Personal or shared
Llooma is one application, installed one way. Data lives server-side in SQLite, provider API keys are encrypted there and never reach a browser, and a turn runs in the server so a reload does not lose it.
What an instance decides is whether anyone signs in.
A personal instance
Section titled “A personal instance”Install it, start it, use it. No login screen, no secret to generate, no account to create: the instance belongs to whoever opens it, and that owner is created on first run.
DATA_DIR=./dataThat is the whole configuration. All state lives under DATA_DIR, one directory to bind-mount to
persist everything, including the secret the instance generates for itself to encrypt provider keys
with.
A shared instance
Section titled “A shared instance”Configure a way to sign in and the same install becomes a multi-user one: a login page appears, data is stored per user, and an admin configures the shared providers and which models to expose, and may allow users to add their own keys on top.
AUTH_CREDENTIALS=true # email and passwordOIDC_ISSUER=https://id.example.com # or an identity provider, or bothThere is no separate switch for this, on purpose. A switch and the configuration could disagree, and both ways of disagreeing are bad: accounts demanded with no provider configured is an instance nobody can enter, and accounts turned off with an identity provider configured is one anybody can.
What changes between them
Section titled “What changes between them”| Personal | Shared | |
|---|---|---|
| Signing in | Nobody does | Email and password, OIDC, or both |
| Who the data is for | The instance’s implicit owner | Each account, separately |
| Sync across devices | Yes, the data is on the server | Yes |
| Provider keys | On the server, encrypted | On the server, encrypted |
| Sharing settings | Nobody to share with | Admin can share and lock providers, prompts, tools |

