The file manager that runs on your customers' own storage
Embed by iframe or SDK, mint a scoped JWT, and each tenant's files live in their own S3, R2, SFTP, or local disk — never copied into a database you have to run, secure, or pay for.
See it in action
Every overwrite keeps a prior version, restorable anytime
{ "event": "upload",
"file": "invoice.pdf" } Signed HTTP POST to your endpoint on file events — Zapier, Make, n8n
Extract text from images and PDFs, returned in the API response
Redact SSNs, card numbers and secrets before a file is ever stored
Every upload scanned before it's stored — ClamAV or your own cloud key
Sign files with verifiable Content Credentials (C2PA provenance)
One-way sync to a second disk — local, S3, R2 or SFTP
Export the full audit trail as NDJSON or CSV, including archived logs
Sign in with your own OIDC identity provider — groups map to permissions
Your customers' files stay in your customers' buckets
FluxFiles is the embeddable file manager where each tenant connects their own S3/R2 bucket — and you never store their data or their credentials.
-
Data sovereignty
Files live in the customer's own cloud account and region — built for GDPR, compliance, and enterprise procurement.
-
Zero data, zero creds at rest
Bucket credentials are AES-256-GCM encrypted inside the JWT and decrypted only at runtime — never written to a database or a log.
-
Storage cost that scales to zero
Storage and egress are billed to each customer, not to you. No storage bill that grows with your user base.
-
Stateless & embeddable
No central database. Drop the picker into any app by iframe or SDK; your backend mints a scoped, short-lived token.
How it works: your app encrypts the tenant’s bucket credentials into a short-lived JWT (HKDF-SHA256 + AES-256-GCM). FluxFiles decrypts them only to run the requested operation.
One token per tenant — each with its own rules
FluxFiles is stateless: the JWT your backend mints is the tenant's config. Storage path, file-size limit, quota, file count, allowed types, permissions — all enforced server-side. No per-tenant config files, no restarts.
// Your backend, per request — the token IS the tenant's config.
import { createToken } from '@fluxfiles/node';
const claims = tenant.plan === 'pro'
// 100 MB/file · any type · 50 GB · unlimited files · own bucket
? { disks: ['s3'], maxUploadMb: 100, allowedExt: null,
maxStorageMb: 51200, maxFiles: 0 }
// 5 MB/file · images only · 500 MB · 200 files
: { disks: ['local'], maxUploadMb: 5, allowedExt: ['jpg','png','webp'],
maxStorageMb: 500, maxFiles: 200 };
const token = createToken({
secret: process.env.FLUXFILES_SECRET,
userId: tenant.id,
prefix: `tenant_${tenant.id}/`, // isolates each tenant's files
perms: ['read', 'write', 'delete'],
...claims,
}); Pair it with BYOB to put each tenant on their own bucket.
Built for teams that ship file features
If your product needs uploads, FluxFiles drops in — without making you the landlord of your customers' data.
SaaS & multi-tenant apps
Give every customer a file manager on their own bucket. Per-tenant token scoping and data sovereignty are built in.
Agencies & freelancers
Ship a polished media library to each client without standing up storage infrastructure per project.
CMS & editor integrations
Drop a media picker into CKEditor, TinyMCE, Summernote, or your own editor via the iframe SDK.
Internal tools & dashboards
Add uploads, previews and audited file operations to admin panels in an afternoon.
FAQ
Frequently asked questions
Is FluxFiles free and open source?
Where are my files stored?
Can I embed it in my existing app or editor?
How secure is it against common attacks?
Ready to embed FluxFiles?
Add a production-ready file manager to your app in minutes — no framework lock-in, MIT licensed.