Sign inSign up

samuelstreets/immich-share

By samuelstreets

โ€ขUpdated about 3 hours ago

Image
0

6.3K

samuelstreets/immich-share repository overview

โ ๐Ÿ–ผ๏ธ Immich Share

A self-hosted web app that sits alongside your Immichโ  instance and lets you share albums or photos with anyone via a password-protected URL โ€” no Immich account required.

โ Features

  • ๐Ÿ”’ Password-protected shares โ€” each share has its own password
  • ๐Ÿ”‘ Passwordless access โ€” generate a token-in-URL link (no password prompt)
  • ๐Ÿ“ Album or tag shares โ€” share a whole Immich album or assets by tag
  • โฑ Expiry dates โ€” shares can auto-expire
  • ๐Ÿ‘ Max view limits โ€” auto-disable a share after N views
  • โฌ‡ Optional downloads โ€” control whether viewers can download originals or a ZIP
  • โฌ† Optional uploads โ€” let viewers contribute photos back to the album (chunked, no file-size limit)
  • ๐Ÿท Auto-tag uploads โ€” automatically apply Immich tags to every uploaded asset
  • ๐Ÿ‘€ Album watcher โ€” periodically tags new assets added to watched albums
  • ๐Ÿ”— Custom slugs โ€” friendly URLs like /s/summer-2024
  • ๐ŸŒ External URL config โ€” set the public URL used in share links
  • ๐Ÿ–ผ Lightbox viewer โ€” full-screen photo/video viewer with pinch-to-zoom, drag-to-pan, and keyboard navigation
  • โœ… Drag-to-select โ€” select multiple photos in the gallery and bulk-download as ZIP
  • ๐Ÿ“Š Admin dashboard โ€” stats, per-share activity charts, access logs with export (CSV/JSON)
  • ๐Ÿ”” Notifications โ€” email (SMTP) and webhook alerts on upload, per-share or global
  • ๐Ÿ” Two-factor authentication โ€” TOTP (Google Authenticator, Authy, etc.) for the admin login
  • ๐Ÿงน Scheduled cleanup โ€” auto-purge expired shares and orphaned upload chunks
  • ๐Ÿ“ฑ Mobile-friendly admin โ€” responsive sidebar + bottom nav for phones
  • ๐Ÿณ Single Docker container โ€” easy to self-host

โ Quick Start (Docker Compose)

# 1. Clone the repo
git clone https://github.com/YOUR_USERNAME/immich-share.git
cd immich-share

# 2. Create your .env file
cp .env.example .env
# Edit .env โ€” set JWT_SECRET at minimum

# 3. Start
docker compose up -d

# 4. Open http://localhost:3000
# Login: admin / admin  (change immediately in Settings!)

โ Configuration

Settings can be configured via environment variables (seed on first boot) or the admin UI โ†’ Settings page at any time.

VariableRequiredDescription
JWT_SECRETYesLong random string for signing admin tokens. Min 32 chars.
IMMICH_URLNo*URL of your Immich instance, e.g. http://192.168.1.100:2283
IMMICH_API_KEYNo*API key from Immich โ†’ Account Settings โ†’ API Keys
EXTERNAL_URLNo*Public URL of this app โ€” used in share links
ADMIN_PASSWORDNoDefault admin password (first run only, default: admin)
PORTNoPort to listen on (default: 3000)
DB_PATHNoPath to SQLite database (default: /app/data/app.db)
ALLOWED_ORIGINSNoNewline-separated list of allowed CORS origins (empty = allow all)
SMTP_HOSTNoSMTP server hostname for email notifications
SMTP_PORTNoSMTP port (default: 587)
SMTP_USERNoSMTP username
SMTP_PASSNoSMTP password
SMTP_FROMNoFrom address for notification emails
GLOBAL_WEBHOOK_URLNoWebhook URL fired on every upload across all shares
GLOBAL_WEBHOOK_SECRETNoHMAC-SHA256 signing secret for the global webhook
CLEANUP_INTERVAL_MSNoHow often the cleanup job runs (default: 30 minutes)
WATCH_INTERVAL_MSNoHow often the album watcher runs (default: 5 minutes)

*These can be set via the Settings UI after first boot.


โ Getting an Immich API Key

  1. Open your Immich web UI
  2. Click your profile icon โ†’ Account Settings
  3. Go to API Keys โ†’ New API Key
  4. Copy the key and paste it into the Settings page (or .env)
โ Required API Key Permissions
PermissionWhy it's needed
album.readList and browse albums in the share creation UI
album.statisticsFetch album asset counts for the admin UI
albumAsset.createAdd uploaded assets to the shared album
asset.readFetch asset metadata
asset.viewServe thumbnails and preview images to share viewers
asset.downloadProxy original file downloads to share viewers
tag.readList tags so you can create tag-based shares
asset.upload(upload-enabled shares) Let viewers upload photos into Immich
tag.asset(upload tags / album watcher) Apply tags to assets automatically

Note: An admin Immich account key has all permissions by default. Scoped permissions apply when using Immich v1.100+ fine-grained API keys.

