Cashora
A petty-cash ledger for the cash box you keep, with a balance that proves out at month-end.
For businesses that keep a petty-cash box. Often replaces Ramp, Pleo or Soldo.
Single license $59 · Extended license $129 · paid once, yours for good
What it does
Every balance is exact to the cent, with an over, under or on-float status. A payout larger than the box holds is refused.
The custodian counts the tin and a second person checks it. The month freezes, and the bookkeeper gets one PDF.
The month as a QuickBooks Online or Xero journal, under your own account names. A file you import; nothing is sent anywhere.
Give each box its own link. Whoever spent cash from it hands in the receipt on their phone, with a photo. The custodian records it or turns it down.
Set a limit, and a payout above it waits for an administrator. Approving still cannot take the box below zero.
A photo or PDF of the receipt attaches to the payout itself. It is served only to signed-in staff.
The payout form opens the phone's camera. Switch on reading with your own AI key, and it proposes the payee, date, amount and category. You check each before saving.
Each box has its own custodian, opening float and currency. Front desk, workshop and events kitty, all in one place.
Opening balance, payouts by category, top-ups and closing balance for each box. Export it as PDF or CSV.
Record date, category, amount, payee and a receipt reference for every cash-out. The categories are your own.
Log top-ups toward the float with notes, so the imprest cycle is visible.
Install it from the browser to a phone or tablet home screen. No app store involved.
Also: hardened CSV exports, a REST API and MCP for your own agent, roles with invitation links, an audit trail, two-factor sign-in, backups and dark mode.
What Cashora deliberately doesn’t do.
- Cashora records cash movements; it never processes, moves or holds money.
- One business per installation (many cash boxes inside it).
- Receipts are attached files and text references; reading a receipt uses your own AI key or Ollama server, and is off until you switch it on.
- Counts record what was found; Cashora never invents an entry to make a difference disappear.
What renting costs instead
4 months of Ramp costs what Cashora costs once.
Read Sep 3, 2026 · sourceThe full comparison: every rival, what each does better, and who should stay with them →
Replacing one of these? Ramp alternative · Pleo alternative · Soldo alternative
Release history
For Cashora, 4.1 makes two changes that every app gets. What’s new in 4.1 →
For Cashora, 4.0 means updates from inside the app: the Updates page checks for a new release with your license key, verifies Ownware's signature, takes a backup and… What’s new in 4.0 →
This release opened the box to the people who spend from it. What’s new in 3.3 →
This release took Cashora to month-end: the custodian counts the tin, a second person checks it, the month's figures freeze, and the bookkeeper gets one PDF and a…
The 3.1 wave gave the catalog ways to reach the other side of the transaction.
An agent can list boxes with live balances, open one entry by entry, pull the month-end report and record a payout or top-up over MCP — and the one rule does not…
Cashora 2.0 adds the 2.0 owner layer.
What’s in the zip
The tree as the zip ships it — the working leftovers the packager deletes are not listed
- .htaccess
- API.md
- Dockerfile
- LICENSE.txt
- QUICKSTART.txt
- README.md
- assets/
- bin/
- config.sample.php
- controllers/
- deploy/
- index.php
- install/
- manifest.json
- offline.html
- router.php
- src/
- sw.js
- tests/
- views/
src/ReceiptRead.php: a real module, the first 24 of 186 lines
Chosen as the largest module in src/ that is not one of the shared cores — this product's own logic, not a file every product carries.
<?php
/**
* ReceiptRead.php — 3.2 pass B (sprint 26H): read a receipt photo with the owner's OWN AI key and
* PROPOSE the payee, date, amount and category for a person to check before anything is saved.
*
* Cashora has no AI of its own and sends nothing anywhere by default. When the owner switches
* reading on in Settings and enters their own key (OpenAI or Anthropic) or their own Ollama server,
* "Read the receipt" sends that one photo to that provider and fills in the form. The person
* recording the payout checks every field and presses save; a proposal is never a record.
*
* Key safety (the same rules as Extracta's reader, from this catalog):
* · the key comes from settings and goes only into the provider's auth header;
* · it is never logged, never in an error message, never in the audit trail;
* · the shareable JSON backup leaves it out (its column name matches the credential pattern).
*
* The provider calls are pure transport; propose() does every piece of parsing, in one tested place.
