GolangTAK documentation
GolangTAK is one program that runs your TAK server. You install it with one command, open its dashboard in a browser, and connect your devices with a QR code. This page walks through everything in plain steps.
1. Install
Paste one command. It installs GolangTAK as a service that starts at boot, opens the firewall, creates the certificate authority and the administrator account, and tests every port before it finishes.
Linux, Raspberry Pi, cloud server, macOS
curl -fsSL https://raw.githubusercontent.com/grangedevgroup-code/TAK-Backend/main/GolangTAK/scripts/install.sh | shWindows (PowerShell)
irm https://raw.githubusercontent.com/grangedevgroup-code/TAK-Backend/main/GolangTAK/scripts/install.ps1 | iexLinux without curl, and FreeBSD
wget -qO- https://raw.githubusercontent.com/grangedevgroup-code/TAK-Backend/main/GolangTAK/scripts/install.sh | shfetch -qo - https://raw.githubusercontent.com/grangedevgroup-code/TAK-Backend/main/GolangTAK/scripts/install.sh | shWhen it finishes it prints the dashboard address, the administrator user name and password, and a QR code for iTAK. Nothing else needs to be installed: no Docker, no database, no Java or Python.
Running on a cloud server? Also allow the ports in your provider's firewall or security group. The list is under Troubleshooting.
2. Sign in to the dashboard
- Open
https://SERVER:8446in a browser, using the address the installer printed. On a trusted networkhttp://SERVER:8080also works. - Your browser warns about the certificate the first time, because the server made its own. Continue to the site, or set up a trusted certificate under Let's Encrypt.
- Sign in as
adminwith the printed password, then choose your own password when asked.
Lost the password? It stays in admin-password.txt in the data folder until you change it: /var/lib/golangtak on Linux, C:\ProgramData\GolangTAK on Windows.
The dashboard is in English, Spanish, French, German, Portuguese and Ukrainian. Change the language on the sign-in page or under My account. Turn on two-step sign-in there too.
3. Connect devices
Open Connect a device in the dashboard. Pick the user, then use whichever way suits the device.
ATAK
Settings, Network, Servers, Add, Scan QR, and scan the enrollment code. ATAK signs in and gets its own certificate. The code works once.
iTAK
Settings, Network, Servers, Connect with QR, and scan the iTAK code. Then sign in with the user name and password.
WinTAK
Download the connection package and import it, or add a server on port 8089 with Enroll for client certificate and Use authentication turned on.
Any device
Copy a connection package (a .zip) to the device and import it. ATAK: Import, Local SD. iTAK: Upload server package.
Other CoT software
Connect to TCP port 8087, SSL port 8089 with a certificate, UDP 8087, or CoT over WebSocket on port 8090.
Devices appear under Online now and on the Map. Units are drawn with MIL-STD-2525 symbols.
4. Users and groups
Give each person their own user under Users. Groups are channels: people see traffic only from the groups they share. Each user has groups they receive from and groups they send to.
- Sign in with company accounts: Settings, Directory sign-in for LDAP or Active Directory.
- Let people sign up themselves: Settings, Email and accounts, with optional approval and allowed email domains.
- Scripts and tools use an API token from API tokens instead of a password.
5. Link other servers
Open Server links. Traffic flows both ways, and loop protection keeps messages from echoing back.
Another GolangTAK
Choose Create a link code on one server and paste it on the other. Certificates and trust are set up for you.
TAK Server
Federation version 1 (port 9000) or version 2 (port 9001, gRPC), in either direction. Exchange CA certificates under Federation. Missions and files are shared over version 2.
OpenTAKServer
A link to its SSL port 8089 with a certificate it issued, or its TCP port 8088 on a trusted network.
FreeTAKServer
A link to its TCP port 8087, or SSL 8089 with a certificate.
6. Video
The video server is built in. Publish with rtsp://SERVER:8554/live/NAME, or from drone apps and OBS with rtmp://SERVER:1935/live/NAME?user=USER&pass=PASSWORD. Sign in with a GolangTAK user name and password.
Every stream appears in each TAK client's video list and on the dashboard's Video page, where it plays in the browser. Press Record on a stream, or record everything automatically under Settings, Video server. To relay an IP camera, add it as a pull source.
7. Voice
Mumble, Mumla and the TAK voice plugins connect to port 64738 with the same user name and password as TAK. Each group has its own channel, so people talk with the same team they share a map with.
8. Feeds and trackers
Turn feeds on under Settings, Data feeds, or add your own under Feeds and layers.
Aircraft and ships
From ADS-B exchanges (adsb.lol by default) and AISHub, or your own receivers: dump1090, readsb, tar1090, rtl_ais and AIS-catcher.
Phone trackers
Phones running Traccar Client report to port 5055, and every device on a Traccar server can be shown.
Meshtastic
Point gateway radios' MQTT setting at the server. Mesh positions and chat appear in TAK, and TAK traffic can go out to the mesh.
Sensors
CoT over TCP, TLS, UDP or multicast, each on its own port with its own groups.
Map layers
Tile, WMS and WMTS sources offered to TAK clients and missions.
9. Telegram
- Create a bot with @BotFather in Telegram and copy its token.
- Add the bot to your group and send
/startthere. - Get the group's ID (bots such as @getidsbot show it; groups start with
-100). - Enter both under Settings, Telegram, save, and restart when asked.
Group messages appear in TAK's All Chat Rooms and the other way round, emergencies are posted to the group, and locations people share in Telegram show on the map.
10. Reach it from anywhere
ZeroTier
No port forwarding needed. Create a network at my.zerotier.com and add its ID to the install command. Devices running the ZeroTier app connect to the server's ZeroTier address.
