HitKeep is privacy-first analytics for humans and AI agents, self-hosted or in managed cloud.
10K+
AI-native, sovereign, privacy-first web analytics in one binary.
HitKeep is a 100% open-source web analytics platform licensed under MIT. Analyze traffic, conversions, ecommerce, Search Console, Web Vitals, AI crawlers, AI referrals, and chatbot outcomes—without operating a separate database, queue, or cache.
Website · Documentation · Source code · Managed cloud

The image runs as a non-root user, includes a built-in health check, and supports linux/amd64 and linux/arm64.
Create a long random secret in your password manager, replace the placeholder below, and start HitKeep:
docker run -d \
--name hitkeep \
--restart unless-stopped \
-p 8080:8080 \
-v hitkeep_data:/var/lib/hitkeep/data \
-e HITKEEP_PUBLIC_URL=http://localhost:8080 \
-e HITKEEP_JWT_SECRET='replace-with-a-long-random-secret' \
pascalebeier/hitkeep:latest
Open http://localhost:8080 and create the first account.
Keep HITKEEP_JWT_SECRET private and unchanged across restarts. The named Docker volume preserves the DuckDB database, archives, and backups when the container is replaced.
For a production deployment with HTTPS, reverse-proxy configuration, and separate data volumes, use the maintained Docker Compose guide.
| Variable | Purpose |
|---|---|
HITKEEP_PUBLIC_URL | Exact browser-visible URL of the instance, including any path prefix |
HITKEEP_JWT_SECRET | Stable private secret used to sign authentication sessions |
HITKEEP_TRUSTED_PROXIES | Trusted reverse-proxy network CIDRs |
HITKEEP_DB_PATH | DuckDB database location |
HITKEEP_DATA_PATH | Persistent application data directory |
HITKEEP_ARCHIVE_PATH | Retention archive directory |
HITKEEP_BACKUP_PATH | Automatic backup directory |
See the configuration reference for email, social sign-in, Search Console, custom tracking domains, AI providers, MCP, backups, and other settings.
Health endpoints are available at:
/healthz for process health/readyz for readinesslatest — latest stable releaseX.Y.Z — exact release; recommended for repeatable production deploymentsX.Y — latest patch release in a minor seriesX — latest release in a major seriessnapshot or main — current development build; not recommended for productionBrowse all available tags on Docker Hub and review GitHub Releases before upgrading.
Back up persistent data before an upgrade. See Backups and Restore for the supported workflow.
Create a site in HitKeep, then add the tracker to your website:
<script async src="https://analytics.example.com/hk.js"></script>
Replace analytics.example.com with your HitKeep domain. Pageviews, outbound clicks, downloads, and form submissions begin flowing automatically.
Use custom events for actions such as signups, purchases, and qualified leads.
Want to support independent open-source analytics? Fund HitKeep on GitHub Sponsors or make a one-time contribution.
HitKeep is distributed under the MIT License.
Content type
Image
Digest
sha256:32eddbc0d…
Size
85.9 MB
Last updated
about 4 hours ago
docker pull pascalebeier/hitkeep:sha-9b5ad6a