Lending Infrastructure

Open-source loan management systems: what Apache Fineract gives you and what you still build

Is Apache Fineract free, what does it do, and how is it installed? What an open-source loan management system gives an Indian lender, and what you still build.

Open-source loan management systems: what Apache Fineract gives you and what you still build: cover art
Quick answer

Apache Fineract* is an open-source core for loans, savings and accounting, released under the Apache License 2.0 with no licence fee. It gives you a loan engine, a general ledger, a REST API, multi-tenancy, maker-checker and batch jobs for accruals and NPA updates. It ships no user interface, no comprehensive production deployment guide and no Indian payment or bureau integrations. Those, and the work of running it, fall to the lender.

If you are a CTO weighing an open-source loan management system, the licence is the smallest line in the decision. What decides it is the work between the core and a book you can run in India, and who does that work for the next five years.

This post takes Apache Fineract as the example. Lokta’s founders built it, which is a reason to be plain about what it covers and what it leaves out.

Key takeaways
  1. Free to use, under Apache 2.0. No licence fee, no warranty, no support from the foundation.
  2. A real core. Loan engine, general ledger, API, multi-tenancy, maker-checker and daily batch jobs.
  3. No front end and no rails. No UI, no payment network integration, no borrower self-service.
  4. The Indian layer is yours. Mandates, Indian bureaus, RBI’s SMA categories and RBI returns are not in the upstream code.
  5. Production is yours too. The project gives no full production guide, and only the current release line is supported.

What is Apache Fineract?

An open-source core for lending and savings, run as a top-level project of the Apache Software Foundation. It entered the Apache Incubator on 15 December 2015 and became a top-level project on 19 April 2017. The project describes its scope as “client data management, loan and savings portfolio management, integrated real-time accounting, and extensive reporting capabilities”.

The Fineract project management committee maintains the code. As of 25 September 2026, the current stable release is 1.15.0, published on 14 July 2026. The project supports only the current release line, so 1.13.0 (October 2025) and 1.14.0 (December 2025) are marked end of life.

Fineract also reaches lenders through Mifos X, a distribution built on it by the Mifos Initiative, a US non-profit. Mifos X adds web and mobile clients that use Fineract as their backend. The two carry different licences: Fineract is under the Apache License 2.0, Mifos X under the Mozilla Public License 2.0. The Fineract alternative comparison sets out how they differ.

Is Apache Fineract free?

Yes, to download and use. Section 2 of the Apache License 2.0 grants a “perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable” licence to use, change and distribute the code, and section 3 adds a patent licence. The foundation says its projects “will never charge a fee for downloading or using their software”.

The licence asks four things of anyone who distributes the code or a changed version:

  • include a copy of the licence
  • mark every file you changed with a prominent notice saying so
  • keep the copyright, patent, trademark and attribution notices
  • carry the NOTICE file, which for Fineract credits software developed at the Apache Software Foundation

It also gives no warranty. The code is provided “AS IS” (section 7), and the foundation’s own FAQ says it does not provide formal or commercial support for any of its packages. Section 9 lets you, or a vendor, sell support and warranties on top. So the software costs nothing, and standing behind it in production is work a lender does in-house or pays a vendor for.

One licence detail affects the database choice. The MySQL and MariaDB database drivers are not bundled with Fineract’s builds, because of licence incompatibility, and the README marks support for databases other than PostgreSQL as deprecated.

What does Fineract give a lender?

A working book of record. From the project’s documentation and code:

  • loan products with declining balance and flat interest methods, and configurable charges
  • a chart of accounts and general ledger, with accounting integrated in real time
  • a REST API that exposes all of the platform’s functions
  • multi-tenancy built into the core
  • maker-checker that can be switched on for any state-changing command, each of which is persisted as an audit record
  • Spring Batch jobs for close of business on loans, delinquency classification, accrual transactions, non-performing asset updates and loan loss provisioning
  • delinquency buckets, with a pause feature that holds an account’s bucket
  • asset externalization, which tracks ownership when loans are sold or securitised

For a lender, that is the hard part of a loan management system: a deterministic engine that turns a product and a set of events into a schedule, a balance and ledger entries. It is the part Lokta’s founders spent a decade on.

What does the project leave to you?

Everything around the core. Fineract’s own README and threat model (SECURITY.md) are direct about it:

  • No user interface. “Fineract does not provide a UI, but provides an API.” Teams use the Mifos X web app or build their own.
  • No payment rails. The threat model says “integration with external payment networks is a downstream responsibility”.
  • No borrower-facing channel. The same document says Fineract “is used by back-office users, not bank customers”. The Mifos community keeps a self-service plugin in a separate repository.
  • No comprehensive production deployment guide. The README says the project “does not provide a comprehensive guide for deploying Fineract in production”, and that its Docker images are not production-ready. It suggests paying a vendor for deployment and maintenance as an alternative.

None of this is a flaw. It is the scope a core is meant to have. It does mean an open-source loan management system is a component, and the lender assembles the rest.

What does an Indian NBFC still add?

The rules and rails that make a loan Indian. A search of the upstream repository’s default branch on 25 September 2026 found no reference to NACH, eNACH, CIBIL, CKYC or Aadhaar, and none to RBI’s Special Mention Account categories. The one RBI-named feature is a repayment allocation strategy that takes all interest, current and overdue, before principal. Fineract has a credit bureau module, and its one built-in connector is for ThitsaWorks, which is not one of India’s credit information companies.

