mrkeyoor.com_
Sat 03 Oct 15:38 UTC
Self-Hostedevaluationupdated 03 Oct 2026

DocsGPT review

DocsGPT is a self-hosted system for turning documents, websites, and connected business apps into searchable AI agents. It combines ingestion, cited answers, visual workflows, tools, access controls, a web app, widgets, an OpenAI-compatible API, and an MCP server in one project.

Verdict

Our DocsGPT run installed 279 packages and built in 12 seconds, but tests stopped during collection and pip-audit found 3 known vulnerabilities, so production adoption needs a dependency and test review first. The product is a strong fit when one self-hosted system must serve documents through agents, widgets, APIs, and MCP. For a single local knowledge base, choose a smaller tool.

We ran it

Lab card: what happened when we ran DocsGPTScreenshot of DocsGPT (app.docsgpt.cloud)
Install✓ · 130s279 packages · 787 MB
Build✓ · 12s
Tests✗ · 7sran, no count parsed
Known vulns3(pip-audit)
Repo2500 files~584,722 lines of source · 103.9 MB · 22 CI workflows · tests dir

Answers from our run

Does DocsGPT build from source?

Dependencies installed in 130 seconds (279 packages), and the build succeeded in 12 seconds. We cloned commit 3d392b6 into a clean Debian container with 3 CPUs and no project-specific setup.

Do DocsGPT's tests pass?

The test command failed in our container, and its output did not report a pass or fail count.

Does DocsGPT have known vulnerabilities in its dependencies?

pip-audit flagged 3 known advisories in the dependency tree at the time of our run.

Who should not use DocsGPT?

Developers who only need local PDF question answering: the 2,500-file repo contains agents, workflows, connectors, team controls, several deployment paths, and a frontend.

What are the alternatives to DocsGPT?

AnythingLLM, PrivateGPT, Haystack. Our DocsGPT run installed 279 packages and built in 12 seconds, but tests stopped during collection and pip-audit found 3 known vulnerabilities, so production adoption needs a dependency and test review first.

Setup3/5Quick installer exists, but our test collection stopped
Docs5/5Deployment, security, air-gap, API, and contributor guides
Community5/518,303 stars and active code, issue, and release work
Maturity4/5v0.21.0 has broad operations support; our audit found 3 advisories

Who it’s for

Teams that need document agents inside their own network or an air-gapped environment.
Platform owners who want one system for connectors, retrieval, workflows, access control, and model choice.
Product teams exposing the same knowledge through a web app, widget, OpenAI-compatible API, or MCP client.
Organizations prepared to operate PostgreSQL, Redis, workers, vector storage, files, and model credentials.

Who it’s NOT for

Developers who only need local PDF question answering: the 2,500-file repo contains agents, workflows, connectors, team controls, several deployment paths, and a frontend.
Teams with a zero-advisory release rule: pip-audit reported 3 known vulnerabilities in our installed environment.
Contributors expecting the first test command to collect cleanly: our run stopped because pytest_postgresql could not be imported.
Python-only teams avoiding frontend tooling: contributors also need Node.js 22 for the React interface.
Operators unwilling to own databases, queues, storage, model access, upgrades, backups, and security policy after installation.

Setup reality

Our sandbox installed commit 3d392b6 in 130 seconds, pulling 279 packages and using 787 MB. The build passed in 12 seconds. Tests exited with code 4 after 7 seconds, before the suite ran, because tests/conftest.py could not import pytest_postgresql. Pip-audit found 3 known vulnerabilities.

The packaged quickstart uses Docker and asks which users can reach the service and which model to use. A real deployment also needs PostgreSQL, Redis, worker processes, file and vector storage, plus cloud model credentials or a local inference server. Connectors, SSO, and external tools bring their own secrets.

Source contributors need Python 3.12 or newer, Node.js 22, uv, PostgreSQL server binaries, and Redis. The repo declares pytest-postgresql, but it was absent from the environment that reached collection in our run. The log does not explain why, so the result should not be turned into a dependency diagnosis.

DocsGPT earns its size when documents need a product surface

DocsGPT goes beyond a chat box over uploaded PDFs. A team can create agents with their own prompts, knowledge, models, and tools, then connect those agents in a visual workflow. Sources can come from files, websites, Google Drive, SharePoint, Confluence, GitHub, or S3. Answers cite their documents, and guardrails can flag or block secrets, personal data, prompt injection, and ungrounded output.

The same knowledge can appear in the built-in web app, an embeddable widget, an OpenAI-compatible /v1 API, webhooks, or an MCP server. Schedules can run agents without a user waiting in chat. This breadth makes sense for an internal support or research platform. It is excess machinery if your requirement is one folder, one model, and one user.

