---
title: "Serving a web UI"
---

> Documentation Index
> Fetch the complete documentation index at: https://kmworks.date/llms.txt
> Use this file to discover all available pages before exploring further.

# Serving a web UI

The release Docker image bundles [kmweb](https://github.com/kmworks/kmweb), the React UI built for KMServer (dashboard, browsing with facet filters, full-text search, the comic reader, account settings, live updates over SSE), and serves it at `/` out of the box. Nothing to configure: `http://<host>:25600/` works in a browser immediately.

## Keeping the UI up to date

The bundled UI is only a baseline. Turn on auto-update and KMServer tracks new kmweb releases at runtime, with no container rebuild or restart:

```sh
KOMGA_WEBUI_AUTOUPDATE=true
KOMGA_WEBUI_UPDATEINTERVAL=6h   # how often to check, default 1d
```

On startup and then on the interval, KMServer checks the latest kmweb release, downloads the bundle, verifies it against the published sha256, and swaps the served directory atomically. The managed copy lives under `<config-dir>/webui` (`/config/webui` in the container), so it survives image upgrades, and browsers pick the new version up on the next page load. As long as no managed copy exists (fresh or offline install), the bundled one is served, so the UI always works.

Air-gapped hosts: leave auto-update off and keep the bundled copy.

## Bare binary

The standalone binary carries no UI, which is fine for API-only clients (KMReader, KOReader, OPDS readers). To serve a UI anyway, point `webui.dir` at a kmweb bundle from a [kmweb release](https://github.com/kmworks/kmweb/releases) (or your own build) — this is only needed to force a specific UI:

```sh
KOMGA_WEBUI_DIR=/path/to/kmweb kmrs
```

With auto-update also enabled, the managed copy replaces whatever `webui.dir` points at once the first download lands. Run with an empty `KOMGA_WEBUI_DIR=` to explicitly disable the UI.

## Notes

- KMServer speaks plain HTTP. If you need HTTPS, put any TLS-terminating proxy in front; it can be a dumb pipe, since KMServer tells the SPA and the API apart itself.
- Cross-origin hosting (web UI on a different origin than the API) is not supported: KMServer parses `KOMGA_CORS_ALLOWEDORIGINS` but does not apply CORS headers. Serve same-origin.
- The web UI's files and SPA routes are served without authentication — the login page has to load anonymously. Authentication is enforced by the API, same as the Java version.

Source: https://kmworks.date/server/webui/index.mdx
