Moving between hosted and self-hosted

Export one organization as a single SQLite file and import it on checky.team, Docker or your own Cloudflare account — in either direction.

Your data is never locked in. One organization exports into one file that imports anywhere Checky runs: hosted ⇄ Docker ⇄ Deploy to Cloudflare.

Export

Owners: Settings → Move your data → Export organization (API: POST /api/v1/organization/export).

The file contains the organization’s members, departments, checks, check-ins, absences, settings, webhooks, SSO providers and the audit log, plus checksums. It also contains the members’ sign-in data (password hashes, passkeys) so people keep their logins — store the file like a password. It never contains sessions, API keys, OAuth tokens of ChatGPT/Claude connections or data of other organizations.

Secrets (webhook signing secrets, SSO client secrets) are left out by default. Enter an export passphrase to include them encrypted; you then need the passphrase for the import.

Import into a new self-hosted install (Docker or Cloudflare)

  1. Start a fresh, empty installation (Quick start or Deploy to Cloudflare).
  2. On the setup screen choose Moving from another Checky? and upload the file (plus the passphrase, if you used one).
  3. Everything is restored as it was — people keep their passwords and passkeys. Secrets are re-encrypted with the new APP_SECRET; webhooks exported without secrets get a new secret and are paused until you re-enable them.

A self-hosted instance accepts an import only while it is still empty.

People who belonged to more than one organization at the source are exported without credentials (their password would otherwise travel with one organization’s file). They sign in with an email code, magic link or a password reset.

Import into hosted checky.team

Signed in on the hosted service: create the organization from the file (Import organization). You must be an owner in the file. For safety, hosted imports never carry credentials and never add people without consent: everyone else gets an invitation, and verified domains must be verified again.

Afterwards

  • Update DNS / BASE_URL, and the redirect URIs at your SSO provider (they contain the host).
  • Reconnect ChatGPT/Claude (the OAuth connection belongs to the old address).
  • Point inbound email (reply domain) at the new installation.

Compatibility

A file from an older version imports into a newer one. A file from a newer version is refused by an older one (import.version_unsupported) — upgrade the target first.

Stuck? We help with installations: contact us