← All articles
Guide

Self-host your chat on Prosody: a practical getting-started guide

25 September 2026 · 2 min · xmpp · prosody · self-hosting · guide

Running your own chat server used to mean serious ops work. Prosody makes it approachable: a lightweight XMPP server in pure Lua that runs happily on a $5 VPS. This guide walks through a real, working setup — the same shape our own infrastructure uses.

Before you start

You need:

  • A small VPS (1 GB RAM is plenty for a handful of accounts).
  • A domain, e.g. chat.example.com.
  • A wildcard or dedicated TLS certificate for it.

We’ll use Debian/Ubuntu. All commands assume you’re logged in as a user with sudo.

1. Install and configure Prosody

sudo apt update
sudo apt install prosody

Prosody’s config lives in /etc/prosody/prosody.cfg.lua. Set your virtual host:

VirtualHost "chat.example.com"
    admins = { "admin@chat.example.com" }

Enable the modules you care about. For a trustworthy setup we recommend:

modules_enabled = {
    "roster";          -- contact lists
    "saslauth";        -- authentication
    "tls";             -- STARTTLS
    "carbons";         -- multi-device sync
    "mam";             -- message archive
    "http_upload";     -- file sharing
}

2. TLS — non-negotiable

Put your certificate and key where Prosody expects them:

sudo mkdir -p /etc/prosody/certs
sudo cp /path/to/fullchain.pem /etc/prosody/certs/chat.example.com.crt
sudo cp /path/to/privkey.pem      /etc/prosody/certs/chat.example.com.key

Then in the config:

-- global cert settings
certificates = "/etc/prosody/certs"

Restart and verify with openssl s_client that STARTTLS is offered.

3. Create your first accounts

XMPP accounts are just JIDs with a password:

sudo prosodyctl adduser me@chat.example.com

Account management and invites are admin tasks. In our case those live in a small admin layer on top of Prosody so invite tokens stay one-time and private — you can manage users the same way with prosodyctl register.

4. Where end-to-end encryption fits

TLS protects transport. End-to-end encryption protects content: the server relays ciphertext and never sees plaintext. With Prosody you add OpenPGP-based encryption (OX-IM) at the client level — this is exactly what Infium does. The server stores encrypted archives for multi-device sync; keys never leave the device.

Recommendation: run TLS and E2E. They solve different problems. No amount of transport encryption helps if your own server can read everything.

5. Go live

sudo systemctl enable --now prosody
sudo prosodyctl status

Test with any standards-compliant client. You now own your identity and your metadata.

Trade-offs to know

  • You’re the operator now — security updates and backups are on you.
  • No federated address book; invite people you actually know.
  • That’s kind of the point. A sovereign server is built for a community, not for a billion users.

Want this without the ops work? Infium runs a hardened Prosody server with E2E for its members. Request an invite or try the live demo.

← back to infium.net