# Local development environment variables. # Copy to .env and fill in the values: cp .env.example .env # ── Required ────────────────────────────────────────────── # Supabase project credentials (Dashboard -> Settings -> API) NEXT_PUBLIC_SUPABASE_URL=https://your-project.supabase.co NEXT_PUBLIC_SUPABASE_ANON_KEY=your-anon-or-publishable-key SUPABASE_SERVICE_ROLE_KEY=your-service-role-or-secret-key # App base URL (local dev) NEXT_PUBLIC_APP_URL=http://localhost:3000 # Secret for authenticating cron/scheduled requests. # Any non-empty random string for local dev: openssl rand -hex 16 CRON_SECRET=generate-a-random-secret # ── Optional: extension features (core runs without these) ─ # AI features # ANTHROPIC_API_KEY= # OPENAI_API_KEY= # Bank connections (Enable Banking) # ENABLE_BANKING_APP_ID= # ENABLE_BANKING_PRIVATE_KEY= # Accounting integrations # FORTNOX_CLIENT_ID= # FORTNOX_CLIENT_SECRET= # FORTNOX_REDIRECT_URI= # Björn Lundén app credentials (OAuth2 client credentials; per-company # User-Key is entered by the user in the migration wizard) # BJORN_LUNDEN_CLIENT_ID= # BJORN_LUNDEN_CLIENT_SECRET= # Bolagsverket: digital inlämning av årsredovisning (bolagsverket extension). # BOLAGSVERKET_ENV is test | accept | prod (default test) and also caps which # environment a company may select in settings (test < accept < prod). # Certificate material is read from env ONLY (PEM or base64-wrapped PEM): # never from extension settings or the database. # # SECRET CUSTODY (prod): never keep the real mTLS private key in a plaintext # .env file. Inject these at runtime from a secrets manager (Vercel encrypted # env vars, AWS Secrets Manager, Vault, Doppler, …), restrict read access to # the deploy pipeline, and rotate the client certificate/key on the cadence # agreed with Bolagsverket (and immediately on suspected exposure). Outbound # hosts are pinned per environment in extensions/general/bolagsverket/lib/ # client.ts (HOSTS): the endpoint is not configurable via env. # BOLAGSVERKET_ENV= # BOLAGSVERKET_CLIENT_CERT= # BOLAGSVERKET_CLIENT_KEY= # BOLAGSVERKET_CA= # Safety gate: enable only after agreement, certificate, test-bank fixtures, # acceptance testing, and production runbook approval are complete. # BOLAGSVERKET_FILING_ENABLED=false # NEXT_PUBLIC_BOLAGSVERKET_FILING_ENABLED=false # BOLAGSVERKET_ARELLE_VALIDATOR_URL= # BOLAGSVERKET_ARELLE_VALIDATOR_TOKEN= # ── Optional: product analytics + error tracking (PostHog) ─ # Hosted only. Self-hosted deployments never load PostHog: isAnalyticsEnabled() # (lib/analytics/enabled.ts) short-circuits on NEXT_PUBLIC_SELF_HOSTED=true, and # no __NEXT_PUBLIC_POSTHOG_*__ sentinel is baked into the Docker image, so an # operator cannot accidentally ship their users' behaviour to our project. # # The token is the PUBLIC project token (phc_...). It is embedded in the client # bundle by design and is not a secret. Leave unset to run with analytics off. # Browser traffic goes through the same-origin /rl rewrite in next.config.ts; # NEXT_PUBLIC_POSTHOG_HOST is only used by the server-side SDK. # NEXT_PUBLIC_POSTHOG_PROJECT_TOKEN= # NEXT_PUBLIC_POSTHOG_HOST=https://eu.i.posthog.com # # PostHog Support identity verification. A REAL SECRET (it also authenticates # external API requests), so no NEXT_PUBLIC_ prefix: it must never reach the # client bundle. Only the derived per-user HMAC crosses to the browser # (lib/analytics/identity-hash.ts). Unset means support tickets are scoped to # one browser session and users recover them by email link, which is the # normal state for local dev, CI and self-hosted. # POSTHOG_SECRET_API_KEY= # ── Optional: error tracking / observability ────────────── # The app routes every error-level log line, and anything flagged # `alert: true`, to a provider-agnostic sink (lib/observability). When the # PostHog token above is set, lib/init.ts registers the PostHog adapter # (lib/analytics/posthog-observability.ts) as that sink; otherwise the sink # stays a NO-OP, the PostHog client is never constructed and nothing is ever # sent. (The SDK is still bundled in those builds, since the imports are # static; it simply never initialises.) The variables below are for a # DIFFERENT vendor adapter and still change nothing on their own. # # Names are generic placeholders. When a provider is picked, either keep these # and read them in the adapter, or replace them with the vendor's own names. # OBSERVABILITY_DSN= # server-side ingest endpoint / key # NEXT_PUBLIC_OBSERVABILITY_DSN= # browser ingest endpoint / key, if used # Any adapter reading these MUST forward only post-redaction payloads # (lib/observability/redact.ts): see docs/security/logging-and-observability.md # Optional overrides. Both have sensible defaults: the environment falls back # to VERCEL_ENV then NODE_ENV, and the release falls back to # NEXT_PUBLIC_BUILD_ID (the commit sha next.config.ts inlines at build time) # then VERCEL_GIT_COMMIT_SHA. Set them only when tagging must differ. # OBSERVABILITY_ENVIRONMENT= # OBSERVABILITY_RELEASE=