Configuration
Every control-plane environment variable, which ones can also be managed in the dashboard, and how a change takes effect.
Self-hosted
Settings are environment variables, validated at startup: invalid configuration stops the process with a list of problems. Settings marked web can also be managed in the dashboard without a restart.
Required
| Variable | Notes |
|---|---|
JWT_SECRET | At least 32 characters. Signs access tokens. |
ENCRYPTION_KEY | 64 hex characters. Encrypts organization secrets and two-factor secrets. Back it up: without it, stored secrets cannot be recovered. |
MONGODB_URI | MongoDB is the source of truth. |
PUBLIC_URL, WEB_URL, CORS_ORIGINS | Required in production. Used for pairing links, emails and CORS. WEB_URL and CORS_ORIGINS are web. |
Common
| Variable | Notes |
|---|---|
REDIS_URL | Enables BullMQ dispatch. Without it an in-memory queue is used — one API instance only. |
TRUST_PROXY | Set behind a reverse proxy, for correct client IPs in rate limits and the audit log. |
SMTP_URL, SMTP_FROM | web. Without SMTP, emails are logged, not sent. |
ALLOW_REGISTRATION, REQUIRE_EMAIL_VERIFICATION | web. The first user can always register. |
ACCESS_TOKEN_TTL_SEC, REFRESH_TOKEN_TTL_DAYS | web. Default 900 seconds and 30 days. |
RATE_LIMIT_PER_MINUTE, AUTH_RATE_LIMIT_PER_MINUTE | web. Default 300, and 20 on sign-in routes. |
ENCRYPTION_KEYS_PREVIOUS | Only while rotating ENCRYPTION_KEY. |
FIRST_USER_IS_PLATFORM_ADMIN | Default on. Turn off where strangers could sign up before you, and grant with the platform-admin command. |
Optional features
| Variable | Notes |
|---|---|
GOOGLE_*, GITHUB_*, OIDC_* | web. Sign-in providers — see Sign-in. |
EXPO_PUSH_ENABLED, TELEMETRY_ENABLED | web. Outbound calls, off by default. |
METRICS_ENABLED | Prometheus metrics at /metrics. |
ERROR_TRACKING_DSN, ERROR_TRACKING_WEBHOOK_URL, ERROR_TRACKING_ENVIRONMENT | web. Sentry-compatible error reports, redacted. |
FEATURE_FLAGS | Comma-separated flags forced on for everyone (for example plugins.execution). |
S3_ENDPOINT, S3_BUCKET, S3_ACCESS_KEY_ID, S3_SECRET_ACCESS_KEY | Object storage. |
DEPLOYMENT_MODE, REQUIRE_PUBLIC_CALLBACK_URLS | For shared, multi-tenant installations: callback URLs of integrations must then be public https addresses. |
Server settings in the dashboard
Platform administrators see Server settings: the effective value and source (environment, dashboard or default) of every variable, secrets shown only as set or not set, and the live status of database, queue, email, storage and sign-in providers.
- A change to a web setting applies at once; other API instances pick it up within 10 seconds.
- An environment variable always wins. A web setting that is also set in the environment is shown as locked. Remove it from the environment and restart once to manage it in the dashboard.
- Secret settings are stored encrypted with
ENCRYPTION_KEY, are never shown again, and are included in key rotation. Changes are audited by name, without values. - Database, Redis, keys, ports, storage,
PUBLIC_URL,TRUST_PROXYand intervals are read once at startup.
Feature flags
Feature flags (platform administrators) turn optional features on for all organizations, with exceptions
for single organizations. Plugin execution (plugins.execution) is one of them and is off by default.
Health
GET /healthz (liveness) and GET /readyz (MongoDB and queue).