.env.example to .env.local
(source installs) or put the values in the environment of the container.
Third-party service credentials are not environment variables. Unipile,
Google Workspace (Gmail), Cloudflare R2, OpenRouter and the enrichment
providers are connected per organization from Settings in the running app and
stored encrypted in the database. There is no environment fallback. See
integrations.md. The environment only holds what is needed
before the database can be read, public URLs, cron secrets and tuning knobs.
“Read in” lists the file that reads the variable.
Minimum production configuration
Generate each secret with
openssl rand -hex 32.
Core
Auth
Secrets
URLs
Docker Compose and demo
Workers and tuning
Kill switches
Operational switches written for the unified-People data migration. They are off by default and normally stay off. A value of1, true, yes or on
(case-insensitive) turns a switch on. They are re-read on every call, so they
take effect without a restart on platforms that refresh the environment. All
are read in src/lib/migration/controls.ts.
These are also a handy emergency brake: setting
PAUSE_EMAIL_OUTBOUND=true and
restarting stops sending without touching data.
Prospecting (domain qualification)
Used only by the Domains / qualification feature, which is slated for removal. Apollo for Tables is a separate per-organization connection.User-named variables (Tables HTTP column)
The HTTP column in Tables can authenticate with a bearer token read from an environment variable whose name the user types in the column settings (authEnvVar). The secret therefore comes from the server’s environment, never
from the database. Set whatever variable names your users reference. Read in
src/lib/grid/runners/http.ts.
Runtime variables set by the platform
Script-only variables
Read by tooling inscripts/, never by the running app.
Removed variables
AUTH_PASSWORD and AUTH_SECRET belonged to the old single shared password
and are no longer read by the app (AUTH_SECRET survives only as a legacy
key in the rotation script). OPENROUTER_API_KEY, UNIPILE_*, GOOGLE_*
service-account keys and R2_* are not read either: those services are
connected in Settings.