Guide
Part of: Club & account
Automatic export: encrypted backups
With the automatic export (Pro plan) your club's full export reaches you regularly – fetched by a script or uploaded by us to your own destination. It is always encrypted with your own key: whoever intercepts the file cannot read it, and we keep it for 24 hours at most.
10 min read
First: no private key, no backup
- Every automatic export is encrypted with age. It can only be opened with your private key (the file club-backup.key) or with your password. If both are lost, all backups are unreadable – we cannot recover them either.
- Keep the private key in two safe places (e.g. an encrypted USB stick in the club safe and the board's password manager) – but not on the computer or NAS that stores the backups.
- Only the owner sets up the automatic export. Every setup step is confirmed with a code we send to the owner's address.
How it works
- Pro plan: the automatic export is part of the Pro plan. The manual full export with a one-time code stays free in every plan.
- Two ways: an export key lets a script on your side (Windows Task Scheduler, Synology, Linux) fetch the export. Or you enter a destination (WebDAV/Nextcloud, SFTP, S3) and we upload the export on a schedule.
- At most one automatic export per day and club – fetching and uploading together.
- Always encrypted: the export is encrypted on our side before it is stored. We delete it right after it is fetched or uploaded, otherwise after 24 hours.
- After every automatic export the owner receives an e-mail with time, size and address – or a weekly summary instead.
- Set it up in the admin console (/admin) under “Organisation” → “Master data” → “Full export” → tab “Automatic”, in the WebApp or app under “Settings” → “Admin area” → “Master data”.
Install age
- age is a small, free encryption tool (age-encryption.org). You need it on the computer where you create the key and open the backups – not on a NAS that only fetches them.
- Windows: run “winget install FiloSottile.age” in the command prompt or PowerShell.
- macOS: “brew install age”. Linux: through the package manager, e.g. “sudo apt install age”.
- Check: “age --version” shows the installed version.
Create a key
age-keygen -o club-backup.key
Public key: age1… ← enter this line in the admin console
Set up encryption – step by step
- Open the tab “Automatic” of the full export and click “Set up encryption”.
- Choose “Public key (recommended)” and paste the line that starts with age1.
- Click “Create test file”. The small file test-automatischer-export.txt.age is saved.
- Decrypt it on your side: “age -d -i club-backup.key test-automatischer-export.txt.age”. A check word such as K7Q4-M2XD appears.
- Enter the check word and click “Confirm check word”. We send a code to the owner; with the code the encryption becomes active.
- This makes sure you can really open your backups – a wrongly copied key shows up now, not in an emergency.
Password instead of a key
Instead of a key you can use a password of at least 12 characters. Open the file with “age -d file.zip.age”; age asks for the password.
Keep in mind: to encrypt, our server has to know the password. We store it only encrypted, but the operator could technically decrypt. With a public key that is impossible – which is why we recommend the key.
Create an export key for a script
- Under “Export keys” enter a name, e.g. “NAS in the clubhouse”, and choose the lifetime (at most 12 months).
- Optional: if you have a fixed IP address, enter it under “only from these IP addresses” – the key then only works from there.
- Click “Create export key” and enter the code from the e-mail.
- The key is shown exactly once. Store it right away in a safe place for the script – not in the script itself.
- We remind you by e-mail 30 and 7 days before it expires. “Renew” creates a new key; the old one keeps working for 7 more days so you can update the script calmly.
Windows: script for Task Scheduler (PowerShell)
# backup-export.ps1 – fetches the encrypted full export
# Install-Module CredentialManager -Scope CurrentUser (einmalig / once)
# New-StoredCredential -Target 'drinklist-export' -UserName export -Password '<Export-Schlüssel / export key>' -Persist LocalMachine
$key = (Get-StoredCredential -Target 'drinklist-export').GetNetworkCredential().Password
$base = 'https://drinklist.app/api/v1'
$h = @{ Authorization = "Bearer $key" }
$export = Invoke-RestMethod -Method Post -Uri "$base/exports" -Headers $h
do { Start-Sleep -Seconds 30; $state = Invoke-RestMethod -Uri "$base/exports/$($export.id)" -Headers $h } while ($state.status -in 'Waiting','Running')
if ($state.status -ne 'Ready') { throw "Export: $($state.status)" }
$file = "D:\Backup\Verein\komplettexport-$(Get-Date -Format yyyy-MM-dd).zip.age"
Invoke-WebRequest -Uri "$base/exports/$($export.id)/download" -Headers $h -OutFile $file
# Open only when needed, on a trusted computer: age -d -i club-backup.key -o export.zip <file>
Set up Windows Task Scheduler
- Save the script as backup-export.ps1, e.g. in C:\Scripts. Store the export key once with New-StoredCredential in the Windows Credential Manager (lines 2 and 3 of the script).
