Account and running it · Chapter 20
As the operator
The first account on your server is the operator, and you can make others operators too. As the operator you manage accounts and set the server up, but you see no entries: every diary belongs to its own person only. Your tools are in the account menu under “Settings”; other accounts do not see that item.
The ten tabs
| Tab | What for |
|---|---|
| Accounts | who uses nexdiary, invitations, storage per person |
| Sign-in | “Ready for the internet?”, public address, password, second factor, sign-in provider |
| a mail server for invitations and links | |
| AI | which AI the family can use, if any |
| Immich | whether, and to which Immich addresses, the server may connect |
| Web Push | messages to the phone |
| Backup | backups and the master key, see Backups |
| Languages | more languages as a JSON file |
| Log | what the server did, without the content of entries |
| API | whether accounts may make API tokens, see API |
Managing accounts
Under “Accounts” each person is listed with their role and how they sign in, plus “second factor on”, “locked for a while” after too many wrong tries, or “blocked”. Next to each account are the button “Send a link to reset” and a menu with three dots (“More for …”):
- “Make operator” and “Make member” give or take away the settings. An operator never sees the others' diaries either.
- “Remove second factor” is for a lost phone: the code, the passkeys and the recovery codes go, every device is signed out, the person is told and sets the second factor up again at their next sign-in.
- “Sign out everywhere” signs every device of the account out.
- “Block” keeps somebody out, and open sessions end at once. “Unblock” works at any time.
- “Delete account” deletes the account with everything that belongs to it. It cannot be brought back. Members cannot delete their own account; they ask you.
Most of these steps ask for your password once more. You cannot block, delete or demote yourself. New people come in through “Invite somebody”, as the chapter Inviting describes.
Below the list sits the card “Storage per person”. Out of the box each person may use 5 GB, and 0 means no limit. It counts everything a person keeps: photos, pages, notes, values, templates and the time capsules they sent, photos included.
When someone cannot get in any more
Nobody sets a password for another person. Instead the person gets a link and chooses their password themselves.
- “Send a link to reset”
Press it next to the account. For an account that signs in through the sign-in provider only, the button reads “Send a link for a password”.
- Confirm with your password
nexdiary asks once for your own password.
- Pass the link on
If mail is set up and the account has an address, the link goes out by mail. Otherwise nexdiary shows it to you exactly once, and you pass it on yourself, say in a message to Ruth.
The link works once and for 24 hours. Afterwards the person signs in again on every device; their second factor stays, and their diary stays readable, because it does not hang on their password. If you have forgotten your own password, the chapter Backups helps.
Allowing the AI and Immich
Both are off out of the box. Under “AI”, instead of “No AI” you choose a local model in your own network, for example with Ollama, or a service that speaks the OpenAI interface, and press “Save and try it”. What goes out with it is on the page AI. Leave the switch “Allow writing up automatically” off as long as nobody wants a draft in the morning.
Under “Immich” you switch on “Allow Immich” and enter one host per line under “Allowed Immich addresses”, best with its port, such as immich.example.com:2283. Then each person connects their own Immich. In the account list, the ticks “AI allowed” and “Immich allowed” leave single people out again.
Mail and Web Push
Under “Mail” you enter “Server”, “Port” (587 out of the box), “Encryption” (STARTTLS, TLS or none), “User”, password and “Sender”, and try it with “Test mail to” and “Send”. nexdiary sends invitations through it, links to reset a password, the notice of a new sign-in and the notice that a second factor was removed. Every mail is in English and never holds anything from a diary. Without a mail server nexdiary sends no mail, and you pass links on yourself.
Web Push is set up from the start. Under “Web Push” you can enter a “Contact for the push services”, send a test to your own devices (“Test to my devices”), and under “More push services” allow a service if a browser uses another one than those of Google, Mozilla, Apple and Microsoft. “Make new” makes a new key pair and signs every device in the family off as it does.
Ready for the internet?
At the top of “Sign-in”, nexdiary checks itself every time you open the page. Eight points stand there as “fine”, “check” or “open”, and each says what to do:
- “Public address with https” and “Second factor for everybody”
- “Your own account” has a second factor
- “Protection against guessing” and “Entries encrypted”
- “Sessions and cookies” and “Behind the proxy”
- “Master key saved”
Below it you set the “Public address” nexdiary is reached under, “Sign-in with a password” and “Require a second factor”, both on out of the box, and a sign-in provider such as authentik.
Signing in through a provider
If you already run a sign-in service such as authentik, you can connect nexdiary to it. The sign-in page then has a button “Sign in with …” carrying the name you choose. Out of the box no provider is set up.
- “authentik in one step”: Enter the “Address of authentik” and an “API token” that may create applications, and press “Set up”. nexdiary creates the provider and the application in authentik itself and then fills in its own settings. The token is used for that only and not stored. If you would rather not hand out a token, use “Download a blueprint instead”.
- Any other provider: On the card “OpenID Connect” enter the “Issuer”, “Client ID”, “Client secret” and the “Name on the button”. nexdiary shows you the “Redirect address for the provider” there.
- “New people get an account” is off out of the box. Then only invited or already linked accounts get in through the provider.
- The second factor: Whoever comes in through the provider also sets up one of their own in nexdiary by default. If your provider already requires one, switch on “… checks the second factor”.
Once a provider is set up, you can also switch off “Sign-in with a password”. Members then get in only through the provider; your own password as the operator keeps working.
Good to knowSave the master key on the very first evening, before the family starts writing. As long as it lies only on the server, every backup is worthless without it should the disk ever die.