Self-hosted recipe manager — single Docker container, AGPL-3.0, no telemetry, no cloud sync.
Svelte
63
37 commits
updated Oct 2, 2026
Trace Every Recipe, From Pantry to Plate
A self-hosted recipe, pantry, and cooking tracker.
No accounts, no telemetry, no cloud sync unless you opt in.
Coming to Apple devices: the Trace apps have no iPhone app yet, because building and testing one needs a Mac and an iPhone. Chip in on Ko-fi. Self-hosting stays free either way.
Jump to: What it is · Features · Install · Env vars · Docs
CookTrace runs as a single Docker container on your own hardware, with a PWA for the browser and a native Android app for your phone. No accounts on external services, no data leaving your network, no subscriptions.
Third app in the Trace family alongside NutriTrace, LiftTrace, and NoteTrace.

MCP_ENABLED=1. Read, write, and destructive tool tiers, each independently gated by its own env flag and token scope. → full guidePublished to two registries with identical tag sets: ghcr.io/traceapps/cooktrace (primary) and traceapps/cooktrace on Docker Hub (mirror). The snippet below uses GHCR; swap in traceapps/cooktrace:latest if that suits your setup.
Minimal docker-compose.yml:
services:
cooktrace:
image: ghcr.io/traceapps/cooktrace:latest
container_name: cooktrace
ports:
- "3003:3003"
volumes:
- ./data/db:/data/db
- ./data/uploads:/data/uploads
environment:
- JWT_SECRET=change-me-to-a-long-random-string
- DB_PATH=/data/db/cooktrace.db
- UPLOADS_PATH=/data/uploads
# OIDC (optional): uncomment and fill in for SSO
# - OIDC_ISSUER=https://auth.example.com
# - OIDC_CLIENT_ID=cooktrace
# - OIDC_CLIENT_SECRET=...
restart: unless-stopped
Generate the JWT secret with openssl rand -base64 48, then:
docker compose up -d
Open http://localhost:3003 and a first-run wizard walks you through enabling user management and creating an admin account.
Full walkthrough (env-file layout, reverse proxy, LAN-HTTP notes) at docs/getting-started/compose. Pre-release testers can grab the rolling dev-latest APK; occasional milestone builds also get numbered -devNN pre-releases. See DEPLOY.md for details.
The most-asked knobs. Full list at docs/self-hosting/env-vars.
| Variable | Default | Purpose |
|---|---|---|
JWT_SECRET | - | Signing key for auth tokens. Required when user management is on. |
DB_PATH | /data/db/cooktrace.db | SQLite file inside the container. |
UPLOADS_PATH | /data/uploads | Uploaded images and server-side backups. |
PORT | 3003 | Port the server listens on inside the container (3001 before 1.3.0). |
BASE_URL | - | Mount at a subpath, e.g. /cooktrace. |
LOG_LEVEL | info | error | warn | info | debug. |
INSECURE_COOKIES | unset | Set to 1 on plain-HTTP LAN deployments so the auth cookie isn't dropped. See LAN-HTTP notes. |
MAX_SESSION_HOURS | 8760 | Session-length cap in hours. Lower for shared / kiosk machines. |
IMPORT_ZIP_MAX_MB | 512 | Upload cap for Mealie / Tandoor / Paprika bulk-import zips. |
BACKUP_UPLOAD_MAX_MB | 512 | Upload cap for restore-from-zip. |
BACKUP_SCHEDULE | - | off | daily | weekly | monthly. Locks the UI field when set. |
BACKUP_TIME | - | Auto-backup time (HH:MM, container TZ). Locks the UI field. |
BACKUP_RETENTION | - | How many auto-backups to keep. |
SMTP_HOST / SMTP_PORT / SMTP_USER / SMTP_PASS / SMTP_FROM / SMTP_SECURE | - | Password reset + invite email. Without SMTP, invites fall back to a copyable link. |
AI_PROVIDER / AI_API_KEY / AI_MODEL / AI_BASE_URL / AI_ENABLED | - | Lock Trace to a server-side provider. Required combo for local endpoints is AI_PROVIDER=oai-compat + AI_BASE_URL + AI_MODEL. |
OIDC_ISSUER / OIDC_CLIENT_ID / OIDC_CLIENT_SECRET (or numbered OIDC_PROVIDER_N_*) | - | OIDC SSO provider(s). Env-defined providers are read-only in the UI. Full setup at docs/auth/oidc. |
Env values take priority over Settings-UI values and lock the field for all users.
