An open-source household finance manager designed to replace spreadsheets with a structured, long-term solution.
- About
- Why Plinto?
- What does Plinto do?
- Is Plinto for you?
- Getting Started
- Upgrading
- Self-Hosting
- Your data is yours
- What is not here yet
- Versions and releases
- Contributing
- Code of Conduct
- Security
Plinto is an open-source household finance manager you run yourself. It keeps accounts, movements, recurring rules, monthly obligations, debts and credit cards for one or more households, and it stores nothing anywhere you do not control.
It is free software under AGPL-3.0, and it is used daily to manage a real household's finances β the features here exist because somebody needed them, not because a roadmap called for them.
Most households track money in a spreadsheet until the spreadsheet stops answering the questions they actually have: what do we owe this month, what did that card cost us, is this expense normal. Plinto is that spreadsheet given structure β and given somewhere to live that is not a vendor's server.
- β¨ Practicality - Real-world solutions for real-world problems
- π Clarity - Intuitive design and transparent processes
- ποΈ Long-term maintainability - Built to last and evolve
It is also, openly, a project built to be built well: the decisions behind it are recorded as ADRs and the features as PRDs, so anyone can see why it is shaped the way it is.
| Area | What you get |
|---|---|
| π Households | Several households under one login, with invited members and per-household roles |
| π³ Accounts | Bank, cash and liability accounts, each in its own currency |
| π Movements | Income, expenses, transfers between accounts including across currencies, and categories. Filtered and paginated on the server |
| π Recurring rules | Define a monthly movement once and let it record itself |
| π Obligations | What the household owes this month, settled by recording the payment or linking a movement already in the ledger |
| π¦ Debts and credit | Loan schedules, what is owed per lender, card statements per cutoff, revolving balance and available credit |
| π Reports | Spending by category |
| π Sign-in | Any OpenID Connect provider. Plinto stores no passwords |
The full list for the current release is in the changelog. What is deliberately absent is in What is not here yet.
Every screen below is the example household β the one Plinto can build for you from Settings in a click. The numbers are invented, which is why the banner across the top says so.
Open-source personal finance is a crowded shelf, and the honest answer is that Plinto is not the right pick for everyone. Three assumptions run through it, and if any of them is wrong for you, something else will serve you better.
It assumes a household, not a person. Several people share the same accounts, obligations and categories, under one login each, with roles that decide who can see and who can change. One account can belong to more than one household β your own and your parents' β and switch between them without signing out. If you are tracking only your own money, that structure is overhead you do not need.
It assumes what you owe matters as much as what you spent. Obligations are a first-class engine here, not a tag on a transaction: what is due this month, what is still pending, what a payment settled. Most tools model spending well and owing poorly. If your question is "where did the money go", other tools answer it at least as well. If your question is "what do we owe and did we pay it", that is what this was built for.
It assumes you already have an identity provider. Plinto stores no passwords at all β sign-in is delegated to Auth0, Google, Keycloak, Authentik or anything else that speaks standard OpenID Connect. That is a real barrier if you just want a container and a login form, and a real advantage if you already run single sign-on for your household or your homelab.
Worth looking at instead: Firefly III if you want a mature, feature-dense personal finance manager for one person; Actual Budget if what you want is envelope budgeting; Ghostfolio if you are tracking investments rather than household cash flow.
You need Docker Compose v2 and an OpenID Connect provider you control a client registration on β Auth0, Google, Keycloak, Authentik, or anything else that speaks standard OIDC. Plinto is the client; it has no built-in identity provider and stores no passwords.
git clone https://github.com/victorolave/plinto.git
cd plinto
cp deploy/self-host.env.example .envFill in every REPLACE_ME in .env, point PLINTO_PUBLIC_URL at how you will
reach the instance, and add your provider's credentials. Then:
docker compose up -d
docker compose ps # wait for api, web and postgres to report "healthy"That pulls published images from GitHub Container Registry, so there is no
build to sit through. Pin a version in production with PLINTO_VERSION=0.2.0
in your .env; without it you get latest. To build from source instead, add
--build.
Open the URL you configured. docs/delivery/self-host.md
has the full guide, including the two things that trip people up: the OIDC
redirect URI must match character for character, and cookies on plain HTTP need
COOKIE_SECURE turned off.
