TypeScriptAGPL-3.0Created Mar 19, 2026Last push 2d agoLatest release v4.3.3+217 stars this week+1.4K this month
Quick answers
What is TREK?
A self-hosted travel planner to visually organize trips, track expenses, and manage reservations with AI assistance.
What does TREK do?
TREK is an open-source, self-hosted travel planning application serving as an alternative to commercial services like Wanderlog. It provides a highly visual, drag-and-drop interface for users to build comprehensive day plans, plot routes on interactive maps, and collaborate in real-time with other travelers. Beyond route mapping, the platform tracks shared trip budgets, manages ticket reservations, and stores essential documents in one centralized location. Additionally, it integrates a built-in MCP server that allows AI agents to automatically generate packing lists, plan itineraries, and analyze trip costs based on user prompts.
Who is TREK for?
TREK is designed for frequent travelers, homelab enthusiasts, and friend groups who want a private, comprehensive tool to plan and document their trips. It is ideal for users looking for a feature-rich, self-hosted alternative to proprietary travel planners.
How do I get started with TREK?
docker compose up -d
How popular is TREK on GitHub?
liketrek/TREK has 14,528 stars and 1,258 forks on GitHub, and gained 217 stars in the last 7 days.
What license does TREK use?
liketrek/TREK is released under the AGPL-3.0 license.
Star history
since Jul 29, 2026
14.5K stars as of Oct 2, 2026. Measured daily since Jul 29, 2026; GitHub no longer exposes earlier star timestamps.
Update history
1 recorded
Oct 4, 2026Previously tracked as mauriceboe/TREK; its 1 daily snapshot and 3 trending appearances were merged into this profile. Stars: 11,124 on 2026-07-29 under the old name, 14,528 on 2026-10-02 (+3,404).
Contribution activity
commits per day, last 52 weeks
2,500 commits in the last yearLessMore
Signals and awards
derived from tracked data
Widely adopted
14,528 stars
Very active
2,500 commits in 52 weeks
Well documented
High community health score
Continuous integration
Automated checks passing
Repeat trending
3 trending appearances
What TREK does
TREK is an open-source, self-hosted travel planning application serving as an alternative to commercial services like Wanderlog. It provides a highly visual, drag-and-drop interface for users to build comprehensive day plans, plot routes on interactive maps, and collaborate in real-time with other travelers. Beyond route mapping, the platform tracks shared trip budgets, manages ticket reservations, and stores essential documents in one centralized location. Additionally, it integrates a built-in MCP server that allows AI agents to automatically generate packing lists, plan itineraries, and analyze trip costs based on user prompts.
TREK is designed for frequent travelers, homelab enthusiasts, and friend groups who want a private, comprehensive tool to plan and document their trips. It is ideal for users looking for a feature-rich, self-hosted alternative to proprietary travel planners.
Interactive trip mapping: Features a drag-and-drop planner paired with 3D terrain maps to optimize daily travel routes.
Expense splitting: Tracks multi-currency trip costs and calculates who owes whom, similar to Splitwise.
Real-time collaboration: Utilizes WebSockets to instantly sync itinerary changes, chat messages, and polls across multiple users.
Reservation management: Imports and organizes flights, hotels, and tickets from booking confirmation emails or PDFs.
AI automation: Exposes a built-in MCP server allowing AI assistants to plan days, build budgets, and create packing lists.
Where teams use it
Group trip coordination
Friend groups use the platform to collaboratively plan itineraries, vote on activities, and split shared expenses equitably.
Offline travel access
Travelers install the PWA on their mobile devices to access maps, tickets, and plans reliably without cellular service.
AI-assisted itinerary generation
Users connect their AI assistants via the MCP server to automatically draft day-by-day travel plans for new destinations.
Homelab travel archiving
Privacy-conscious individuals host the app locally to securely store their travel history, photos, and passport documents.
Getting started: docker compose up -d
README
main branch
A self-hosted, real-time collaborative travel planner — with maps, budgets, packing lists, a journal, and AI built in.
What you get
See all features
Most of what follows is an addon an admin switches on or off. Lists, Costs, Documents, Collab, Vacay and Atlas ship on; Journey, Collections, MCP, AI Parsing and AirTrail ship off and are marked below.
