Skip to main content
Set secrets through your deployment’s secret manager. For local development, copy .env.example to .env. The UI and API have separate environments.

API

Root credentials are used for issuance and consent. They cannot authenticate health requests directly. Changing root credentials affects new sign-ins and issuance after the API restarts; revoke existing keys and sessions separately if needed.

Web app

The UI does not need AUTH_KEY, database credentials or root credentials in its environment. Origin settings are read at runtime, so the same image can serve different installations. See API keys for issuance and management, and MCP OAuth for client registration, token lifetimes and scopes.

Attachment storage

Set optional S3_BUCKET, S3_ACCESS_KEY_ID, S3_SECRET_ACCESS_KEY, S3_ENDPOINT, S3_REGION, S3_FORCE_PATH_STYLE and S3_PREFIX on the API. A private bucket enables reusable image/PDF uploads capped at 20 MB per file. See attachments for provider setup, private URLs, backups and cleanup. The web app does not receive these credentials.