ToolHive
ToolHive is an open-source MCP server management platform that lets you run, secure, and orchestrate Model Context Protocol servers in isolated containers, giving AI agents structured access to tools like GitHub, databases, and cloud services without exposing host credentials or network. Every server launches inside its own sandboxed container with a minimal permission file, network access filtering, and encrypted secrets management, preventing misbehaving connectors from reaching beyond their defined scope. The built-in registry provides a catalog of vetted servers you can install with one command, while custom images and package-manager references let you onboard proprietary connectors without writing Dockerfiles. Platform teams deploy the Kubernetes operator to declare MCP servers as cluster resources using Custom Resource Definitions, with automated lifecycle management and multi-namespace isolation. The Virtual MCP Server gateway aggregates multiple backends behind a single endpoint, centralizing OIDC authentication, tool filtering, and composite cross-server workflows so clients connect once instead of juggling separate URLs. An MCP Optimizer analyzes tool schemas via semantic search and surfaces only relevant tools per request, cutting token consumption by up to 85%. OpenTelemetry traces and Prometheus metrics deliver full visibility into tool execution, latency, and request audit trails across every managed server. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache 2.0 licensed.
SD WebUI Forge
With 12,800 GitHub stars and backing from the same developer who created ControlNet, Stable Diffusion WebUI Forge replaces Automatic1111's inference backend with a dynamic GPU memory management system that runs SDXL 30-75% faster while consuming significantly less VRAM — enabling 1024x1024 generation on 6GB cards where A1111 requires 8GB or more. The Gradio 4 interface provides txt2img, img2img, inpainting, and outpainting workflows with a Forge Canvas supporting pressure-sensitive input from Wacom tablets and Microsoft Surface devices. Native Flux.1 model support loads Flux Dev and Schnell checkpoints using BitsandBytes NF4 and FP8 quantization for deployment on consumer GPUs without model splitting. Built-in ControlNet integration includes all preprocessors — Canny, Depth, Normal, OpenPose, MLSD, Scribble, Segmentation, Tile, and IP-Adapter — without requiring separate extension installation. The extension ecosystem maintains full compatibility with popular Automatic1111 extensions including Adetailer for face enhancement, After Detailer, Regional Prompter, and Dynamic Prompts. LoRA loading supports standard, LyCORIS, and DoRA formats with automatic weight detection. The API provides RESTful endpoints for txt2img, img2img, extra single/batch processing, and progress monitoring enabling headless batch generation. Deploy via one-click installer package, Python virtual environment, or Docker with NVIDIA GPU passthrough. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3.0 licensed.
OctoBot
OctoBot provides a free and fully configurable cryptocurrency trading platform that runs on your own server. The bot automates investment strategies across 15+ exchanges including Binance, Coinbase, MEXC, Hyperliquid, Kucoin, OKX, and Bybit, supporting spot, futures, and perpetual markets. The AI trading system connects to any OpenAI-compatible API or local Ollama server, enabling strategies powered by ChatGPT, Llama, Mistral, or any custom model for market analysis and signal generation. TradingView integration accepts PineScript indicator signals and strategy alerts via webhooks, while built-in technical analysis covers RSI, Moving Averages, MACD, Bollinger Bands, and other standard indicators. The modular tentacle architecture allows community-developed plugins to extend strategy logic, evaluators, data sources, and exchange interfaces. The backtesting engine replays historical market data against any configured strategy, reporting profit and loss, drawdown, win rate, and trade-by-trade breakdown before committing real funds. Paper trading provides risk-free live simulation with the same execution logic as production. The web dashboard displays real-time portfolio value, open positions, trade history, and strategy performance with interactive charts. Telegram bot integration enables remote monitoring, notifications, and command execution from mobile devices. Docker deployment runs the full stack in a single container with persistent volume storage for configuration and trade data. On RepoCloud, deploy OctoBot on a dedicated VPS with root SSH access, persistent storage for your trading data and strategy configurations, and complete control over exchange API keys and AI model connections, all under the GPL-3.0 license.