Let's Encrypt
Have a domain name? Enter it under Settings, Let's Encrypt for a certificate browsers trust. Port 80 must be reachable.
Port forwarding
Forward 8089 for TAK devices and 8446 for enrollment and the dashboard. Add the others from the port list only if you use them.
curl -fsSL https://raw.githubusercontent.com/grangedevgroup-code/TAK-Backend/main/GolangTAK/scripts/install.sh | GOLANGTAK_ZEROTIER=NETWORK_ID sh11. Files, missions and checklists
Data packages shared from devices appear under Files, where you can upload, send to devices or delete them. Missions (Data Sync) are shared collections of map items and files with subscribers, roles, invitations and change history. ExCheck checklists work with the ATAK and WinTAK plugins. Repeated objects (choose an item on the map and select Repeat) are sent to every device that connects.
Publish ATAK plugins through the built-in update server, and push settings to devices with device profiles, both under Plugins and profiles.
12. APIs and plugins
TAK Server API
The Marti API used by TAK clients and CloudTAK, including OAuth sign-in, missions, files, video, data feeds, certificates and users.
FreeTAKServer API
On port 19023: map objects, chat, presence, routes, emergencies, drones and sensor points, video, KML points, objects in a zone, repeated messages, data packages, missions, ExCheck, system users and federations. Send an API token as Authorization: Bearer TOKEN.
Server plugins
Your own programs run next to the server with their own API token, settings form and dashboard page. Install one with golangtak plugin install FOLDER|ZIP|URL. A Go SDK is included.
13. Commands
| Command | What it does |
|---|---|
golangtak status | Service state, addresses and connected devices |
golangtak user add NAME | Add a user; user list, passwd, del and package work the same way |
golangtak qr NAME | Print a QR code for a device in the terminal |
golangtak peer invite NAME | Make a link code for another GolangTAK; peer join CODE uses it |
golangtak config set KEY VALUE | Change a setting, for example config set address tak.example.org |
golangtak logs -f | Follow the server log |
golangtak selftest | Check that every port answers |
golangtak backup | Save settings, users, certificates and missions to a zip file |
golangtak zerotier join ID | Join a ZeroTier network |
golangtak bench | Load test with simulated clients |
golangtak help COMMAND | Every option of a command |
On Linux and macOS put sudo in front of commands that change things.
14. Update, back up and remove
- Update: run the install command again. Settings, users, certificates and data are kept.
- Back up: Settings, Maintenance, Download backup, or
golangtak backup. - Background jobs: data cleanup, certificate renewal and feeds are listed under Settings, Maintenance, where each can be run now or paused.
- Remove:
golangtak uninstall, orgolangtak uninstall --purgeto delete all data too.
15. Troubleshooting
A device cannot connect
Run golangtak selftest. If it passes, the problem is between the device and the server: a cloud firewall, a router, or the wrong address. Check the address under Settings, General.
Certificate errors
The server address changed? Use Settings, Maintenance, Renew the server certificate and enroll the device again.
People do not see each other
They are in different groups. Check both users' send and receive groups under Users.
Something stopped working
Open Logs in the dashboard, or run golangtak logs -f. Warnings are bold and errors highlighted.
| Port | Used for |
|---|---|
8089 TCP | TAK devices with certificates (SSL) |
8087 TCP and UDP | TAK without encryption, and CoT datagrams |
8446 TCP | Certificate enrollment and the dashboard over HTTPS |
8443 TCP | TAK API with certificates (Data Sync, files, update server) |
8080 TCP | Dashboard and API over HTTP |
8090 TCP | CoT over WebSocket |
19023 TCP | FreeTAKServer API |
9000, 9001 TCP | TAK Server federation version 1 and 2 (off by default) |
8554, 1935 TCP | Video: RTSP and RTMP |
64738 TCP and UDP | Voice (Mumble) |
1883 TCP | Meshtastic MQTT (off by default) |
Compared with OpenTAKServer and FreeTAKServer
Based on each project's own documentation. GolangTAK covers every feature listed for both, in one program.
| Feature | GolangTAK | OpenTAKServer | FreeTAKServer |
|---|---|---|---|
| TCP and SSL streaming, CoT routing | Yes | Yes | Yes |
| TAK Protocol (protobuf) | Yes | Not listed | In 2.x |
| Certificate authority made at install | Yes | Yes | No |
| Certificate enrollment, QR codes | Yes | Yes | No |
| Federation with TAK Server (v1 and v2) | Yes | Planned | Yes |
| Data packages, Data Sync, missions | Yes | Yes | Yes |
| ExCheck checklists | Yes | Coming soon | Yes |
| Video server built in, recording and playback | Yes | Yes (MediaMTX) | Separate |
| Voice server built in | Yes | Mumble sign-in | Separate |
| Groups and channels, LDAP / Active Directory | Yes | Yes | In 2.x |
| Two-step sign-in, email registration | Yes | Yes | No |
| ADS-B and AIS, your own SDR receivers | Yes | APIs only | No |
| Traccar trackers | Yes | Planned | No |
| Meshtastic | Yes | Yes | No |
| Telegram | Yes | No | In 2.x |
| Plugin update server, device profiles | Yes | Yes | No |
| Server plugins | Yes | Yes | No |
| FreeTAKServer REST API | Yes | No | Yes |
| MIL-STD-2525 symbols, web map | Yes | Yes | Yes |
| Let's Encrypt, ZeroTier | Yes | Yes | No |
| Dashboard languages | 6 | Several | English |
| Install | One command, no dependencies | Script with Python, PostgreSQL, RabbitMQ, nginx, MediaMTX | Python, or Docker / Ansible |
GolangTAK is an independent open source project and is not affiliated with OpenTAKServer, FreeTAKServer, tak.gov or the TAK Product Center.