# Integration with Collaboration Server On-Premises

This page covers running CKEditor AI On-Premises together with [Collaboration Server On-Premises](../cs-onpremises/overview.md): the prerequisites, the configuration that connects the two, what changes once they are connected, and the token that authorizes both. Read it if your users already collaborate in CKEditor 5 with the Collaboration Server.

CKEditor AI On-Premises can share its data layer with Collaboration Server On-Premises. Both services then use the same SQL database and Redis instance, so you do not set up separate ones for AI.

> **Warning**
>
> This integration requires Collaboration Server On-Premises **5.0.0 or newer**.

Collaboration Server On-Premises and CKEditor AI On-Premises are released at the same time. Update them together and keep them on the same version.

<a id="prerequisites">

## Prerequisites

Before integrating, make sure you have a working Collaboration Server On-Premises deployment. See [Collaboration Server Quick Start](../cs-onpremises/installation/quickstart.md) or [Collaboration Server Architecture](../cs-onpremises/architecture.md) for the setup.

<a id="configuration">

## Configuration

Give CKEditor AI On-Premises the same `DATABASE_*` and `REDIS_*` values your Collaboration Server uses:

```bash
docker run --init -p 8000:8000 \
	-e LICENSE_KEY=[your license key] \
	-e DATABASE_DRIVER=[mysql|postgres] \
	-e DATABASE_HOST=[same host as Collaboration Server] \
	-e DATABASE_USER=[same user as Collaboration Server] \
	-e DATABASE_PASSWORD=[same password as Collaboration Server] \
	-e DATABASE_DATABASE=[same database as Collaboration Server] \
	-e REDIS_HOST=[same Redis host as Collaboration Server] \
	-e PROVIDERS='{"openai":{"type":"openai","apiKeys":["your-api-key"]}}' \
	-e STORAGE_DRIVER=[s3|azure|filesystem|database] \
	docker.cke-cs.com/ai-service:[version]
```

> **Note**
>
> Compare the `DATABASE_*` and `REDIS_*` variables in both configurations before you start the container. On a mismatch, the service does not find the Collaboration Server tables, and it sets up a data layer of its own.

<a id="what-changes-when-integrated">

## What changes when integrated

* **Shared environments** – the environments and access keys you create in the Collaboration Server [Management Panel](../cs-onpremises/management.md) work for CKEditor AI On-Premises too.
* **Single management panel** – you configure both services in the Collaboration Server Management Panel. The AI-specific one is disabled.
* **Shared data layer** – both services read and write the same SQL database and Redis instance. You do not create a separate database for AI.

<a id="token-endpoint-for-collaboration-and-ai">

## Token endpoint for collaboration and AI

One token covers both services. Put the collaboration roles in `auth.collaboration` and the AI permissions in `auth.ai.permissions` in the same payload:

```json
{
	"aud": "your-environment-id",
	"sub": "user-123",
	"auth": {
		"collaboration": {
			"*": {
				"role": "writer"
			}
		},
		"ai": {
			"permissions": [
				"ai:conversations:*",
				"ai:models:agent",
				"ai:actions:system:*",
				"ai:reviews:system:*"
			]
		}
	}
}
```

See [Example token payload for collaboration and AI](../../developer-resources/security/token-endpoint.md#example-token-payload-for-collaboration-and-ai) on the Token endpoint page.

<a id="next-steps">

## Next steps

* [Deployment](deployment.md) – Pull the image and launch the container.
* [Architecture](architecture.md) – Plan the application and data layers the two services share.
* [Token endpoint](../../developer-resources/security/token-endpoint.md) – Build the endpoint that signs tokens for collaboration and AI.

---

Full index of the Cloud Services documentation: [llms.txt](../../../llms.txt)
