Configuration

The environment variables for hosting a Sugabots installation.

Sugabots reads its settings from environment variables. With Docker Compose, set them under environment in compose.yml.

Database

VariableDefaultDescription
DATABASE_URLRequiredPostgreSQL connection string.

Server

VariableDefaultDescription
NODE_ENVproductiondevelopment or production.
PORT3000Port the API binds.
PUBLIC_URLhttp://localhost: followed by PORTWhere a browser reaches the API, without its /api path. Links in emails and OAuth redirects start here, so it must not be a container-internal address.
WEB_APP_URLPUBLIC_URLWhere the web app is served, when it is hosted apart from the API. Invite links and connection sign-ins return here.
SUGABOTS_SKIP_MIGRATIONSfalseDocker image only. Set to true to skip applying pending migrations on start.

Secrets

Generate each with openssl rand -base64 32. Keep them private and backed up.

VariableDefaultDescription
BETTER_AUTH_SECRETRequiredSigning key for sessions and tokens. Changing it signs everybody out.
CREDENTIALS_ENCRYPTION_KEYRequiredSeals every stored credential: model and search provider keys, connection secrets, and connection sign-ins. Losing it makes them unreadable.

Access

VariableDefaultDescription
ALLOW_OPEN_SIGNUPfalseWhether anybody may create an account. Off, the first person to arrive owns the installation, and after that the only way in is an invitation from a member.
REQUIRE_EMAIL_VERIFICATIONfalseWhether a new account must open a link in its inbox before it gets a session. With the console email provider, the link is printed to the server's console.

Network

VariableDefaultDescription
ALLOW_PRIVATE_MODEL_PROVIDER_NETWORKfalseWhether model providers may be reached over plain HTTP or at private addresses such as localhost or your LAN. Turn it on for a self-hosted install using Ollama, LM Studio, vLLM and the like; keep it off on an installation serving other people's workspaces.
ALLOW_PRIVATE_WEB_FETCH_NETWORKfalseWhether an agent's web_fetch tool may read pages at private addresses. Turn it on for a self-hosted install whose agents should read an intranet.

Email

VariableDefaultDescription
EMAIL_PROVIDERconsoleconsole, which prints each email to the server's log, or webhook.
EMAIL_WEBHOOK_URLRequired for webhookReceives each email as JSON: from, to, cc, bcc and replyTo as {email, name} addresses, subject, and text and/or html. Must use HTTPS in production.
EMAIL_WEBHOOK_TOKENNoneFor webhook. Sent as a bearer token with each delivery.
EMAIL_TRANSACTIONAL_FROMRequired in productionSender of emails a user's own action triggers, such as verification and invitations, like Sugabots <no-reply@example.com>.

Web app

Vite inlines anything prefixed VITE_ into the bundle, so nothing secret goes here.

VariableDefaultDescription
VITE_API_URL/api on the page's own originWhere the API is, path included. Set it when the web app is hosted apart from the API.