Full Immich permission reference
ScopePermissions
activityactivity.create activity.read activity.update activity.delete activity.statistics
apiKeyapiKey.create apiKey.read apiKey.update apiKey.delete
assetasset.read asset.update asset.delete asset.statistics asset.share asset.view asset.download asset.upload asset.replace asset.copy asset.derive asset.edit.get asset.edit.create asset.edit.delete
albumalbum.create album.read album.update album.delete album.statistics album.share album.download
albumAssetalbumAsset.create albumAsset.delete
albumUseralbumUser.create albumUser.update albumUser.delete
authauth.changePassword
authDeviceauthDevice.delete
archivearchive.read
backupbackup.list backup.download backup.upload backup.delete
duplicateduplicate.read duplicate.delete
faceface.create face.read face.update face.delete
folderfolder.read
jobjob.create job.read
librarylibrary.create library.read library.update library.delete library.statistics
timelinetimeline.read timeline.download
maintenancemaintenance
mapmap.read map.search
memorymemory.create memory.read memory.update memory.delete memory.statistics
memoryAssetmemoryAsset.create memoryAsset.delete
notificationnotification.create notification.read notification.update notification.delete
partnerpartner.create partner.read partner.update partner.delete
personperson.create person.read person.update person.delete person.statistics person.merge person.reassign
pinCodepinCode.create pinCode.update pinCode.delete
pluginplugin.create plugin.read plugin.update plugin.delete
serverserver.about server.apkLinks server.storage server.statistics server.versionCheck
serverLicenseserverLicense.read serverLicense.update serverLicense.delete
sessionsession.create session.read session.update session.lock
sharedLinksharedLink.create sharedLink.read sharedLink.update sharedLink.delete
stackstack.create stack.read stack.update stack.delete
syncsync.stream
syncCheckpointsyncCheckpoint.read syncCheckpoint.update syncCheckpoint.delete
systemConfigsystemConfig.read systemConfig.update
systemMetadatasystemMetadata.read systemMetadata.update
tagtag.create tag.read tag.update tag.delete tag.asset
useruser.read user.update
userLicenseuserLicense.create userLicense.read userLicense.update userLicense.delete
userOnboardinguserOnboarding.read userOnboarding.update userOnboarding.delete
userPreferenceuserPreference.read userPreference.update
userProfileImageuserProfileImage.create userProfileImage.read userProfileImage.update userProfileImage.delete
queuequeue.read queue.update
queueJobqueueJob.create queueJob.read queueJob.update queueJob.delete
workflowworkflow.create workflow.read workflow.update workflow.delete
adminUseradminUser.create adminUser.read adminUser.update adminUser.delete
adminSessionadminSession.read
adminAuthadminAuth.unlinkAll

โ Share Features

โ Passwordless Access

Generate a static token-in-URL link for a share โ€” visitors open the link and go straight to the gallery without a password prompt. Tokens can be generated or revoked at any time from the Shares admin page.

โ Custom Slugs

Instead of /s/<uuid>, give a share a memorable URL like /s/wedding-photos. Slugs must be 3โ€“60 lowercase alphanumeric characters or hyphens and must be unique.

โ Max Views

Set a view limit on a share โ€” it is automatically disabled once the limit is reached (checked every 30 minutes by the cleanup job).

โ Upload Tags

When uploads are enabled, select one or more Immich tags to be automatically applied to every photo uploaded through that share.

โ Album Watcher

For album shares, configure "watch tags" โ€” the watcher runs every 5 minutes and applies those tags to any assets that have been newly added to the album since the last check.

โ Notifications

Configure SMTP settings globally and set a per-share notify email to receive an alert whenever someone uploads a file. Webhooks (global or per-share) fire a signed JSON payload on each upload and can be used to trigger automations.


โ Reverse Proxy (nginx example)

server {
    listen 443 ssl;
    server_name share.yourdomain.com;

    location / {
        proxy_pass http://localhost:3000;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
        # Required for large uploads and downloads
        proxy_buffering off;
        proxy_read_timeout 300s;
        client_max_body_size 0;
    }
}

โ Local Development

โ Prerequisites
  • Node.js 20+
  • An Immich instance
โ Run locally
# Quickstart script (copies .env.example if no .env exists)
./dev.sh

# Or manually:

# Backend
cd backend
cp ../.env.example .env  # edit it โ€” set JWT_SECRET at minimum
npm install
node src/index.js

# Frontend (separate terminal)
cd frontend
npm install
npm run dev
# โ†’ http://localhost:5173 (proxies /api to :3000)
โ Build Docker image locally
docker build -t immich-share .
docker run -p 3000:3000 \
  -e JWT_SECRET=change-me-to-something-long \
  -e IMMICH_URL=http://your-immich:2283 \
  -e IMMICH_API_KEY=your-key \
  -e EXTERNAL_URL=http://localhost:3000 \
  -v immich-share-data:/app/data \
  immich-share

โ Data & Privacy

  • All share metadata is stored in a local SQLite database at /app/data/app.db
  • No photo data is stored โ€” all media is proxied directly from your Immich instance
  • Share passwords are bcrypt-hashed (cost factor 10)
  • Admin passwords are bcrypt-hashed (cost factor 12)
  • Share session tokens are HMAC-SHA256 signed, valid for 8 hours
  • Webhook payloads are optionally HMAC-SHA256 signed (X-ImmichShare-Signature: sha256=โ€ฆ)
  • Rate limiting is applied to auth, share-verify, and token-access endpoints

โ License

MIT

Tag summary

Content type

Image

Digest

sha256:c47935c97โ€ฆ

Size

57.4 MB

Last updated

about 3 hours ago

docker pull samuelstreets/immich-share