🧭 Planning
Day plans: drag places between days and reorder inside a day, with undo. Notes and bookings drag the same way, and a map marker drops straight onto a day
Maps: Leaflet, Mapbox GL or MapLibre GL (OpenFreeMap, no token), with clustering, photo markers and route lines. 3D buildings and terrain are Mapbox only
Place search: Google Places when a key is set (photos, ratings, opening hours), otherwise OpenStreetMap with no key
Place enrichment: descriptions, facts, hours and photo candidates from OpenStreetMap, Wikipedia, Wikidata and Wikimedia Commons
POI explore: pull OpenStreetMap POIs by category for the current viewport over Overpass
Import: shared Google Maps and Naver Maps lists, plus GPX, KML and KMZ files
Export: GPX of a trip's places and tracks, and an ICS feed per trip or across all of them
Routes: auto-sort a day (nearest neighbour then 2-opt, locked stops and hotel anchors stay put), driving, walking or cycling profiles over OSRM, then open it in Google Maps or CoMaps
Public transport: door-to-door itineraries over Transitous
Weather: 16-day forecast from Open-Meteo, no key. Dates outside that window read the archive for the same date instead
Day notes: markdown body with an icon and a colour, reordered by drag and drop or moved to another day
Trip dates: move a trip and the days re-date themselves, either dragging the bookings along or re-anchoring them. Trips also copy and archive
🧳 Bookings and money
Reservations: 16 booking types with status, confirmation code, travellers and attached files
Flights and trains: several legs with stopovers, per-leg times and endpoint timezones, against 4,045 bundled airports so local times resolve without a key
Accommodation: a stay spans a range of days with a check-in window, and shows on every night it covers
Booking import: EML, PDF, PKPass, HTML and TXT confirmations through KItinerary. Needs the kitinerary-extractor binary, which ships in the Docker image
AirTrail (off by default): link a self-hosted AirTrail instance to import flights as reservations and keep them in sync
Costs: split expenses in integer cents with equal or custom shares, several payers per expense, settle-up suggestions, a settlement log, and CSV export
Currencies: a currency per expense with the rate frozen at entry. Rates come from Frankfurter, no key
Packing lists: categories, admin-managed templates, assignees, three visibility tiers, and a packed-of-total line. Bags with weight roll-up are a separate admin switch, off by default
To-dos: assignee, due date, priority, and a reminder before one falls due
Files: attach to a trip, place, day entry or reservation. 50 MB each, 500 MB for video, with trash and restore
PDF export: cover page, place photos, day notes, bookings and costs, with an optional page break per day
👥 Collaboration
Real-time sync (WebSocket): edits land live for everyone who has that trip open
Members: add by email or username, hand ownership to someone else, or add guests who have no login at all
Permissions: an admin maps each of 16 trip actions to admin, trip owner, trip member or everybody
Invite links: one reusable link per trip with an optional expiry. Admins can also issue signup invites with a use limit that drop the new account straight into a trip
Public share: a read-only trip page anyone can open without an account
Collab: group chat with replies, reactions and link previews, shared notes with attachments, polls, and a What's Next list of upcoming activities. Each of the four switches on its own
📔 Journal, Atlas and Vacay
Journey (off by default): dated entries with story, mood, weather and tags, photos and video from uploads or a linked Immich or Synology Photos library, map views, co-authors, and a public share link
Atlas: mark countries and sub-national regions visited on geoBoundaries outlines, plus a bucket list, travel stats and a consecutive-years-travelled count
Vacay: leave calendar with half days, public holidays from date.nager.at, school holiday overlays for 16 European countries, carry-over between years, and joint or read-only sharing of a plan
Collections (off by default): a place library outside any trip, with labels, ratings, a custom image per place, copy-into-a-trip, and sharing by invite
🧩 Plugins
Third-party plugins: install from the TREK registry or sideload a zip, switch on per instance, with their own pages under /plugins/<id>
Sandboxed: one child process per plugin, 63 grantable permissions, an admin-edited outbound host allowlist, memory and RPC caps, and daily caps on AI and notification calls
