netspeedy/paperclip is an automated multi-architecture container image for
Paperclip, built from upstream
release source without vendoring the full repository into this packaging repo.
This image is intended to feel like a polished upstream-style container:
v2026.403.0latest tracks the newest stable upstream v... tagbuildxlinux/amd64linux/arm64netspeedy/paperclip:latestnetspeedy/paperclip:v2026.403.0DATABASE_URL is unsetconfig.json is missinggit, gh, curl, wget, ripgrep, python3claude, codex, opencodeOn a fresh /paperclip volume, this image will:
DATABASE_URL is not set.PAPERCLIP_AGENT_JWT_SECRET in
/paperclip/instances/default/.env if neither BETTER_AUTH_SECRET nor
PAPERCLIP_AGENT_JWT_SECRET is provided.PAPERCLIP_PUBLIC_URL to http://localhost:$PORT when no explicit
auth/public URL env vars are set.paperclipai onboard --yes automatically when
/paperclip/instances/default/config.json is missing.This makes docker run and small Compose setups work out of the box while
still allowing explicit production settings.
If DATABASE_URL is set, first-boot auto-onboarding still runs when
config.json is missing. In that case Paperclip writes a PostgreSQL-backed
config instead of an embedded-PostgreSQL one, and startup depends on the
external database already being reachable.
Mount /paperclip to persistent storage.
This directory holds:
DATABASE_URL is unset.env bootstrap values such as PAPERCLIP_AGENT_JWT_SECRETmkdir -p ./data/paperclip
docker run --name paperclip \
-p 3100:3100 \
-v "$(pwd)/data/paperclip:/paperclip" \
netspeedy/paperclip:latest
Open http://localhost:3100.
For a fresh authenticated first boot, follow the container logs and open the printed CEO invite URL to claim the first admin account:
docker logs -f paperclip
The invite URL is printed after Paperclip finishes first-run setup.
services:
paperclip:
image: netspeedy/paperclip:latest
container_name: paperclip
restart: unless-stopped
ports:
- "3100:3100"
environment:
HOST: 0.0.0.0
# Set this when the app is reached via a different host or port.
# PAPERCLIP_PUBLIC_URL: https://paperclip.example.com
# Optional local adapter credentials:
# OPENAI_API_KEY: ${OPENAI_API_KEY}
# ANTHROPIC_API_KEY: ${ANTHROPIC_API_KEY}
volumes:
- ./data/paperclip:/paperclip
Start it with:
docker compose up -d
docker compose logs -f paperclip
If you prefer a separate PostgreSQL container or managed database, set
DATABASE_URL. Even then, keep the /paperclip mount for files, secrets,
backups, and instance state.
On a fresh /paperclip volume, this path still auto-runs
paperclipai onboard --yes and writes config.json on first boot. In
authenticated mode, the first admin bootstrap invite should also be created,
but your external PostgreSQL service must be available before Paperclip starts.
services:
paperclip:
image: netspeedy/paperclip:latest
container_name: paperclip
restart: unless-stopped
depends_on:
- postgres
ports:
- "3100:3100"
environment:
HOST: 0.0.0.0
DATABASE_URL: postgres://paperclip:paperclip@postgres:5432/paperclip
PAPERCLIP_PUBLIC_URL: https://paperclip.example.com
BETTER_AUTH_SECRET: ${BETTER_AUTH_SECRET}
volumes:
- ./data/paperclip:/paperclip
postgres:
image: postgres:17
container_name: paperclip-postgres
restart: unless-stopped
environment:
POSTGRES_USER: paperclip
POSTGRES_PASSWORD: paperclip
POSTGRES_DB: paperclip
volumes:
- ./data/postgres:/var/lib/postgresql/data
| Variable | Default | Description |
|---|---|---|
OPENAI_API_KEY | unset | OpenAI API key used by Paperclip local adapters and Codex CLI workflows |
ANTHROPIC_API_KEY | unset | Anthropic API key used for Claude local adapter workflows |
DATABASE_URL | unset | PostgreSQL connection string. If unset, this image uses embedded PostgreSQL |
HOST | 0.0.0.0 | Bind address for the Paperclip server |
PORT | 3100 | Server port |
SERVE_UI | true | Enable the Paperclip web UI |
PAPERCLIP_DEPLOYMENT_MODE | authenticated | Deployment mode used by the server |
PAPERCLIP_DEPLOYMENT_EXPOSURE | private | Exposure mode for authenticated deployments |
PAPERCLIP_PUBLIC_URL | auto | Public URL where Paperclip is reachable. Defaults to http://localhost:$PORT when unset and no other auth/public URL vars are provided |
BETTER_AUTH_SECRET | unset | Better Auth secret. Recommended to set explicitly for long-lived or shared deployments |
PAPERCLIP_AGENT_JWT_SECRET | auto on first boot | Alternate auth secret input. If unset alongside BETTER_AUTH_SECRET, this image generates and persists one on first boot |
PAPERCLIP_AUTO_ONBOARD | true | Packaging-specific toggle for automatic paperclipai onboard --yes when config.json is missing |
PAPERCLIP_AUTO_BOOTSTRAP_CEO | true | Packaging-specific toggle for automatic CEO bootstrap invite handling on authenticated server starts |
USER_UID | 1000 | Runtime UID remap for the node user to match bind-mounted host permissions |
USER_GID | 1000 | Runtime GID remap for the node group to match bind-mounted host permissions |
Common notes:
DATABASE_URL is optional in this image. Embedded PostgreSQL is enabled.PAPERCLIP_PUBLIC_URL explicitly.BETTER_AUTH_SECRET explicitly.OPENAI_API_KEY, ANTHROPIC_API_KEY, DATABASE_URL, HOST, PORT, SERVE_UI, PAPERCLIP_DEPLOYMENT_MODE, PAPERCLIP_DEPLOYMENT_EXPOSURE, PAPERCLIP_PUBLIC_URL, BETTER_AUTH_SECRET, and PAPERCLIP_AGENT_JWT_SECRET are upstream-supported runtime variables.PAPERCLIP_AUTO_ONBOARD and PAPERCLIP_AUTO_BOOTSTRAP_CEO, plus the automatic localhost/auth-secret defaults, are packaging-specific conveniences provided by this image.The image supports these Docker build arguments:
| Build arg | Default | Description |
|---|---|---|
USER_UID | 1000 | Initial UID for the container node user |
USER_GID | 1000 | Initial GID for the container node group |
Example:
docker build -t paperclip-local \
--build-arg USER_UID=$(id -u) \
--build-arg USER_GID=$(id -g) \
.
This packaging repo builds from upstream Paperclip release archives using:
.gitlab/scripts/prepare_source.py to fetch and prepare the upstream source.gitlab/scripts/docker_build.py to run docker buildxThe published image is labeled with standard OCI metadata including source URL, project URL, vendor, title, and upstream version.
latest follows the newest stable upstream v... release./.docker run and Compose users.Content type
Image
Digest
sha256:832450f69…
Size
897.5 MB
Last updated
6 months ago
docker pull netspeedy/paperclip