Kenneth Skovhede e3f1aefec2 Implemented a nonce for refresh tokens
This adds a nonce to the refresh token such that each request to obtain a refresh token must now also provide a matching nonce.

When using non-persisted logins, the request to the server is the same, but the "remember me" flag toggles a shorter duration for the refresh token.

The FE can then store the nonce in either local storage for persisted logins or in session storage for non-persisted logins.

The default is currently to always issue refresh tokens with a nonce, but this can be toggled with the JWT configuration.

The ngax client does not have the non-persisted login so it stores the nonce in local storage, using a name that is compatible with ngclient so the user can swap between them without needing to re-login.

The server util was updated to also store the nonce.

This fixes #6451
2025-08-07 23:10:54 +02:00
2025-08-07 11:11:03 +02:00
2025-04-24 16:36:14 +02:00
2019-12-08 18:22:59 -08:00
2025-07-01 16:32:19 +02:00
2025-07-07 13:38:45 +02:00
2025-08-05 13:02:56 +02:00
2025-07-01 16:32:19 +02:00
2025-07-08 15:27:36 +02:00
2025-06-13 12:54:22 +02:00
2024-11-07 23:05:55 +01:00
2024-08-14 13:52:53 -04:00
2025-04-23 15:12:56 +02:00
2024-11-05 00:06:29 -05:00
2025-05-22 15:28:59 +02:00
2025-07-28 16:32:18 -04:00
2025-05-23 08:12:55 +02:00

Duplicati

English | 中文 | 日本語

Store securely encrypted backups on cloud storage services!

Backers on Open Collective Sponsors on Open Collective Build Status on Travis-CI Coverage Status License Gurubase

Duplicati is a free, open-source backup client that securely stores encrypted, incremental, and compressed backups on cloud storage services and remote file servers. It supports:

   Amazon S3, IDrive e2, Backblaze (B2), Box, Dropbox, FTP, Google Cloud and Drive, MEGA, Microsoft Azure and OneDrive, Rackspace Cloud Files, OpenStack Storage (Swift), Storj DCS, SSH (SFTP), WebDAV, Tencent Cloud Object Storage (COS), Aliyun OSS, and more!

Duplicati is licensed under the MIT license and is available for Windows, macOS, and Linux.

Download

Click here to download the latest Duplicati release.

The beta release will automatically notify you of updates and allows you to upgrade with a single click (or command in the terminal). For even more bleeding edge access, check the latest releases or choose another update channel in the UI or on the commandline.

All releases are GPG-signed with the public key 3DAC703D. The latest signature file and ASCII signature file are available on the Duplicati download page.

Support

Duplicati is supported by an active community and you can reach them via our forum.

We also provide a comprehensive Duplicati manual, which you can contribute to.

Features

  • Duplicati uses AES-256 encryption (or GNU Privacy Guard) to secure all data before uploading.
  • Initial full backup followed by smaller, incremental updates to save bandwidth and storage.
  • Built-in scheduler ensures backups stay up-to-date automatically.
  • An integrated updater notifies you of new releases.
  • Encrypted backups can be transferred to destinations like FTP, WebDAV, SSH (SFTP), Amazon S3, and more.
  • Flexible backup options: back up folders, specific file types (e.g., documents or images), or use custom filters.
  • Available as a user-friendly application or a command-line tool.
  • Supports backing up open or locked files using Volume Snapshot Service (VSS) on Windows or Logical Volume Manager (LVM) on Linux.
  • Advanced options for filters, deletion rules, transfer settings, bandwidth limits, and more.

Why Use Duplicati?

Keep your data safe, store it remotely, and back it up regularly! Many backup solutions fail to meet these essential requirements, but Duplicati excels at all three:

  • Keep your data safe: Duplicati uses strong encryption to ensure your data remains private. With a secure password, your backup files are safer on a public web server than unencrypted files at home.
  • Store your backup remotely: Protect your data from local disasters like fires by storing backups on remote servers. Duplicati supports incremental backups, making it efficient to use distant storage destinations.
  • Backup regularly: Outdated backups are as good as no backups. Duplicati's built-in scheduler ensures your backups are always current. It also uses compression and incremental backups to save storage and bandwidth.

Contributing

Reporting Bugs

We use GitHub for bug tracking. Please search existing issues before creating a new one: https://github.com/duplicati/duplicati/issues.

Contributing Translations

Want to help translate Duplicati? Contributions are welcome on Transifex: https://explore.transifex.com/duplicati/duplicati/.

Contributing Code

Instructions for setting up your development environment and building Duplicati are available in the documentation. Pull requests for bug fixes or improvements are highly appreciated.

Looking for something to work on? Check out minor change issues or UI-related issues.

Thank you to all our contributors:

Backers

Thank you to all our backers! 🙏

Sponsors

A special thanks to our sponsors for supporting this open-source project:

Languages
C# 93.7%
JavaScript 2.7%
HTML 1.4%
Less 0.7%
Python 0.5%
Other 0.8%