README.md

April 7, 2026 · View on GitHub

VoucherVault

Django web application to store and manage vouchers, coupons, loyalty and gift cards digitally





Buy Me A Coffee

⭐ Features

  • User-friendly, mobile-optimized web portal with PWA support
  • Manual offline mode with 48h caching supported
  • Light and dark theme support
  • Integration of vouchers, coupons, gift cards and loyalty cards
  • Transaction history tracking (gift cards only)
  • Item-specific file uploads (images and PDFs)
  • Item sharing between users
  • Display of redeem codes as QR codes or barcodes (many types supported)
  • Client-side redeem code scanning (1D/2D) during item creation with automatic type detection using camera or file upload
  • Expiry notifications via Apprise
  • Multi-user support
  • Multi-language support (English, German, French, Italian)
  • Single Sign-On (SSO) via OIDC
  • Database compatibility with SQLite3 and PostgreSQL
  • REST API endpoint with stats for Home Assisstant (HA) and other dashboards

📷 Screenshots

🐳 Usage

READ THE WIKI - UNRAID SUPPORTED

# create volume dir for persistence
mkdir -p ./volume-data/database

# adjust volume ownership to www-data
sudo chown -R 33:33 volume-data/*

# spawn the container stack
docker compose -f docker/docker-compose-sqlite.yml up -d

Once the container is up and running, you can access the web portal at http://127.0.0.1:8000.

The default username is admin. The default password is auto-generated. You can obtain the auto-generated password via the Docker container logs:

docker compose -f docker/docker-compose-sqlite.yml logs -f

Warning

The container runs as low-privileged www-data user with UID/GID 33. So you have to adjust the permissions for the persistent database bind mount volume. A command like sudo chown -R 33:33 <path-to-volume-data-dir> should work. Afterwards, please restart the container.

Tip

This repository follows the Conventional Commits standard. Therefore, you will find patch, minor and major release version tags on DockerHub. No one stops you from using the latest image tag but I recommend pinning a minor version series tag such as 1.27.x.

This is safer for automatic upgrades and you still get recent patches as well as bug fixes.

🌍 Environment Variables

The docker container takes various environment variables:

VariableDescriptionDefaultOptional/Mandatory
DOMAINYour Fully Qualified Domain Name (FQDN) or IP address. Used to define ALLOWED_HOSTS and CSRF_TRUSTED_ORIGINS for the Django framework. May define multiple ones by using a comma as delimiter.localhostMandatory
SECURE_COOKIESSet to True if you use a reverse proxy with TLS. Enables the secure cookie flag and HSTS HTTP response header.FalseOptional
SESSION_EXPIRE_AT_BROWSER_CLOSESet to False if you want to keep sessions valid after browser close.TrueOptional
SESSION_COOKIE_AGEDefine the maximum cookie age in minutes.30Optional
EXPIRY_THRESHOLD_DAYSDefines the days prior item expiry when an Apprise expiry notification should be sent out.30Optional
EXPIRY_LAST_NOTIFICATION_DAYSDefines the days prior item expiry when another final Apprise expiry notification should be sent out.7Optional
TZDefines the TIME_ZONE variable in Django's settings.py.Europe/BerlinOptional
SECRET_KEYDefines a fixed secret key for the Django framework. If missing, a secure secret is auto-generated on the server-side each time the container starts.<auto-generated>Optional
PORTDefines a custom port. Used to set CSRF_TRUSTED_ORIGINS in conjunction with the DOMAIN environment variable for the Django framework. Only necessary, if VoucherVault is operated on a different port than 8000, 80 or 443.8000Optional
REDIS_URLDefines the Redis URL to use for Django-Celery-Beat task processing.redis://redis:6379/0Optional
CSP_FRAME_ANCESTORSComma-separated list of allowed sources for the CSP frame-ancestors directive.'none'Optional
OIDC_ENABLEDSet to True to enable OIDC authentication.FalseOptional
OIDC_AUTOLOGINSet to True if you want to automatically trigger OIDC flow on login pageFalseOptional
OIDC_CREATE_USERSet to True to allow the creation of new users through OIDC.TrueOptional
OIDC_RP_SIGN_ALGOThe signing algorithm used by the OIDC provider (e.g., RS256, HS256).HS256Optional
OIDC_OP_JWKS_ENDPOINTURL of the JWKS endpoint for the OIDC provider. Mandatory if RS256 signing algo is used.NoneOptional
OIDC_RP_CLIENT_IDClient ID for your OIDC RP.NoneOptional
OIDC_RP_CLIENT_SECRETClient secret for your OIDC RP.NoneOptional
OIDC_OP_AUTHORIZATION_ENDPOINTAuthorization endpoint URL of the OIDC provider.NoneOptional
OIDC_OP_TOKEN_ENDPOINTToken endpoint URL of the OIDC provider.NoneOptional
OIDC_OP_USER_ENDPOINTUser info endpoint URL of the OIDC provider.NoneOptional
DB_ENGINEDatabase engine to use (e.g., postgres for PostgreSQL or sqlite3 for SQLite3).sqlite3Optional
POSTGRES_HOSTHostname for the PostgreSQL database.dbOptional
POSTGRES_PORTPort number for the PostgreSQL database.5432Optional
POSTGRES_USERPostgreSQL database user.vouchervaultOptional
POSTGRES_PASSWORDPostgreSQL database password.vouchervaultOptional
POSTGRES_DBPostgreSQL database name.vouchervaultOptional
CELERY_WORKER_CONCURRENCYCelery worker concurrency.1Optional
CELERY_WORKER_PREFETCH_MULTIPLIERCelery worker prefetch multiplier.1Optional
DEBUGEnable HTTP debug logging.FalseOptional

You can find detailed instructions on how to setup OIDC SSO in the wiki.

🔔 Notifications

Notifications are handled by Apprise. May read the wiki.

You can define custom Apprise URLs in the user profile settings. The input form takes a single or a comma-separated list of multiple Apprise URLs.

The interval, how often items are checked against a potential expiry, is pre-defined (daily at 9AM) in the Django admin area. Here, we are utilizing Django-Celery-Beat + a Redis instance for periodic task execution.

An item will trigger an expiry notification if the expiry date is within the number of days defined by the environment variable EXPIRY_THRESHOLD_DAYS. By default, this threshold is set to 30 days. Additionally, a final reminder is sent out another time if the item expires within the next 7 days.

🔐 Multi-User Setup

VoucherVault is initialized with a default superuser account named admin and a secure auto-generated password.

This administrative account has full privileges to the Django admin panel, located at /admin.

Therefore, all database model entries can be read and modified by this user. Additionally, new user accounts and groups can be freely created too.

Finally, Single-Sign-On (SSO) via OIDC is supported. Check out the environment variables above as well as the wiki.

💾 Backups

All application data is stored within a Docker bind mount volume.

This volume is defined in the example Docker Compose files given. The default location is defined as ./volume-data/database.

Therefore, by backing up this bind mount volume, all your application data is saved.

Warning

Read the official SQLite3 documentation or PostgreSQL documentation regarding backups.

🤖 Repo Statistics

Alt