Kan
What Trello fans wanted Trello to stay: Kan (kan.bn) is a minimalist, frills-free kanban board capturing the original vision before the enterprise pivots - and then adds the things 2025 actually demands. The core is exactly right: drag-and-drop cards across lists, labels and filters to find work fast, comments for discussion on cards, checklists, a detailed activity log tracking every change, and reusable board templates. Workspaces gather your team with member invites and role management, and board visibility controls decide who can view or edit each board. Migration is first-class: a built-in Trello importer brings existing boards over, so switching costs an afternoon, not a quarter. The standout differentiator is the bundled Model Context Protocol server exposing 46 tools across workspaces, boards, lists, cards, comments, checklists, labels, and members - meaning Claude Desktop, Cursor, Copilot, or any MCP client can read and manage your boards in natural language: "move everything assigned to me into Done" becomes a sentence, not a click marathon. The stack is modern TypeScript - Next.js, tRPC, Drizzle ORM over PostgreSQL, Better Auth (credentials or OAuth), Tailwind - with optional SMTP email and S3 file storage. Unlimited boards, lists, and cards; AGPL-licensed.
Exceptionless
Exceptionless has earned over 2,400 GitHub stars and has been processing production errors since 2014 as the real-time event monitoring platform that captures far more than crashes. Built with ASP.NET Core on Elasticsearch for storage and Redis for caching, Exceptionless ingests exceptions, log messages, feature usage events, broken links, and custom event types through official SDKs for JavaScript, Node.js, .NET Core, ASP.NET, WPF, Web API, WebForms, Console apps, and React Native. Automatic event stacking groups related occurrences by exception type, message, and call stack into single actionable items, while manual stacking keys let developers create custom groupings for specific features or workflows. The real-time dashboard displays Most Frequent, Most Recent, and New event views with filtering by project, date range, environment, and custom tags. Stack management tracks resolution status with version-aware regression detection that automatically reopens resolved issues when the same error surfaces in a newer release. Webhook integrations connect to Slack, Discord, and external services through Zapier for automated issue tracking in GitHub Issues and Jira. Per-project notification settings control email and chat alerts for new errors, regressions, and critical events. OpenTelemetry support captures distributed traces alongside error data. The v8.6.0 release introduced a hosted Model Context Protocol server at the /mcp endpoint, enabling AI tools to query error data via OAuth-authenticated access. Deploy via Docker with the exceptionless/exceptionless image alongside Elasticsearch and Redis. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache 2.0 licensed.
CubeJS
Between your databases and everything that consumes data - BI tools, embedded analytics, AI agents - sits Cube (formerly Cube.js), an open-source semantic layer. Metrics, dimensions, joins, and access rules are defined once as code in YAML, JavaScript, or Python, forming a governed data model that every downstream consumer shares, so "revenue" means the same thing in every dashboard. Caching is two-level: an in-memory cache absorbs bursts of identical queries, and declared pre-aggregations - rollup tables built in the warehouse or in Cube Store, Cube's distributed columnar engine, and refreshed in the background - deliver sub-second latency while cutting warehouse compute costs. The query planner routes each request to cache, rollup, or source automatically. Consumers connect through a Postgres-compatible SQL API (any tool that speaks Postgres works), plus REST, GraphQL, and a Meta API for model introspection. Row-level security and multi-tenancy are enforced in the layer itself, upstream of every client. Sources include Snowflake, BigQuery, Databricks, Postgres, MySQL, Presto, and Athena. Headless by design - bring your own UI.
Dockhand
Dockhand is a Docker management platforms, offering a modern alternative to Portainer with free OIDC SSO and vulnerability scanning that competitors gate behind paid tiers. Real-time container management provides start, stop, restart, and remove operations with live resource monitoring across CPU, memory, and network usage on a dashboard with real-time metrics. The visual Docker Compose editor enables stack creation and modification with syntax highlighting, while Git integration deploys stacks directly from repositories with webhooks and auto-sync for GitOps workflows. Vulnerability scanning powered by Grype and Trivy analyzes container images against CVE databases, with configurable auto-update scheduling that can trigger updates based on vulnerability severity criteria. The Hawser Go agent enables management of remote Docker hosts in Standard mode for LAN environments or Edge mode using outbound WebSocket connections for hosts behind NAT, firewalls, or dynamic IPs without exposing inbound ports. Interactive terminal sessions provide shell access into running containers, while the file browser enables uploading, downloading, and editing files directly within containers. Image management includes registry browsing, pull operations, and layer inspection alongside network and volume administration. The security-focused architecture builds its own OS layer from scratch using Wolfi packages via apko with every package explicitly declared. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. BSL 1.1 licensed, converting to Apache 2.0 in 2029.
