Skip to content

Guide

Part of: Club & account

Automatic export: encrypted backups

With the automatic export (Pro plan) your club's full export reaches you regularly – fetched by a script or uploaded by us to your own destination. It is always encrypted with your own key: whoever intercepts the file cannot read it, and we keep it for 24 hours at most.

10 min read

First: no private key, no backup

  • Every automatic export is encrypted with age. It can only be opened with your private key (the file club-backup.key) or with your password. If both are lost, all backups are unreadable – we cannot recover them either.
  • Keep the private key in two safe places (e.g. an encrypted USB stick in the club safe and the board's password manager) – but not on the computer or NAS that stores the backups.
  • Only the owner sets up the automatic export. Every setup step is confirmed with a code we send to the owner's address.

How it works

  • Pro plan: the automatic export is part of the Pro plan. The manual full export with a one-time code stays free in every plan.
  • Two ways: an export key lets a script on your side (Windows Task Scheduler, Synology, Linux) fetch the export. Or you enter a destination (WebDAV/Nextcloud, SFTP, S3) and we upload the export on a schedule.
  • At most one automatic export per day and club – fetching and uploading together.
  • Always encrypted: the export is encrypted on our side before it is stored. We delete it right after it is fetched or uploaded, otherwise after 24 hours.
  • After every automatic export the owner receives an e-mail with time, size and address – or a weekly summary instead.
  • Set it up in the admin console (/admin) under “Organisation” → “Master data” → “Full export” → tab “Automatic”, in the WebApp or app under “Settings” → “Admin area” → “Master data”.

Install age

  1. age is a small, free encryption tool (age-encryption.org). You need it on the computer where you create the key and open the backups – not on a NAS that only fetches them.
  2. Windows: run “winget install FiloSottile.age” in the command prompt or PowerShell.
  3. macOS: “brew install age”. Linux: through the package manager, e.g. “sudo apt install age”.
  4. Check: “age --version” shows the installed version.

Create a key

age-keygen -o club-backup.key
Public key: age1…   ← enter this line in the admin console

Set up encryption – step by step

  1. Open the tab “Automatic” of the full export and click “Set up encryption”.
  2. Choose “Public key (recommended)” and paste the line that starts with age1.
  3. Click “Create test file”. The small file test-automatischer-export.txt.age is saved.
  4. Decrypt it on your side: “age -d -i club-backup.key test-automatischer-export.txt.age”. A check word such as K7Q4-M2XD appears.
  5. Enter the check word and click “Confirm check word”. We send a code to the owner; with the code the encryption becomes active.
  6. This makes sure you can really open your backups – a wrongly copied key shows up now, not in an emergency.

Password instead of a key

Instead of a key you can use a password of at least 12 characters. Open the file with “age -d file.zip.age”; age asks for the password.

Keep in mind: to encrypt, our server has to know the password. We store it only encrypted, but the operator could technically decrypt. With a public key that is impossible – which is why we recommend the key.

Create an export key for a script

  1. Under “Export keys” enter a name, e.g. “NAS in the clubhouse”, and choose the lifetime (at most 12 months).
  2. Optional: if you have a fixed IP address, enter it under “only from these IP addresses” – the key then only works from there.
  3. Click “Create export key” and enter the code from the e-mail.
  4. The key is shown exactly once. Store it right away in a safe place for the script – not in the script itself.
  5. We remind you by e-mail 30 and 7 days before it expires. “Renew” creates a new key; the old one keeps working for 7 more days so you can update the script calmly.

Windows: script for Task Scheduler (PowerShell)

# backup-export.ps1 – fetches the encrypted full export
# Install-Module CredentialManager -Scope CurrentUser   (einmalig / once)
# New-StoredCredential -Target 'drinklist-export' -UserName export -Password '<Export-Schlüssel / export key>' -Persist LocalMachine
$key  = (Get-StoredCredential -Target 'drinklist-export').GetNetworkCredential().Password
$base = 'https://drinklist.app/api/v1'
$h    = @{ Authorization = "Bearer $key" }
$export = Invoke-RestMethod -Method Post -Uri "$base/exports" -Headers $h
do { Start-Sleep -Seconds 30; $state = Invoke-RestMethod -Uri "$base/exports/$($export.id)" -Headers $h } while ($state.status -in 'Waiting','Running')
if ($state.status -ne 'Ready') { throw "Export: $($state.status)" }
$file = "D:\Backup\Verein\komplettexport-$(Get-Date -Format yyyy-MM-dd).zip.age"
Invoke-WebRequest -Uri "$base/exports/$($export.id)/download" -Headers $h -OutFile $file
# Open only when needed, on a trusted computer: age -d -i club-backup.key -o export.zip <file>

