learn

Environment variables

One table per service, with defaults and requirements.

Secrets

Never commit real values. Service-local files override the shared root file. Use placeholders like <random-32+-chars> for every secret.

HTTP service

VariablePurposeNotes
DATABASE_URLPostgres connectionRequired — the client throws without it.
REDIS_URLRedis connection for rate limits and eventsRequired.
PORTListen portDefault 5000.
BETTER_AUTH_URLPublic API origin for authDefault http://localhost:PORT.
BETTER_AUTH_SECRETAuth signingRequired, use <random-32+-chars>.
WEB_ORIGINWeb origin for CORS and cookiesDefault http://localhost:3000; must be the deployed web URL.
PRESENCE_TICKET_SECRETWebSocket ticket signingRequired, must match the WS service.
ROOM_INVITE_SECRETInvite signingOptional — falls back to BETTER_AUTH_SECRET.
GOOGLE_CLIENT_ID / GOOGLE_CLIENT_SECRETGoogle OAuthOptional; Google is enabled only when both are set.
RESEND_API_KEY / EMAIL_FROMVerification emailRequired in production; in development the link is logged.

WebSocket service

VariablePurposeNotes
DATABASE_URLAccess checksRequired.
REDIS_URLLive snapshots and presenceRequired.
PRESENCE_TICKET_SECRETTicket verificationRequired, must match the HTTP service.
WS_PORTListen portDefault 8080; separate from PORT.
WEB_ORIGINAllowed originDefault http://localhost:3000.
WS_ALLOWED_ORIGINSExtra allowed originsOptional, comma-separated.

Flush worker

VariablePurposeNotes
DATABASE_URLRevision writesRequired.
REDIS_URLSnapshot reads and queueRequired.

Web app (NEXT_PUBLIC_*, build-time)

VariablePurposeNotes
NEXT_PUBLIC_API_URLHTTP service URLDefault http://localhost:5000; changing it needs a redeploy.
NEXT_PUBLIC_WS_URLWebSocket URLDefault ws://localhost:8080; changing it needs a redeploy.
NEXT_PUBLIC_GOOGLE_AUTH_ENABLEDGoogle sign-in buttonOff unless exactly true.

Last verified: 2026-10-11.

Provider docs

What it owns

  • Every variable each service reads
  • Which values must match across services

Talks to

Sources: .env.example, apps/http-server/.env.example, apps/ws-server/.env.example, apps/web/.env.example, packages/db/.env.example, packages/db/src/prisma/db.ts, packages/auth/src/server.ts, packages/auth/src/presenceTicket.ts, packages/auth/src/roomInvitation.ts (documented at commit b0026d9)

On this page