Bring-your-own-storage · MIT Licensed

The file manager that runs on your customers' own storage

Embed by iframe or SDK, mint a scoped JWT, and each tenant's files live in their own S3, R2, SFTP, or local disk — never copied into a database you have to run, secure, or pay for.

4
Storage backends supported
0
Servers that see your files
MIT
Open source license
16
Languages supported
Live Preview

See it in action

FluxFiles desktop file manager with image thumbnails
Grid view with instant WebP thumbnails
FluxFiles browsing an S3 / R2 bucket with the local, S3 and SFTP disk switcher
Multi-cloud — S3 / R2 / SFTP, one UI
FluxFiles managing a remote VPS deploy directory over SFTP, same UI as the S3 bucket
Remote VPS over SFTP — no FTP client needed
Editing an nginx config file inside FluxFiles with syntax highlighting
Edit config files in place — no SSH, no FTP client
FluxFiles previewing a video inline in the detail panel
Video, audio and PDF preview without downloading
FluxFiles Bucket Doctor health checks for an S3 bucket with CORS and IAM remediation
Bucket Doctor — S3/R2 health checks + fixes
FluxFiles activity log of file operations
Activity log — kept in your own bucket
FluxFiles trash with restore and delete forever
Trash — restore or delete forever
FluxFiles free AI auto-tag panel generating searchable tags for an image
Free AI auto-tag — searchable tags generated on upload
FluxFiles responsive mobile file manager
Responsive on mobile
FluxFiles compliance readiness scorecard showing which safeguards are enabled
Compliance readiness scorecard — see which safeguards are on at a glance
Creating a FluxFiles share link with an expiry, a password and a download limit
Share a file — expiry, password, download cap
Creating a FluxFiles upload portal with a file limit, size cap and allowed file types
Upload portals — clients send files, no account
FluxFiles links panel listing shared links with views, downloads and revoke
Manage every link, revoke any of them
FluxFiles AI Vision panel removing the background from an image with your own vision API key
Background removal, upscale and smart-crop with your own vision key
How it works

Every overwrite keeps a prior version, restorable anytime

How it works
{ "event": "upload",
  "file": "invoice.pdf" }

Signed HTTP POST to your endpoint on file events — Zapier, Make, n8n

How it works

Extract text from images and PDFs, returned in the API response

FluxFiles legal hold panel blocking delete, rename and move with a reason and audit trail
Legal hold — blocks delete, rename and move until released, with a full audit trail
How it works

Redact SSNs, card numbers and secrets before a file is ever stored

How it works

Every upload scanned before it's stored — ClamAV or your own cloud key

How it works

Sign files with verifiable Content Credentials (C2PA provenance)

How it works

One-way sync to a second disk — local, S3, R2 or SFTP

How it works

Export the full audit trail as NDJSON or CSV, including archived logs

How it works

Sign in with your own OIDC identity provider — groups map to permissions

The moat · BYOB

Your customers' files stay in your customers' buckets

FluxFiles is the embeddable file manager where each tenant connects their own S3/R2 bucket — and you never store their data or their credentials.

  • Data sovereignty

    Files live in the customer's own cloud account and region — built for GDPR, compliance, and enterprise procurement.

  • Zero data, zero creds at rest

    Bucket credentials are AES-256-GCM encrypted inside the JWT and decrypted only at runtime — never written to a database or a log.

  • Storage cost that scales to zero

    Storage and egress are billed to each customer, not to you. No storage bill that grows with your user base.

  • Stateless & embeddable

    No central database. Drop the picker into any app by iframe or SDK; your backend mints a scoped, short-lived token.

Your SaaS app
scoped JWT (encrypted creds)
FluxFiles
decrypts at runtime only
Tenant A
own bucket
Tenant B
own bucket
Tenant C
own bucket

How it works: your app encrypts the tenant’s bucket credentials into a short-lived JWT (HKDF-SHA256 + AES-256-GCM). FluxFiles decrypts them only to run the requested operation.

Multi-tenant

One token per tenant — each with its own rules

FluxFiles is stateless: the JWT your backend mints is the tenant's config. Storage path, file-size limit, quota, file count, allowed types, permissions — all enforced server-side. No per-tenant config files, no restarts.

// Your backend, per request — the token IS the tenant's config.
import { createToken } from '@fluxfiles/node';

const claims = tenant.plan === 'pro'
  // 100 MB/file · any type · 50 GB · unlimited files · own bucket
  ? { disks: ['s3'],    maxUploadMb: 100, allowedExt: null,
      maxStorageMb: 51200, maxFiles: 0 }
  // 5 MB/file · images only · 500 MB · 200 files
  : { disks: ['local'], maxUploadMb: 5,   allowedExt: ['jpg','png','webp'],
      maxStorageMb: 500,   maxFiles: 200 };

const token = createToken({
  secret: process.env.FLUXFILES_SECRET,
  userId: tenant.id,
  prefix: `tenant_${tenant.id}/`,   // isolates each tenant's files
  perms:  ['read', 'write', 'delete'],
  ...claims,
});
prefix disks / BYOB max_upload max_storage max_files allowed_ext perms

Pair it with BYOB to put each tenant on their own bucket.

Who it's for

Built for teams that ship file features

If your product needs uploads, FluxFiles drops in — without making you the landlord of your customers' data.

SaaS & multi-tenant apps

Give every customer a file manager on their own bucket. Per-tenant token scoping and data sovereignty are built in.

Agencies & freelancers

Ship a polished media library to each client without standing up storage infrastructure per project.

CMS & editor integrations

Drop a media picker into CKEditor, TinyMCE, Summernote, or your own editor via the iframe SDK.

Internal tools & dashboards

Add uploads, previews and audited file operations to admin panels in an afternoon.

FAQ

Frequently asked questions

Is FluxFiles free and open source?
Yes — MIT licensed, free to self-host, and published on Composer and npm. The core has no usage limits; optional paid modules add extras like Share links and Upload Portals.
Where are my files stored?
Wherever you point it: local disk, AWS S3, Cloudflare R2, or a remote server over SFTP via Flysystem. You own the storage — nothing goes through a third party.
Can I embed it in my existing app or editor?
Yes — the iframe + JS SDK works in any page, with official adapters for Laravel, WordPress, React, Vue/Nuxt, CKEditor 4, TinyMCE and Summernote.
How secure is it against common attacks?
JWT claims scope every request (permissions, disk, path prefix, extensions, owner-only); server-side fetches like URL import and BYOB checks go through an SSRF guard that blocks private/internal IPs; uploads get anti-XSS response headers, and a file's extension is locked at upload time so rename/move/copy can't change it.

Ready to embed FluxFiles?

Add a production-ready file manager to your app in minutes — no framework lock-in, MIT licensed.