{{sidenavigation.sidenavigationExpandLabel}}
{{getMsg('Help_YouAreHere')}}: /  {{page.title}} {{page.title}}
{{$root.getMsg("downLoadHelpAsPdf")}} {{helpModel.downloadHelpPdfDataStatus}}

ONLYOFFICE on Windows

Last updated: June 2026
Compatibility setup: This page describes a fallback path with a separate ONLYOFFICE Docs Community Edition server on Windows Server. The recommended primary setup path for Euro-Office is Euro-Office with Docker.

This page describes a standard setup with a separate ONLYOFFICE Docs Community Edition server on Windows Server and an i-net HelpDesk server that reaches it through fixed HTTPS URLs.

Overview

Important for stable operation:

  • Both public browser-facing sides should run over HTTPS: the public HelpDesk URL and the public document server URL.
  • The JWT secret and the HelpDesk session signing secret are two different secrets. Both should be set deliberately.
  • Internal URLs are only needed when reverse proxying, NAT, Docker host names, or separate internal and external networks are involved.

Install the document server on Windows

According to ONLYOFFICE, the Community Edition on Windows requires 64-bit Windows Server 2016 or later. The standard installation uses onlyoffice-documentserver.exe and installs the document server to C:\Program Files\ONLYOFFICE\DocumentServer\ by default.

After installation, the start page should be reachable via http://localhost or the server address.

Switch ONLYOFFICE to HTTPS

For the integration, the document server should be exposed through a real HTTPS URL, for example https://docs.example.com. According to ONLYOFFICE, the HTTPS switch on Windows is done through the document server's NGINX configuration:

  1. Stop the DsProxySvc service.
  2. Copy %ProgramFiles%\ONLYOFFICE\DocumentServer\nginx\conf\ds-ssl.conf.tmpl to %ProgramFiles%\ONLYOFFICE\DocumentServer\nginx\conf\ds.conf.
  3. In ds.conf, replace the placeholders for certificate, private key, optional client verification, HSTS, and Diffie-Hellman parameters.
  4. Start the DsProxySvc service again.
  5. Open port 443 in the firewall.
  6. Afterwards, run %ProgramFiles%\ONLYOFFICE\DocumentServer\bin\documentserver-update-securelink.bat.

This means the ds-ssl template is the authoritative basis for SSL on the ONLYOFFICE NGINX side.

Configure JWT explicitly on the ONLYOFFICE server

ONLYOFFICE uses JWT to protect the editor configuration and callback communication. This documentation assumes a current ONLYOFFICE Docs version with active JWT support. For a reproducible integration, it is better to use a consciously chosen fixed value.

On Windows, the configuration is stored in:

  • %ProgramFiles%\ONLYOFFICE\DocumentServer\config\local.json

The same secret value should be set in all three places:

  • services.CoAuthoring.secret.inbox.string
  • services.CoAuthoring.secret.outbox.string
  • services.CoAuthoring.secret.session.string

After changing local.json, restart the ONLYOFFICE services so the configuration takes effect.

Configure HelpDesk

In the default configuration view, these fields should be set:

  • Document server URL: the public HTTPS URL of the ONLYOFFICE server, for example https://docs.example.com
  • Document server JWT secret: the same fixed JWT value as in local.json
  • Session signing secret: a dedicated fixed HelpDesk secret for signing Euro-Office session tokens

In the simple standard case, these fields stay empty:

  • Internal document server URL
  • Internal HelpDesk URL
  • Document server API URL

Important: the HelpDesk Session signing secret is not the same value as services.CoAuthoring.secret.session.string on the ONLYOFFICE server. The first secures the editor launch tokens generated by HelpDesk, while the second belongs to ONLYOFFICE's internal JWT configuration.

Verify HTTPS and reachability rules

For the standard setup, the following connections must work:

  • The browser reaches HelpDesk via its public HTTPS URL.
  • The browser reaches the document server via its public HTTPS URL.
  • The ONLYOFFICE server reaches HelpDesk for content downloads and callbacks.

If a reverse proxy is involved, ONLYOFFICE states that the X-Forwarded-Proto and X-Forwarded-Host headers should be forwarded correctly.

If either side has additional origin, CORS, CSP, or frame restrictions, the corresponding public origins need to be allowed on both sides, typically:

  • https://helpdesk.example.com
  • https://docs.example.com

On the HelpDesk side, this is configured through the web server settings. On the document server side, it may need to be configured in the proxy, web server, or security settings of the deployed system.

Why HTTPS on both sides matters

If HelpDesk or the document server runs over plain HTTP, browser and proxy behavior can cause problems with mixed content, cookies, embedded iframes, WebSocket connections, or callback requests. For the standard installation, both public URLs should therefore consistently use HTTPS.

Test the connection

  1. Save the configuration in HelpDesk.
  2. Open an editable attachment such as .docx or .xlsx.
  3. Verify that the editor loads in the browser.
  4. Save a small change and confirm that the callback writes the file back to HelpDesk.
  5. If the editor does not start, first verify HTTPS, JWT value equality, and reachability of the HelpDesk callback URL.

When advanced fields become necessary

The advanced URL fields are only needed when the browser, the HelpDesk server, and the document server cannot all use the same addresses, for example because of reverse proxies, NAT, Docker host names, or separate internal and external networks.

Then the fields apply as follows:

  • Internal document server URL for server-side downloads from HelpDesk to the document server
  • Internal HelpDesk URL for downloads and callbacks from the document server back to HelpDesk
  • Document server API URL only if the API script is served from a non-standard location

Official ONLYOFFICE References

i-net Clear Reports
This application uses cookies to allow login. By continuing to use this application, you agree to the use of cookies.


Help