Managed Kimai hosting

BusinessOn-prem or sovereign site

Time tracking, billable hours and invoices for teams, run on your own hardware or in the Pilae Cloud region you choose, with no per-user fee for the open-source core. Pilae runs it on your own servers, or in Zurich, Switzerland, and eleven other Pilae Cloud regions.

Talk to us about Kimai

Licence
AGPL-3.0-or-later
Runs on
Your own hardware, or any of twelve Pilae regions — six of them in Switzerland and the EU
Upgrades
Pinned, tested against your configuration, applied in your window
Upstream
www.kimai.org

Running Kimai in production: what it takes

  1. Deploy with the data directories on volumes

    A Kimai image we have run, on its own MariaDB, with the application secret set by us rather than generated inside the container, and the three data directories on volumes from the first day.

  2. SAML sign-on, roles from groups

    SAML sign-on through Keycloak or your existing IdP. Directory groups map to Kimai's team lead and admin roles and are applied again at every sign-in, so a role removed in the directory does not linger in Kimai.

  3. Set rates, teams and a lockdown period

    Rates by customer, project and person, teams deciding who sees which projects, and a lockdown period so hours cannot be changed after the month has been invoiced.

  4. Restore onto the same Kimai version

    A daily, encrypted copy of the database and the data directories goes offsite. The monthly drill puts it back into a scratch instance on the same Kimai version and opens an invoice from it.

  5. Upgrade in your window, plugins included

    The container migrates the database when it starts, so the way back is the copy taken just before. We check each plugin against the release and the upstream upgrade notes, then the Pilae Agent rehearses the upgrade on a copy and, once you approve, applies it in your window.

What Kimai is, and who runs it

Self-hosted Kimai for time tracking and billable hours

Kimai records time against customers, projects and activities, and turns it into reports, exports and invoices. People start a timer or enter hours afterwards, team leads see their teams, and rates by customer, project or person put a price on every entry. For attendance rather than project time, a time-clock mode limits people to clocking in and out. It covers what most teams use Toggl Track, Clockify or Harvest for.

Timesheets say who worked for whom and on what, and their descriptions often name clients and matters. Kimai runs on a dedicated machine, yours or one in a Pilae Cloud region you choose from twelve, six of them in Switzerland and the EU, and it answers only on your private network.

Kimai in production: MariaDB, SAML sign-on and plugin upgrades

Kimai supports MariaDB and MySQL only, so it gets its own MariaDB even where the rest of your estate runs on PostgreSQL. Sign-on is SAML through Keycloak or Microsoft Entra ID, with directory groups mapped to Kimai roles. Generated invoices, uploaded invoice templates and plugin code sit in three directories on volumes. They are backed up with the database daily, encrypted, to an offsite location in your chosen country, and restored once a month into a scratch instance on the same Kimai version. Probes check the instance every 60 seconds and alert an engineer.

The Kimai container migrates the database when it starts, so an upgrade is undone by restoring the copy taken just before it, not by starting the old image. Each plugin release names the minimum Kimai version it needs, so we check every installed plugin against a release before the Pilae Agent tests the upgrade on a copy, waits for your approval and applies it in your window.

Kimai licence and paid plugins

Kimai has no per-user fee, and two-factor authentication is in the open-source core as well. Any paid plugin your requirements need is named in the proposal, before anything is installed. Pricing for our operation is on request. Talk to us about the time tracking you want to move.

Kimai is AGPL-3.0-or-later, and the core includes SAML and LDAP sign-in, the JSON API, invoicing, exports, and contracted hours with an overtime balance. Further features, such as vacation, sickness and public holidays, expenses and custom fields, come as plugins from the Kimai store, some free and some paid. Paid plugins by Kimai's author, Kevin Papst, are annual subscriptions under the Kimai plugin licence, which covers one installation plus one test copy and forbids redistribution. When a subscription ends, you keep the last version released before it ended; later updates and compatibility fixes need a renewal. If you need a paid plugin, the subscription is bought in your name for your installation, and we list it in the proposal. Kimai is his registered trademark, and we operate Kimai independently of the project.

Kimai system requirements

Before anything is deployed, this is what has to exist. We size it with you in the first session, and we say so when your own hardware is already enough.

CPU and memory
2 vCPU · 4 GBUpstream publishes no minimum. This is our starting size for Kimai and MariaDB on one machine, and we resize it from what monitoring shows during long reports and large exports.
Database
MariaDB 10.6+ or MySQL 8.4+Kimai supports MariaDB and MySQL only. PostgreSQL is not supported and not planned upstream, so Kimai gets its own database with its own backup and restore drill.
Sign-in
SAML 2.0 or LDAPBoth are in the open-source core. SAML covers Keycloak and Microsoft Entra ID. There is no OpenID Connect sign-in; it is an open feature request upstream. The official image already includes the LDAP library that a manual install has to add.
Persistent storage
var/data · var/invoices · var/pluginsGenerated invoices, uploaded invoice templates and plugin code. All three are volumes backed up with the database, because a template kept only inside the container is lost when the container is removed.
DNS and TLS
1 hostnameKimai has to run at the root of its own hostname; a subdirectory is not supported. Behind the Pilae gate on port 443 if people record time from outside the network.

Migrating from Toggl Track to Kimai

Toggl Track's CSV export of time entries imports into Kimai through the free Importer plugin. Clients become customers, projects stay projects, tasks become activities, and each entry keeps its description, tags, billable flag and amount. People are matched by email and created if they do not exist yet, so the default time zone for new users is set before the first file goes in. The currency is not imported, so it is set on each customer first. Toggl has to export with a date format the importer can parse. The Toggl format carries time entries only, so project budgets, estimates, saved reports and integrations do not come across. Most of the work is in the mapping and the rates, which we check until Kimai's totals match Toggl's for the same months.