Bind-mount two host directories: the SQLite database (DB_PATH dir) and uploads (UPLOADS_PATH, which also holds uploads/backups/). The container is stateless beyond these two volumes.
docker compose pull
docker compose up -d
Schema migrates on startup. Images are multi-arch (linux/amd64 + linux/arm64), so the same command works on x86 hosts, Raspberry Pi 4 / 5, Apple Silicon servers, and ARM cloud instances.
Svelte 5 (compat mode) + Vite 7 PWA · Capacitor 8 Android · Node.js + Express 5 + better-sqlite3 · recipe-scrapers Python bridge (baked into the image) · JWT httpOnly cookies + OIDC 1.0 (PKCE + state + nonce) · multi-arch Docker via GitHub Actions → GHCR.
Part of the TraceApps family. Sister apps: NutriTrace for nutrition tracking, LiftTrace for weightlifting, NoteTrace for notes, tasks and reminders. Docs for the family at traceapps.github.io/docs.
ROADMAP.md · CHANGELOG.md · CONTRIBUTING.md · PRIVACY.md · Full documentation
CookTrace is free to self-host and always will be. No paid tier, nothing behind a donation, no telemetry. It's built and maintained by one person.
The current goal is a Mac and an iPhone. None of the Trace apps run properly on an iPhone, because building and testing for iOS needs Apple hardware, plus the developer accounts for both app stores. That comes to about $1,300, and the itemised breakdown is on the Support page.
Helping doesn't have to cost anything: starring the repo, reporting bugs with detail, and translating all count, and stars are how self-hosted projects get found.
CookTrace is not medical, health, or nutrition-professional software. Recipe entries, pantry tracking, AI-extracted nutrition, Trace AI suggestions, Smart Log parsing, and any analytical output are for informational and self-tracking purposes only. Consult a qualified healthcare professional, registered dietitian, or licensed nutritionist before starting a new eating plan or making significant dietary changes, especially with medical conditions in play (diabetes, eating disorders, food allergies, pregnancy, breastfeeding, pediatric needs, kidney or liver disease, metabolic disorders). Trace AI answers can be incorrect; third-party nutrition data (Open Food Facts, recipe websites, schema.org markup, AI photo extraction) is community-curated and may contain inaccuracies. Use at your own risk.
AGPL-3.0: entire codebase including the Android app source.
Svelte
50.9%
JavaScript
44.2%
Kotlin
3.1%
Self-hosted recipe manager — single Docker container, AGPL-3.0, no telemetry, no cloud sync.
Svelte
63
37 commits
updated Oct 2, 2026
Trace Every Recipe, From Pantry to Plate
A self-hosted recipe, pantry, and cooking tracker.
No accounts, no telemetry, no cloud sync unless you opt in.
Coming to Apple devices: the Trace apps have no iPhone app yet, because building and testing one needs a Mac and an iPhone. Chip in on Ko-fi. Self-hosting stays free either way.
Jump to: What it is · Features · Install · Env vars · Docs
CookTrace runs as a single Docker container on your own hardware, with a PWA for the browser and a native Android app for your phone. No accounts on external services, no data leaving your network, no subscriptions.
Third app in the Trace family alongside NutriTrace, LiftTrace, and NoteTrace.

MCP_ENABLED=1. Read, write, and destructive tool tiers, each independently gated by its own env flag and token scope. → full guidePublished to two registries with identical tag sets: ghcr.io/traceapps/cooktrace (primary) and traceapps/cooktrace on Docker Hub (mirror). The snippet below uses GHCR; swap in traceapps/cooktrace:latest if that suits your setup.
Minimal docker-compose.yml:
services:
cooktrace:
image: ghcr.io/traceapps/cooktrace:latest
container_name: cooktrace
ports:
- "3003:3003"
volumes:
- ./data/db:/data/db
- ./data/uploads:/data/uploads
environment:
- JWT_SECRET=change-me-to-a-long-random-string
- DB_PATH=/data/db/cooktrace.db
- UPLOADS_PATH=/data/uploads
# OIDC (optional): uncomment and fill in for SSO
# - OIDC_ISSUER=https://auth.example.com
# - OIDC_CLIENT_ID=cooktrace
# - OIDC_CLIENT_SECRET=...
restart: unless-stopped
Generate the JWT secret with openssl rand -base64 48, then:
docker compose up -d
Open http://localhost:3003 and a first-run wizard walks you through enabling user management and creating an admin account.
Full walkthrough (env-file layout, reverse proxy, LAN-HTTP notes) at docs/getting-started/compose. Pre-release testers can grab the rolling dev-latest APK; occasional milestone builds also get numbered -devNN pre-releases. See DEPLOY.md for details.