- Open Task Scheduler → “Create Task” → name “Club backup”, “Run whether user is logged on or not”.
- Trigger: daily, e.g. 03:30. Action: program “powershell.exe”, arguments “-NoProfile -ExecutionPolicy Bypass -File C:\Scripts\backup-export.ps1”.
- Run it once by hand and check that a *.zip.age file appears in the backup folder.
Synology/NAS or Linux: script for cron
#!/bin/sh
# backup-export.sh – fetches the encrypted full export
set -eu
KEY=$(cat /volume1/scripts/.drinklist-export-key) # chmod 600
BASE=https://drinklist.app/api/v1
ID=$(curl -fsS -X POST -H "Authorization: Bearer $KEY" "$BASE/exports" | sed -n 's/.*"id":\([0-9]*\).*/\1/p')
while :; do
STATUS=$(curl -fsS -H "Authorization: Bearer $KEY" "$BASE/exports/$ID" | sed -n 's/.*"status":"\([A-Za-z]*\)".*/\1/p')
[ "$STATUS" = "Ready" ] && break
case "$STATUS" in Waiting|Running) sleep 30 ;; *) echo "Export: $STATUS" >&2; exit 1 ;; esac
done
curl -fsS -H "Authorization: Bearer $KEY" -o "/volume1/backup/verein/export-$(date +%F).zip.age" "$BASE/exports/$ID/download"
# The NAS does not need age – files are opened only on a trusted computer
Synology: set up Task Scheduler
- Write the export key to a file (e.g. /volume1/scripts/.drinklist-export-key) and make it readable only for the backup user with “chmod 600”.
- Save the script as /volume1/scripts/backup-export.sh and make it executable (“chmod 700”).
- Control Panel → Task Scheduler → Create → Scheduled Task → User-defined script; user: the backup user; schedule: daily 03:30; command: /volume1/scripts/backup-export.sh.
- On Linux a crontab entry is enough: “30 3 * * * /volume1/scripts/backup-export.sh”.
No script: we upload to your destination
- Under “Destination” choose the type: WebDAV (Nextcloud, Synology with the WebDAV Server package, https port 5006), SFTP or S3.
- Nextcloud: use the folder address such as https://cloud.club.org/remote.php/dav/files/backup/drinklist/ and an app password of a separate backup user. Create the folder first.
- SFTP: enter server, port (22 or 2222), folder, user and password or a private SSH key. We remember the server's key on the first test – if it changes, we stop for security reasons.
- S3: endpoint (empty = Amazon), region, bucket and credentials that may only write (PutObject) – they need neither read nor delete.
- Choose the frequency (daily or weekly) and the time – it applies in your club's time zone.
- “Test connection and set up”: we write a small test file. If that works, the code goes to the owner; with the code the destination becomes active.
- If an upload fails, we retry three times and send an e-mail. After three failed runs in a row we pause the destination until you release it again.
Open a backup (decrypt)
age -d -i club-backup.key -o full-export.zip komplettexport-2026-10-07.zip.age
age -d -o full-export.zip komplettexport-2026-10-07.zip.age # password variant
Security at a glance
- An export key can only fetch the encrypted export – no accounts, no bookings, no other data.
- Only the owner can create one, confirmed with a code by e-mail; administrators and support cannot create export keys.
- Access from a new country or repeated rejected requests pause the key; the owner gets an e-mail and can release or revoke it.
- If the organisation is locked for a violation, the automatic export is paused; the manual export in the admin console stays available.
- If the owner changes, keys and destinations stay. The new owner gets an e-mail and can revoke them and set up the encryption again.
If it does not work
- 429 “only one automatic export per day”: there already was an automatic export today – try again tomorrow.
- 403 “export key paused”: abuse detection paused the key. The owner releases it in the admin console with “Enable again”.
- 409 on download: the export was already fetched or deleted after 24 hours – request a new one the next day.
- 423: the organisation is locked; please contact support.
- Instead of polling in the script, a webhook can report the event “export.ready” (admin console → Integrations).
Still stuck?
If a guide leaves a question open, or something looks different from the description: open a ticket and we will reply inside it. Support runs through tickets only, not by email.