  1. Set up the structure first

    Currency on each customer, the default time zone for new users, and rates by customer, project or person, agreed before any history is imported.

  2. Import into a scratch copy

    The Toggl Track CSV export goes through the Importer plugin into a scratch instance first. Totals per project and month are compared with Toggl reports before anything reaches production.

  3. Wire sign-on to the imported accounts

    Kimai matches the SAML NameID against a username or an email address, so your identity provider sends the email people used in Toggl and they sign in to the account that holds their history.

  4. Cut over at a month end

    History comes across up to the last closed month, and the open month follows as a final import on the night of the switch. Toggl stays readable until the first invoicing run closes on Kimai.

What a Kimai restore needs

  • mariadb/kimaientries, rates and invoice records, 1.8 GB
    • kimai2_timesheetevery entry, begin and end
    • kimai2_invoicesinvoice numbers and payment state
    • migration_versionsschema version, must match the image
    • bundle_migration_*schema state of each plugin
  • /opt/kimai/var/datavolume
    • invoices/generated invoice files, 410 MB
  • /opt/kimai/var/invoicesuploaded invoice templates, DOCX, ODS or XLSX
  • /opt/kimai/var/pluginsplugin code, paid ones licensed per installation
    • ImportBundleimporter used for the Toggl move
  • repo: acme/ops/kimaiin your repository
    • compose.yamlpinned image, volumes, environment
    • local.yamlSAML connection and role mapping
  • s3://acme-backups/kimaioffsite, daily, encrypted
An example layout. The database and the three data directories are backed up at the same moment, and a restore goes onto the Kimai version the backup was taken on, because that is where the upstream restore procedure starts. Uploaded invoice templates live outside the data directory and are the part a default install forgets.

What Pilae is responsible for

A pinned version

A version we have run, not whatever latest resolves to that day.

A runbook

What it depends on, how it fails, what to do about it. In your repository.

A restore drill

Backups restored on a schedule. A backup nobody has restored is a file.

A patch window

Security updates in a window you agreed, with a rollback ready.

Someone watching

Every endpoint probed on the minute. An alert reaches a person, not a dashboard nobody opens.

Where it runs
zur1, fra1, fal1, gra1, ams1, hel1, lon1, ash1, hil1, sin1, tok1, syd1, on-premZurich, Frankfurt, Falkenstein, Gravelines, Amsterdam, Helsinki, London, Ashburn, Hillsboro, Singapore, Tokyo, Sydney, Your own hardware
Who holds the credentials
You do. Ours are separate, named, logged and revocable with one command. We ask before anything changes outside an agreed window.
If you leave
The machine, the data, the compose files and the runbook are already yours. Nothing stops when our access does.

What drives the price of running Kimai

Pricing is on request: a fixed price for onboarding, then a monthly price for Kimai, quoted in writing within five business days. The plans set what every deployment includes; these are the inputs the quote is built from.

Instance size
The CPU, memory and, where a model runs, the GPUs the app needs for your users and your data.
High availability
One machine with tested restores, or a replicated setup that keeps serving when a node fails.
Storage and backups
How much data it holds, how long backups are kept, and point-in-time recovery for its database.
Plan and support
Essential, Business or Enterprise: support hours, response times in the contract and how often we review the service with you.
Region
Your own hardware, where the infrastructure is already yours, or a Pilae Cloud region, where it is passed through at cost plus a fixed margin.
Sign-on and integrations
Single sign-on, directory sync, mail relays and the other systems the app has to reach.

Kimai: common questions

Is Kimai open source?

Yes. Kimai is AGPL-3.0-or-later with no per-user fee, and the core includes SAML and LDAP sign-in, two-factor authentication, the JSON API, invoicing and exports. Some plugins in the Kimai store are paid annual subscriptions under the Kimai plugin licence, which is per installation. We tell you which ones your requirements need before you commit.

Can Kimai replace Toggl Track?

Yes, for recording time against customers and projects, reporting on it and invoicing from it, and Toggl Track entries import through the free Importer plugin. Project budgets and estimates are set again by hand. Contracted hours and an overtime balance are in the core; vacation, sickness and public holidays are a paid plugin, and we price it with you if you need it.

Does Kimai keep the working-time records Swiss law asks for?

Kimai keeps the timestamps those records are built from, and whether your setup meets the law is for your HR and legal advisers to decide. It records who worked, on what, and when each entry began and ended, and its time-clock mode limits people to clocking in and out. Article 46 of the Labour Act and Article 73 of its Ordinance 1 ask employers to keep records of the daily and weekly hours worked and when they were worked, including compensatory and overtime work, and of the timing and length of breaks of half an hour or more, for at least five years. Waivers and simplified recording are possible under Articles 73a and 73b. We run the system that keeps the records.

Can Kimai run on PostgreSQL?

No. Kimai supports MariaDB and MySQL only, and the maintainer has said PostgreSQL support is not planned. We run it on its own MariaDB, with its own daily backup and monthly restore drill, rather than on a database it was not built for.

Where do our timesheets live?

In MariaDB on one dedicated machine in the country you picked, on your own hardware or in a Pilae region. Backups go offsite, encrypted, to a location in the country you chose. The compose files and runbook are in your repository, and removing our access is one command.

Also in business

Back to apps

Bring us your Kimai. We will tell you what it takes.

Thirty minutes on the deployment you already have, or the one you are about to start.