# Database DATABASE_URL=postgresql://epicure:epicure@localhost:5432/epicure # Redis REDIS_URL=redis://localhost:6379 # Storage (MinIO / S3-compatible) STORAGE_ENDPOINT=http://localhost:9000 STORAGE_ACCESS_KEY=minioadmin STORAGE_SECRET_KEY=minioadmin STORAGE_BUCKET=epicure-uploads STORAGE_REGION=us-east-1 # Auth (generate with: openssl rand -base64 32) BETTER_AUTH_SECRET= BETTER_AUTH_URL=http://localhost:3000 # Encryption key for BYOK AI keys stored in DB (generate with: openssl rand -base64 32) # Separate from BETTER_AUTH_SECRET for key separation. Falls back to BETTER_AUTH_SECRET if unset. ENCRYPTION_SECRET= # OAuth — Google (always available) GOOGLE_CLIENT_ID= GOOGLE_CLIENT_SECRET= # OAuth — GitHub (optional; set NEXT_PUBLIC_GITHUB_ENABLED=true to show button in UI) GITHUB_CLIENT_ID= GITHUB_CLIENT_SECRET= NEXT_PUBLIC_GITHUB_ENABLED= # OAuth — Discord (optional; set NEXT_PUBLIC_DISCORD_ENABLED=true to show button in UI) DISCORD_CLIENT_ID= DISCORD_CLIENT_SECRET= NEXT_PUBLIC_DISCORD_ENABLED= # OIDC — Authentik (or any OIDC provider) # AUTHENTIK_BASE_URL: base URL including application slug, e.g. # https://auth.example.com/application/o/epicure # The discovery document is fetched from $AUTHENTIK_BASE_URL/.well-known/openid-configuration # In authentik: create an OAuth2/OpenID provider, set redirect URI to # $BETTER_AUTH_URL/api/auth/callback/authentik AUTHENTIK_CLIENT_ID= AUTHENTIK_CLIENT_SECRET= AUTHENTIK_BASE_URL= # Set to true to show Authentik login button in UI NEXT_PUBLIC_AUTHENTIK_ENABLED= # SMTP (leave blank to log emails to console in dev) SMTP_HOST= SMTP_PORT=587 SMTP_SECURE=false SMTP_USER= SMTP_PASS= SMTP_FROM=Epicure # Web push (generate with: npx web-push generate-vapid-keys) NEXT_PUBLIC_VAPID_PUBLIC_KEY= VAPID_PRIVATE_KEY= # Gitea (optional — in-app support tickets open an issue here if all three are set) GITEA_URL= GITEA_TOKEN= GITEA_REPO=owner/repo # Set as the webhook secret on the Gitea repo's webhook config (issues + issue_comment # events) to sync issue close/reopen/comments back into Epicure support tickets. GITEA_WEBHOOK_SECRET= # Stripe (optional — webhook stub only) STRIPE_WEBHOOK_SECRET= # Shared secret for internal cron-triggered endpoints (e.g. weekly digest email). # Generate with: openssl rand -base64 32 CRON_SECRET= # AI Providers (configure at least one) OPENROUTER_API_KEY= OPENROUTER_DEFAULT_MODEL=google/gemini-flash-1.5 OPENAI_API_KEY= ANTHROPIC_API_KEY= OLLAMA_BASE_URL=http://localhost:11434 # Grocery delivery handoff (optional — without these, shopping lists only offer "copy as text") NEXT_PUBLIC_GROCERY_PROVIDER= INSTACART_API_KEY=