Skip to content

Environment reference ​

Common settings are listed below. See backend/src/config/registry/ for all variables, defaults, and validation rules.

Core ​

VariableDefaultPurpose
PORT8000Backend HTTP port
BACKEND_HOST0.0.0.0Backend listen address; use 127.0.0.1 for a private local server
NODE_ENVdevelopmentEnables production validation and hardening when set to production
FRONTEND_URLunsetComma-separated allowed frontend origins
TRUST_PROXYfalseExpress proxy trust; use a positive hop count behind a trusted proxy

Data ​

VariableDefaultPurpose
DATABASE_PROVIDERsqlite in production ComposeDocker entrypoint selects sqlite or postgresql
DATABASE_URLlocal SQLite filePrisma connection string
SNAPSHOT_RETENTION_DAYS2Drawing snapshot retention period
UPLOAD_MAX_MB100Import and database-restore upload limit
FILE_UPLOAD_MAX_MB100Per-image upload limit
BODY_LIMIT_MB50Scene request body and Socket.IO buffer limit

The frontend image limits HTTP request bodies to 50 MB in frontend/nginx.conf.template.

Authentication ​

VariableDefaultPurpose
AUTH_MODElocallocal, hybrid, oidc_enforced, or disabled
JWT_SECRETgenerated in some single-instance flowsSigns authentication tokens; set a stable production value
CSRF_SECRETgenerated in some single-instance flowsProtects state-changing browser requests
JWT_ACCESS_EXPIRES_IN15mAccess-token lifetime
JWT_REFRESH_EXPIRES_IN7dRefresh-token lifetime
BOOTSTRAP_SETUP_CODE_TTL_MS900000First administrator setup-code lifetime (15 minutes)

With local authentication enabled, users sign in through the email and password form.

Email and password sign-in when local authentication is enabledEmail and password sign-in when local authentication is enabled

OpenID Connect ​

Set OIDC_ISSUER_URL, OIDC_CLIENT_ID, OIDC_CLIENT_SECRET, and OIDC_REDIRECT_URI. Set AUTH_MODE to hybrid or oidc_enforced.

Use https://YOUR_HOST/api/auth/oidc/callback as the redirect URI. It must match the provider registration. See authentication.

Images and backups ​

VariableDefaultPurpose
S3_BUCKETunsetEnables S3 image storage
S3_REGIONus-east-1Bucket region
S3_ENDPOINTunsetEndpoint for an S3-compatible service
S3_PUBLIC_URLunsetPublic object URL; required for non-AWS endpoints
BACKUP_SCHEDULEunsetSQLite backup cron schedule; unset disables it
BACKUP_DIRbackend backups/ directoryDirectory for database backups
BACKUP_RETENTION_DAYS14Days to retain database backups

See backup configuration for a Compose example.

Email and password reset ​

Set ENABLE_PASSWORD_RESET=true, select MAIL_TRANSPORT, and configure either SMTP or Resend credentials. MAIL_FROM controls the visible sender.

After configuring delivery, users can select Forgot your password? on the sign-in page to request a reset link.

Password reset request form when the feature is enabledPassword reset request form when the feature is enabled

Self-hosted, open source, and built around Excalidraw.