The most-asked knobs. Full list at docs/self-hosting/env-vars.
| Variable | Default | Purpose |
|---|---|---|
JWT_SECRET | - | Signing key for auth tokens. Required when user management is on. |
DB_PATH | /data/db/cooktrace.db | SQLite file inside the container. |
UPLOADS_PATH | /data/uploads | Uploaded images and server-side backups. |
PORT | 3003 | Port the server listens on inside the container (3001 before 1.3.0). |
BASE_URL | - | Mount at a subpath, e.g. /cooktrace. |
LOG_LEVEL | info | error | warn | info | debug. |
INSECURE_COOKIES | unset | Set to 1 on plain-HTTP LAN deployments so the auth cookie isn't dropped. See LAN-HTTP notes. |
MAX_SESSION_HOURS | 8760 | Session-length cap in hours. Lower for shared / kiosk machines. |
IMPORT_ZIP_MAX_MB | 512 | Upload cap for Mealie / Tandoor / Paprika bulk-import zips. |
BACKUP_UPLOAD_MAX_MB | 512 | Upload cap for restore-from-zip. |
BACKUP_SCHEDULE | - | off | daily | weekly | monthly. Locks the UI field when set. |
BACKUP_TIME | - | Auto-backup time (HH:MM, container TZ). Locks the UI field. |
BACKUP_RETENTION | - | How many auto-backups to keep. |
SMTP_HOST / SMTP_PORT / SMTP_USER / SMTP_PASS / SMTP_FROM / SMTP_SECURE | - | Password reset + invite email. Without SMTP, invites fall back to a copyable link. |
AI_PROVIDER / AI_API_KEY / AI_MODEL / AI_BASE_URL / AI_ENABLED | - | Lock Trace to a server-side provider. Required combo for local endpoints is AI_PROVIDER=oai-compat + AI_BASE_URL + AI_MODEL. |
OIDC_ISSUER / OIDC_CLIENT_ID / OIDC_CLIENT_SECRET (or numbered OIDC_PROVIDER_N_*) | - | OIDC SSO provider(s). Env-defined providers are read-only in the UI. Full setup at docs/auth/oidc. |
Env values take priority over Settings-UI values and lock the field for all users.
Bind-mount two host directories: the SQLite database (DB_PATH dir) and uploads (UPLOADS_PATH, which also holds uploads/backups/). The container is stateless beyond these two volumes.
docker compose pull
docker compose up -d
Schema migrates on startup. Images are multi-arch (linux/amd64 + linux/arm64), so the same command works on x86 hosts, Raspberry Pi 4 / 5, Apple Silicon servers, and ARM cloud instances.
Svelte 5 (compat mode) + Vite 7 PWA · Capacitor 8 Android · Node.js + Express 5 + better-sqlite3 · recipe-scrapers Python bridge (baked into the image) · JWT httpOnly cookies + OIDC 1.0 (PKCE + state + nonce) · multi-arch Docker via GitHub Actions → GHCR.
Part of the TraceApps family. Sister apps: NutriTrace for nutrition tracking, LiftTrace for weightlifting, NoteTrace for notes, tasks and reminders. Docs for the family at traceapps.github.io/docs.
ROADMAP.md · CHANGELOG.md · CONTRIBUTING.md · PRIVACY.md · Full documentation
CookTrace is free to self-host and always will be. No paid tier, nothing behind a donation, no telemetry. It's built and maintained by one person.
The current goal is a Mac and an iPhone. None of the Trace apps run properly on an iPhone, because building and testing for iOS needs Apple hardware, plus the developer accounts for both app stores. That comes to about $1,300, and the itemised breakdown is on the Support page.
Helping doesn't have to cost anything: starring the repo, reporting bugs with detail, and translating all count, and stars are how self-hosted projects get found.
CookTrace is not medical, health, or nutrition-professional software. Recipe entries, pantry tracking, AI-extracted nutrition, Trace AI suggestions, Smart Log parsing, and any analytical output are for informational and self-tracking purposes only. Consult a qualified healthcare professional, registered dietitian, or licensed nutritionist before starting a new eating plan or making significant dietary changes, especially with medical conditions in play (diabetes, eating disorders, food allergies, pregnancy, breastfeeding, pediatric needs, kidney or liver disease, metabolic disorders). Trace AI answers can be incorrect; third-party nutrition data (Open Food Facts, recipe websites, schema.org markup, AI photo extraction) is community-curated and may contain inaccuracies. Use at your own risk.
AGPL-3.0: entire codebase including the Android app source.
Svelte
50.9%
JavaScript
44.2%
Kotlin
3.1%