Skip to main content
Every environment variable the code reads. Copy .env.example to .env.local (source installs) or put the values in the environment of the container. Third-party service credentials are not environment variables. Unipile, Google Workspace (Gmail), Cloudflare R2, OpenRouter and the enrichment providers are connected per organization from Settings in the running app and stored encrypted in the database. There is no environment fallback. See integrations.md. The environment only holds what is needed before the database can be read, public URLs, cron secrets and tuning knobs. “Read in” lists the file that reads the variable.

Minimum production configuration

Generate each secret with openssl rand -hex 32.

Core

Auth

Secrets

URLs

Docker Compose and demo

Workers and tuning

Kill switches

Operational switches written for the unified-People data migration. They are off by default and normally stay off. A value of 1, true, yes or on (case-insensitive) turns a switch on. They are re-read on every call, so they take effect without a restart on platforms that refresh the environment. All are read in src/lib/migration/controls.ts. These are also a handy emergency brake: setting PAUSE_EMAIL_OUTBOUND=true and restarting stops sending without touching data.

Prospecting (domain qualification)

Used only by the Domains / qualification feature, which is slated for removal. Apollo for Tables is a separate per-organization connection.

User-named variables (Tables HTTP column)

The HTTP column in Tables can authenticate with a bearer token read from an environment variable whose name the user types in the column settings (authEnvVar). The secret therefore comes from the server’s environment, never from the database. Set whatever variable names your users reference. Read in src/lib/grid/runners/http.ts.

Runtime variables set by the platform

Script-only variables

Read by tooling in scripts/, never by the running app.

Removed variables

AUTH_PASSWORD and AUTH_SECRET belonged to the old single shared password and are no longer read by the app (AUTH_SECRET survives only as a legacy key in the rotation script). OPENROUTER_API_KEY, UNIPILE_*, GOOGLE_* service-account keys and R2_* are not read either: those services are connected in Settings.