Skip to content
Niftyhelp 2026.10.1-beta.1 Support

Beta This is the help for Nifty 2026.10.1-beta.1, which isn't released yet. Help for the current release

Behind a proxy

Put Caddy, nginx or another proxy in front of Nifty.

On this page

Let the proxy handle HTTPS and pass requests to Nifty on 127.0.0.1:4000, its default. Tell Nifty two things in /etc/nifty.env:

NIFTY_ORIGIN=https://notes.example.com
NIFTY_TRUSTED_PROXIES=127.0.0.1
  • NIFTY_ORIGIN is the address you open Nifty at. Always set it: Nifty answers only to that name, and a new server's setup trusts requests from this machine without it.
  • NIFTY_TRUSTED_PROXIES names the proxy, so Nifty sees each visitor's address. Without it, every visitor counts as the proxy, so one visitor hitting a rate limit (too many sign-in attempts, say) blocks everyone. It takes addresses or CIDRs, comma separated.

Then sudo systemctl restart nifty. install.sh --origin https://notes.example.com writes both for you.

Caddy

Caddy gets its own certificate and redirects http://:

notes.example.com {
	reverse_proxy 127.0.0.1:4000
}

nginx

server {
    listen 443 ssl;
    server_name notes.example.com;
    # ssl_certificate and ssl_certificate_key here

    client_max_body_size 51m;
    proxy_read_timeout 120s;

    location / {
        proxy_pass http://127.0.0.1:4000;
        proxy_set_header Host $host;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
    }
}
  • client_max_body_size: documents can be 50 MB; nginx refuses anything over 1 MB by default.
  • proxy_read_timeout: an AI reply can take up to 90 seconds.
  • Redirect http:// to HTTPS in a second server block.

A proxy on another machine

Set NIFTY_LISTEN to an address the proxy can reach (10.0.0.5:4000), name the proxy in NIFTY_TRUSTED_PROXIES, and pass the original Host header through. Keep that port closed to everything else: traffic between them is plain HTTP.

Menu

2026.10.1-beta.1Contact support