# Environment variables read by the backend. # # NOTE: the app reads real environment variables — it does NOT auto-load this # file. Set them in your shell, in docker-compose.yml, or in your host's # dashboard. This file is documentation (and a template for deploy configs). # Absolute path for the SQLite database file. Parent directory is created if # missing. Default when unset: backend/data.db # Docker compose sets this to /data/data.db (a named volume). AIDND_DB_PATH= # --------------------------------------------------------------------------- # Phase 9 — production hardening # --------------------------------------------------------------------------- # Switch from SQLite to a server database (hosted deploys use Neon Postgres). # Any SQLAlchemy URL; postgres:// and postgresql:// schemes are rewritten to # the psycopg3 driver automatically. The platform-conventional DATABASE_URL # is honored too (AIDND_DATABASE_URL wins if both are set). Unset = SQLite. AIDND_DATABASE_URL= # Comma-separated list of allowed CORS origins. Only needed when the frontend # is served from a different origin than the API; the production build is # served same-origin by FastAPI, so hosted deploys can leave this unset. # Default: http://localhost:5173,http://127.0.0.1:5173 (the Vite dev server). AIDND_CORS_ORIGINS= # --------------------------------------------------------------------------- # Phase 8 — optional accounts & multi-user (all optional; defaults keep the # app in frictionless single-user "local mode") # --------------------------------------------------------------------------- # "1"/"true" turns on multi-user mode: guest sessions via signed cookies, # register/login UI, per-user data. Leave unset for local installs. AIDND_MULTI_USER= # Secret for signing session cookies and encrypting stored API keys at rest. # If unset in local mode, one is auto-generated into `secret.key` next to the # database (fine for local/docker-volume runs). REQUIRED when # AIDND_MULTI_USER is on — the app refuses to start without it, because a # regenerated secret on an ephemeral hosted filesystem would log out every # user on each deploy. Generate one: # python -c "import secrets; print(secrets.token_urlsafe(48))" AIDND_SECRET_KEY= # Session cookie Secure flag (HTTPS-only). Defaults to on when # AIDND_MULTI_USER is on, off otherwise — set 0/1 only to override (e.g. 0 # when testing multi-user mode over plain http on a LAN address). AIDND_COOKIE_SECURE= # --- Shared demo key (BYOK fallback; only active when AIDND_MULTI_USER=1) --- # Users with no API key of their own get this server-funded endpoint with a # model whitelist and a per-day turn cap. Unset = no demo, users must bring # their own key. Memory bank/auto-summarization are disabled on demo turns. AIDND_DEMO_API_KEY= # Default endpoint if unset: https://openrouter.ai/api/v1 AIDND_DEMO_ENDPOINT_URL= # Comma-separated model whitelist. Default: google/gemma-4-26b-a4b-it:free AIDND_DEMO_MODELS= # Successful AI turns per user per day on the demo key. Default: 20 AIDND_DEMO_TURNS_PER_DAY= # Comma-separated emails of "power users" (trusted testers) who bypass the daily # demo cap entirely — unmetered turns on the shared demo key — and get the AI Chat # page (a plain scratchpad for talking to a model, hidden from everyone else). # Registered accounts only (guests have no email). Matched case-insensitively. # Local (single-user) installs are always treated as power users. AIDND_POWER_USERS= # The AI endpoint/API key/model are NOT env vars — they are configured at # runtime in the app's Settings page and stored (encrypted) in the database. # # Rate limits, request size limits, and per-user row caps are hardcoded with # generous values (see backend/app/limits.py) and active only in multi-user # mode — local installs are never throttled.