Skip to main content
Copy .env.example to .env in the repository root and fill in the values below. Docker Compose reads .env automatically.
Variables marked Required must be set before starting the stack in production. The API will refuse to start (or log a fatal error) if JWT_SECRET is shorter than 32 characters or HS_SSH_ENCRYPTION_KEY is missing when DEBUG is not set.

Required

Never ship the placeholder values from .env.example to production. The API rejects JWT_SECRET shorter than 32 characters and any known default value when DEBUG is unset.

Network and CORS

Caddy and TLS

DNS for CADDY_PUBLIC_HOST must resolve to your server’s public IP before Caddy can obtain a certificate. See TLS & HTTPS for the full setup flow.

Database and storage

Provisioning (gifted subdomain)

These variables enable the optional Hyperspeed-operated provisioning gateway that creates *.hyperspeedapp.com DNS records for your install. Leave them unset if you are using a BYO domain.
When all three provisioning variables are set, GET /api/v1/public/instance returns provisioning_enabled: true and provisioning_base_domain: "hyperspeedapp.com". Authenticated users can then call POST /api/v1/provisioning/claim from the setup wizard or workspace settings.

Build metadata

These are typically passed as Docker build arguments rather than set in .env directly. See the repository docker-compose.yml for how they forward to the API image build.

Update notices

Neither UPSTREAM_GITHUB_REPO nor UPDATE_MANIFEST_URL causes any outbound requests from the server. The browser contacts the source directly, and only after the user opts in on the Dashboard.

OpenRouter tuning

These variables tune server-side tool calling for OpenRouter AI integrations. Organization API keys are managed in the app itself; these variables configure how the server invokes tools on behalf of users.

Cursor

These variables configure the Cursor-compatible API integration used for org-backed chat completions and Cloud Agents.

Debug and development