ClientSt0r
Self-hosted IT documentation and service desk for MSPs. A ticket opens with the client’s contract, the affected asset, the runbook, and the vault entries the technician needs — all in one database.
The problem
An MSP technician working a ticket needs the client’s contract terms, the asset in question, the runbook that covers it, and the credentials to fix it. When those live in four different subscriptions, every ticket starts with a search.
Why existing tools fell short
IT documentation tools and PSA/service-desk tools are usually separate subscriptions, so a ticket doesn’t automatically carry the asset, runbook, contract, and credentials it needs.
The solution
ClientSt0r keeps documentation, assets, runbooks, an encrypted vault, and an optional service desk in one self-hosted database. A ticket opens with everything related to it already linked, and the service desk adds queues, SLA timers with pause logic, time entries, quotes, invoices, contracts, projects, approvals, workflow rules, a dispatch board, rack elevations, and profitability reports.
- Client documentation, assets, runbooks, and an encrypted password vault
- Opt-in service desk: queues, SLA timers, time entries, quotes, invoices, and contracts
- One organization per client, with parent/child organizations
- Enforced TOTP 2FA and optional Entra ID SSO or LDAP
- PSA and RMM integrations and a browser extension
Engineering involved
Verified from the public repository: README, dependency manifests, and source files.
- Backend
- Django 6 with Django REST Framework, OpenAPI schema generation, and optional GraphQL; served by Gunicorn.
- Database design
- MariaDB. Organization-scoped data across dozens of models (an organization foreign key on each), with memberships and a current-organization middleware.
- Tenant isolation
- One tenant per client with parent/child organizations; API queries pass through a dedicated scoping layer.
- Authentication & authorization
- Enforced TOTP 2FA, Argon2 password hashing, brute-force lockout, and optional Microsoft Entra ID SSO and LDAP/Active Directory.
- Security
- AES-256-GCM encryption with HKDF-derived keys per purpose (vault, API keys, TOTP secrets, PSA/RMM credentials), context-bound with associated data and versioned for key rotation.
- Integrations
- ConnectWise, Autotask, HaloPSA, NinjaOne, Datto RMM, Syncro, and Atera; a Manifest V3 browser extension for vault search and autofill.
- Deployment
- Install script with systemd, or Docker Compose with published container images.
What makes it interesting
The vault doesn’t use one key for everything. Each kind of secret gets its own key derived with HKDF, ciphertexts are bound to their context so a value can’t be moved to another record, and version tags allow keys to be rotated without a flag day.
Outcome
Measured Public GitHub figures as of 10 October 2026: 75 stars, 19 forks, and 64 published releases since the repository was created in January 2026. Stars and forks show public interest, not active installations — the project doesn’t collect usage data.
Current status
Open Source Free, MIT-licensed, self-hosted. The source code is public on GitHub.
Open source under the MIT license and actively released. Self-hosted on a single server by design; there is no hosted version or public demo instance. AI features are optional and off by default.
See it working
The repository includes dozens of screenshots and a walkthrough video recorded with demo data: github.com/agit8or1/clientst0r. Overview: mspzero.com/tools/clientst0r.
Want something similar?
Need a system like this, built around your own business? MyAppDone can design, build, deploy, and maintain an application tailored to your workflow.


