Skip to content

Personal or shared

Llooma is one application, installed one way. Data lives server-side in SQLite, provider API keys are encrypted there and never reach a browser, and a turn runs in the server so a reload does not lose it.

What an instance decides is whether anyone signs in.

Install it, start it, use it. No login screen, no secret to generate, no account to create: the instance belongs to whoever opens it, and that owner is created on first run.

Terminal window
DATA_DIR=./data

That is the whole configuration. All state lives under DATA_DIR, one directory to bind-mount to persist everything, including the secret the instance generates for itself to encrypt provider keys with.

Configure a way to sign in and the same install becomes a multi-user one: a login page appears, data is stored per user, and an admin configures the shared providers and which models to expose, and may allow users to add their own keys on top.

Terminal window
AUTH_CREDENTIALS=true # email and password
OIDC_ISSUER=https://id.example.com # or an identity provider, or both

There is no separate switch for this, on purpose. A switch and the configuration could disagree, and both ways of disagreeing are bad: accounts demanded with no provider configured is an instance nobody can enter, and accounts turned off with an identity provider configured is one anybody can.

Personal Shared
Signing in Nobody does Email and password, OIDC, or both
Who the data is for The instance’s implicit owner Each account, separately
Sync across devices Yes, the data is on the server Yes
Provider keys On the server, encrypted On the server, encrypted
Sharing settings Nobody to share with Admin can share and lock providers, prompts, tools