Vexa
Vexa is the only Apache 2.0 meeting bot API that self-hosts the complete transcription pipeline, from bot dispatch to Whisper speech-to-text to knowledge agents, with zero audio leaving your infrastructure. A single POST /bots request sends a transcription bot into any Google Meet, Microsoft Teams, or Zoom call, where it captures audio, runs speaker-attributed transcription through faster-whisper or any OpenAI-compatible endpoint, and streams results to your application via real-time WebSocket with sub-second latency. The built-in agent framework watches live transcripts and your accumulated workspace context, answering mid-call questions grounded in your own meeting history and wiki. An MCP server connects Vexa to Claude, Cursor, and other compatible AI tools, turning every captured meeting into queryable context for external agents. The Terminal, a bundled Next.js web workbench, lets you send bots, watch live transcripts, manage users and API tokens, and chat with your meeting archive from a browser. Docker Compose brings the full stack up on one Linux host in five minutes; the Helm chart scales to thousands of users on Kubernetes with a Pod-per-bot architecture and built-in RBAC. Recordings persist in MinIO or any S3-compatible store, transcripts in Postgres, with Redis handling queues and scheduling. Deploy on RepoCloud for a dedicated VPS with full root SSH access and browser console. Apache 2.0 licensed.
Stalwart
With 14,000 GitHub stars and 81 releases since March 2023, Stalwart is the most protocol-complete open-source mail server available — delivering JMAP, IMAP4rev2, IMAP4rev1, POP3, SMTP, CalDAV, CardDAV, and WebDAV from a single Rust binary that compiles to a memory-safe, zero-garbage-collection executable with predictable latency under load. The SMTP server implements DMARC, DKIMv2, DKIMv1, SPF, and ARC for complete message authentication with automatic DKIM key rotation, while transport security enforces DANE, MTA-STS, and SMTP TLS reporting to prevent downgrade attacks. Built-in spam filtering with statistical classifiers, DNS blocklists, and collaborative reputation databases eliminates the need for external Rspamd or SpamAssassin deployments. Encryption at rest protects stored messages with S/MIME or OpenPGP, and automatic TLS certificate provisioning via ACME supports TLS-ALPN-01, DNS-01, and HTTP-01 challenges without manual certificate management. The ManageSieve server enables server-side email filtering rules, while full-text search indexes message bodies and attachments for instant retrieval. Pluggable storage backends support RocksDB for embedded deployments, PostgreSQL, MySQL, and S3-compatible object storage for distributed architectures. LDAP and SQL-based authentication integrate with existing directory services, and the web administration panel manages domains, accounts, quotas, and DKIM keys. Security audited with memory safety guaranteed by Rust's ownership model. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3.0 licensed.
Dograh
Build a voice AI agent that answers calls, qualifies leads, books appointments, and transfers to a human when needed, all from a drag-and-drop workflow builder in your browser. Dograh ships as a Docker Compose stack (API, web UI, Postgres, Redis, MinIO) that you self-host on any Linux server with automatic HTTPS provisioning via Let's Encrypt. The visual workflow builder lets you design multi-turn conversation flows by connecting nodes for greetings, intent classification, tool calls, and handoffs; describe your use case in plain English and the platform generates the LLM prompt and node graph for you. Connect your own speech-to-text, LLM, and text-to-speech providers (OpenAI, Anthropic, Gemini, ElevenLabs, Deepgram, local Whisper, Kokoro, or any OpenAI-compatible endpoint) or use the built-in Speech-to-Speech mode with Gemini Flash Live and GPT-Realtime-2 for sub-200ms latency. Telephony plugs in through Twilio, Vonage, Vobiz, or Cloudonix for inbound and outbound calling, with live agent transfer when the conversation needs a human. Webhook tool calls connect to Salesforce, HubSpot, Google Calendar, Cal.com, or any REST API without writing orchestration code. The ClonedVoice feature mixes real human voice recordings for high-frequency phrases with neural TTS fallback for dynamic content, cutting costs while improving caller trust. A built-in MCP server lets AI coding agents like Claude Code or Cursor design, test, and edit workflows through natural language. Deploy on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. BSD 2-Clause licensed.
Gatus
With 11,400+ GitHub stars and active development since 2019, Gatus is the developer-oriented status page and health monitoring tool that ships as a single statically-linked Go binary in a scratch Docker image under 20 MB — deploying in seconds while monitoring your entire infrastructure across 12 protocols from a single YAML configuration file. Define health checks for HTTP, ICMP, TCP, DNS, gRPC, WebSocket, SSH, UDP, SCTP, STARTTLS, and TLS endpoints with conditions that go far beyond simple ping: evaluate response status codes, body content with JSONPath expressions, response time thresholds, certificate expiration days, DNS record values, and IP address ranges. Each endpoint supports independent alerting through Slack, Microsoft Teams, PagerDuty, Discord, Telegram, Twilio, Mattermost, Google Chat, email, Gotify, Pushover, and custom webhook providers with configurable failure thresholds and descriptions. The built-in status page displays uptime badges, response time graphs, and incident timelines with maintenance window support for planned downtime communication. External endpoints accept push-based health reports from services behind firewalls. Prometheus metrics export via the /metrics endpoint enables integration with existing observability stacks. OIDC and Basic Authentication protect the dashboard. PostgreSQL persistence stores historical uptime data. The official Helm chart supports Kubernetes deployment with liveness probes and PVC storage, while a community sidecar auto-generates endpoint configurations from Kubernetes Ingress and HTTPRoute resources. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. Apache 2.0 licensed.
