Environment
Template: pnxt-api-nestjs/.env.example. Validation: environment.validation.ts. Domain code is expected to read settings with ConfigService, not process.env.
Do not commit .env. This page names variables. It does not include secret values.
Required to boot
From comments in the example file and the validation module:
- Database URL for host runs.
- Redis URL.
- JWT access and refresh secrets. They must differ. In production each must be at least 32 characters.
- Credential vault key
CREDENTIAL_VAULT_KEY_V1. This is not the JWT secret. Integration credentials are encrypted with it, with a version field. - S3-compatible access key, secret, region, and bucket. Comments say Cloudflare R2 works through the same client. If
AWS_S3_PUBLIC_URLis unset, the public URL fallback 404s on R2. - AI base URL, API key, and model names, even when the AI workspace feature is off.
SENTRY_DSNwhenAPP_ENV=production.DEMO_SEED_PASSWORDon any reachable host.
AI_WORKSPACE_ENABLED must be the exact string true. Any other value fails AI routes closed with ai.error.workspaceDisabled. A daily token budget of 0 disables that limit (example-file comment).
Groups that become mandatory together
Once the first key in a group is set, the rest of the group is required at boot: SMTP, Razorpay, Amazon SP-API, Flipkart, BigCommerce.
| Group | Trigger observed |
|---|---|
| SMTP | SMTP_HOST set makes port and from-address mandatory |
| Razorpay | RAZORPAY_KEY_ID set makes secret and webhook secret mandatory |
| Amazon | client id set makes region and marketplace id required |
Stripe for WhatsApp is not in the main env block that was read. The adapter reads a secret from agent configuration.
Feature flags and local sidecars
| Variable | Observed behavior |
|---|---|
APP_ENV | production skips Swagger and tightens validation. Enum values include production, staging, development, local |
APP_LOG_LEVEL | Pino level. Containers default to info |
APP_DEBUG / app.debug | Stack traces and validation arrays in HTTP bodies only when debug is on |
| Cloudflare Turnstile keys | Blank keys disable the login/register CAPTCHA |
META_APP_SECRET | WhatsApp webhook HMAC. Unsigned payloads are rejected when it is unset (env comment) |
BHARATADDRESS_SIDECAR_URL | Address validation sidecar |
VOICE_STT_URL / VOICE_TTS_URL | Default to local Faster-Whisper and Kokoro |
BULL_BOARD_USER / BULL_BOARD_PASSWORD | Basic auth for /admin/queues |
Admin and warehouse
| App | Variable | Source |
|---|---|---|
| Admin | VITE_API_URL | pnxt-admin/.env.example, example value http://localhost:3001 |
| Admin | VITE_CLOUDFLARE_TURNSTILE_SITE_KEY, VITE_META_APP_ID, VITE_META_EMBEDDED_SIGNUP_CONFIG_ID | same example file |
| Warehouse | EXPO_PUBLIC_API_URL | pnxt-warehouse/README.md |
API CORS and ADMIN_APP_URL in the API example file point at http://localhost:5173.