Env variables
Raw environment of the application. Changes apply on the next deploy.
This server is yours, and you can reach it directly over SSH — that is how your coding agent builds the project, restarts it and reads why something failed.
This is the raw environment of your project. A wrong value here does not fail loudly — it changes how a service behaves, or stops it starting. Prefer the dedicated pages (App settings, Languages, Login methods, OpenAI) where a value is validated before it is written.
Move it to your machine
Working on this project from your own machine? Download the environment file: your local copy then reads and writes the SERVER's rows, files and vector memory through it. Nothing is copied to your laptop, so there are no two versions of the data drifting apart.
Git never carries this file: .env, .env.local and .env.*.local are ignored on purpose, so keys cannot leak into a public repository. Downloading is not moving — put the file next to package.json in your local clone, then tick the box.
Give your agent access to the server
Your agent builds the project on the server and reads why something failed. To do that it needs a key — and the key is issued here, by you, in one click. Until you click, the agent has no way in: the environment file simply arrives without the access lines, and every attempt to build ends with a refusal.
One button is enough: press .env.local on the left. The access key is created on the server, authorised there and travels inside that same file — you place nothing by hand. Save the file next to package.json in your clone and tell your agent it can deploy.
The key is issued. Press again only to replace it — the previous one stops working.
The file carries the data-layer key. Put it in the project root, never into git — the starter's .gitignore already excludes it.
| Name | Value | |
|---|---|---|
| USER_GITHUB_ACCESS_TOKEN | ||
| USER_GITHUB_REPO_URL | ||
| APP_DB_PATH | ||
| AUTH_SECRET | ||
| CHANNELS_HOOK_SECRET | ||
| CHANNELS_HOOK_URL | ||
| COOKIE_SECURE | ||
| DATA_SECRET | ||
| DEPLOY_SECRET | ||
| FRACTERA_IP_NODOMAIN_MODE | ||
| LIGHTRAG_API_KEY | ||
| LIGHTRAG_URL | ||
| NEXT_PUBLIC_APP_SHELL_AUTH | ||
| NEXT_PUBLIC_MEDIA_URL | ||
| RAG_ENV_PATH | ||
| REMOTE_DATA_URL | ||
| TELEGRAM_HOOK_SECRET | ||
| COOKIE_DOMAIN | — | |
| NEXT_PUBLIC_ADMIN_URL | — | |
| NEXT_PUBLIC_AUTH_URL | — | |
| ALLOWED_ORIGINS | http://localhost:3000,http://localhost:3002,http://158.220.98.143:3000,http://158.220.98.143:3001,http://158.220.98.143:3002,http://158.220.98.143:3003,http://158.220.98.143:3004,http://158.220.98.143:3300,http://158.220.98.143:3600 | |
| AUTH_TRUST_HOST | true | |
| DATABASE_URL | file:/opt/fractera/app/data/app.db | |
| NEXT_PUBLIC_DEFAULT_LOCALE | en | |
| NEXT_PUBLIC_SUPPORTED_LANGUAGES | en | |
| NEXTAUTH_URL | http://158.220.98.143:3001 |
A locked name is derived from how the server runs — the mode, the domain, the language set, the way sign-in is wired. Editing it by hand would put it out of step with what is configured elsewhere, and what breaks is not this page but the way in. Change these through their own pages.
Values that live in the services
These do not sit in the environment file: the Telegram token and chat id belong to the channels service, the OpenAI key to the knowledge service. Shown here so you can check them without leaving the page.
not setnot setnot setnot setWhat these values are, and when they take effect
When a change takes effect. Most values are read by a service when it starts, so a save is only half the work — the service has to be restarted to see it. That is why the dedicated pages restart what they change and this one does not: here you may be editing anything, and restarting everything on every save would be worse than making you do it deliberately.
Some values are baked at build time. Anything beginning with NEXT_PUBLIC_ is compiled INTO the application, not read at runtime. Changing it here does nothing until the next deploy — the running application still carries the old value. This surprises people often enough to be worth stating plainly.
Why secrets show as a mask. A value whose name contains KEY, SECRET, TOKEN or PASSWORD is masked on the server and never sent to your browser. You can replace it; you cannot read it back. There is nothing to gain from looking at a key you already own, and plenty to lose from having it sit in a page.
Why some names cannot be edited. Their values follow from decisions made elsewhere — the mode the server runs in, the domain, the language set. A hand-edit here would rewrite one half of a pair and leave the other, and the failure would show up as “I cannot sign in” rather than “I mistyped a variable”.