So an NBFC running upstream Fineract builds or buys:

  • NACH and UPI AutoPay mandates, debits and return handling, including the charges and borrower notices covered in the bounce post
  • reporting to all four credit information companies on RBI’s four monthly reporting dates, as the bureau reporting post sets out
  • borrower-level SMA and NPA classification run by RBI’s rules at each day end
  • penal charges, prepayment and reset rules, and the KFS, as covered in penal charges, prepayment and rate resets
  • co-lending splits, if the book has a partner bank
  • the returns RBI expects from the loan book

Vendors and forks built on Fineract add some of these. The upstream project does not ship them, and each one has to be kept in step with RBI’s changes.

How do you install Apache Fineract?

For release 1.15.0, the README lists Java 21 or later, PostgreSQL 18 or later, and at least 16 GB of RAM and 8 CPU cores. Its quick start runs Fineract locally for evaluation:

  1. Clone the repository from GitHub.
  2. Start PostgreSQL on port 5432 (the README gives a Docker command).
  3. Create the two databases: ./gradlew createPGDB -PdbName=fineract_tenants, then the same task for fineract_default.
  4. Start the server with ./gradlew devRun.
  5. Check /fineract-provider/actuator/health on port 8443.
  6. Log in with the default credentials from the README, and change them before anything else.

The README also covers Docker (build the image with the jibDockerBuild task, then start the development compose file), a runnable JAR, which it recommends, a WAR on Tomcat and Kubernetes. The development branch has moved to Java 25, so check the requirements for the release you install.

What does it cost to run in production?

No licence fee, and a list of costs a vendor quote would otherwise bundle:

  • engineers who can read and patch a large Java codebase, and stay long enough to own it
  • hosting, databases, backups and monitoring
  • upgrades, since only the current release line gets fixes
  • security patches, reported to and released by the project, applied by you
  • the Indian integrations above, built once and changed each time RBI or NPCI changes a rule
  • a user interface for operations staff, and borrower channels if you need them
  • a support vendor, if you want one to answer at 2 am on a day-end failure

Which of these is expensive depends on your team and your book. The cost of a loan management system sets out how to compare that total with a vendor’s price.

How should a lender choose an open-source core?

If you want to be the CTO who picks a core the team can still run in five years, weigh three routes by who owns the work around the core. The build-versus-buy decision starts with a funded owner for calculations, regulatory change and incidents after launch.

  1. Run upstream Fineract with your own team. You control every line and pay no licence fee. You carry the Indian integrations, upgrades, security patches and on-call, and the knowledge sits with the few engineers who built it.
  2. Buy a commercial platform, a Fineract-based vendor or a separate codebase such as Lokta, that carries the RBI rules in the product and hosts, patches and upgrades it. It costs a subscription and some control over the code. In exchange, RBI changes and upgrades reach you as vendor releases your team tests and signs off, not as builds your engineers own.
  3. Build your own loan management system from scratch. It fits your products exactly. You rebuild the ledger, schedule engine and accounting that Fineract already solved, before any Indian work begins.

The second path costs you the freedom to change the core yourself. For a lender whose edge is credit and collections rather than ledger engineering, that trade can be worth making, but test it against your own roadmap. The Fineract alternative comparison sets the options side by side.

Lokta is not a fork of Fineract. Its founders built Fineract, then started a new codebase, and what we learned building Fineract explains why. Lokta’s loan management system configures RBI’s IRAC and SMA classification, the KFS with its APR, and penal charges per product, and bureau reporting is part of the platform.

Frequently asked questions

Is Apache Fineract free?

Yes, to download and use. Fineract is released under the Apache License 2.0, which grants a perpetual, worldwide, no-charge, royalty-free licence to use, modify and distribute it, and the Apache Software Foundation never charges for its software. If you distribute it or a changed version, the licence asks you to keep its notices and mark the files you changed. It comes with no warranty, and the foundation offers no commercial support or service level agreement, so hosting, support and upgrades are costs a lender carries itself or buys from a vendor.

Do you need Mifos X to run Apache Fineract?

No. Fineract is the core: the loan and savings engine, the accounting and the API, maintained by the Fineract project management committee at the Apache Software Foundation under the Apache License 2.0. It ships no user interface, so teams either build their own or use a distribution. Mifos X is one, built on Fineract by the Mifos Initiative, with web and mobile clients that use Fineract as their backend, released under the Mozilla Public License 2.0.

Can an Indian NBFC use Apache Fineract?

It can, with work. The core handles loan products, accounting, delinquency buckets, accruals and NPA updates. A search of the upstream repository on 25 September 2026 found no NACH, eNACH, CIBIL, CKYC or Aadhaar integration, and no reference to RBI's Special Mention Account categories. The one RBI-named feature is a repayment allocation strategy. Mandates, reporting to Indian credit information companies, RBI returns, and borrower-level SMA and NPA classification to RBI's rules have to be built, or configured and tested. Fineract's delinquency ranges and NPA flag work per loan account, and it has no SMA categories.

How do you install Apache Fineract?

For release 1.15.0, the README lists Java 21 or later, PostgreSQL 18 or later and at least 16 GB of RAM and 8 CPU cores. Clone the repository, start PostgreSQL on port 5432, create the fineract_tenants and fineract_default databases with the Gradle createPGDB task, start the server with ./gradlew devRun and check the health endpoint on port 8443. Change the default login at once. The project says its Docker images are not production-ready and it provides no comprehensive production deployment guide.


Sources:

Bring us your live book

See what agents can do after approval.

Talk to us
Founder-led adoption

Adopt the agentic loan servicing platform.

Lokta is built for enterprise deployment, VPC or single-tenant cloud, with an audit trail in every state change. We work with a select group of institutions through a founder-led model: deep adoption, deliberate scope, a delivery window the team commits to in writing.