Environment variables

Environment variables

Everything the Personal Agent Proxy server reads from its environment.

These tables are built from the server's own list of what it reads, so they always match the version they are published with. An empty variable counts as unset. With Docker Compose, the compose file's settings fill in most of them.

Core

Personal Agent Proxy does not work without these, though it still starts, so that its errors can say what is missing.

VariableRequired / defaultDescription
DATABASE_URLRequiredThe Postgres connection string. Percent-encode special characters in the password (@ is %40).
APP_URLRequiredWhere people open Personal Agent Proxy, such as https://proxy.example.com. Sign-in links and Google sign-in return here, and it is the only origin the api accepts browser requests from.
AUTH_SECRETRequiredHashes magic-link tokens before they are stored. Any long random string: openssl rand -hex 32.
ENCRYPTION_KEYRequiredEncrypts the app passwords and Information records Personal Agent Proxy stores: 32 random bytes, base64 (openssl rand -base64 32). Back it up: changing or losing it makes everything stored with it unreadable.

Sign-in

VariableRequired / defaultDescription
ALLOWED_SIGNUP_EMAILSOptionalWho can create an account: comma-separated addresses and domains, such as me@example.com,example.org (@example.org works too). People who already have an account can always sign in. Unset, anyone who can reach Personal Agent Proxy can sign up.
GOOGLE_CLIENT_IDOptionalTurns on Google sign-in, with GOOGLE_CLIENT_SECRET. Register <APP_URL>/auth/google/callback as the redirect URI.
GOOGLE_CLIENT_SECRETOptionalThe secret of the Google OAuth client.
RESEND_KEYOptionalSends magic-link emails through Resend, with EMAIL_FROM. Without it the api writes each link to its log instead, which is enough when you are the only one signing in.
EMAIL_FROMOptionalThe sender of magic-link emails, such as Personal Agent Proxy <login@example.com>, on a domain verified with Resend.

Deployment

VariableRequired / defaultDescription
NODE_ENVproductiondevelopment turns on the dev-only sign-in and logs magic links instead of sending them. Only bun run dev sets it.
PORT4000The port the api listens on.