Zum Inhalt springen

The
tech.

CoWorkboard is a PHP application that runs on ordinary web hosting. Here’s what you need for it, how the installation works, and what data leaves your installation.

What you need

  • Web hosting with Apache or LiteSpeed. Both read the .htaccess files that lock the internal folders. A pure nginx server doesn’t read them, so those locks would be missing.
  • PHP 8.1 or newer with the extensions pdo_mysql, sodium, curl, fileinfo and mbstring.
  • An empty MySQL or MariaDB database.
  • Your own domain or subdomain with an SSL certificate, for example board.yourcompany.com. CoWorkboard doesn’t run in a subfolder like company.com/board.
  • A cron job every five minutes. It sends emails, creates recurring cards, runs automations, and checks daily for updates.

CoWorkboard itself runs at All-Inkl. Most hosts with Apache or LiteSpeed meet the requirements above.

Installation in ten minutes

  1. At your host, create a subdomain, enable SSL and create an empty database. Note the database name, user and password.
  2. Upload the contents of the “coworkboard” folder by FTP into the subdomain’s directory, including the hidden .htaccess file.
  3. Open https://board.yourcompany.com/install.php in your browser.
  4. Fill in the form: database, your account, sender address and licence key.
  5. Enter the shown cron address in your hosting menu as a cron job, every five minutes.
  6. Delete install.php by FTP. Done.

The installer checks the server requirements first, creates the tables and sets up the first account with its team. Google sign-in and your own AI are optional and can be set up later. The installation video shows the steps; the installation guide comes with the package.

Updates with one click

CoWorkboard reports new versions itself: team owners and admins see an orange “Update available” field at the top with “What’s new?”. “Update now” downloads the package, checks the signature, backs up the previous state, installs the new files and database changes, and rolls back automatically on error. Your settings (.env) and uploaded files stay untouched. Anyone with CoWorkboard open at the time sees a “Reload page” notice. Updates are included in the first year after purchase; after that the update package extends the period, without it the installed version just keeps running unchanged.

  • The licence key must be entered under Settings → Version & Updates.
  • The cron job must be running; it checks for new versions once a day.
  • If PHP isn’t allowed to write its own files, upload the new version by FTP and open install.php → “Update database”.

What leaves the installation

Your boards, cards, comments and attachments sit in your database and your storage folder, on your hosting. Nothing goes out except what you turn on yourself:

Table 1 – Outside connections
WhatTo whereWhat is sent
Licence check and update lookupmy licence serverlicence key, domain, version number
Email notificationsthrough your own mail sendingnotifications to members, sent with your sender address
Your own AI (optional)the provider the person enters: Claude, ChatGPT, Gemini or a server of their ownthe selected text and the instruction, with that person’s own key
Claude connection (optional)requests from claude.ai, Claude Desktop or Claude Code to your domainonly what the connected person asks or changes in Claude
Google sign-in and calendar (optional)Googleonly if you set up a Google connection; otherwise it’s hidden

Security

  • AI keys sit encrypted (libsodium) in the database, the master key in a file outside web access. AI calls only run server-side.
  • The Claude connection uses OAuth 2.1 with PKCE and refresh-token rotation. Tokens and personal keys are stored only as a hash.
  • The internal folders (src, bin, migrations, storage) and copies of .env are locked against web access by .htaccess.
  • Updates are signed. A backup of the previous state is made before every update.
  • The licence key is bound to your domain. The number of seats and the end of the update period come from the licence server with the update check; the app counts accounts with their own email address and refuses more once seats are full (viewers don’t count).

Connecting Claude, ChatGPT & Gemini

Under Settings → Connect Claude you’ll find your MCP access address, ending in /api/mcp.php. In claude.ai and Claude Desktop, enter it as a connector, sign in to CoWorkboard, and confirm “Allow access?”. For Claude Code there’s a personal key and a ready-made command to copy.

The access is a standard MCP server with OAuth 2.1, not tied to Claude. ChatGPT connects in Developer mode (web, Plus/Pro/Business) as a custom connector with the same address and OAuth. Gemini uses it via Google Antigravity: the address as serverUrl in mcp_config.json, signing in via OAuth or with the personal key. The Gemini app in the browser can’t connect custom MCP servers yet.

Claude gets twelve tools: read boards and lists, search cards, create, change and move them, comment, create and check off checklist items, create lists. Everything runs with the rights of the connected person, including automations, notifications and activity history. Connected apps can be disconnected at any time.

Ask a question.

No cart, no subscription: just tell me briefly what you need. I’ll get back to you within one business day with an invoice and licence key.

Package

Send with the right arrow key, End or Enter.

Your details go by encrypted email to me, only for your request. No cookies, nothing from third parties; against spam, the server counts requests per connection as a checksum and deletes it after 24 hours. More in the privacy policy (opens in a new tab).

Prefer to talk directly? +49 176 32334839 info@coworkboard.de