.env.
What you need
- Its own hostname, such as
id.example. Pocket ID can’t live under a path of another site. - HTTPS on that hostname. Passkeys only work on a secure origin. If you followed VPS + Caddy, a second site block in the same Caddyfile does it.
- A persistent volume for Pocket ID’s data.
- An
ENCRYPTION_KEYfor Pocket ID, kept with your backups. It encrypts Pocket ID’s signing keys; without it, a restore won’t start. - plamotrack itself on an
https://address, as OIDC mode requires.
Run Pocket ID
This is the setup plamotrack was tested with: Pocket ID v2.16.0 on the same host, behind Caddy. Pocket ID’s own documentation covers its other options.Generate an encryption key
.env file that only you can read, holding a random key:.env backup.Create docker-compose.yml
docker-compose.yml, using your own hostname:APP_URL is the bare hostname, with no path. The port is published on loopback only, so Caddy is the only way in.Add Pocket ID to Caddy
/etc/caddy/Caddyfile, beside plamotrack’s:tls { … } block: without the Cloudflare module, Caddy refuses a Caddyfile that names it, and that would stop plamotrack’s site too.Restart Caddy
Start Pocket ID
https://id.example/.well-known/openid-configuration. The issuer it shows is the value plamotrack needs — the bare https://id.example, with no trailing slash.Create your account and a passkey
Create your user in Pocket ID as its documentation describes. This account becomes the owner of your plamotrack instance. To sign in to Pocket ID without a passkey — the first time, or on a new device — get a one-time login code from Pocket ID’s directory on the host:Create the plamotrack client in Pocket ID
plamotrack needs one client in Pocket ID. It carries both the browser login and the OAuth links for AI assistants.Add an OIDC client
plamotrack.Enter both callback URLs
https://plamotrack.example/api/auth/oidc/callback— the browser loginhttps://plamotrack.example/mcp/auth/callback— AI assistants
Keep it confidential, with PKCE
Let your account use it
Note the client ID and secret
.env./mcp with Pocket ID in any other way. Assistants register with plamotrack, not with Pocket ID, so Pocket ID only ever sees this one client.
Update plamotrack’s .env
Add these to plamotrack’s .env, then restart the stack:
Claim the instance
The first sign-in works as on the OIDC page:Enter the setup token
Sign in at Pocket ID
Allow plamotrack
Link an AI assistant
Connect Claude.ai, ChatGPT, Gemini Spark or Mistral as described in Web clients (OAuth). When the assistant sends you to sign in, you sign in at Pocket ID with your passkey. Pocket ID has to be reachable from your browser and from the plamotrack host. It doesn’t have to be reachable from the internet: the assistant talks only to plamotrack, and plamotrack talks to Pocket ID on its behalf. This was tested with Claude.ai and a Pocket ID on a private network.Back up Pocket ID
Back up Pocket ID alongside plamotrack’s backups. Without Pocket ID’s data you can’t sign in, and without itsENCRYPTION_KEY that data is useless: under a different key, Pocket ID doesn’t start.
Pocket ID marks its export as experimental.
Export Pocket ID's data
Keep the export private
Keep Pocket ID's .env with it
.env, which holds the ENCRYPTION_KEY, to the same place as the export.Restore Pocket ID
Put the .env back
.env into Pocket ID’s directory on the host.Import the export into a fresh volume
Start Pocket ID
If you lose your passkey
Losing a passkey doesn’t change your identity, so plamotrack needs no recovery step.Get a login code
Sign in and add a new passkey
Sign in to plamotrack
rebind-oidc, on the OIDC page, is only for moving the instance to a different account or provider.
Revoking an assistant is local to plamotrack
Pocket ID has no endpoint for revoking tokens. When a link ends at plamotrack — the assistant revokes it, or you runrebind-oidc — plamotrack ends it at once, but it has nothing to call at Pocket ID. The refresh token Pocket ID issued for that link stays valid at Pocket ID until it expires — 30 days by default. plamotrack never accepts it again, so the assistant stays disconnected. Nothing for you to do.
Upgrading from an earlier release
Before v0.6.0-alpha, linking an assistant through Pocket ID only worked if you had registered your instance’s/mcp as an API in Pocket ID. That’s no longer needed.
Upgrade plamotrack
Delete the API registration
/mcp.Reconnect each assistant once