Clockora
Staff clock in from their phone or a shared tablet; you approve exact hours, never a pay figure.
For studios, agencies, support teams and workshops. Often replaces TimeCamp, Hubstaff, Toggl Track, Clockify or Harvest.
Single license $69 · Extended license $149 · paid once, yours for good
What it does
Each person can have their own My time login: clock in, clock out, see their week, submit. They see their own hours only.
Open a kiosk link on a shared tablet and staff clock in with their own PIN. No login, no location, no photo.
Submitted time arrives as one card per person and week, with the total against their overtime threshold. One tap approves what the card shows.
Kiosk, phone or timesheet, every clock-out is checked for overlaps, a day over 24 hours and locked periods. The clock keeps running rather than losing time.
A week or any date range, with totals per employee and per project reconciled to the minute. Time is stored as whole minutes.
Start and end an unpaid break from the timesheet, a phone or the tablet. The worked hours are net.
Set a weekly overtime threshold and weeks over it are flagged. It is a flag, never a pay figure.
One row per person, one per person per day, or decimal hours beside the exact minutes. CSV or Excel.
Entries move from submitted to approved or rejected, per entry or in bulk. The approver and the time are kept.
Approve or reject and the person can be told by email, through your own SMTP. Off by default.
A daily scheduled job reminds people whose week has hours but no submitted timesheet. Each person is reminded once per period.
Use the live timer, start and end times, or a manual duration. Entries that cross midnight are handled.
Also: projects as simple labels, a per-employee PDF timesheet, decimal hours in the CSV, locked pay periods, and a phone install from the browser.
What Clockora deliberately doesn’t do.
- Single-tenant: one business per installation.
- Hours only — no invoicing, pricing, rates, wages or payroll. No email can contain a pay figure because the product stores none.
- Overlap detection applies to clock entries (start + end); manual-duration entries have no position on the clock, so a per-employee-per-day 24-hour ceiling refuses the impossible day instead.
- Email sends through your own SMTP server; every staff-facing message is off until you turn it on.
- Reminders need a scheduler: `cron/reminders.php` must run daily — the app does not run background jobs by itself.
What renting costs instead
6 months of TimeCamp costs what Clockora costs once.
Read Sep 3, 2026 · source5 months of Hubstaff costs what Clockora costs once.
Read Sep 3, 2026 · source3 months of Toggl Track costs what Clockora costs once.
Read Sep 26, 2026 · sourceThe full comparison: every rival, what each does better, and who should stay with them →
Replacing one of these? TimeCamp alternative · Hubstaff alternative · Toggl Track alternative · Clockify alternative · Harvest alternative
Release history
For Clockora, 4.1 makes two changes that every app gets. What’s new in 4.1 →
For Clockora, 4.0 means updates from inside the app: the Updates page checks for a new release with your license key, verifies Ownware's signature, takes a backup and… What’s new in 4.0 →
3.3 brings approval to your phone. What’s new in 3.3 →
3.2 took clocking to the people doing the work: each person clocks in and out from their own phone, or with their own PIN at a shared tablet by the door, and every way…
The 3.1 wave gave the catalog a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar…
Close a pay period and it is closed in the app, over the REST API and for an agent — one rule, one implementation, three doors, with unlocking audited.
Clockora 2.0 adds the 2.0 owner layer.
What’s in the zip
The tree as the zip ships it — the working leftovers the packager deletes are not listed
- .htaccess
- API.md
- Dockerfile
- LICENSE.txt
- QUICKSTART.txt
- README.md
- assets/
- bin/
- config.sample.php
- controllers/
- cron/
- deploy/
- index.php
- install/
- manifest.json
- offline.html
- router.php
- src/
- sw.js
- tests/
- views/
src/Timesheet.php: a real module, the first 24 of 385 lines
Chosen as the largest module in src/ that is not one of the shared cores — this product's own logic, not a file every product carries.
<?php
/**
* Timesheet.php — THE time-tracking core Clockora stands behind (fully covered by tests/run.php,
* offline). Nothing here touches the database or the network. Every rule the product enforces —
* clock-time parsing, manual-duration parsing, per-entry duration (including entries that CROSS
* MIDNIGHT), placing an entry on one absolute minute-timeline, overlap / double-booking detection,
* exact period totals (per employee, per project), week bucketing, the overtime FLAG, and the CSV
* export hardening — lives here as pure, deterministic functions so it can be proven in isolation
* and reused identically by the web UI, the seeder, and the exporters.
*
* UNIT: worked time is INTEGER MINUTES, end to end. There is no float anywhere in a duration or a
* total — a clock span is a difference of two minutes-of-day integers, a manual entry is parsed
* straight to integer minutes, and every sum is done in PHP with a final clamp (never a SQL SUM(),
* which can overflow INT and 500 under strict mode). Because minutes are integers, period totals
* reconcile EXACTLY.
*
* Positioning: Clockora tracks HOURS WORKED ONLY. It is NOT invoicing and NOT payroll: it never
* stores a billing rate, never computes a money amount, never touches cards/bank rails/crypto, and
* initiates no payments. Projects are labels for grouping hours, nothing more.