Wealthfolio
Wealthfolio is a portfolio tracker offering a complete wealth management platform where financial data never leaves your infrastructure. Built on Rust with an Axum HTTP server, Diesel ORM, and SQLite storage, paired with a React 19 and Vite frontend, version 3.6 tracks stocks, ETFs, mutual funds, crypto, and cash savings across unlimited accounts with unified holdings. The performance engine calculates time-weighted returns (TWR), internal rate of return (IRR), volatility, maximum drawdown, and benchmark comparisons against the S&P 500 and custom indices, scoped per-account or across the entire portfolio. Net worth tracking monitors assets including real estate, vehicles, collectibles, and precious metals alongside liabilities, with stale-valuation warnings for items not updated in 90+ days. The spending module categorizes transactions automatically, supports multi-currency credit cards, builds budgets with monthly targets and rollovers, and generates narrative insights. A built-in AI assistant answers portfolio questions, suggests asset classifications, and imports transactions conversationally — bring your own API key from OpenAI, Anthropic, or use local LLMs. The addon system provides sandboxed extensions with granular permission declarations across 16 capability domains. CSV import maps broker exports with per-broker recipes for Interactive Brokers, Schwab, Fidelity, and dozens more. Market data streams from Yahoo Finance with automatic currency conversion. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3.0 licensed.
Redmine
Nearly two decades running engineering organizations: Redmine is the veteran open-source project management and issue tracker, a Ruby on Rails application (GPLv2) still in active development. Its core strength is configurability: define your own trackers (bug, feature, task, or anything else), issue statuses, and role-based workflows that control exactly which transitions each role may perform, then extend records with custom fields of every type. Issues support subtasks, relations (blocks, precedes, duplicates), watchers, categories, and full journaled history, with saved custom queries and cross-project filtering for slicing the backlog any way you need. Around the tracker sit Gantt charts and calendars, a roadmap driven by versions, per-project wikis, forums, news, and document repositories, plus time tracking with estimated versus spent hours and activity-based reporting. Multi-project support runs deep - subprojects, per-project modules, and granular role-based permissions - and repository integration (Git, Subversion, Mercurial) links commits to issues automatically. Email notifications, inbound email-to-issue creation, LDAP authentication, a REST API, and a large plugin and theme ecosystem round it out. Recent 6.x releases brought substantial query and rendering optimizations. Self-hosting keeps your entire project history in your own database, free of per-seat licensing.
Glean
Information overload is the default state of the modern internet, and Glean exists to tame it by pulling every blog, newsletter, and news source you follow into a single, organized reading experience with an interface that prioritizes clarity over clutter. Subscribe to RSS and Atom feeds, import your existing subscriptions via OPML, and organize everything into multi-level folders with a flexible tagging system that lets you slice your reading list by topic, priority, or mood. A three-pane layout presents your feed list, article summaries, and full content side by side, with one-click actions for marking articles as read, saving them for later, bookmarking favorites, or archiving what you have already processed. Background workers fetch new articles every 15 minutes so your feeds stay current without manual refreshes. The preference learning engine (backed by Milvus vector embeddings) scores incoming articles against your reading history and surfaces a personalized Smart Feed of content you are most likely to care about, reducing the time spent scrolling past irrelevant posts. A built-in MCP server lets AI assistants like Claude Desktop search and interact with your feed library directly. The admin dashboard on a separate port provides user management, system monitoring, and configuration controls for multi-user deployments. Bookmark external URLs from any browser with the Chrome extension, or access your feeds on mobile through the Progressive Web App. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3.0 licensed.