Do not start from an empty screen. From Settings, create the example household: a populated set of accounts, movements, obligations and a credit line you can click through, and delete in one action when you are done. It is the fastest way to see whether Plinto fits how your household thinks before you type in a single real number.
β οΈ This is a0.xrelease. It runs a real household's finances daily, but the HTTP API is still gaining endpoints and an upgrade between minor versions may ask you for a manual step. See versioning.
| Runtime | Docker Compose v2 β four containers: nginx, web, API, PostgreSQL 16 |
| Download | 167 MB for the API image, 114 MB for the web image, compressed |
| Architectures | linux/amd64 and linux/arm64, so a Raspberry Pi or an ARM VPS works |
| Identity | An OpenID Connect provider you control a client registration on |
Memory and CPU figures are deliberately absent: nobody has benchmarked a deployment yet, and a number invented for a README is worse than no number. If you run Plinto somewhere small, open an issue and say what it needed β that is a genuinely useful contribution.
docker compose pull
docker compose up -dDatabase migrations run on their own, in the migrate service, before the API
starts. Read the changelog entry for the version you are moving
to first: while Plinto is 0.x, an upgrade that needs a manual step says so in
the first line of its entry.
Back up before a version that touches the database:
./deploy/backup.shPlinto ships as Docker images with a self-host docker-compose.yml (nginx +
web + api + postgres, per ADR 0005).
See docs/delivery/self-host.md for the full
guide, including the OIDC provider setup and a gotcha around cookies on
plain HTTP. Setting up Google or Auth0 specifically? See
docs/delivery/oidc-providers.md.
- In-app export. The household owner can download everything from Settings β the whole household as one JSON file, or just the transaction ledger as CSV. No support ticket, no waiting.
- Backup and restore. Self-hosters get two scripts,
deploy/backup.shanddeploy/restore.sh, that wrap Postgres's ownpg_dump/pg_restore. See docs/delivery/self-host.md. - What is missing, plainly. You can take your data out; you cannot yet feed it back in through the app. Restoring an export means the database-level script above, which restores a whole database rather than one household. Import is the next thing on the roadmap.
Four things are deliberately absent from this release, and the reasoning for each is written down in the roadmap:
- Importing data back in β export exists, import does not.
- Revolving debt in the debt summary β the figure exists on the credit board, just not beside the other two.
- Reports beyond spending by category β no month-over-month, no comparisons, nothing per account.
- A consolidated multi-currency figure β two correct numbers rather than one invented one, because a combined total needs exchange rates Plinto does not store.
There is no billing code in this repository today, and Community is self-hosted and free. A hosted offering, if it happens, is a separate product and does not change what Community delivers.
Plinto follows Semantic Versioning starting at v0.1.0,
where MAJOR means the upgrade breaks an existing installation. While the
version is 0.x, a breaking change can arrive in a minor bump, and the
changelog says so in the first line of the entry when it does.
Contributions are welcome β code, documentation, design or plain feedback from running it. The roadmap is the honest list of what is missing and why, and it is a reasonable place to start looking for something to take on.
See the Contributing Guidelines before opening a pull request.
On support: this is maintained by one person alongside a job. Issues get read and answered as time allows, with no service level attached to that. Being self-hosted and AGPL means you are never blocked waiting for me β the code and your data are both yours.
This project adheres to the Contributor Covenant Code of Conduct version 3.0. By participating in this project, you are expected to uphold this code. Please report unacceptable behavior to victorolave1131@gmail.com.
Plinto holds financial records, so a vulnerability here is not an
inconvenience. Report one privately, never in a public issue: use the
Report a vulnerability button under the Security tab, or email
victorolave1131@gmail.com with SECURITY in the subject.
SECURITY.md says what is in scope, what to expect, and how long "a while" actually is for a project maintained by one person.
Copyright (c) 2025 Victor Olave.
Plinto is free software, released under the GNU Affero General Public License v3.0 (AGPL-3.0-only). You may run, study, modify and redistribute it, including as a hosted service, provided that anyone who interacts with a modified version over a network can obtain its complete source code under the same license. See the LICENSE file for the full text.
The name Plinto and its logo are trademarks of the author and are not covered by the license. Forks and hosted deployments must not present themselves as Plinto or use the logo without permission.