*/
declare(strict_types=1);
final class Timesheet
{Runs on: 2-minute web installer, plain PHP 8.1+ with MySQL (or SQLite for a trial), no Composer or build step — Docker image included. Tested on PHP 8.3. Or run it in Docker: the Dockerfile is in the zip.
Technical owners can install it with one line and their license key: curl -fsSL https://ownware.io/install.sh | sh -s -- clockora <your license key>
Nothing is obfuscated or encoded; what you read is what runs. Manual · API · the test run
Which license do I need?
It comes down to how many installations you need. Running your own business on one site is the Single license. A second domain of your own, or sites you build or run for other people, is the Extended license.
- Install it on one domain or subdomain you own or operate
- Change the source however you like for that installation
- Run your own business on it commercially, client work included
- Re-download the current build any time from your buyer portal
- A second site, or an installation you hand to a client as theirs, needs the Extended license
- No reselling, redistributing or sublicensing the source
- Not for offering it to other people as a hosted service
- Everything the Single license grants
- Install it on as many domains as you own or operate — no cap on the number
- Up to ten client installations, one per client project, handed over or hosted for each client; for more, buy another Extended license
- White-label: remove or replace the product name and logo in the screens of client installations
- Still no reselling or redistributing the source itself
- Running it as a multi-tenant service others sign up for needs a SaaS agreement
Every download carries the full terms as LICENSE.txt. The complete wording is on the terms page.
After you buy
The app’s Updates page installs a new release with your license key, with the release’s signature checked and a backup taken first. Your download link always serves the current build. Download again any time from your order page or the buyer portal; there is no renewal fee.
Email support for installation and for defects in the code as delivered: a person reads and answers every message. It does not cover custom development or server administration. What support covers
Refunds are handled by Lemon Squeezy as merchant of record, case by case. EU consumers keep the statutory 14-day right until delivery starts. Refund terms
It keeps running: your server, the full PHP source, no license check that can fail. If no stable release is published for 365 days, the domain limit lifts; after three such years your copy becomes MIT-licensed. The terms have the exact wording: continuity.
Questions
Does Clockora invoice or bill these hours?
Is it payroll?
How exact are the totals?
MySQL or SQLite?
What if the developer disappears?
Is this shareware?
Is it priced per user, per month?
Can somebody log more than 24 hours in a day?
Does overtime turn into a payment?
Does it chase missing timesheets?
Covered in these guides
- What's new in Own It 3.3
- What's new in Own It 3.2
- Best self-hosted project management software: six projects, their real prices, and what each needs from your server
- There is no freelancer suite here, and this is what one person actually needs
- What SaaS in PHP actually means, and the two people searching for it
- Shareware time tracking: what that search is really asking, and what the alternatives cost
Also covered in: The workforce stack, bought once: rota, timesheet, leave, onboarding and training records that agree with each other · What's new in Own It 3.1 · "You Own Your Data" Is Only True If You Can Restore It · What a Freelancer Pays for Software Every Year — And Why Most of It Should Be Free · Timesheet Software Without Per-Seat Pricing · Stop Paying Per Person to Write a Rota — The Honest Deputy Cost Breakdown (2026), and 2 more in the guides.
More about Clockora
Self-hosted staff timesheet — hours by project, exact totals, approvals. No invoicing.
The problem it solves
Studios, agencies, support teams, and workshops need to know who worked how many hours on what — and they track it in a spreadsheet nobody trusts, or in a time-tracking SaaS that insists on bundling invoicing, billing rates, and payroll they never asked for, priced per employee every month. All most teams actually need is exact hours, by project, approved.
- Hours logged in a spreadsheet that never quite adds up
- Time-tracking SaaS bolting on billing/payroll you don't want
- Per-seat monthly pricing for what is a timesheet and a total
Every feature
- Clock in, clock out. Start a live timer for anyone from the timesheet or their record. Stopping it files a draft entry that passes the same overlap and 24-hour checks; if a check refuses it, the timer keeps running rather than losing the hours.
- The employee hears the decision. Approve or reject a timesheet and the person who submitted it can be told by email — through your own SMTP, off by default, and never carrying a pay figure because the product stores none.
- A weekly nudge for unsubmitted time. A cron chases employees whose week has hours but no submitted timesheet — each person claimed once per period before any mail is sent, so a double-fired cron can never nag twice. Dry-run mode shows who would be reminded.
- Employees & projects. Employees with a role and an optional weekly-hours target; projects as simple labels for tagging time — no billing rates anywhere.
- Clock or manual entries. Log time with the live timer, by clock start and end times (crossing midnight handled), or as a manual duration — stored as exact integer minutes, never floats.
- Overlap detection. One employee can't have two clock entries overlapping in time on a day, checked on an absolute minute-timeline; clean back-to-back entries are allowed. Manual duration entries have no clock position and are not overlap-checked.
- Timesheet per period. A week (with prev/next) or a custom date range, with exact totals per employee and per project — reconciled to the minute.
- Submit → approve workflow. Entries move pending → approved / rejected with an approver and timestamp, per entry or in bulk for a period.
