Open source
Free and open source: the licences, how to contribute, and how to report a security problem. The code is all in one public repository.
All of it is in github.com/trckable/trckable:
the server, the dashboard, the tracker and the trckable npm package.
Licences
| Part | Licence |
|---|---|
| Server and dashboard | AGPL-3.0 |
Tracker and the trckable npm package | MIT |
| Geolocation database | DB-IP, CC BY 4.0 |
Run it, change it and share it. Running trckable for yourself or your team, as it is or with your own tweaks, needs nothing more. The AGPL asks that anyone you offer a changed version to over a network can get its source.
The name trckable and the logo are not part of those licences. A fork is welcome under its own name and without the logo, and "based on trckable" is welcome too. Writing about it or building something that works with it can say "trckable" freely. The details are in TRADEMARKS.md.
Contributing
Bug reports, fixes and small improvements are welcome. For anything larger, open an issue first so the approach is agreed before you spend time on it. CONTRIBUTING.md has how to build, test and send a change.
- Build it with Go 1.27, Node 22 and pnpm 12; the dashboard and tracker builds are committed, so a Go toolchain is all a server change needs.
pnpm checkruns what CI runs, on any branch.- Every change people will notice carries a line in the changelog.
- On your first pull request a bot asks you to sign the short contributor licence agreement, once. It promises that every accepted contribution stays available under its open-source licence.
- Every feature works when you host trckable yourself: nothing is held back.
Security
Please report a problem privately, not in a public issue. How, what is in scope and what to expect is in SECURITY.md. Security fixes go into the latest release, so keep your instance up to date: Upgrading.
What the server does to protect your data is on these pages: no IP address is ever stored (Privacy), provider keys and backups are encrypted with your instance key (Backups), and every tool of the MCP server is read-only (MCP).