Set up Windows Task Scheduler

  1. Save the script as backup-export.ps1, e.g. in C:\Scripts. Store the export key once with New-StoredCredential in the Windows Credential Manager (lines 2 and 3 of the script).
  2. Open Task Scheduler → “Create Task” → name “Club backup”, “Run whether user is logged on or not”.
  3. Trigger: daily, e.g. 03:30. Action: program “powershell.exe”, arguments “-NoProfile -ExecutionPolicy Bypass -File C:\Scripts\backup-export.ps1”.
  4. Run it once by hand and check that a *.zip.age file appears in the backup folder.

Synology/NAS or Linux: script for cron

#!/bin/sh
# backup-export.sh – fetches the encrypted full export
set -eu
KEY=$(cat /volume1/scripts/.drinklist-export-key)   # chmod 600
BASE=https://drinklist.app/api/v1
ID=$(curl -fsS -X POST -H "Authorization: Bearer $KEY" "$BASE/exports" | sed -n 's/.*"id":\([0-9]*\).*/\1/p')
while :; do
  STATUS=$(curl -fsS -H "Authorization: Bearer $KEY" "$BASE/exports/$ID" | sed -n 's/.*"status":"\([A-Za-z]*\)".*/\1/p')
  [ "$STATUS" = "Ready" ] && break
  case "$STATUS" in Waiting|Running) sleep 30 ;; *) echo "Export: $STATUS" >&2; exit 1 ;; esac
done
curl -fsS -H "Authorization: Bearer $KEY" -o "/volume1/backup/verein/export-$(date +%F).zip.age" "$BASE/exports/$ID/download"
# The NAS does not need age – files are opened only on a trusted computer

Synology: set up Task Scheduler

  1. Write the export key to a file (e.g. /volume1/scripts/.drinklist-export-key) and make it readable only for the backup user with “chmod 600”.
  2. Save the script as /volume1/scripts/backup-export.sh and make it executable (“chmod 700”).
  3. Control Panel → Task Scheduler → Create → Scheduled Task → User-defined script; user: the backup user; schedule: daily 03:30; command: /volume1/scripts/backup-export.sh.
  4. On Linux a crontab entry is enough: “30 3 * * * /volume1/scripts/backup-export.sh”.

No script: we upload to your destination

  1. Under “Destination” choose the type: WebDAV (Nextcloud, Synology with the WebDAV Server package, https port 5006), SFTP or S3.
  2. Nextcloud: use the folder address such as https://cloud.club.org/remote.php/dav/files/backup/drinklist/ and an app password of a separate backup user. Create the folder first.
  3. SFTP: enter server, port (22 or 2222), folder, user and password or a private SSH key. We remember the server's key on the first test – if it changes, we stop for security reasons.
  4. S3: endpoint (empty = Amazon), region, bucket and credentials that may only write (PutObject) – they need neither read nor delete.
  5. Choose the frequency (daily or weekly) and the time – it applies in your club's time zone.
  6. “Test connection and set up”: we write a small test file. If that works, the code goes to the owner; with the code the destination becomes active.
  7. If an upload fails, we retry three times and send an e-mail. After three failed runs in a row we pause the destination until you release it again.

Open a backup (decrypt)

age -d -i club-backup.key -o full-export.zip komplettexport-2026-10-07.zip.age
age -d -o full-export.zip komplettexport-2026-10-07.zip.age   # password variant

Security at a glance

  • An export key can only fetch the encrypted export – no accounts, no bookings, no other data.
  • Only the owner can create one, confirmed with a code by e-mail; administrators and support cannot create export keys.
  • Access from a new country or repeated rejected requests pause the key; the owner gets an e-mail and can release or revoke it.
  • If the organisation is locked for a violation, the automatic export is paused; the manual export in the admin console stays available.
  • If the owner changes, keys and destinations stay. The new owner gets an e-mail and can revoke them and set up the encryption again.

If it does not work

  • 429 “only one automatic export per day”: there already was an automatic export today – try again tomorrow.
  • 403 “export key paused”: abuse detection paused the key. The owner releases it in the admin console with “Enable again”.
  • 409 on download: the export was already fetched or deleted after 24 hours – request a new one the next day.
  • 423: the organisation is locked; please contact support.
  • Instead of polling in the script, a webhook can report the event “export.ready” (admin console → Integrations).

Still stuck?

If a guide leaves a question open, or something looks different from the description: open a ticket and we will reply inside it. Support runs through tickets only, not by email.