# Local development environment variables. # Copy to .env and fill in the values: cp .env.example .env # ── Required ────────────────────────────────────────────── # Supabase project credentials (Dashboard -> Settings -> API) NEXT_PUBLIC_SUPABASE_URL=https://your-project.supabase.co NEXT_PUBLIC_SUPABASE_ANON_KEY=your-anon-or-publishable-key SUPABASE_SERVICE_ROLE_KEY=your-service-role-or-secret-key # App base URL (local dev) NEXT_PUBLIC_APP_URL=http://localhost:3000 # Secret for authenticating cron/scheduled requests. # Any non-empty random string for local dev: openssl rand -hex 16 CRON_SECRET=generate-a-random-secret # Hosted session security defaults: 30 minutes idle, 12 hours absolute, # with a warning 2 minutes before expiry. Set a timeout to 0 to disable that # limit. Self-hosted deployments default both limits to 0 unless overridden. # The signing key falls back to SUPABASE_SERVICE_ROLE_KEY; set a dedicated # random secret if session signing should rotate independently. # NEXT_PUBLIC_SESSION_IDLE_TIMEOUT_MS=1800000 # NEXT_PUBLIC_SESSION_ABSOLUTE_TIMEOUT_MS=43200000 # NEXT_PUBLIC_SESSION_WARNING_MS=120000 # SESSION_TIMEOUT_SECRET= # Self-hosted only: set to true when public signup is turned off in your # GoTrue/Supabase auth config (GOTRUE_DISABLE_SIGNUP / "Allow new users to # sign up" off). GoTrue offers no clean server-side read of that setting, so # this flag mirrors it. When true, inviting a teammate who has no account # provisions the account server-side via the auth admin invite API (GoTrue # must have SMTP configured to deliver that mail) instead of relying on # public /register, which GoTrue would reject with "Signups not allowed". # The GoTrue redirect URI allow-list (URI Allow List / GOTRUE_URI_ALLOW_LIST) # must include /invite/* or the invite email's redirect silently falls back # to SITE_URL. # Hosted keeps this unset: public signup stays open there. # AUTH_SIGNUPS_DISABLED=false # ── Optional: extension features (core runs without these) ─ # AI features: Claude via AWS Bedrock (document extraction + AI assistant). # Needs an AWS account with Bedrock model access to Claude. Plain # ANTHROPIC_API_KEY is NOT supported yet, see issue #1406. # AWS_ACCESS_KEY_ID= # AWS_SECRET_ACCESS_KEY= # AWS_REGION=eu-north-1 # BEDROCK_MODEL_ID= # Bank connections (Enable Banking) # ENABLE_BANKING_APP_ID= # ENABLE_BANKING_PRIVATE_KEY= # Accounting integrations # FORTNOX_CLIENT_ID= # FORTNOX_CLIENT_SECRET= # FORTNOX_REDIRECT_URI= # Björn Lundén app credentials (OAuth2 client credentials; per-company # User-Key is entered by the user in the migration wizard) # BJORN_LUNDEN_CLIENT_ID= # BJORN_LUNDEN_CLIENT_SECRET= # WhatsApp receipt intake (whatsapp-inbox extension, Meta Cloud API). # ACCESS_TOKEN: system-user permanent token with whatsapp_business_messaging # scope only. PHONE_NUMBER_ID: the Graph object id of the sending number. # APP_SECRET verifies X-Hub-Signature-256 on the webhook; VERIFY_TOKEN is the # GET-handshake shared secret you also enter in the Meta app dashboard. # PHONE_HASH_KEY: random pepper for phone lookup hashes (openssl rand -hex 32). # PHONE_ENCRYPTION_KEY: 32-byte hex AES-256-GCM key (openssl rand -hex 32). # WHATSAPP_ACCESS_TOKEN= # WHATSAPP_PHONE_NUMBER_ID= # WHATSAPP_APP_SECRET= # WHATSAPP_VERIFY_TOKEN= # WHATSAPP_PHONE_HASH_KEY= # WHATSAPP_PHONE_ENCRYPTION_KEY= # Optional: the public number as E.164 digits (e.g. 46766867041) for the # wa.me deep link in settings. Unset = resolved from the Graph API instead. # WHATSAPP_PUBLIC_NUMBER= # Bolagsverket: digital inlämning av årsredovisning (bolagsverket extension). # BOLAGSVERKET_ENV is test | accept | prod (default test) and also caps which # environment a company may select in