Running your own chat server used to mean serious ops work. Prosody makes it approachable: a lightweight XMPP server in pure Lua that runs happily on a $5 VPS. This guide walks through a real, working setup — the same shape our own infrastructure uses.
Before you start
You need:
- A small VPS (1 GB RAM is plenty for a handful of accounts).
- A domain, e.g.
chat.example.com. - A wildcard or dedicated TLS certificate for it.
We’ll use Debian/Ubuntu. All commands assume you’re logged in as a user with sudo.
1. Install and configure Prosody
sudo apt update
sudo apt install prosody
Prosody’s config lives in /etc/prosody/prosody.cfg.lua. Set your virtual host:
VirtualHost "chat.example.com"
admins = { "admin@chat.example.com" }
Enable the modules you care about. For a trustworthy setup we recommend:
modules_enabled = {
"roster"; -- contact lists
"saslauth"; -- authentication
"tls"; -- STARTTLS
"carbons"; -- multi-device sync
"mam"; -- message archive
"http_upload"; -- file sharing
}
2. TLS — non-negotiable
Put your certificate and key where Prosody expects them:
sudo mkdir -p /etc/prosody/certs
sudo cp /path/to/fullchain.pem /etc/prosody/certs/chat.example.com.crt
sudo cp /path/to/privkey.pem /etc/prosody/certs/chat.example.com.key
Then in the config:
-- global cert settings
certificates = "/etc/prosody/certs"
Restart and verify with openssl s_client that STARTTLS is offered.
3. Create your first accounts
XMPP accounts are just JIDs with a password:
sudo prosodyctl adduser me@chat.example.com
Account management and invites are admin tasks. In our case those live in a small admin layer on top of Prosody so invite tokens stay one-time and private — you can manage users the same way with prosodyctl register.
4. Where end-to-end encryption fits
TLS protects transport. End-to-end encryption protects content: the server relays ciphertext and never sees plaintext. With Prosody you add OpenPGP-based encryption (OX-IM) at the client level — this is exactly what Infium does. The server stores encrypted archives for multi-device sync; keys never leave the device.
Recommendation: run TLS and E2E. They solve different problems. No amount of transport encryption helps if your own server can read everything.
5. Go live
sudo systemctl enable --now prosody
sudo prosodyctl status
Test with any standards-compliant client. You now own your identity and your metadata.
Trade-offs to know
- You’re the operator now — security updates and backups are on you.
- No federated address book; invite people you actually know.
- That’s kind of the point. A sovereign server is built for a community, not for a billion users.
Want this without the ops work? Infium runs a hardened Prosody server with E2E for its members. Request an invite or try the live demo.