Skip to content

Configuration

Everything is set in one file, .env, copied from the .env.example the repository ships. Docker Compose puts that copy in its place in the sequence; this page is what goes in the file.

Three values ship empty and have to be set before the first start. The stack refuses to come up while any of them is empty, naming every empty variable in one pass and the command that fills it.

They ship empty rather than pre-generated on purpose. An example file carrying real keys is a set of keys that is public and identical on every installation, and anyone who forgets to replace them runs on those.

Terminal window
openssl rand -hex 24 # paste after POSTGRES_PASSWORD=
openssl rand -hex 32 # paste after JWT_ACCESS_SECRET=
openssl rand -base64 32 # paste after SECRET_ENCRYPTION_KEY=
Variable What it is for Constraint
POSTGRES_PASSWORD the database password letters and digits only
JWT_ACCESS_SECRET signs the session token at least 16 characters
SECRET_ENCRYPTION_KEY encrypts your 2FA secret and stored provider API keys must decode to exactly 32 bytes

A passphrase-sealed JSON export is deliberately not tied to that key: the file carries its own derivation parameters, so it survives a key you no longer have.

Two things about the database password. It is interpolated into the connection URL as written, so a /, a ? or a # in it makes that URL unparsable and the application never starts. And it is read once and only once, when the database directory is created: changing it later locks the application out of its own database instead of changing anything.

Variable Default What it decides
WEB_PORT 8080 the port the whole app is reached on
BIND_ADDRESS 0.0.0.0 which host interfaces that port is published on; 127.0.0.1 keeps it on the machine
PUBLIC_URL http://localhost:8080 the address password-reset links are built from, and the cookie origin
COOKIE_SECURE false marks the session cookie HTTPS-only; set it behind a proxy terminating TLS
TRUSTED_PROXY_HOPS 0 how many reverse proxies of yours stand in front (see Behind a proxy)
REGISTRATION_ENABLED true whether public sign-up is open, as a fallback only
DEMO_SEED_ENABLED false seeds the read-only demonstration account on boot
ACCESS_TOKEN_TTL 15m how long a session token lives before it is refreshed
REFRESH_TOKEN_TTL_DAYS 7 how long a session survives without being used
COINGECKO_DEMO_KEY, OPENFIGI_API_KEY empty optional free integration keys; both sources work without one

The last two are the operator’s and are set here only: the settings screen has no field for either. REGISTRATION_ENABLED and DEMO_SEED_ENABLED are fallbacks: the equivalent toggles in Settings → Administration are stored in the database and win over these values from the moment either is first used.

Privacy