*/
declare(strict_types=1);
final class ReceiptRead
{
public const PROVIDERS = ['openai' => 'OpenAI', 'anthropic' => 'Anthropic', 'ollama' => 'Ollama (your own server)'];
public const DEFAULT_MODELS = ['openai' => 'gpt-4o-mini', 'anthropic' => 'claude-haiku-4-5-20251001', 'ollama' => 'llama3.2-vision'];
private const TIMEOUT = 60;Runs on: 2-minute web installer, plain PHP 8.1+ with MySQL (or SQLite for a trial), no Composer or build step — Docker image included. Tested on PHP 8.3. Or run it in Docker: the Dockerfile is in the zip.
Technical owners can install it with one line and their license key: curl -fsSL https://ownware.io/install.sh | sh -s -- cashora <your license key>
Nothing is obfuscated or encoded; what you read is what runs. Manual · API · the test run
Which license do I need?
It comes down to how many installations you need. Running your own business on one site is the Single license. A second domain of your own, or sites you build or run for other people, is the Extended license.
- Install it on one domain or subdomain you own or operate
- Change the source however you like for that installation
- Run your own business on it commercially, client work included
- Re-download the current build any time from your buyer portal
- A second site, or an installation you hand to a client as theirs, needs the Extended license
- No reselling, redistributing or sublicensing the source
- Not for offering it to other people as a hosted service
- Everything the Single license grants
- Install it on as many domains as you own or operate — no cap on the number
- Up to ten client installations, one per client project, handed over or hosted for each client; for more, buy another Extended license
- White-label: remove or replace the product name and logo in the screens of client installations
- Still no reselling or redistributing the source itself
- Running it as a multi-tenant service others sign up for needs a SaaS agreement
Every download carries the full terms as LICENSE.txt. The complete wording is on the terms page.
After you buy
The app’s Updates page installs a new release with your license key, with the release’s signature checked and a backup taken first. Your download link always serves the current build. Download again any time from your order page or the buyer portal; there is no renewal fee.
Email support for installation and for defects in the code as delivered: a person reads and answers every message. It does not cover custom development or server administration. What support covers
Refunds are handled by Lemon Squeezy as merchant of record, case by case. EU consumers keep the statutory 14-day right until delivery starts. Refund terms
It keeps running: your server, the full PHP source, no license check that can fail. If no stable release is published for 365 days, the domain limit lifts; after three such years your copy becomes MIT-licensed. The terms have the exact wording: continuity.
Questions
Does Cashora move money?
How is the math kept exact?
Can I run more than one cash box?
MySQL or SQLite?
What if the developer disappears?
Can I attach the actual receipt?
Is Cashora a subscription?
We use a spreadsheet on a shared drive. Why change?
What exactly do I get for the money?
Can I take the ledger with me?
Covered in these guides
More about Cashora
Self-hosted petty cash ledger software for the cash box you already keep: an imprest float, categorized disbursements, and a balance that proves out at month-end.
The problem it solves
Petty cash is the last corner of most small businesses still run on paper: a locked drawer, a wad of receipts, and a spreadsheet nobody reconciles until month-end — when the count doesn't match and nobody can say why. Cashora's real competitor is that spreadsheet, so here is the honest comparison: a spreadsheet's =SUM() will happily record a cash box going negative — something a physical tin cannot do — and say nothing. Cashora refuses the impossible payout and tells you which replenishment went unrecorded. The float-vs-balance status is computed, not maintained by a formula someone eventually breaks; the custodian is a first-class field, not a column heading; and each box keeps its own currency, so the EUR tin never contaminates the USD ones. Full expense-management SaaS is a different tool for a different flow — it reimburses employees spending their own money; petty cash is the business's cash leaving a tin.
- Cash counts that don't match the receipts, discovered weeks late
- A spreadsheet that records impossible negative balances without complaint
- No live view of which box is over or under its float
- A monthly SaaS fee for what a simple, exact ledger should do
Every feature
- The receipt, attached to the payout. A photo or PDF of the receipt attaches to the disbursement itself — decided by the file's bytes (PNG, JPEG, WebP, PDF), replaceable while the record is open, and served only to signed-in staff. The paper trail lives on the row it explains.
- Multiple cash boxes. Each box or fund gets its own custodian, opening (imprest) float, and currency — front desk, workshop, events kitty, all in one place.
- Exact running balances. Every balance is computed in integer cents in PHP — no floating-point drift — with a live over / under / on-float status per box. A payout larger than the box balance is refused (a tin cannot go negative), and a box that somehow reads below zero gets its own Overdrawn status, never a routine label.
- Categorized disbursements. Record date, category, amount, payee, description, and a receipt reference for every cash-out, against expense categories you configure.
- Replenishments. Log top-ups toward the float with notes, so the imprest cycle is visible instead of implied.
- Month-end period report. Per-box period report — opening balance, disbursements by category, replenishments, closing balance — exported as PDF and CSV.
