer keys and an OpenAPI spec from the same Zod schemas; company-scoped keys where out of scope is 404; PUT /external-refs and GET /lookup for PSA integration; /go/{system}/company/{id} deep links; HMAC-SHA256 webhooks retried 8 times; POST /api/mcp with read-only documentation tools and knowledge base read/write tools; secrets stripped from every MCP response.
- Resolvd (https://resolvd.dev), the same vendor's issue tracker, uses Trove KB as its knowledge base: client docs on the ticket via /lookup, matching articles and runbooks surfaced in the ticket with runbook progress tracked by step id, resolutions written back as articles, and AI-drafted replies and resolutions sourced from those articles when a tech asks. Running in production over the public REST API and webhooks; the same surfaces (lookup, runbook step ids, KB API and MCP, webhooks) are open to any ticketing system.
- [Rack elevations](https://trove-kb.com/racks/): a Rack doc type draws a printable SVG per face from mounted Switch/Server documents; colour per equipment kind with per-client overrides; warnings for clashing colours and double-booked units.
- [Domain checks](https://trove-kb.com/domains/): DNS, TLS, RDAP, SPF/DMARC/DKIM on request; findings offered with a Use this button, never applied.
- [Access + security](https://trove-kb.com/security/): roles admin/tech/readonly; per-company grants for users and keys; Argon2id with breach checks; authenticator apps, passkeys, recovery codes; OIDC; append-only audit; attachments typed by magic bytes, HEIC converted, macro Office refused.

## Install and docs

- [Install](https://trove-kb.com/install/): generates a .env with fresh secrets for your choices.
- [Docs](https://trove-kb.com/docs/): getting started, environment variables, REST API and webhooks, MCP, knowledge base, vault integration, Cloudflare (tunnel, public KB hostname, Workers), backup and restore, accounts and access, starter doc types.
- Quick start: `git clone https://github.com/joshhearne/trove-kb.git && cd trove-kb && cp .env.example .env` then set POSTGRES_PASSWORD, DATABASE_URL, AUTH_SECRET and `docker compose up -d`; open http://localhost:3080 and create the first administrator.
- Stack: Next.js + TypeScript, Postgres 16, Drizzle, Zod, Better Auth, TipTap, dnd-kit. No Redis, no queue, no search service.

## Updates

- [Blog](https://trove-kb.com/blog/): one post per minor or major release.
- [Changelog](https://trove-kb.com/changelog/): pulled from GitHub Releases.

## Optional

- [Sitemap](https://trove-kb.com/sitemap-index.xml)