One command still starts a multi-service system

The README leads with a shell installer that checks for Docker, installs the docsgpt command, and runs docsgpt up. A local installation opens on port 7091. The CLI can show status, follow logs, upgrade, back up data, and stop the stack while keeping its state. Release 0.21.0 also added a one-port standalone Compose arrangement and an air-gapped deployment guide.

Behind that command sit an API, a worker, PostgreSQL, Redis, a vector store, and file storage. You also choose a cloud model provider or provide local inference through Ollama, vLLM, or another OpenAI-compatible server. The abstraction is useful, but it cannot decide retention, backups, network exposure, credential rotation, or model capacity for you. Read the security checklist before giving other people access.

What happened when we ran it

Our sandbox installed commit 3d392b6 in 130 seconds, adding 279 packages and occupying 787 MB on disk. The build succeeded in 12 seconds. The checkout itself contained 2,500 files, about 584,722 lines of source, and used 103.9 MB. We ran it in an unprivileged Debian container with 3 CPUs, 8 GB of RAM, Python 3.12, and no secrets.

The tests stopped after 7 seconds with exit code 4. Pytest was loading tests/conftest.py when Python raised ModuleNotFoundError: No module named 'pytest_postgresql'. No test cases ran, so there is no passed or failed test count to soften that result. The repository declares the plugin in its development group. Our log only establishes that the module was missing from the installed environment that reached collection.

Pip-audit reported 3 known vulnerabilities. The supplied measurement does not name the packages or severity, so claiming a direct exploit path would go beyond the evidence. It is still a release gate: resolve the audit against the exact deployment image, rerun it, and record why any accepted advisory cannot be reached through the service. The repo had 22 CI workflow files and a tests directory, though no root Dockerfile was detected.

Contributors need Node 22 and PostgreSQL binaries

The backend package supports Python 3.12 or newer. The React frontend uses Node.js 22, and contributors are expected to run its lint, test, and build commands separately. Backend tests use pytest-postgresql to start a temporary database cluster. The contribution guide says pg_ctl and initdb must be on the path, even if an ordinary development database already runs in Docker.

That is a credible contributor setup for a 584,722-line platform, but it is not a casual clone-and-test experience. End-to-end checks add PostgreSQL, Redis, a mock language model, the API, worker, and Vite frontend. Some scripts expect explicit database roles and an internal key. The documentation spells this out well. Our 7-second collection failure shows why those details need to be followed exactly.

Team controls distinguish it from a personal RAG app

DocsGPT includes OIDC single sign-on, SCIM provisioning, roles, teams, sharing rules, audit logs, and per-team token or spending quotas. Operators can add OpenTelemetry and use several vector backends, including pgvector, FAISS, Qdrant, Milvus, Elasticsearch, and MongoDB. The MIT license applies to the team features listed in the README.

Those controls make DocsGPT credible for shared use. They also increase the number of policies an owner must settle before launch. A connector can read business data. A REST tool or MCP server can act outside the document store. Sandboxed code and paired-device shell access expand the blast radius further. Start with a narrow agent, minimum permissions, and a model endpoint whose data policy you have reviewed.

October activity is high, with 122 open pull requests

GitHub showed 18,303 stars and a same-day push on October 3, 2026. Release 0.21.0 arrived on September 16 with air-gap work, installer changes, a one-port stack, and a fix for connector OAuth tokens crossing origins. The project was not sitting still when we checked it.

The 169 combined open items split into 47 issues and 122 pull requests. Several new pull requests and connector requests appeared on October 3 alone. That volume indicates active development and a meaningful review burden at the same time. DocsGPT is worth a pilot when its several access paths replace separate internal tools. Make the pilot prove clean test collection, an explained dependency audit, and recovery from a real backup before calling the platform ready.

Alternatives

ProjectWhat it isPick it when
AnythingLLM gh↗A local-first desktop and server app for document chat, agents, and shared workspaces.pick this instead when a desktop-friendly workspace matters more than DocsGPT's deployment and connector depth.
PrivateGPTAn API layer for private RAG, local models, tools, skills, and MCP use.pick this instead when you want a code-facing private AI backend without adopting DocsGPT's full product surface.
Haystack gh↗A Python framework for building custom retrieval pipelines and agent workflows.pick this instead when your team wants to design the application in code rather than operate a ready-made document platform.

What people are saying

  1. [github-trending] arc53/DocsGPT

Sources

  1. DocsGPT repository
  2. DocsGPT README
  3. DocsGPT contribution guide
  4. DocsGPT deployment documentation
  5. DocsGPT security checklist
  6. DocsGPT v0.21.0 release

More self-hosted reviews

glances · lunel · vodiwalker_panel · srs · FluxDown · life-recorder · the whole board →