- Overtime flag, PDF & hardened CSV. A configurable weekly overtime FLAG (never a pay figure), a dependency-free per-employee PDF timesheet, and a spreadsheet-formula-injection-hardened CSV export. DST-safe throughout.
- Installable mobile app (PWA). Add it to a phone or tablet home screen straight from the browser — a full-screen app served from your own server, with no app store involved. Business data is not stored offline on the device; what you see is read live.
- Clock in from your own phone. Each person can have their own My time login: Clock in, Clock out, their week, Submit. They see their own hours only; you approve.
- A tablet by the door. Open a kiosk link on a shared tablet; staff clock in and out with their own PIN. No login on the tablet, no location, no photo.
- Same rules on every door. A clock-out from the kiosk, a phone or your timesheet is checked for overlaps, a day over 24 hours and locked pay periods, and the clock keeps running rather than losing the time.
- Breaks that come off. Start and end an unpaid break on the clock, from the timesheet, a phone or the tablet, and the worked hours are net.
- Payroll in the shape you need. One row per person, one row per person per day, or decimal hours beside the exact minutes.
- Excel as well as CSV. Entries and payroll download as spreadsheets that open straight in Excel.
- Approve from your phone. Submitted time as cards, one per person and week, with the week's total against their overtime threshold and one tap to approve what the card shows.
- Decimal hours in the CSV. The time-entries CSV carries hours to 2 decimal places beside the exact minutes.
- Updates from inside the app. The Updates page installs a new release with your license key: Ownware's signature is checked, a backup is taken first, and the app puts the previous version back by itself if the update is interrupted or the database step or start-up check of the new version fails. It never checks by itself.
- Backups by themselves. Automatic backups, an optional copy to S3-compatible storage you own, and a weekly check that the latest backup reads back. The Health page names anything that needs attention.
- Own It 4.0.1 — fixes and an up-to-date manual. For Clockora, 4.0.1 fixes an installer that had lost its styling, a rollback that a page opened during an update could stop, scheduled tasks that a browser could start and a command-line update that ended in an error after putting the previous version back. Its manual, FAQ and QUICKSTART now cover everything 4.0 added, including two Nginx rules that keep the data folder private. Your license covers it: press Check for updates on the Updates page, or download it from your order page.
- Own It 4.0.2 — the installer opens on every host. For Clockora, 4.0.2 fixes a fresh install on an Apache host: the one-page setup at /install/ looped back to itself and never opened, and now it opens. Your license covers it: press Check for updates on the Updates page, or download it from your order page.
Release notes in full
- Own It 4.1: client installations and your other tools. For Clockora, 4.1 makes two changes that every app gets. An Extended license bought from October 4, 2026 covers up to ten client installations, one per client project: hand each one over to the client or host it for them, with the client's logo and colors from the app's branding settings. The API reference now shows how to connect Clockora to Zapier, Make or n8n, using its own webhooks and API key. Your license covers the update: press Check for updates on the Updates page, or download it from your order page.
- Own It 4.0: it updates and backs itself up. For Clockora, 4.0 means updates from inside the app: the Updates page checks for a new release with your license key, verifies Ownware's signature, takes a backup and puts the previous version back by itself if the update is interrupted or the database step or start-up check of the new version fails. A new install can start with a sample business and remove it in one click; backups run by themselves, with an optional offsite copy and a weekly check that the latest one reads back; and the Health page says whether the install is looking after itself.
- Own It 3.3: approve from your phone. 3.3 brings approval to your phone. Submitted time arrives as one card per person and week, with the week's total against their overtime threshold, and one tap approves what the card shows. The time-entries CSV also carries decimal hours beside the exact minutes.
- Own It 3.2: staff clock themselves in. 3.2 took clocking to the people doing the work: each person clocks in and out from their own phone, or with their own PIN at a shared tablet by the door, and every way in is held to the same checks. Unpaid breaks come off the worked hours, and payroll downloads in the layout you need, as CSV or Excel.
- Own It 3.1: it writes to the people you serve. The 3.1 wave gave the catalog a way to reach the other side of the transaction: counterparty email through your own SMTP server, calendar feeds your own calendar subscribes to, attachments filed where the paperwork belongs, and export presets other people's software imports. Each outbound feature ships switched off and runs on your own credentials; a failed send is recorded, and the action that triggered it stands. What this app gained is listed at the top of this section.
- Own It 3.0: works for your AI, not just for you. Close a pay period and it is closed in the app, over the REST API and for an agent — one rule, one implementation, three doors, with unlocking audited. MCP runs the submit and approve cycle under the same refusals you get. Payroll CSV exports approved time only, exact minutes, no money.
- Own It 2.0: API, 2FA, backups, dark mode. Clockora 2.0 adds the 2.0 owner layer. Upgrade by replacing the files — the database migrates itself, and it is still the same one-time purchase.
Browse self-hosted: Workforce management software · Gym & studio software · Restaurant & café software · Trades & field-work software · Construction & building-trade software · Warehouse & logistics software · Cleaning & facilities-management software · Hotel & hospitality software · Farm & agriculture software · IT support & managed-service software