Mstream
"The easiest music streaming server available" is mStream's own billing, and the claim holds up: a lightweight Node.js app that turns a folder of audio files into a private streaming service in minutes, no external database required. Its filesystem-based design is the clever part - the API mirrors your folder structure, so you can browse and play music immediately, before any library scan finishes, and your organization on disk is your organization in the app. It streams flac, mp3, wav, ogg, opus, aac, and m4a, which matters to the audiophile crowd: FLAC plays uncompressed, bit-perfect, with gapless playback for live albums and continuous mixes. The web player runs anywhere a browser does and packs personality - a Milkdrop-style visualizer (Butterchurn), playlist sharing via links, and drag-and-drop uploads straight through the file explorer. Native iOS and Android apps add the feature streaming subscriptions can't match: sync your collection to your phone for true offline playback of music you own. Multi-user support assigns separate directories and permissions per account. Resource usage is famously light - mStream is tested on multi-terabyte libraries and runs happily on a Raspberry Pi, so a small RepoCloud instance serves a lifetime's collection. GPL-licensed, with zero listening-habit telemetry.
Zitadel
Securing a SaaS product, running B2B onboarding, or replacing Auth0 and Keycloak with a stack they own - teams needing more than basic auth reach for ZITADEL, an open-source identity and access management platform built in Go. Its multi-tenancy model is the differentiator: a strict Instance, Organization, Project hierarchy isolates data and scopes policy at each level, with identity brokering (pre-built templates for Google, GitHub, Microsoft, Apple, plus generic OIDC, OAuth, SAML, and LDAP), domain discovery that routes users to the right organization by email domain, and delegated management so customers administer their own users and roles. Authentication covers OpenID Connect (certified, including device authorization and token exchange), SAML 2.0 as both IdP and SP, SCIM, FIDO2 passkeys for phishing-resistant passwordless login, and MFA via OTP, email, SMS, and U2F; machine-to-machine flows support JWT profile, PATs, and client credentials. The architecture is event-sourced - every mutation is an immutable event, yielding a complete audit trail - with relational projections for queries and no external session store, so it scales horizontally. API-first with gRPC and REST, extensible via Actions webhooks, and the same codebase self-hosted (Docker Compose or Helm on PostgreSQL) as in the cloud.
Lobe Chat
A private ChatGPT built with Next.js: Lobe Chat is the open-source AI chat interface teams self-host instead. Its main advantage is provider breadth: one interface connects to 40+ model providers, including OpenAI, Anthropic Claude, Google Gemini, Mistral, Groq, AWS Bedrock, Azure, and local models served through Ollama, so you can switch models per conversation and compare outputs. It handles multi-modal work: image recognition, image generation, text-to-speech, and speech-to-text. A plugin system based on function calling and the Model Context Protocol (MCP) adds external tools like web search and code execution. Run it in standalone mode as a single container with settings in browser storage, or in database mode with PostgreSQL and S3-compatible storage for persistent history, multi-user auth, and RAG knowledge bases built from uploaded documents with pgvector retrieval. Because tools arrive through function calling and MCP rather than a proprietary plugin format, custom internal tools can be exposed to the assistant with a standard server over STDIO or HTTP. Hundreds of pre-configured assistant roles import from the community marketplace. For teams the cost model matters: provider API keys billed per token typically undercut a ChatGPT Plus seat per person, and self-hosting keeps API keys, uploaded files, embeddings, and conversation history entirely on your own server.
OpenSign
With 6,700 GitHub stars, 79 releases, and 40 contributors since its October 2023 launch, OpenSign delivers a fully free electronic signature platform that removes the per-envelope pricing and seat limits of commercial e-signing services. The React-based frontend provides a drag-and-drop interface for placing signature fields, initials, date stamps, text inputs, and checkboxes onto PDF documents, while the Parse Server backend built on Node.js handles document routing through configurable multi-signer workflows with sequential or parallel signing order. Guest signers authenticate via one-time-password email verification without requiring account creation, while registered users manage documents through OpenSign Drive — a centralized vault with folder organization and status tracking across draft, in-progress, completed, and declined states. Every signing action generates tamper-proof audit trails logging timestamps, IP addresses, email addresses, and phone numbers, culminating in a detailed completion certificate attached to the finished document. The REST API v1.2 exposes endpoints for document creation, template dispatch, self-signing, and real-time webhook notifications on document lifecycle events, with regional deployments available in US and EU. PDF templates with pre-placed widgets enable repeated dispatch to different signers in a single API call. Custom branding controls email invitation templates, signing page appearance, and completion certificate styling. Deploy via Docker Compose with MongoDB, Caddy reverse proxy, and automatic HTTPS provisioning. Running on a dedicated VPS on RepoCloud with guaranteed CPU, RAM, and SSD, full root SSH access, and a browser serial console. AGPL-3 licensed.