Where a browser reaches the API, without its /api path. Links in emails and OAuth redirects start here, so it must not be a container-internal address.
WEB_APP_URL
PUBLIC_URL
Where the web app is served, when it is hosted apart from the API. Invite links and connection sign-ins return here.
SUGABOTS_SKIP_MIGRATIONS
false
Docker image only. Set to true to skip applying pending migrations on start.
Whether anybody may create an account. Off, the first person to arrive owns the installation, and after that the only way in is an invitation from a member.
REQUIRE_EMAIL_VERIFICATION
false
Whether a new account must open a link in its inbox before it gets a session. With the console email provider, the link is printed to the server's console.
Whether model providers may be reached over plain HTTP or at private addresses such as localhost or your LAN. Turn it on for a self-hosted install using Ollama, LM Studio, vLLM and the like; keep it off on an installation serving other people's workspaces.
ALLOW_PRIVATE_WEB_FETCH_NETWORK
false
Whether an agent's web_fetch tool may read pages at private addresses. Turn it on for a self-hosted install whose agents should read an intranet.