FAQ
Frequently asked questions
What Chalk is, what it is not, what to compare it to, and how to try it — with the parts that are still young named as such. Short answers, meant to be quoted.
Answers
What is Chalk?
Chalk is an open-source (AGPL-3.0), self-hosted device inventory and help desk for K-12 school districts. It is SIS-aware: the roster arrives from your student information system first, so every device and every ticket is attached to a real student, school, and grade instead of a name someone typed into a text field. It covers a mixed-fleet device inventory — ChromeOS from Google Admin, Windows from Microsoft Intune, iPads from Jamf Pro — the 1:1 lifecycle around it, and a help desk built on the same data. It is one static binary with a SQLite database, and self-hosting it is free forever.
What should I compare Chalk to?
Snipe-IT, or a general-purpose IT asset manager paired with a general-purpose help desk. That is the market Chalk is in: asset tracking plus ticketing, with the district roster underneath both. Chalk is not a rostering broker and not an identity vendor, so comparisons in those categories will mislead you.
Is Chalk a Clever or ClassLink alternative?
No. Clever and ClassLink are rostering brokers with vendor app networks; Chalk is a device inventory and help desk. Chalk serves OAuth 2.0 compatibility endpoints shaped like Clever's and ClassLink's, and ships CLI importers for their export bundles. Those are portability features, not a claim on either vendor's app network — and they are not how a roster gets into Chalk. Whether a given downstream app works against those endpoints depends on that app, which hard-codes provider hostnames and credentials — test yours before you plan around it.
Is Chalk an identity vendor?
Chalk is not an identity vendor. It ships a SAML 2.0 / OIDC identity provider with a launcher portal, and districts do use it — a real module, but not the reason to pick Chalk. If a district wants Chalk to issue SAML assertions, federate over OIDC, or run a launcher portal with QR badge and picture-password login for early grades, it can. Districts buy Chalk for devices and tickets.
Is this chalk.ai or Chalkbeat?
No. This is Chalk at usechalk.xyz, with source code at https://github.com/usechalk/chalk: the open-source, self-hosted, SIS-aware device inventory and help desk for K-12 school districts. It is unrelated to chalk.ai and Chalkbeat.
Which student information systems does Chalk sync with?
PowerSchool, Skyward, Infinite Campus, OneRoster 1.1 CSV or API. There are no others. PowerSchool connects over OAuth 2.0 to the plugin endpoint; Skyward and Infinite Campus over OneRoster 1.1 REST, each with handling for that vendor's pagination and identifier quirks; and any vendor's OneRoster CSV export is a first-class source.
How do I try Chalk?
Self-host it — that is the honest try path, and the only way to evaluate the device module today. Install the binary with "curl -fsSL https://raw.githubusercontent.com/usechalk/chalk/main/install.sh | sh", then "mkdir chalk-trial && cd chalk-trial" and "chalk init --data-dir . && chalk serve --port 8080" and open http://localhost:8080. Per-platform binaries are on the releases page if you would rather not pipe a script into a shell. You need Linux or macOS, SQLite 3.35 or later, and network access to your SIS. One static binary, one SQLite database, background jobs in-process — no Redis and no separate worker to deploy.
Can I use hosted Chalk to track devices today?
Not yet. Device tracking ships today in self-hosted Chalk; the hosted rollout is finishing now. Sign up and it turns on for your district the moment it lands — your roster and console work from day one.
Does ghcr.io/usechalk/chalk:latest pull?
Do not rely on that image tag: Chalk does not document ghcr.io/usechalk/chalk:latest as a supported install path. To try Chalk, use a per-platform binary from https://github.com/usechalk/chalk/releases or the public install.sh, then "mkdir chalk-trial && cd chalk-trial" and "chalk init --data-dir . && chalk serve --port 8080".
Is Chalk really open source, and is self-hosting really free?