- Hardened exports. Dependency-free PDF generation and CSV exports hardened against spreadsheet formula injection.
- Installable mobile app (PWA). Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is not stored offline on the device; what you see is read live.
- Count and close the month. At month-end the custodian counts the tin, note by note or as a total, and a second person checks it. Cashora keeps the expected balance beside the counted one and records a difference as a difference, never an invented entry. The month's figures freeze, nothing dated in it can be changed on that box, and the bookkeeper gets one PDF: the figures, the count sheet with both names, and every payout's receipt status.
- A journal your bookkeeper can import. The month as a QuickBooks Online or Xero journal: each category's spend to its expense account, the total out of the box's cash account, top-ups from your bank, under your own account names. A file you import; nothing is sent anywhere.
- Large payouts wait for approval. Set a limit, and a payout above it waits for an administrator before the cash goes out. Approving still cannot take the box below zero.
- Snap the receipt. The payout form opens the phone's camera. Switch on reading with your own AI key (OpenAI, Anthropic or your own Ollama server) and it fills in the payee, date, amount and category for you to check before saving.
- Receipts from people without an account. Give each cash box its own link. Whoever spent cash from the box hands in the receipt on their phone: their name, the amount, the day, what it was for and a photo. It waits on the box's page until the custodian records it as a payout, with the photo attached, or turns it down. Replace the link or switch it off at any time.
- Updates from inside the app. The Updates page installs a new release with your license key: Ownware's signature is checked, a backup is taken first, and the app puts the previous version back by itself if the update is interrupted or the database step or start-up check of the new version fails. It never checks by itself.
- Backups by themselves. Automatic backups, an optional copy to S3-compatible storage you own, and a weekly check that the latest backup reads back. The Health page names anything that needs attention.
- Own It 4.0.1 — fixes and an up-to-date manual. For Cashora, 4.0.1 fixes an installer that had lost its styling, a rollback that a page opened during an update could stop and a command-line update that ended in an error after putting the previous version back. Its manual, FAQ and QUICKSTART now cover everything 4.0 added, including two Nginx rules that keep the data folder private. Your license covers it: press Check for updates on the Updates page, or download it from your order page.
- Own It 4.0.2 — the installer opens on every host. For Cashora, 4.0.2 fixes a fresh install on an Apache host: the one-page setup at /install/ looped back to itself and never opened, and now it opens. Your license covers it: press Check for updates on the Updates page, or download it from your order page.
Release notes in full
- Own It 4.1: client installations and your other tools. For Cashora, 4.1 makes two changes that every app gets. An Extended license bought from October 4, 2026 covers up to ten client installations, one per client project: hand each one over to the client or host it for them, with the client's logo and colors from the app's branding settings. The API reference now shows how to connect Cashora to Zapier, Make or n8n, using its own webhooks and API key. Your license covers the update: press Check for updates on the Updates page, or download it from your order page.
- Own It 4.0: it updates and backs itself up. For Cashora, 4.0 means updates from inside the app: the Updates page checks for a new release with your license key, verifies Ownware's signature, takes a backup and puts the previous version back by itself if the update is interrupted or the database step or start-up check of the new version fails. A new install can start with a sample business and remove it in one click; backups run by themselves, with an optional offsite copy and a weekly check that the latest one reads back; and the Health page says whether the install is looking after itself.
- Own It 3.3: receipts from people without an account. This release opened the box to the people who spend from it. Each cash box can have its own link, where whoever spent cash from the box hands in the receipt on their phone, with a photo. It waits on the box's page until the custodian records it as a payout, with the photo attached, or turns it down.
- Own It 3.2: the month, counted and closed. This release took Cashora to month-end: the custodian counts the tin, a second person checks it, the month's figures freeze, and the bookkeeper gets one PDF and a QuickBooks Online or Xero journal to import. Payouts above a limit you set wait for an administrator. The payout form opens the phone's camera for the receipt.
- Own It 3.1: the paperwork on the record. The 3.1 wave gave the catalog ways to reach the other side of the transaction. For Cashora, which sends no email at all, it meant the receipt filed on the payout it explains, replaceable while the record is open.
- Own It 3.0: works for your AI, not just for you. An agent can list boxes with live balances, open one entry by entry, pull the month-end report and record a payout or top-up over MCP — and the one rule does not relax: the never-below-zero guard refuses with the same sentence the screen uses, word for word. The month-end PDF pack is what you actually hand a bookkeeper.
- Own It 2.0: API, 2FA, backups, dark mode. Cashora 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase.
Browse self-hosted: Front-office software · Office & finance software · Accountancy & bookkeeping software