Trust: registry downloads are pinned by sha256 and checked against the author's minisign key. A sideloaded zip is marked unverified, and TREK_PLUGINS_ENABLED=false turns the whole system off
Extension points: map markers and layers, place details, day schedules, PDF sections, Atlas layers, journal rows, trip warnings, calendar sources, route profiles and notification channels. Plugin pages run in an opaque-origin iframe
SDK: trek-plugin-sdk on npm, with a manifest validator, a mock host, and a dev-link mode that runs a local build against real data
🤖 AI and MCP
MCP server (off by default): OAuth 2.1 with mandatory PKCE and dynamic client registration. 199 tools, 30 resources, 4 prompts
Scopes: 29 scopes in 14 groups, each one tickable on the consent screen. Tokens are bound to the /mcp resource, and every tool call lands in the audit log
Reach: create trips and days, edit places, packing lists, to-dos, costs, reservations, collections and journeys, mark countries visited, all inside the scopes the token holds
Prompts: trip-summary, plus packing-list and budget-overview when those addons are on
Addon-aware: seven addon gates decide which tools and resources a session sees. Flipping one drops live sessions so the surface re-registers
Booking extraction (off by default): read a confirmation with a local Ollama server, any OpenAI-compatible endpoint, or Anthropic, configured instance-wide or per user
📱 Mobile and offline
Installable: iOS and Android straight from the browser, no App Store. Runs standalone without browser chrome, with the status bar tinted per theme
Phone layouts: a separate shell below 768px with its own tokens, a bottom bar and safe-area insets. Which items sit in that bar is up to the user
Offline reads: the app shell and every route chunk are precached, and trips, places and file blobs live in a per-user IndexedDB store, so a trip opens with no network
Offline writes: mutations queue and replay with an X-Idempotency-Key, so a reconnect cannot double-apply. A stale edit is parked for a keep-mine or keep-theirs choice
Offline maps: pre-download a trip's raster tiles, and clear them again
API responses are never cached by the service worker. They vary per session, so they always come from the network
⚙️ Admin, accounts and security
Login methods: password login, password registration, OIDC login, OIDC registration and passkey login each switch on and off on their own. OIDC_ONLY leaves SSO as the only way in
SSO (OIDC): one provider by discovery, with PKCE and id_token verification (Authentik, Keycloak, Google and the like)
2FA: TOTP with ten single-use backup codes, and an admin can require it instance-wide
Passkeys: WebAuthn login by fingerprint, face, PIN or security key, off until an admin enables it. A passkey also satisfies the 2FA requirement
Hardening: per-IP limits on login, password reset and 2FA attempts, a password policy, secrets encrypted at rest and masked on read, and an SSRF guard on every URL you configure
Admin panel: users and invites, the permission matrix, packing templates, categories, addons, plugins, API keys, MCP tokens and OAuth sessions, backups, storage, audit log, and GitHub releases
Backups: manual or scheduled hourly, daily, weekly or monthly, with retention in days. The zip carries the at-rest key, so a restore can decrypt its own secrets
Storage: pluggable storage backends per content category — keep everything on local disk, or add S3-compatible backends and replicate any category to them, configured entirely from the admin panel
Notifications: a per-user matrix of events against in-app, email (SMTP), webhook and ntfy, plus any channel a plugin registers
Appearance: light, dark or follow the OS, seven colour schemes plus a custom accent, transparency, compact density, reduce motion, and text size per tier
23 languages: en, de, es, fr, it, nl, hu, ru, zh, zh-TW, pl, cs, ar (right to left), br, id, tr, ja, ko, uk, gr, sv, vi, ca
In-app help: the wiki ships inside the image and is served from disk at /help, so the docs match the version you are running
AI usage
We use LLM-assisted coding tools across parts of this codebase. Nothing ships that a
maintainer has not read and understood: every change goes through a pull request, is
reviewed and tested, and has a human who can answer for it. "The AI wrote that" is not
an answer any of us would accept from ourselves.
Open http://localhost:3000. On first boot TREK seeds an admin account — if you set ADMIN_EMAIL/ADMIN_PASSWORD those are used, otherwise the credentials are printed to the container log (docker logs trek).
