DevHoardDocs
TermsPrivacyHomeOpen app

reference · ops

Environment variables

Updated Sun Aug 16 2026 00:00:00 GMT+0000 (Coordinated Universal Time)

Environment variables

Auth URL (common footgun)

  • Local: AUTH_URL=http://localhost:3000 — if this is set to https://devhoard.me, OAuth and magic-link callbacks leave localhost for production.
  • Vercel Production: AUTH_URL=https://devhoard.me

Also register localhost callbacks in GitHub/Google OAuth apps:

  • http://localhost:3000/api/auth/callback/github
  • http://localhost:3000/api/auth/callback/google

Core

VariableRole
DATABASE_URLNeon pooled URL (runtime + ideally Build)
DIRECT_URL / DATABASE_URL_UNPOOLEDMigrations
AUTH_SECRETAuth.js session secret
ITEM_ENCRYPTION_KEYSECRET item AES key (base64 32 bytes)

Soft-launch ops

VariableRole
ADMIN_EMAILSComma-separated emails for Owner metrics (/app/admin/metrics). Case-insensitive match to session email. Does not grant Pro or IMAGE uploads. Local: .env.local + restart npm run dev. Prod: Vercel env + redeploy.
R2_ACCOUNT_IDCloudflare R2 account
R2_ACCESS_KEY_ID / R2_SECRET_ACCESS_KEYR2 API token
R2_BUCKETPrivate bucket name
R2_ENDPOINTOptional; defaults to https://$R2_ACCOUNT_ID.r2.cloudflarestorage.com
CRON_SECRETBearer for /api/cron/purge-trash

Missing R2_* with a Pro user → 503 “Storage is not configured” on upload (not a Pro issue). CORS must allow your app origin (including http://localhost:3000 for local PUT).

See .env.example for the full list (OAuth, Resend, Upstash, Turnstile, Sentry).