Self-hosted SDKs
Enterprise feature
This feature is available only for the Enterprise plan. To get started, reach out to support@buildwithfern.com.
Fern SDK generation runs on Fern’s infrastructure by default. Self-hosting allows you to run SDK generation on your own infrastructure. Use self-hosting if your organization:
- Operates without internet access
- Has strict compliance or security requirements
- Needs full control over your SDK generation process
When you self-host, you’re responsible for infrastructure management, SDK distribution, and computing SDK version numbers. Self-hosted SDK generation includes all Fern SDK features.
Unless you have specific requirements that prevent using Fern’s default hosting, we recommend using our managed cloud generation solution for easier setup and maintenance.
Infrastructure requirements
Each machine that runs fern generate --local needs:
- A Docker runtime. Generation runs inside a generator container, so a Docker daemon must be available (
docker pssucceeds). In CI, use a runner with Docker preinstalled or a Docker-in-Docker service. - A
FERN_TOKEN. Organization verification requires a Fern API key, injected as theFERN_TOKENenvironment variable. Store it as a CI secret rather than in the repo. - Outbound network access to two endpoints. The CLI verifies your organization with Fern and pulls the generator image. No API definition leaves your infrastructure. Air-gapped environments must mirror generator images into a private registry reachable from the runner.
- Write access to the output location. Local-file-system output writes to disk; GitHub output needs a
GITHUB_TOKENwith write access to the SDK repository.
Setup
This page assumes that you have:
- An initialized
fernfolder. See Set up thefernfolder. - SDK generators configured in
generators.yml. See language-specific quickstarts: TypeScript, Python, Go, Java, etc.
Self-hosted SDK generation allows you to output to your local file system or push directly to a GitHub repository you control. Follow these steps to set up and run local generation:
Ensure Docker is running
Verify that a Docker daemon is running on your machine, as SDK generation runs inside a Docker container:
Generate a Fern API key
Generate a Fern API key, which is required for local generation to verify your organization. Create one from the API keys page in the Dashboard, or run fern token in your terminal:
The API key is specific to your organization defined in fern.config.json and doesn’t expire.
Configure output location
Configure your generators.yml to output SDKs to your local file system or a GitHub repository you control.
Local file system
GitHub repository
Output generated SDKs directly to a local directory:
Set up authentication
Configure authentication based on your chosen output location.
Local file system
GitHub repository
Set your Fern API key as an environment variable:
Configure version computation
Cloud generation picks SDK version numbers automatically. With self-hosting, your pipeline computes the next version itself — see Self-hosted SDK versioning for the two supported workflows.
Run generation locally
Use the --local flag to generate SDKs locally instead of using Fern’s cloud infrastructure. You can combine --local with --group to generate specific SDKs locally.
To pull generator images from a private registry your organization controls instead of Docker Hub, see Private registry setup.
Private registry setup
By default, fern generate --local pulls generator Docker images from Docker Hub. Organizations that restrict outbound traffic or require vetted images can mirror Fern’s generator images into a private registry and point the CLI at it. Remote (cloud) generation doesn’t support custom registries.
Mirror the generator image
Pull each generator image at the version you intend to use, retag it for your registry, and push. The CLI resolves the full reference as {registry}/{name}:{version}.
Reference the registry in generators.yml
Replace the generator’s name field with an image object containing name and registry:
The image.name must be a recognized Fern generator name (for example, fern-python-sdk or fern-typescript-sdk) so the CLI can resolve the correct IR version, and version must match a published Fern generator version. Generators configured with an image are skipped during fern generator upgrade, so bump their versions manually and re-mirror the matching image when you upgrade.
How it works
When you run fern generate --local, the Fern CLI executes SDK generation on your local machine instead of using Fern’s cloud infrastructure.
The underlying SDK generation architecture is the same whether you use cloud or self-hosted generation. See the expanded architecture diagram for details.
The self-hosted process works as follows:
- Organization verification (network call) - The CLI verifies your organization registration with Fern
- Download generator image (network call if not cached) - The CLI downloads the generator’s Docker image if not already available locally
- Generate SDK (local) - The CLI runs the generator container locally to produce SDK files based on your API definition and
generators.ymlconfiguration - Output SDK (local) - Generated SDK files are saved to your configured output location (local file system or GitHub repository)
Steps 1 and 2 are the only network calls made when using the --local flag. No API definition or specification data is sent over the network: all SDK generation happens locally on your machine.