Install with one command
Run OneDrop on your computer or on a server with one command. Docker is the only requirement.
Run OneDrop on your computer or on a server with one command. Docker is the only requirement.
OneDrop runs as a single Docker container with its own SQLite database. Each project you build gets its own sandbox container next to it. The same command installs it on your computer or, with a domain, on a server for your team.
curl -fsSL https://raw.githubusercontent.com/onedrop-io/onedrop/main/install.sh | sh
The installer:
drop command to ~/.local/bin.http://localhost:8000, or the next free port.The first account you create is the admin. After signing up, connect your AI and describe your first app.
You don’t need sudo. On Linux, installing Docker itself asks for your
password.
Add --domain to serve OneDrop over HTTPS. With auto, it uses <your server's IP>.sslip.io, a free address that needs no DNS setup:
curl -fsSL https://raw.githubusercontent.com/onedrop-io/onedrop/main/install.sh | sh -s -- --domain auto
Or use your own domain:
curl -fsSL https://raw.githubusercontent.com/onedrop-io/onedrop/main/install.sh | sh -s -- --domain onedrop.example.com
Run over SSH without --domain, the installer offers the sslip.io address itself.
Allow incoming traffic on ports 80 and 443, for example in your cloud’s security group or firewall. OneDrop uses them to get its certificates from Let’s Encrypt and to serve the app.
Create two records pointing at the server’s IP address:
onedrop.example.com and *.onedrop.example.com. Skip this with
--domain auto.
The installer prints a one-time setup link. Open it to create the first account, which is the admin. Until that account exists, sign-up works only through this link, so nobody who finds the server first can take it over. After that, invite your team from Settings → Invite people.
On a server, each project’s preview and shell are at preview-<id>.<domain> and shell-<id>.<domain>, and only people who can see the project get through (see Server mode). Sandbox ports aren’t reachable from outside.
Projects can also be published on the domain, at <name>-<id>.<domain>: publicly, or privately to anyone signed in to OneDrop. Publishing to Tailscale works too.
Running the installer again keeps the domain. Use --domain to change it, or --local to go back to http://localhost only.
| Command | What it does |
|---|---|
drop update | Download the latest version and restart. Your data is kept. |
drop start | Start OneDrop. Unless you stopped it, it starts whenever Docker does. |
drop stop | Stop OneDrop |
drop status | Show whether it’s running, and its address |
drop open | Open OneDrop in your browser |
drop logs | Follow OneDrop’s logs |
drop config | List settings; drop config KEY=VALUE changes one and restarts |
drop uninstall | Remove OneDrop. It asks before deleting your projects and data. |
Running the install command again does the same as drop update.
Settings live in the container’s .env file. Use drop config for any setting in Configuration, for example to turn on social login:
drop config GOOGLE_CLIENT_ID=your-client-id GOOGLE_CLIENT_SECRET=your-client-secret
To install on a different port, set DROP_PORT when you run the installer:
curl -fsSL https://raw.githubusercontent.com/onedrop-io/onedrop/main/install.sh | DROP_PORT=9000 sh
| Part | Details |
|---|---|
drop container | The web app and its queue worker, from ghcr.io/onedrop-io/onedrop |
drop-data volume | The database, settings, and code backups. Kept across updates. |
| Project sandboxes | One container per project, from ghcr.io/onedrop-io/onedrop-sandbox |
drop network | Connects the sandboxes to the app so the agent can report what it’s doing |
| Docker socket | Mounted into the drop container so OneDrop can start and stop sandboxes |
On your computer, OneDrop and project previews listen only on 127.0.0.1, so other computers on your network can’t reach them. To share a project, publish it. On a server, only ports 80 and 443 are open.
Access to the Docker socket gives the drop container full control of
Docker on your computer. That’s how it manages sandboxes; run only images
you trust this way.
drop uninstall
If you keep your data, the drop-data volume stays, and installing again picks it up.