Skip to content

HTTPS

By default Monica and the MCP server listen on this machine only: Monica on 127.0.0.1:8080 and the MCP server on 127.0.0.1:7011 (MONICA_BIND and MCP_BIND in .env). From elsewhere, an SSH tunnel reaches them:

ssh -L 8080:127.0.0.1:8080 -L 7011:127.0.0.1:7011 user@server

For a real address, the installer offers four options. Each puts Monica at the domain's root and the MCP server at /mcp on the same domain.

Option Needs Address
Caddy A domain pointing at the server, ports 80 and 443 open https://<domain>, with a Let's Encrypt certificate
Tailscale A Tailscale auth key https://<name>.<tailnet>.ts.net, private to the tailnet
Cloudflare Tunnel A domain on Cloudflare and a tunnel token https://<domain>, no open ports
An existing reverse proxy The proxy already running on the server Its domain

The installer sets COMPOSE_PROFILES (which of caddy, tailscale or cloudflare starts) and APP_URL. Monica builds its links from APP_URL, so it has to match the address people use.

Caddy

Set COMPOSE_PROFILES=caddy, DOMAIN and ACME_EMAIL, and APP_URL=https://<domain>. Caddy gets and renews the certificate; its configuration is config/Caddyfile.

Tailscale

Set COMPOSE_PROFILES=tailscale, TS_AUTHKEY (admin console → Settings → Keys) and optionally TS_HOSTNAME (default monica). The installer reads the machine's tailnet name once it has joined and sets APP_URL to it. HTTPS must be enabled for the tailnet (admin console → DNS → HTTPS Certificates). The routes are in config/ts-serve.json.

Cloudflare Tunnel

Set COMPOSE_PROFILES=cloudflare and CF_TUNNEL_TOKEN (Zero Trust → Networks → Tunnels), and APP_URL=https://<hostname>. The tunnel's public hostname routes are set in Cloudflare: /mcp* to http://monica-mcp:8080, and everything else to http://monica:80.

An existing reverse proxy

Point it at MONICA_BIND for Monica and at MCP_BIND for /mcp and /.well-known/oauth-protected-resource, and set APP_URL to its address. For example, with Caddy:

monica.example.com {
    @mcp path /mcp /mcp/* /.well-known/oauth-protected-resource
    reverse_proxy @mcp 127.0.0.1:7011
    reverse_proxy 127.0.0.1:8080
}