Install guide

Set up Nightwire

Install the app and connect to your crew's server, or run your own server in about five minutes.

Windows

  1. Download the installer from the download page.
  2. Run it. Nightwire installs for your user account only, so it doesn't need administrator rights.
  3. If Windows shows “Windows protected your PC”, click More info → Run anyway. This appears for new apps that Windows doesn't know yet.
  4. Nightwire opens, and from then on it lives in the tray next to the clock. Closing the window keeps it running in the tray so you still get notifications. Use Quit in the tray menu to close it completely.

Updates download in the background, and Nightwire asks once to restart when a new version is ready. You can turn Launch at startup on or off in Settings.

Android

  1. On your phone, open the download page and tap Download APK.
  2. Open the downloaded file. Android asks to allow installs from your browser: tap Settings → Allow from this source, go back, and tap Install.
  3. Open Nightwire and allow notifications when asked. Without that permission, messages can't alert you while the app is closed.

When a new version is out, a banner appears in the app. Tap Update: it downloads inside the app, shows its progress, and opens Android's installer. The first time, Android asks you to allow Nightwire to install updates.

Some phones (Xiaomi, Huawei, some Samsung models) stop apps in the background to save battery. If notifications arrive late, set Nightwire's battery usage to Unrestricted in the app's Android settings.

iPhone, iPad and web

Every Nightwire server includes the web app. Open the server's address in a browser and sign in. It works in Chrome, Edge, Firefox and Safari on any computer.

Add it to your iPhone or iPad home screen

  1. Open the server's address in Safari and sign in.
  2. Tap the Share button, then Add to Home Screen.
  3. Nightwire now opens full-screen from its own icon, like an app.

Connecting to a server

Nightwire has no central service: every team or community runs its own server. The first screen asks for:

FieldWhat to enter
Server addressThe domain or IP address your admin gave you, e.g. chat.example.com or 203.0.113.24
PortOnly if your admin gave you one (e.g. 8443). Leave it empty otherwise.

The app remembers the server, even after you sign out. To switch servers, sign out and tap Change server.

“Trust this server?”

Servers on a private network or without a public certificate use their own certificate. The app shows its fingerprint once and asks you to trust it. Your admin can check that it matches with nightwire info on the server. After that the app only accepts that exact certificate, so nobody can impersonate the server later.

Accounts

  • Invite only (default): use the invite link or code from your admin and tap Got an invite?
  • Open: the sign-in screen shows Create account.
  • Turn on two-factor sign-in in Settings → Security with any authenticator app. Keep your recovery codes somewhere safe.

Server: before you start

NeedDetails
A Linux serverUbuntu 22.04 or 24.04, or Debian 12, recommended. 64-bit Intel/AMD or ARM. A small cloud VPS or a machine on your own network works.
Memory and disk1 GB RAM minimum, 2 GB recommended. 10 GB of disk plus room for the files people share.
Root accessYou run the installer with sudo.
Open portsWith a domain: 80 and 443. With an IP address: the port you choose (443 by default), plus 80 for a free certificate on a public IP.
DockerInstalled for you if it's missing. An existing Docker installation is never replaced; it just needs the Compose plugin.
A domain (optional)Not required. A plain IP address works, with HTTPS.

Run the installer

Connect to your server over SSH and run:

curl -fsSL https://get.nightwire.chat | sudo bash

It asks a few questions, then sets everything up in about three minutes:

  1. How people will connect: a domain, the server's IP address, or through a web server you already run (see below).
  2. Workspace name: shown on the sign-in screen, e.g. “Night Watch”.
  3. Your admin account: username, full name and password.

It then installs Docker if needed, generates every password and secret key, gets an HTTPS certificate, starts the server and creates your admin account. At the end it prints the address to enter in the apps.

The server lives in /opt/nightwire. Its settings are in /opt/nightwire/.env; keep that file private.

Domain, IP address or proxy

ChoiceUse it whenHTTPS
1 · DomainYou have a name like chat.example.com pointing to the server (an A record).Free Let's Encrypt certificate, renewed automatically.
2 · IP addressNo domain. People type the IP, and a port if you pick one other than 443.Public IP: free Let's Encrypt certificate for the IP (needs port 80). Private or LAN IP: the server's own certificate, which the apps trust once.
3 · Behind a proxyYou already run nginx, Caddy or Apache on ports 80/443 and want Nightwire behind it.Handled by your web server. Forward traffic, including WebSockets, to the local port the installer shows.

Example nginx settings for option 3

location / {
    proxy_pass http://127.0.0.1:8080;
    proxy_http_version 1.1;
    proxy_set_header Upgrade $http_upgrade;
    proxy_set_header Connection "upgrade";
    proxy_set_header Host $host;
    proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
    proxy_set_header X-Forwarded-Proto https;
    client_max_body_size 26m;
}

After installing

  1. Open the app (or the server's address in a browser) and sign in with your admin account.
  2. Open Settings → Administration to name your workspace, add a logo and colors, and choose who can join: invite only, anyone, or nobody.
  3. Create channels and invite people. Each invite is a link or code you can send.
  4. Optionally make trusted people operators (they moderate the whole server) or channel moderators (they moderate one channel).

Managing the server

The nightwire command manages everything. Run it as root on the server:

CommandWhat it does
nightwire statusVersion, address, and whether every part is running
nightwire infoThe address to use in the apps and the certificate type (with its fingerprint if it's the server's own)
nightwire logsLive logs (Ctrl+C to stop)
nightwire start / stop / restartStart, stop or restart the server
nightwire updateInstall the newest server version (makes a backup first)
nightwire backupSave all messages, users and files to /opt/nightwire/backups
nightwire restore <file>Restore a backup (replaces everything currently on the server)
nightwire admin listList admin accounts
nightwire admin create <user>Create another admin
nightwire admin reset-password <user>Set a new password for an account (e.g. a locked-out admin)
nightwire tls ip / tls selfsignedSwitch an IP-address server between a Let's Encrypt and its own certificate
nightwire push statusCheck push notifications

Running the installer again on an installed server never touches your data; it only offers to start the server.

Backups and updates

  • Run nightwire backup regularly, or add it to cron, and copy the files in /opt/nightwire/backups to another machine.
  • nightwire update always backs up before updating. Your settings, certificates and data are kept.
  • The apps update themselves. Windows and Android get new versions from nightwire.chat, whichever server they're connected to.
# example: back up every night at 03:30
30 3 * * * /usr/local/bin/nightwire backup >/dev/null 2>&1

Push notifications

Android phones get messages even when the app is closed. Your server encrypts each notification for the receiving phone and hands it to the Nightwire push relay, which forwards it through Google's push service. The relay and Google only ever see sealed data: no message text, names or chat titles.

There's no Firebase account or setup needed on your side. It's on by default. Turn it off with nightwire push off; phones then only get messages while the app is open.

Troubleshooting

The app says it can't reach the server

  • Check the address and port with nightwire info.
  • Make sure the port is open in your cloud provider's firewall (security group) and in ufw, if you use it.
  • See whether everything is running: nightwire status.

The certificate didn't come through

  • Domain: its DNS A record must point to this server, and ports 80 and 443 must be reachable from the internet.
  • IP address: Let's Encrypt checks the server on port 80. If another program uses port 80, the installer uses the server's own certificate instead. Switch later with nightwire tls ip.

Notifications arrive late on Android

See the battery note under Android.

Forgot the admin password

sudo nightwire admin reset-password <username>