settings (test < accept < prod). # Certificate material is read from env ONLY (PEM or base64-wrapped PEM): # never from extension settings or the database. # # SECRET CUSTODY (prod): never keep the real mTLS private key in a plaintext # .env file. Inject these at runtime from a secrets manager (Vercel encrypted # env vars, AWS Secrets Manager, Vault, Doppler, …), restrict read access to # the deploy pipeline, and rotate the client certificate/key on the cadence # agreed with Bolagsverket (and immediately on suspected exposure). Outbound # hosts are pinned per environment in extensions/general/bolagsverket/lib/ # client.ts (HOSTS): the endpoint is not configurable via env. # BOLAGSVERKET_ENV= # BOLAGSVERKET_CLIENT_CERT= # BOLAGSVERKET_CLIENT_KEY= # BOLAGSVERKET_CA= # Safety gate: enable only after agreement, certificate, test-bank fixtures, # acceptance testing, and production runbook approval are complete. # BOLAGSVERKET_FILING_ENABLED=false # NEXT_PUBLIC_BOLAGSVERKET_FILING_ENABLED=false # BOLAGSVERKET_ARELLE_VALIDATOR_URL= # BOLAGSVERKET_ARELLE_VALIDATOR_TOKEN= # ── Optional: product analytics + error tracking (PostHog) ─ # Hosted only. Self-hosted deployments never load PostHog: isAnalyticsEnabled() # (lib/analytics/enabled.ts) short-circuits on NEXT_PUBLIC_SELF_HOSTED=true, and # no __NEXT_PUBLIC_POSTHOG_*__ sentinel is baked into the Docker image, so an # operator cannot accidentally ship their users' behaviour to our project. # # The token is the PUBLIC project token (phc_...). It is embedded in the client # bundle by design and is not a secret. Leave unset to run with analytics off. # Browser traffic goes through the same-origin /rl rewrite in next.config.ts; # NEXT_PUBLIC_POSTHOG_HOST is only used by the server-side SDK. # NEXT_PUBLIC_POSTHOG_PROJECT_TOKEN= # NEXT_PUBLIC_POSTHOG_HOST=https://eu.i.posthog.com # # PostHog Support identity verification. A REAL SECRET (it also authenticates # external API requests), so no NEXT_PUBLIC_ prefix: it must never reach the # client bundle. Only the derived per-user HMAC crosses to the browser # (lib/analytics/identity-hash.ts). Unset means support tickets are scoped to # one browser session and users recover them by email link, which is the # normal state for local dev, CI and self-hosted. # POSTHOG_SECRET_API_KEY= # ── Optional: error tracking / observability ────────────── # The app routes every error-level log line, and anything flagged # `alert: true`, to a provider-agnostic sink (lib/observability). When the # PostHog token above is set, lib/init.ts registers the PostHog adapter # (lib/analytics/posthog-observability.ts) as that sink; otherwise the sink # stays a NO-OP, the PostHog client is never constructed and nothing is ever # sent. (The SDK is still bundled in those builds, since the imports are # static; it simply never initialises.) The variables below are for a # DIFFERENT vendor adapter and still change nothing on their own. # # Names are generic placeholders. When a provider is picked, either keep these # and read them in the adapter, or replace them with the vendor's own names. # OBSERVABILITY_DSN= # server-side ingest endpoint / key # NEXT_PUBLIC_OBSERVABILITY_DSN= # browser ingest endpoint / key, if used # Any adapter reading these MUST forward only post-redaction payloads # (lib/observability/redact.ts): see docs/security/logging-and-observability.md # Optional overrides. Both have sensible defaults: the environment falls back # to VERCEL_ENV then NODE_ENV, and the release falls back to # NEXT_PUBLIC_BUILD_ID (the commit sha next.config.ts inlines at build time) # then VERCEL_GIT_COMMIT_SHA. Set them only when tagging must differ. # OBSERVABILITY_ENVIRONMENT= # OBSERVABILITY_RELEASE=