Open SourceOpen Source

ClientSt0r

Self-hosted IT documentation and service desk for MSPs. A ticket opens with the client’s contract, the affected asset, the runbook, and the vault entries the technician needs — all in one database.

ClientSt0r client dashboard with quick actions, scheduled work, tickets, and monitors for a demo client
ClientSt0r client dashboard with demo data. Source: the ClientSt0r GitHub repository.

The problem

An MSP technician working a ticket needs the client’s contract terms, the asset in question, the runbook that covers it, and the credentials to fix it. When those live in four different subscriptions, every ticket starts with a search.

Why existing tools fell short

IT documentation tools and PSA/service-desk tools are usually separate subscriptions, so a ticket doesn’t automatically carry the asset, runbook, contract, and credentials it needs.

The solution

ClientSt0r keeps documentation, assets, runbooks, an encrypted vault, and an optional service desk in one self-hosted database. A ticket opens with everything related to it already linked, and the service desk adds queues, SLA timers with pause logic, time entries, quotes, invoices, contracts, projects, approvals, workflow rules, a dispatch board, rack elevations, and profitability reports.

  • Client documentation, assets, runbooks, and an encrypted password vault
  • Opt-in service desk: queues, SLA timers, time entries, quotes, invoices, and contracts
  • One organization per client, with parent/child organizations
  • Enforced TOTP 2FA and optional Entra ID SSO or LDAP
  • PSA and RMM integrations and a browser extension

Engineering involved

Verified from the public repository: README, dependency manifests, and source files.

Backend
Django 6 with Django REST Framework, OpenAPI schema generation, and optional GraphQL; served by Gunicorn.
Database design
MariaDB. Organization-scoped data across dozens of models (an organization foreign key on each), with memberships and a current-organization middleware.
Tenant isolation
One tenant per client with parent/child organizations; API queries pass through a dedicated scoping layer.
Authentication & authorization
Enforced TOTP 2FA, Argon2 password hashing, brute-force lockout, and optional Microsoft Entra ID SSO and LDAP/Active Directory.
Security
AES-256-GCM encryption with HKDF-derived keys per purpose (vault, API keys, TOTP secrets, PSA/RMM credentials), context-bound with associated data and versioned for key rotation.
Integrations
ConnectWise, Autotask, HaloPSA, NinjaOne, Datto RMM, Syncro, and Atera; a Manifest V3 browser extension for vault search and autofill.
Deployment
Install script with systemd, or Docker Compose with published container images.

What makes it interesting

The vault doesn’t use one key for everything. Each kind of secret gets its own key derived with HKDF, ciphertexts are bound to their context so a value can’t be moved to another record, and version tags allow keys to be rotated without a flag day.

Outcome

Measured Public GitHub figures as of 10 October 2026: 75 stars, 19 forks, and 64 published releases since the repository was created in January 2026. Stars and forks show public interest, not active installations — the project doesn’t collect usage data.

Current status

Open Source Free, MIT-licensed, self-hosted. The source code is public on GitHub.

Open source under the MIT license and actively released. Self-hosted on a single server by design; there is no hosted version or public demo instance. AI features are optional and off by default.

See it working

The repository includes dozens of screenshots and a walkthrough video recorded with demo data: github.com/agit8or1/clientst0r. Overview: mspzero.com/tools/clientst0r.

Want something similar?

Need a system like this, built around your own business? MyAppDone can design, build, deploy, and maintain an application tailored to your workflow.

Related projects