Real-time sync via WebSocket (ws). Backend on NestJS 11. State with Zustand. Auth via JWT + OAuth 2.1 + OIDC + Passkeys (WebAuthn) + TOTP MFA. Weather via Open-Meteo (no key required). Maps with Leaflet and Mapbox GL.
Docker Compose (production)
The repository ships a ready-to-use docker-compose.yml
with secure defaults and every option documented inline. Download it, then:
TREK works as a Progressive Web App — no App Store needed.
Open TREK in the browser (HTTPS required)
iOS: Share ▸ Add to Home Screen
Android: Menu ▸ Install app (or Add to Home Screen)
TREK then launches fullscreen with its own icon, just like a native app.
Updating
See Updating — Docker Compose,
Docker run, Helm, Portainer, Unraid and Proxmox, plus the encryption-key note.
Reverse Proxy
For production, put TREK behind a TLS-terminating reverse proxy. TREK uses WebSockets for real-time sync, so the proxy must support WebSocket upgrades on /ws.
If you use the MCP addon, the proxy must also pass the Mcp-Session-Id header through in both directions on /mcp — Nginx and Caddy do this by default, but a proxy that strips it makes every tool call open a new session instead of reusing one. See the Reverse Proxy wiki page for details.
Nginx
server{listen80;server_name trek.yourdomain.com;return301 https://$host$request_uri;}server{listen443ssl http2;server_name trek.yourdomain.com;ssl_certificate /etc/ssl/fullchain.pem;ssl_certificate_key /etc/ssl/privkey.pem; # 500 MB covers backup-restore uploads (capped at 500 MB server-side).client_max_body_size500m;location / {proxy_passhttp://localhost:3000;proxy_http_version 1.1;proxy_set_header Host $host;proxy_set_header X-Real-IP $remote_addr;proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;proxy_set_header X-Forwarded-Proto $scheme;}location /ws {proxy_passhttp://localhost:3000;proxy_http_version 1.1;proxy_set_header Upgrade $http_upgrade;proxy_set_header Connection "upgrade";proxy_set_header Host $host;proxy_read_timeout86400;} # Only needed if you use the MCP addon. Responses are Server-Sent Events, # so buffering must be off or tool results arrive late.location /mcp {proxy_passhttp://localhost:3000;proxy_http_version 1.1;proxy_set_header Host $host;proxy_set_header X-Real-IP $remote_addr;proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;proxy_set_header X-Forwarded-Proto $scheme;proxy_buffering off;proxy_read_timeout3600s;}}
The Atlas map's country and sub-national (province/county) boundaries come from
geoBoundaries (Runfola et al., 2020), licensed
CC BY 4.0. See NOTICE.md
for full third-party attributions.
License
TREK is AGPL v3. Self-host freely for personal or internal company use. If you modify and offer TREK as a network service to third parties, your modifications must be open-sourced under the same licence.
## 4.3.3
[Full diff since 4.3.2](https://github.com/liketrek/TREK/compare/v4.3.2...v4.3.3)
### Fixed
- Logging in through a self-hosted identity provider works again when its host name also has an IPv6 link-local record. Since 4.3.0 a single blocked address refused the whole name, and LAN DNS servers commonly publish a host's `fe80::` address next to its IPv4, so every OIDC login failed with "Requests to link-local / cloud-metadata addresses are not allowed". Immich, Synology and the other integrations on such a name failed the same way. TREK now leaves the blocked address out and connects over the host's other addresses, and a name that resolves to nothing else is still refused. `ALLOW_INTERNAL_NETWORK` and `ALLOW_LINK_LOCAL_IPS` work as before, except that the AWS and Alibaba metadata addresses now stay blocked for URLs a user types even with `ALLOW_INTERNAL_NETWORK` on, as they already were for the admin settings, and a link-local or metadata address written as an IPv6 form of its IPv4, such as `::169.254.169.254`, is now refused everywhere. (#2529, Closes #2506)
- Trips can be deleted on a container without a writable temp directory, such as one with a read-only root filesys
## 4.3.2
[Full diff since 4.3.1](https://github.com/liketrek/TREK/compare/v4.3.1...v4.3.2)
