Fractera Admin

Env variables

Raw environment of the application. Changes apply on the next deploy.

This server is yours, and you can reach it directly over SSH — that is how your coding agent builds the project, restarts it and reads why something failed.

This is the raw environment of your project. A wrong value here does not fail loudly — it changes how a service behaves, or stops it starting. Prefer the dedicated pages (App settings, Languages, Login methods, OpenAI) where a value is validated before it is written.

Move it to your machine

Working on this project from your own machine? Download the environment file: your local copy then reads and writes the SERVER's rows, files and vector memory through it. Nothing is copied to your laptop, so there are no two versions of the data drifting apart.

Git never carries this file: .env, .env.local and .env.*.local are ignored on purpose, so keys cannot leak into a public repository. Downloading is not moving — put the file next to package.json in your local clone, then tick the box.

Give your agent access to the server

Your agent builds the project on the server and reads why something failed. To do that it needs a key — and the key is issued here, by you, in one click. Until you click, the agent has no way in: the environment file simply arrives without the access lines, and every attempt to build ends with a refusal.

One button is enough: press .env.local on the left. The access key is created on the server, authorised there and travels inside that same file — you place nothing by hand. Save the file next to package.json in your clone and tell your agent it can deploy.

The key is issued. Press again only to replace it — the previous one stops working.

The file carries the data-layer key. Put it in the project root, never into git — the starter's .gitignore already excludes it.

NameValue
USER_GITHUB_ACCESS_TOKEN
USER_GITHUB_REPO_URL
APP_DB_PATH
AUTH_SECRET
CHANNELS_HOOK_SECRET
CHANNELS_HOOK_URL
COOKIE_SECURE
DATA_SECRET
DEPLOY_SECRET
FRACTERA_IP_NODOMAIN_MODE
LIGHTRAG_API_KEY
LIGHTRAG_URL
NEXT_PUBLIC_APP_SHELL_AUTH
NEXT_PUBLIC_MEDIA_URL
RAG_ENV_PATH
REMOTE_DATA_URL
TELEGRAM_HOOK_SECRET
COOKIE_DOMAIN—
NEXT_PUBLIC_ADMIN_URL—
NEXT_PUBLIC_AUTH_URL—
ALLOWED_ORIGINShttp://localhost:3000,http://localhost:3002,http://158.220.98.143:3000,http://158.220.98.143:3001,http://158.220.98.143:3002,http://158.220.98.143:3003,http://158.220.98.143:3004,http://158.220.98.143:3300,http://158.220.98.143:3600
AUTH_TRUST_HOSTtrue
DATABASE_URLfile:/opt/fractera/app/data/app.db
NEXT_PUBLIC_DEFAULT_LOCALEen
NEXT_PUBLIC_SUPPORTED_LANGUAGESen
NEXTAUTH_URLhttp://158.220.98.143:3001
An empty secret field means “leave unchanged”.

A locked name is derived from how the server runs — the mode, the domain, the language set, the way sign-in is wired. Editing it by hand would put it out of step with what is configured elsewhere, and what breaks is not this page but the way in. Change these through their own pages.

Values that live in the services

These do not sit in the environment file: the Telegram token and chat id belong to the channels service, the OpenAI key to the knowledge service. Shown here so you can check them without leaving the page.

Telegram botnot set
Telegram chat idnot set
Telegram tokennot set
OpenAI keynot set
What these values are, and when they take effect

When a change takes effect. Most values are read by a service when it starts, so a save is only half the work — the service has to be restarted to see it. That is why the dedicated pages restart what they change and this one does not: here you may be editing anything, and restarting everything on every save would be worse than making you do it deliberately.

Some values are baked at build time. Anything beginning with NEXT_PUBLIC_ is compiled INTO the application, not read at runtime. Changing it here does nothing until the next deploy — the running application still carries the old value. This surprises people often enough to be worth stating plainly.

Why secrets show as a mask. A value whose name contains KEY, SECRET, TOKEN or PASSWORD is masked on the server and never sent to your browser. You can replace it; you cannot read it back. There is nothing to gain from looking at a key you already own, and plenty to lose from having it sit in a page.

Why some names cannot be edited. Their values follow from decisions made elsewhere — the mode the server runs in, the domain, the language set. A hand-edit here would rewrite one half of a pair and leave the other, and the failure would show up as “I cannot sign in” rather than “I mistyped a variable”.

GitHub connection required
en

North America

🇺🇸Englishen

Eastern Europe & CIS

🇷🇺Русскийru

Sub-Saharan Africa

🇺🇸Englishen

Asia Pacific

🇺🇸Englishen