Complete registry access and bundle extraction first. Commands use Bash (Git Bash on Windows).
For an SSO-only deployment, provision the license and first administrator mapping before startup using Authentication. Otherwise use the local administrator bootstrap below.
Install Enterprise with Docker Compose
a. Configure .env
cd compose
cp .env.example .env
Minimum required edits:
SESSION_SECRET=replace_with_a_long_random_value # openssl rand -base64 32
DB_PASSWORD=replace_with_secure_password
ADMIN_EMAIL=admin@your-company.com
ADMIN_PASSWORD=ChangeThisSecurePassword123!
APP_URL=https://tokentimer.your-domain.com
API_URL=https://tokentimer.your-domain.com
If you run on plain http://localhost, set
SESSION_COOKIE_SECURE_LOCALHOST_OVERRIDE=true so the browser persists the
session cookie. Do not enable this in production. Put HTTPS in front instead.
For every other variable (SMTP, workers, proxy hops, license grace period),
see the Configuration reference and the annotated
compose/.env.example in the bundle.
b. Supply the license (pick one or combine)
- Set
TT_LICENSE_KEYin.envto the raw JWT (recommended for automation), and/or - Sign in after first boot and import the JWT under System Settings > License, and/or
- For a file on disk: copy
<your-id>.license.keytocompose/license.keyand start with the optional overlay file:
docker compose -f docker-compose.yml -f docker-compose.license-file.yml up -d
If you use only the dashboard import, you can start with plain
docker compose -f docker-compose.yml up -d and no license file on disk. How
the three sources are resolved against each other is documented in the
Configuration reference.
c. Start the stack
docker compose -f docker-compose.yml up -d
Compose pulls these images from harbor.tokentimer.ch/tokentimer-enterprise/
automatically:
tokentimer-enterprise-api:<version>(also runs the one-shot database migrations job)tokentimer-enterprise-worker:<version>(6 worker services: discovery, delivery, weekly digest, auto-sync, endpoint check, certops maintenance)tokentimer-enterprise-dashboard:<version>
d. Verify
curl http://localhost:4000/health
docker compose -f docker-compose.yml ps -a
docker compose -f docker-compose.yml logs --tail 100 migrations api
You should see: the health endpoint responding, and the dashboard login page in the browser.
Log in with ADMIN_EMAIL / ADMIN_PASSWORD. Auto-sync providers (AWS,
Azure, GCP, Vault) appear active in the import modal once your license
entitlements load. If a provider stays greyed out, open
System Settings > License (signed-in admins only; GET /api/license/status
is not available without a session).
Check the effective license in System Settings → License, then follow First asset and alert check. See configuration for secrets and deployment settings.