### Fixed
- The road trip can start and end a day where you slept. It had no way to: the day after a booked night started at its first place, or at the last place of the day before, so a moving day showed only the new hotel and several nights in one hotel drew each day as if it began somewhere else. With "Start and end each day at your stay" switched on under the driving settings, off by default and on the desktop and the phone, a day after a booked night starts at that stay and a day before one ends there. The hotel stands at the edge of the day under its own name, with a badge for the edge it is: Check-out with the latest hour on the day you leave, Day start in the middle of a stay, Overnight in the evening, and Check-in with the hour the room is ready on a moving day. A moving day without places becomes the drive from one stay to the next. The check-out hour is shown and never used as the departure, and a plan that sets out later turns its badge into a warning. Flights, ferries, trains and hire cars at the edge of a day take precedence, a flight or train saved without located terminals
## 4.3.1
[Full diff since 4.3.0](https://github.com/liketrek/TREK/compare/v4.3.0...v4.3.1)
### Changed
- The places filter in the planner's right sidebar (All, Unplanned, Planned, Tracks) is the app's own select instead of four pills. With the tracks tab the row had grown past what the rail holds without clipping a word; the count rides on the trigger the way it rode on the active pill, and every option carries its own in the menu. (#2436)
- Shared links in the Collab tab are chips now, two to a row across the panel: favicon, title and host, a pinned chip in the accent tint, the whole chip being the link. Edit, pin and delete sit faint in its tail and come forward on hover; on touch they are always shown. (#2413)
### Fixed
- The release notice keeps its promise box whole when the window is too short for the note. The right column scrolls in that case, and on a 1080p screen at 100% it does, but the box was pressed down to its label while the paragraphs around it kept their height. Everything inside the two scrolling columns now keeps its size. Below 1080px the two halves stack again as they should; the release half had been squeezed to nothing there, and the support buttons now

## 4.3.0
[Full diff since 4.2.1](https://github.com/liketrek/TREK/compare/v4.2.1...v4.3.0)
### Added
**TREK Places API**
- Place search runs on TREK's own API, rebuilt monthly from Overture and served from places.liketrek.com: 73.6 million places, no key, no quota. It answers search, autocomplete, place details, the map's category pills and booking geocoding.
- The TREK API is on by default, with no admin toggle. `TREK_PLACES_ENABLED=false` keeps search on OpenStreetMap plus Google, and `TREK_PLACES_URL` points an instance at a self-run copy.
- Opening hours come from a separate layer of 5.7 million objects, read in 5 ms: OpenStreetMap first, then the hours a place publishes itself.
- Restaurants, shops and hotels take their description from their own site, credited by host and linked. 43 percent of places in the TREK API carry a website.
- A trip's surroundings download for offline use, up to 3000 places per request and kept per trip. Rostock costs about a megabyte, and search and autocomplete then work with no network, labelled as
<a href="https://github.com/liketrek/TREK/discussions/categories/feature-requests"><img alt="Upvote your favourite feature requests" src="https://raw.githubusercontent.com/liketrek/TREK/74c47a6158d2d1ffc66e0c3a2a65f6e9221230d2/wiki/assets/Banner-Feature-Requests.png" /></a>
Fifteen reported issues off the 4.2.0 tag, two privately reported security advisories, and one operator request. **No breaking changes and no schema change.** This release appends no migrations at all, so a rollback to 4.2.0 stays possible on the data side. Two changes need a word before you update.
## Read this first
* **Installed PWAs reload themselves once, and offline map tiles have to be downloaded again.** The offline fix in this release replaces the old "wipe everything on a version change" behaviour with a proper worker update, but the code that runs on your device right now is still the old one, so it does its clean-up one last time on the first start after this update. Open TREK **with a connection** and leave it open until it has reloaded itself (about 23 MB). Afterwards, go to **Settings → Offline** and press **Download for offline use** once. Your trips, files and anything waiting to sync are sto
Code frequency
additions and deletions
+1.9M lines added, -510.7K removed over the last year.
Commits per week
last 52 weeks
2.5K commits in the last 52 weeks.
When work happens
weekday and hour
Commit volume by weekday and hour (UTC). Larger dots mean more commits.