Rybbit vs Umami
Pick Umami for most sites: since v3 its MIT build has funnels, user journeys, retention, cohorts, session replays, heatmaps and Web Vitals, in two containers (Next.js + PostgreSQL) on 1 GB that you can try on an IP and port before a domain is involved. Pick Rybbit when you want what Umami lacks — error tracking and city-level map visualisations on a ClickHouse store — and will run its six-container AGPL-3.0 stack on the docs' 2 GB floor with a domain pointed at the server on day one, because its tracking script must be served over HTTPS.
Side by side
Rybbit and Umami are the two picks in this hub that go furthest past a pageview counter. Both are cookieless, both have funnels, user journeys, retention and session replays in the build you self-host, and both install with a couple of commands. A year ago the question was "lightweight or feature-rich". Umami v3 closed most of that gap, so now the real difference is what each one runs on and the handful of reports only one of them has.
Two stacks for one job
Umami is a Next.js app and one PostgreSQL database. Two
containers, MIT-licensed, and no published RAM figure. The 1 GB on our
page is our estimate for the app and its database together. Upstream's
compose file serves it on port 3000 with the default admin / umami login,
so you can try it on a bare IP before a domain is involved. For production,
put it behind your own HTTPS proxy.
Rybbit is a TypeScript app on ClickHouse, PostgreSQL and Redis,
AGPL-3.0, installed by a setup.sh that takes your domain and starts six
containers: Caddy, ClickHouse, PostgreSQL, Redis, the backend and the client.
Its docs ask for "at least 2GB of RAM", and they make the domain a hard
requirement: "HTTPS is required because browsers block tracking scripts
served over insecure HTTP." Caddy issues the certificate. If you already run a
proxy, --no-webserver exposes the backend on 3001 and the client on 3002.
So you get two containers against six, 1 GB against 2 GB, and a permissive license against a copyleft one. Both rate 2 / 5 on our difficulty scale, because both are scripted. Umami simply leaves you less to keep running.
Features: closer than the reputation
Rybbit's README describes the product as sessions, unique users, pageviews, bounce rate and session duration, plus session replays, customizable goals, retention, user journeys and funnels, filtering across 15+ dimensions, custom events with JSON properties, country → region → city location with map visualizations, and a real-time dashboard. Its comparison table also ticks user profiles and error tracking.
Umami's v3 line now covers most of that list for free:
- v3.0 added segments and cohorts, plus tracking links and pixels (short redirect URLs and invisible images you can put in emails or on sites where you cannot install a tracker).
- v3.1 added Session Replay (built on rrweb, with masking that defaults to moderate), Boards (custom dashboards) and Web Vitals.
- v3.2 added click and scroll heatmaps. The release notes list "self-hosted heatmap recording and storage support".
Umami's docs also have funnel, journey and retention reports. Replays are off
by default: you enable them per website and add recorder.js to your tracker
snippet. They record 15% of sessions by default and keep them for 30 days.
Here is what is left on each side:
- Only in Rybbit: error tracking and region- and city-level map visualisations.
- Only in Umami: heatmaps, tracking links and pixels, and Web Vitals in the free build. Rybbit's README marks Web Vitals as "Only available on paid tiers" and labels that screenshot "Cloud only".
Storage: the one argument for the heavier box
Rybbit stores events in ClickHouse, a column store built for analytics queries, the same engine Plausible uses. Umami v3 runs on PostgreSQL only (its v3.0.0 notes drop MySQL). Neither project publishes a traffic ceiling, and we have not benchmarked one against the other, so we won't claim one. If you already know you are sizing for heavy event volume, ClickHouse is the more common choice for that job, and the reason Rybbit's floor is 2 GB.
Pick Rybbit if…
- You want error tracking in the same dashboard as your traffic, or region- and city-level maps.
- You would rather your events live in ClickHouse than in PostgreSQL.
- You have a sub-domain to point at the server and are happy for the script to set up Caddy and HTTPS for you.
Pick Umami if…
- You want the smallest stack that still has funnels, journeys, retention and replays: two containers on a 1 GB box.
- You want heatmaps, Web Vitals, tracking links or pixels without a paid tier.
- A permissive MIT license matters, or you want to try it on an IP and a port before you commit a domain.
The honest trade-off
Umami wins this comparison for most self-hosters. Since v3 it has nearly every report Rybbit has, plus heatmaps and Web Vitals in the free build, and it runs as two containers under MIT on a 1 GB box. Rybbit wins when you need the few things Umami lacks (error tracking, region- and city-level map visualisations, a ClickHouse store) and are willing to run six containers on 2 GB and point a domain at the server on day one.
If neither shape fits, compare the neighbours. Rybbit vs Plausible puts Rybbit against the minimal ClickHouse-backed report. Plausible vs Umami is the same footprint-versus-report question from Plausible's side. GoatCounter vs Umami is for when even Umami is more than you want. OpenPanel vs Rybbit covers product analytics beyond web analytics.
Common questions
Rybbit vs Umami — which should I self-host?
Pick Umami for most sites: its MIT build has funnels, journeys, retention, session replays, heatmaps and Web Vitals, and it runs as two containers (Next.js + PostgreSQL) on 1 GB — our estimate, since upstream publishes none. Pick Rybbit if you want error tracking and city-level map visualisations on a ClickHouse store, and you have a domain to point at the server; its docs ask for at least 2 GB of RAM.
Does Umami really have session replay now?
Yes. Session Replay arrived in v3.1 and heatmaps in v3.2, in the same MIT build you self-host. Replays are off by default: you turn them on in the website's settings and add recorder.js to the tracker snippet. The docs default to recording 15% of sessions, mask input fields at the default level, and keep replays for 30 days.
Why does Rybbit need a domain when Umami does not?
Rybbit's docs make it a precondition: browsers block tracking scripts served over plain HTTP, so the setup script takes your domain and its bundled Caddy obtains the certificate (or you use --no-webserver behind your own proxy). Umami's compose simply serves on port 3000, which is enough to evaluate it — but to track a live HTTPS site you will put it behind an HTTPS proxy with a domain too.
Paid link — we earn a commission if you shop through it.
Other comparisons with these apps
The full GA replacement vs. the privacy-first dashboard.
A single Go binary on a SQLite file vs. the lightest modern analytics dashboard.
Two AGPL newcomers on ClickHouse — one replacing Google Analytics, one replacing Mixpanel.