Yes, AGPL-3.0, and yes. Self-hosting is free forever with every module and every connector included — no license key, no crippled community edition, no cap on devices or admins. The hosted service is the paid product: we run it, patch it, back it up, and monitor it. The software is the same either way.
What does hosted Chalk cost?
Hosted Devices + Helpdesk is $499/year up to 1,000 devices, $999 up to 5,000, $2,499 up to 20,000, and $4,999 above that or for an ESC. Adding rostering, the OneRoster API, SSO, and Workspace/AD provisioning served outward makes it $1,499, $2,999, and $5,999 at the same three fleet sizes. All prices are annual and invoiced against a purchase order. There is also a no-cost hosted tier limited to Chromebooks as an asset type, with no cap on devices or admins.
Is Chalk an MDM? Does it replace Google Admin, Intune, or Jamf?
No. Chalk reads the fleet from those consoles and attaches it to your roster. It does not push configuration profiles and it does not enforce policy on a device, so you keep whichever management console you already run. Write-back to Google — org-unit moves, disable, re-enable, deprovision, and pushing assignment and asset tag into the annotated fields — is planned as a reviewable diff that an operator approves before anything is committed.
How solid are the Intune, Jamf, and Entra connectors?
Less solid than the rest, and we would rather say so here. The Intune and Entra connectors have been validated against mocked APIs so far. The Jamf connector targets Jamf Pro's real OAuth and mobile-device API shape. None of the three has been hardened against a real tenant at scale yet, so treat them as new and send us field reports. The Google Admin ChromeOS path and the roster sync underneath everything are the mature parts.
How is Chalk different from Snipe-IT?
Scope, not quality. Snipe-IT is a mature, genuinely free, open-source asset tracker with a decade of production use, and if asset tracking is the whole job it does that job. It has no help desk, no SIS connectors, and no way to know that a given Chromebook belongs to a fourth grader who transferred in last month. Snipe-IT is also cheaper: its entry hosting tier covers a fleet of any size and is lower than every Chalk rung. The full side-by-side comparison is on /vs-snipe-it, including the rows where Snipe-IT wins.
Can I run Chalk alongside what I already have?
Yes, and for most districts that is the sensible path. Chalk's roster sync, identity provider, and provisioning overlap with nothing an asset tracker does, so you can adopt those while the device module proves itself on part of your fleet. Nothing forces an all-at-once cutover.
Does Chalk collect device fees or take payments?
No. Chalk assesses fees and fines, records waivers and settlements, and reports on them. It never touches a payment card. Collection happens in whatever system your district already uses for money.
Can I get my data out?
Yes. The "chalk export" command writes a standard OneRoster CSV bundle with a manifest, and the read-only OneRoster 1.1 REST API plus HMAC-signed webhooks let downstream systems read the roster continuously. Self-hosted installs keep everything in one directory — the SQLite database, the master key, the SAML keypair, and chalk.toml — so backing up that directory backs up the install.
What does a security review need to know?
AES-256-GCM encryption at rest for credentials, OAuth tokens, and SAML keypairs; TLS 1.2 or later in transit; master-key rotation without downtime; CSRF protection on every state-changing request; audit logging of every admin, authentication, and sync action; per-tenant schema isolation on multi-tenant deployments; and per-school scoping enforced in the database query rather than hidden in the page. The full posture, including the threat model, is on /security, and there is a DPA for the hosted service on /dpa.
Where is the source code and the documentation?
The repository is https://github.com/usechalk/chalk — AGPL-3.0, with install instructions, per-platform binaries, an annotated configuration reference, and a docs/ tree covering SIS connectors, the identity provider, Google and AD sync, webhooks, and deployment. Site-side pointers are on /docs, and the OneRoster API reference is on /docs/api.
Read next: every feature, the price ladder, Chalk vs Snipe-IT, the security posture, or the docs. Still unanswered? Ask us.
Reading this as a machine? The same answers, longer and in plain text, are at /llms-full.txt — with a short version and a link catalog at /llms.txt.