Server settings
This page is for the administrator. Most of it is about the Server page of the management page. Two settings that people look for there are on other pages, and this page says where.
Where the server listens
A new installation listens on 127.0.0.1, port 8765. That means this machine only: a browser or an AI client on another machine cannot reach it.
To change it:
- Open Server.
- Choose a Bind address:
- 127.0.0.1 - this machine only;
- 0.0.0.0 - every interface, so other machines can reach it;
- A specific address..., then type it in Address to bind.
- Change the Port if you need to.
- Press Save server settings.
- Stop the server and start it again.
A restart is needed
The bind address and the port take effect the next time the server starts. Everything else on this page takes effect at once.
The heading at the top of the page shows what the running server is really listening on, with This machine only or Reachable from the network beside it. If the server was started with --host or --port, the page says so: the fields then show what is saved, not what is running.
Before you open it to the network
DANGER
The server itself speaks plain HTTP. On anything but this machine, plain HTTP sends passwords and tokens across the network where others can read them.
When the server is reachable from the network and has no HTTPS address, Overview warns you, "Reachable from the network without HTTPS", and the Server page says the same in its own words.
Put HTTPS in front of it. The usual way is a reverse proxy on the same machine, which holds the certificate and passes requests on to the server. Then tell the server its HTTPS address, below.
The public address
The public address is the address people and AI clients use to reach the server. Set it when they reach it through a name or a reverse proxy.
- Open Server.
- Under Public address, type the address in Public URL, such as
https://ads.example.com. - Press Save server settings.
The server then uses that address everywhere it has to name itself:
- the MCP endpoint and the ready-made commands on MCP tokens and Overview;
- the redirect addresses that you register with Google, Meta and LinkedIn.
Under the field the page shows the address clients currently connect to.
Why it should be HTTPS
- Passwords and tokens. See the warning above.
- Signing in to the platforms. After you sign in at Google, Meta or LinkedIn, the platform sends your browser back to the server. Each of them accepts a plain HTTP address only for the machine itself, and HTTPS for anything else. So people on other machines can connect their accounts only when the public address starts with
https://. Until then, an account can be connected from a browser on the server's own machine. The connection pages say so when it applies: see Google, Meta and LinkedIn. - Images from your library to Instagram. Instagram does not take an image upload. It fetches the image from an address, so the server has to be reachable at a public HTTPS address for an image from your Media page to be posted to Instagram. Without one, such a post is refused with that reason. See Media.
TIP
If you change the public address after registering redirect addresses with the platforms, register the new ones too. The Google Ads API, Meta app and LinkedIn app pages show the exact address to register.
Read-only mode
Read-only mode refuses every change, for everyone, whatever each user is allowed. Reports and figures still work.
The switch is on Safety limits, not on Server:
- Open Safety limits.
- Under Read-only server, tick Refuse every change.
- Press Save read-only setting.
- Stop the server and start it again.
It takes effect at the next start. While it is on, Overview says "The server is read-only", and the tools that make changes are not offered to AI clients at all.
A few things still work in read-only mode because they change nothing on a platform, such as adding a file to the media library or watching an account on History.
To give one person read-only access, leave this off and untick May write for that user instead: see Users and access.
Folders
The server reads and writes files in a few folders. Two of them it makes itself; the other two are closed until you name them.
The media library
Files that people upload on the Media page are kept in a folder named media beside the executable. There is nothing to set. The largest upload and how long a file is kept are on Safety limits. See Media.
Media folders
A media folder is a folder on the server from which an AI client may take an image or a video by its path, which is useful when the AI client runs on the same machine. None is open until you name one, and the setting is on Meta app, under Media folders, not on Server. Name a folder that holds only what may be posted. See Media.
The reports folder
A scheduled report that is kept as a file is written to a folder named reports beside the executable, in a folder of its own for each person. There is nothing to set. See Scheduled reports.
Data folders
A data folder is a folder on the server from which a file of customer records may be read, for the tools that send conversions or a customer list to an advertising platform. None is open until you name one:
- Open Server.
- Under Data folders, type one folder on each line.
- Press Save folders.
It takes effect at once. Name a folder that holds only files meant for upload: never a whole drive, a home folder, a media folder or a folder inside one. Each of those tools also has its own switch, off by default. Read Contact data before you open one.
TIP
The media library and the reports folder can be moved, and a media or data folder can be named, with environment variables instead. A folder set that way wins over what is saved on the page. Settings lists them.
History
With History on, the server reads by itself, on a timer, the accounts that each person asked it to watch, and keeps figures that the platforms drop. It is off by default.
- Open Server.
- Under History, tick Let the server watch accounts by itself.
- Set Keep figures for (days). It starts at 800; empty keeps them for good.
- Set Accounts one person may watch. It starts at 20; empty means no limit.
- Press Save history settings.
It takes effect at once. The server only reads and keeps counts; it never posts. It does store what it reads, which your own privacy policy has to say before you switch it on. See History and retention.
Where settings are saved
What you save on these pages goes into config.json, beside the executable. An environment variable with the same meaning wins over the file, and the page then says so beside the field where it matters. See Install and Settings.