# Optional access control. Separate multiple accepted deployment passwords with commas. # Leave empty to disable the password gate. Production local API access also requires # ALLOW_INSECURE_LOCAL_PRODUCTION=true when no password is configured. ACCESS_PASSWORD="" # BYOK server key. Hosted single-instance deployments fall back to an ephemeral # process key when this is empty. Use a stable key for restarts, replicas, and # long-lived production. BYOK_ALLOW_EPHEMERAL_KEY controls non-hosted production. BYOK_PRIVATE_KEY_PEM="" BYOK_KEY_ID="" BYOK_ALLOW_EPHEMERAL_KEY="false" # Deployment safety. User-configured provider, search, RAG, plugin, and MCP # targets may use HTTP(S) and local/private addresses in either mode. Fixed # registries and service endpoints remain HTTPS-only. DEPLOYMENT_MODE="local" # Optional build-time release identifier. Use the same value for every replica # in one rollout; when omitted, each build generates a unique identifier. NEXT_DEPLOYMENT_ID="" ALLOW_INSECURE_LOCAL_PRODUCTION="false" # Retained to opt deployment-gated media/image proxy surfaces into HTTP. ALLOW_LOCAL_NETWORK_PROXY="" # Trust x-forwarded-* and related proxy headers only when your platform strips spoofed values. TRUST_PROXY_HEADERS="false" # Optional for local and single-instance hosted API rate limiting. # RATE_LIMIT_STORE, DOCUMENT_PARSE_JOB_STORE, and PLUGIN_REGISTRY_STORE support memory or upstash. # Hosted rate limiting falls back to process memory when Upstash is unavailable. # Document jobs, plugin registration, sharing, and multi-instance deployments # still require Upstash for consistent or durable behavior. # Deep Research's specialized arXiv, PubMed, EPO OPS, and SEC EDGAR adapters # also use this same Upstash pair for cross-instance provider rate coordination. # Hosted source calls fail closed when the pair is missing or unreachable. RATE_LIMIT_STORE="memory" DOCUMENT_PARSE_JOB_STORE="memory" PLUGIN_REGISTRY_STORE="memory" UPSTASH_REDIS_REST_URL="" UPSTASH_REDIS_REST_TOKEN="" # Conversation sharing is off by default. Enabling also requires the Redis pair. SHARING_ENABLED="false" # Upload limits. Values are bytes. MAX_ATTACHMENT_FILE_BYTES="10485760" # Public URLs. NEXT_PUBLIC_SITE_URL="http://localhost:3000" NEXT_PUBLIC_API_URL="" # Server default model provider. DEFAULT_PROVIDER_TYPE="Google" DEFAULT_PROVIDER_NAME="Default" DEFAULT_PROVIDER_BASE_URL="" DEFAULT_PROVIDER_API_KEY="" DEFAULT_PROVIDER_MODELS="" # Default task models. DEFAULT_MODEL_TITLE_GENERATION="" DEFAULT_MODEL_RELATED_QUESTIONS="" DEFAULT_MODEL_CONTEXT_COMPRESSION="" DEFAULT_MODEL_PROMPT_OPTIMIZATION="" DEFAULT_MODEL_RAG_QUERY="" DEFAULT_MODEL_MEMORY="" # Optional server-side default search provider: # tavily, firecrawl, exa, bocha, or searxng. # Leave empty to use keyless public Firecrawl directly from each user's browser. DEFAULT_SEARCH_PROVIDER="" DEFAULT_SEARCH_API_KEY="" DEFAULT_SEARCH_BASE_URL="" # Default RAG/vector store and document processing. DEFAULT_RAG_BASE_URL="" DEFAULT_RAG_TOKEN="" DEFAULT_RAG_TOP_K="10" DEFAULT_RAG_CHUNK_SIZE="512" DEFAULT_RAG_NAMESPACE="default" DEFAULT_DOCUMENT_PARSE_PROVIDER="mineru" DEFAULT_MINERU_API_TOKEN="" DEFAULT_LLAMA_PARSE_API_KEY="" # Default voice provider settings. DEFAULT_VOICE_PROVIDER="" DEFAULT_ELEVENLABS_API_KEY="" DEFAULT_ELEVENLABS_STT_MODEL="scribe_v2" DEFAULT_ELEVENLABS_TTS_MODEL="eleven_flash_v2_5" DEFAULT_ELEVENLABS_TTS_VOICE_ID="bIHbv24MWmeRgasZH58o" DEFAULT_MIMO_API_KEY="" DEFAULT_MIMO_STT_MODEL="mimo-v2.5-asr" DEFAULT_MIMO_TTS_MODEL="mimo-v2.5-tts" DEFAULT_MIMO_TTS_VOICE_ID="mimo_default" # Default system behavior. DEFAULT_SYSTEM_PROMPT="" DEFAULT_ENABLE_AUTO_TITLE="true" DEFAULT_ENABLE_RELATED_QUESTIONS="true" DEFAULT_ENABLE_AUTO_COMPRESSION="true" DEFAULT_COMPRESSION_THRESHOLD="12" DEFAULT_HISTORY_KEEP_COUNT="4" DEFAULT_ENABLE_CODE_COLLAPSE="true" DEFAULT_ENABLE_HTML_VISUAL_PROMPT="true"