Repository navigation
Expand file tree
/
Copy path.env.example
More file actions
121 lines (100 loc) · 5.59 KB
/
Copy path.env.example
File metadata and controls
121 lines (100 loc) · 5.59 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
# When adding additional environment variables, the schema in "/src/env.ts"
# should be updated accordingly.
REACT_EDITOR="cursor" # When you click a link in a Next.js app error route, it will open here
# Core Auth
AUTH_URL="http://localhost:3000" # Base URL for authentication
AUTH_SECRET="generate_a_secure_secret_here" # Run: `openssl rand -base64 32` in your terminal to generate a secure secret
# OAuth Providers
# GitHub: https://github.com/settings/developers
AUTH_GITHUB_ID="" # GitHub OAuth App Client ID
AUTH_GITHUB_SECRET="" # GitHub OAuth App Client Secret
# Discord: https://discord.com/developers/applications
AUTH_DISCORD_ID="" # Discord OAuth App Client ID
AUTH_DISCORD_SECRET="" # Discord OAuth App Client Secret
# Google: https://console.cloud.google.com/apis/credentials
AUTH_GOOGLE_ID="" # Google OAuth App Client ID
AUTH_GOOGLE_SECRET="" # Google OAuth App Client Secret
# Database
DATABASE_URL="postgresql://postgres:password@localhost:5432/shipkit"
# App Secret
APP_SECRET="" # One master secret; AUTH_SECRET, BETTER_AUTH_SECRET and PAYLOAD_SECRET derive from it
# better-auth (default for new projects), authjs, or clerk.
# clerk needs the @shipkit/clerk registry item and its keys; it is never picked automatically.
AUTH_STRATEGY=better-auth
# Auth options
DEBUG_AUTH="" # Set to "true" to turn on Auth.js debug logging
NEXTAUTH_SESSION_STRATEGY="" # Auth.js session strategy label reported in diagnostics ("jwt" or "database")
# More OAuth Providers
# Bitbucket: https://bitbucket.org/account/settings/app-passwords/
AUTH_BITBUCKET_ID="" # Bitbucket OAuth consumer key
AUTH_BITBUCKET_SECRET="" # Bitbucket OAuth consumer secret
# GitLab: https://gitlab.com/-/user_settings/applications
AUTH_GITLAB_ID="" # GitLab OAuth application ID
AUTH_GITLAB_SECRET="" # GitLab OAuth application secret
# Twitter / X: https://developer.x.com/en/portal/dashboard
AUTH_TWITTER_ID="" # Twitter OAuth 2.0 client ID
AUTH_TWITTER_SECRET="" # Twitter OAuth 2.0 client secret
# Magic link sign-in (Resend): https://resend.com/api-keys
# Both keys are required, and magic link works in production, not just locally.
RESEND_API_KEY="" # Resend API key
RESEND_FROM_EMAIL="" # Sender on a Resend-verified domain (required for magic link)
AUTH_ALLOWED_EMAILS="" # Optional sign-in allowlist: "[email protected], @corp.io". Unset = everyone.
# Admin access
ADMIN_EMAIL="" # Comma-separated emails granted admin
ADMIN_DOMAINS="" # Comma-separated email domains granted admin (exact match)
# Payload CMS (registry item @shipkit/payload)
PAYLOAD_SECRET="" # Payload CMS secret (or rely on APP_SECRET)
PAYLOAD_PUBLIC_DRAFT_SECRET="" # Secret for previewing Payload drafts
PAYLOAD_AUTO_SEED="" # Set to "false" to skip seeding Payload on first boot
PAYLOAD_SEED_FORCE="" # Set to "true" to re-run the Payload seed
# Payments (registry items @shipkit/stripe, @shipkit/lemonsqueezy, @shipkit/polar)
STRIPE_SECRET_KEY="" # Stripe secret key
STRIPE_PUBLISHABLE_KEY="" # Stripe publishable key (mirrored to NEXT_PUBLIC_)
STRIPE_WEBHOOK_SECRET="" # Stripe webhook signing secret
STRIPE_API_VERSION="" # Pin a Stripe API version (optional)
LEMONSQUEEZY_API_KEY="" # Lemon Squeezy API key
LEMONSQUEEZY_STORE_ID="" # Lemon Squeezy store ID
LEMONSQUEEZY_WEBHOOK_SECRET="" # Lemon Squeezy webhook signing secret
LEMONSQUEEZY_SANDBOX="" # Set to "true" to use the Lemon Squeezy test mode
POLAR_ACCESS_TOKEN="" # Polar access token
POLAR_PLATFORM_URL="" # Polar platform URL (sandbox or production)
# Cloudflare Turnstile (registry item @shipkit/turnstile); both keys are required to enable it
NEXT_PUBLIC_TURNSTILE_SITE_KEY="" # Turnstile site key (public)
TURNSTILE_SECRET_KEY="" # Turnstile secret key
# Storage
AWS_REGION="" # S3 region
AWS_ACCESS_KEY_ID="" # S3 access key
AWS_SECRET_ACCESS_KEY="" # S3 secret key
AWS_BUCKET_NAME="" # S3 bucket
VERCEL_BLOB_READ_WRITE_TOKEN="" # Vercel Blob token (registry item @shipkit/vercel-blob)
# Vercel integration
VERCEL_CLIENT_ID="" # Vercel OAuth client ID
VERCEL_CLIENT_SECRET="" # Vercel OAuth client secret
VERCEL_INTEGRATION_SLUG="" # Vercel integration slug
NEXT_PUBLIC_VERCEL_INTEGRATION_SLUG="" # Vercel integration slug (public)
NEXT_PUBLIC_GITHUB_CLIENT_ID="" # GitHub OAuth client ID used by the deploy flow
# Google
GOOGLE_FONTS_API_KEY="" # Google Fonts API key (font picker)
NEXT_PUBLIC_GOOGLE_MAPS_API_KEY="" # Google Maps API key (public)
# AI providers (registry item @shipkit/ai)
DEEPSEEK_API_KEY="" # DeepSeek API key
ELEVENLABS_API_KEY="" # ElevenLabs API key (text to speech)
FAL_API_KEY="" # fal.ai API key
FIRECRAWL_API_KEY="" # Firecrawl API key (web scraping)
GOOGLE_GEMINI_API_KEY="" # Google Gemini API key
HUGGINGFACE_API_KEY="" # Hugging Face API key
PERPLEXITY_API_KEY="" # Perplexity API key
REPLICATE_API_KEY="" # Replicate API key
# Trading APIs
ALPACA_API_KEY="" # Alpaca API key
ALPACA_SECRET_KEY="" # Alpaca secret key
ALPACA_BASE_URL="" # Alpaca base URL (paper or live)
ALPHA_VANTAGE_API_KEY="" # Alpha Vantage API key
STOCKTWITS_ACCESS_TOKEN="" # StockTwits access token
# Social media
TWITTER_API_KEY="" # Twitter API key
TWITTER_API_SECRET="" # Twitter API secret
TWITTER_ACCESS_TOKEN="" # Twitter access token
TWITTER_ACCESS_TOKEN_SECRET="" # Twitter access token secret
# Preview
PREVIEW_SECRET="" # Secret that unlocks feature-flag overrides on preview deployments