Windows
- Download the installer from the download page.
- Run it. Nightwire installs for your user account only, so it doesn't need administrator rights.
- If Windows shows “Windows protected your PC”, click More info → Run anyway. This appears for new apps that Windows doesn't know yet.
- Nightwire opens, and from then on it lives in the tray next to the clock. Closing the window keeps it running in the tray so you still get notifications. Use Quit in the tray menu to close it completely.
Updates download in the background, and Nightwire asks once to restart when a new version is ready. You can turn Launch at startup on or off in Settings.
Android
- On your phone, open the download page and tap Download APK.
- Open the downloaded file. Android asks to allow installs from your browser: tap Settings → Allow from this source, go back, and tap Install.
- Open Nightwire and allow notifications when asked. Without that permission, messages can't alert you while the app is closed.
When a new version is out, a banner appears in the app. Tap Update: it downloads inside the app, shows its progress, and opens Android's installer. The first time, Android asks you to allow Nightwire to install updates.
iPhone, iPad and web
Every Nightwire server includes the web app. Open the server's address in a browser and sign in. It works in Chrome, Edge, Firefox and Safari on any computer.
Add it to your iPhone or iPad home screen
- Open the server's address in Safari and sign in.
- Tap the Share button, then Add to Home Screen.
- Nightwire now opens full-screen from its own icon, like an app.
Connecting to a server
Nightwire has no central service: every team or community runs its own server. The first screen asks for:
| Field | What to enter |
|---|---|
| Server address | The domain or IP address your admin gave you, e.g. chat.example.com or 203.0.113.24 |
| Port | Only if your admin gave you one (e.g. 8443). Leave it empty otherwise. |
The app remembers the server, even after you sign out. To switch servers, sign out and tap Change server.
“Trust this server?”
Servers on a private network or without a public certificate use their own certificate. The app shows its fingerprint once and asks you to trust it. Your admin can check that it matches with nightwire info on the server. After that the app only accepts that exact certificate, so nobody can impersonate the server later.
Accounts
- Invite only (default): use the invite link or code from your admin and tap Got an invite?
- Open: the sign-in screen shows Create account.
- Turn on two-factor sign-in in Settings → Security with any authenticator app. Keep your recovery codes somewhere safe.
Server: before you start
| Need | Details |
|---|---|
| A Linux server | Ubuntu 22.04 or 24.04, or Debian 12, recommended. 64-bit Intel/AMD or ARM. A small cloud VPS or a machine on your own network works. |
| Memory and disk | 1 GB RAM minimum, 2 GB recommended. 10 GB of disk plus room for the files people share. |
| Root access | You run the installer with sudo. |
| Open ports | With a domain: 80 and 443. With an IP address: the port you choose (443 by default), plus 80 for a free certificate on a public IP. |
| Docker | Installed for you if it's missing. An existing Docker installation is never replaced; it just needs the Compose plugin. |
| A domain (optional) | Not required. A plain IP address works, with HTTPS. |
Run the installer
Connect to your server over SSH and run:
curl -fsSL https://get.nightwire.chat | sudo bash
It asks a few questions, then sets everything up in about three minutes:
- How people will connect: a domain, the server's IP address, or through a web server you already run (see below).
- Workspace name: shown on the sign-in screen, e.g. “Night Watch”.
- Your admin account: username, full name and password.
It then installs Docker if needed, generates every password and secret key, gets an HTTPS certificate, starts the server and creates your admin account. At the end it prints the address to enter in the apps.
The server lives in /opt/nightwire. Its settings are in /opt/nightwire/.env; keep that file private.
Domain, IP address or proxy
| Choice | Use it when | HTTPS |
|---|---|---|
| 1 · Domain | You have a name like chat.example.com pointing to the server (an A record). | Free Let's Encrypt certificate, renewed automatically. |
| 2 · IP address | No domain. People type the IP, and a port if you pick one other than 443. | Public IP: free Let's Encrypt certificate for the IP (needs port 80). Private or LAN IP: the server's own certificate, which the apps trust once. |
| 3 · Behind a proxy | You already run nginx, Caddy or Apache on ports 80/443 and want Nightwire behind it. | Handled by your web server. Forward traffic, including WebSockets, to the local port the installer shows. |
Example nginx settings for option 3
location / {
proxy_pass http://127.0.0.1:8080;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_set_header Host $host;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto https;
client_max_body_size 26m;
}
After installing
- Open the app (or the server's address in a browser) and sign in with your admin account.
- Open Settings → Administration to name your workspace, add a logo and colors, and choose who can join: invite only, anyone, or nobody.
- Create channels and invite people. Each invite is a link or code you can send.
- Optionally make trusted people operators (they moderate the whole server) or channel moderators (they moderate one channel).
Managing the server
The nightwire command manages everything. Run it as root on the server:
| Command | What it does |
|---|---|
nightwire status | Version, address, and whether every part is running |
nightwire info | The address to use in the apps and the certificate type (with its fingerprint if it's the server's own) |
nightwire logs | Live logs (Ctrl+C to stop) |
nightwire start / stop / restart | Start, stop or restart the server |
nightwire update | Install the newest server version (makes a backup first) |
nightwire backup | Save all messages, users and files to /opt/nightwire/backups |
nightwire restore <file> | Restore a backup (replaces everything currently on the server) |
nightwire admin list | List admin accounts |
nightwire admin create <user> | Create another admin |
nightwire admin reset-password <user> | Set a new password for an account (e.g. a locked-out admin) |
nightwire tls ip / tls selfsigned | Switch an IP-address server between a Let's Encrypt and its own certificate |
nightwire push status | Check push notifications |
Running the installer again on an installed server never touches your data; it only offers to start the server.
Backups and updates
- Run
nightwire backupregularly, or add it to cron, and copy the files in/opt/nightwire/backupsto another machine. nightwire updatealways backs up before updating. Your settings, certificates and data are kept.- The apps update themselves. Windows and Android get new versions from nightwire.chat, whichever server they're connected to.
# example: back up every night at 03:30
30 3 * * * /usr/local/bin/nightwire backup >/dev/null 2>&1
Push notifications
Android phones get messages even when the app is closed. Your server encrypts each notification for the receiving phone and hands it to the Nightwire push relay, which forwards it through Google's push service. The relay and Google only ever see sealed data: no message text, names or chat titles.
There's no Firebase account or setup needed on your side. It's on by default. Turn it off with nightwire push off; phones then only get messages while the app is open.
Troubleshooting
The app says it can't reach the server
- Check the address and port with
nightwire info. - Make sure the port is open in your cloud provider's firewall (security group) and in
ufw, if you use it. - See whether everything is running:
nightwire status.
The certificate didn't come through
- Domain: its DNS A record must point to this server, and ports 80 and 443 must be reachable from the internet.
- IP address: Let's Encrypt checks the server on port 80. If another program uses port 80, the installer uses the server's own certificate instead. Switch later with
nightwire tls ip.
Notifications arrive late on Android
See the battery note under Android.
Forgot the admin password
sudo nightwire admin reset-password <username>