From 25b12943663d8eb6d1cf479a5020166855549a11 Mon Sep 17 00:00:00 2001
From: Aditya kumar singh <143548997+Adityakk9031@users.noreply.github.com>
Date: Thu, 10 Sep 2026 20:33:06 +0530
Subject: [PATCH] docs(self-hosting): document HOST/SUPERMEMORY_HOST binding
and loopback security (#1441)
---
apps/docs/self-hosting/configuration.mdx | 30 ++++++++++++++++++++++++
apps/docs/self-hosting/quickstart.mdx | 4 ++++
2 files changed, 34 insertions(+)
diff --git a/apps/docs/self-hosting/configuration.mdx b/apps/docs/self-hosting/configuration.mdx
index 09478722..fc45b8d0 100644
--- a/apps/docs/self-hosting/configuration.mdx
+++ b/apps/docs/self-hosting/configuration.mdx
@@ -14,8 +14,38 @@ The installer writes API keys to `~/.supermemory/env`, which is loaded on every
| Variable | Purpose | Default |
|---|---|---|
| `PORT` (or `SUPERMEMORY_PORT`) | HTTP listen port | `6767` |
+| `HOST` (or `SUPERMEMORY_HOST`) | Network interface to bind (`127.0.0.1` for loopback, `0.0.0.0` for all interfaces) | `0.0.0.0` |
| `SUPERMEMORY_DATA_DIR` | Where the graph engine's data, auth secret, and model cache live | `./.supermemory` |
+### Network interface binding & Security
+
+By default, the self-hosted binary binds to all network interfaces (`0.0.0.0`), allowing access from local containers, remote devices, and the host.
+
+
+**Public & Shared Network Caution**: On shared networks (coffee shops, offices, hotels), listening on `0.0.0.0` exposes the server port to other devices on the LAN.
+To enforce loopback-only binding on local machines:
+```bash
+SUPERMEMORY_HOST=127.0.0.1 supermemory-server
+# or in ~/.supermemory/env:
+# SUPERMEMORY_HOST=127.0.0.1
+```
+
+
+#### Localhost Loopback Isolation
+
+For local development alongside tools like Claude Code, Cursor, or Codex, bind explicitly to `127.0.0.1` so that requests can only originate from your local machine:
+
+```bash
+HOST=127.0.0.1 PORT=6767 supermemory-server
+```
+
+If you are running an older binary release (such as v0.0.6) that hardcodes `0.0.0.0`, you can isolate port access to localhost without elevated administrator privileges:
+
+- **Reverse Proxy / Port Forwarding**: Run a local forwarder such as `socat` or Nginx bound strictly to `127.0.0.1`.
+- **Docker / Container Isolation**: Run the container with explicit loopback binding: `-p 127.0.0.1:6767:6767`.
+- **OS Firewall**: Restrict inbound port 6767/6768 traffic via `pfctl` (macOS) or `iptables` / `ufw` (Linux).
+
+
## LLM providers
In production, Supermemory uses its own proprietary models tuned for long-horizon data understanding. Self-hosted, you bring your own LLM for the intelligent steps — summaries, contextual chunking, and memory extraction. Embeddings default to a local model (no API key) and can optionally use OpenAI, Gemini, or Ollama — see [Embeddings](/self-hosting/embeddings). Configure **at least one** LLM provider:
diff --git a/apps/docs/self-hosting/quickstart.mdx b/apps/docs/self-hosting/quickstart.mdx
index d0b37991..5cab868f 100644
--- a/apps/docs/self-hosting/quickstart.mdx
+++ b/apps/docs/self-hosting/quickstart.mdx
@@ -76,6 +76,10 @@ In production, Supermemory runs proprietary models tuned for long-horizon data u
**Docker / non-interactive:** set an LLM key via env and, if you don’t want local embeddings, set `SUPERMEMORY_EMBEDDING_PROVIDER` / `MODEL` / `DIMENSIONS`. There is no wizard without a TTY.
+
+**Loopback-only binding:** By default, the server binds to `0.0.0.0`. To restrict access to your local machine (recommended on shared Wi-Fi networks), start with `SUPERMEMORY_HOST=127.0.0.1 supermemory-server`. See [Configuration](/self-hosting/configuration#network-interface-binding--security).
+
+
## Add your first memory