Skip to content

Security ​

Secrets ​

WhatWhere it's stored
Connection API keysOS credential store: Windows Credential Manager, macOS Keychain, or the Secret Service on Linux. Service name io.meiliops.app.
Local instance master keysSame credential store
Connection names, URLs, colors, themeThe app's settings file (meiliops.json in the app's config folder). No secrets.

Keys are read from the credential store only when needed (connecting, editing a connection, starting an instance), and are sent only to the server they belong to, in the Authorization header.

Tenant tokens are signed locally with the key you choose; nothing is sent to the server to create them.

Network access ​

MeiliOps connects only to the hosts below. There is no telemetry: no analytics, crash reports, usage tracking or accounts.

HostWhenCan you turn it off?
The Meilisearch servers you addWhenever you use them. Keys go only to the server they belong to—
127.0.0.1Checking whether a port is free, and talking to your local instances—
api.github.comOpening Local instances, to list Meilisearch releasesDon't open that screen
GitHub release downloadsInstalling a Meilisearch version (SHA-256 checked, see below)Only on request
github.com/SrilalS/MeiliOps/releases/latest/download/latest.jsonThe update check: at most once a day, a few seconds after launch, and when you choose Check for updatesYes: ⋮ → Check automatically
MeiliOps' GitHub release downloadOnly when you click Update and restart. The installer is verified against the release signing keyOnly on request
Docker Hub (docker.io), through your own Docker or PodmanPulling a Meilisearch image for a container instanceOnly on request

The app sends no identifiers of its own in these requests.

Local instance binaries ​

The Meilisearch binary is downloaded from the official GitHub release and its SHA-256 is checked against the digest GitHub publishes for that release file. A mismatch aborts the install. File operations for instances are restricted to the app's own data folder.

Reporting a vulnerability ​

Please report security issues privately through GitHub security advisories rather than a public issue.

Released under the MIT License. Not affiliated with Meilisearch.