Configure environment variables
Key environment variables for the Apantio AI admin, worker, voice gateway, storage, and providers.
Use .env.example as the source of truth. Store production values in your deployment secret manager or a permission-restricted .env file.
Application and database
| Variable | Purpose | | --- | --- | | APP_BASE_URL | Public HTTPS URL for the dashboard and API. | | DEPLOYMENT_MODE | cloud, self_hosted_standard, or development. | | DATABASE_URL | PostgreSQL connection for the service's main role: apantio_app for the admin, apantio_worker for the worker. | | APANTIO_AUTH_PASSWORD, APANTIO_WORKER_PASSWORD, APANTIO_DISPATCHER_PASSWORD | Passwords for the other roles. A service connects as each role by combining DATABASE_URL's host and database with that role's password. | | APANTIO_<ROLE>_DATABASE_URL | Optional. Overrides the built connection string for one role, for example to use a different host. | | BETTER_AUTH_SECRET | Better Auth signing secret. Use at least 32 random characters. | | ENCRYPTION_KEY | Encrypts stored application credentials and the one-time codes and links held in the email outbox until they are sent. | | NEXT_PUBLIC_LANDING_SITE_URL | Origin of the marketing site, used for the dashboard's links to pricing and legal pages. Set it at build time; without it links point at http://localhost:4321. | | OTP_HASH_SECRET | Hashes one-time verification codes. |
Internal services
| Variable | Purpose | | --- | --- | | BACKEND_INTERNAL_URL | Private admin URL used by the voice gateway. Compose sets this to http://admin:3000. | | INTERNAL_SERVICE_SECRET | HMAC secret for signed service requests. | | INTERNAL_SERVICE_TOKEN | Token used by protected internal health and compatibility routes. | | VOICE_GATEWAY_BASE_URL | Public HTTPS URL for Twilio callbacks and media streams. | | WEB_CALL_ALLOWED_ORIGINS | Comma-separated browser origins allowed to start web calls, in addition to APP_BASE_URL. Empty by default. Add each website that embeds the call button. | | NEXT_PUBLIC_WEB_CALL_ENDPOINT | Public browser endpoint ending in /web-call/sessions. |
Redis and file storage
| Variable | Purpose | | --- | --- | | REDIS_URL | Redis connection URL used by admin and worker runtimes. | | STORAGE_PROVIDER | local by default. Set to s3 for AWS S3, MinIO, or another compatible service. | | LOCAL_STORAGE_PATH | Filesystem path shared by the admin and worker. Compose mounts its persistent volume at /var/lib/apantio/storage. | | LOCAL_STORAGE_SIGNING_SECRET | Signs short-lived local upload and download URLs. Use a long random value. Falls back to INTERNAL_SERVICE_SECRET outside Compose. | | S3_ENDPOINT | Optional S3-compatible endpoint. Leave empty for AWS S3. | | S3_BUCKET | Bucket for recordings and uploads. | | S3_REGION | S3 region. Defaults to us-east-1. | | S3_ACCESS_KEY_ID, S3_SECRET_ACCESS_KEY | Object-storage credentials. | | S3_FORCE_PATH_STYLE | Set to true for MinIO. |
Local storage fits a single-host deployment. Use S3 when the admin and worker run on different hosts or when you need storage managed outside the Docker host.
Observability
| Variable | Purpose | | --- | --- | | OTEL_EXPORTER_OTLP_ENDPOINT | OTLP base URL. Apantio AI appends /v1/traces, /v1/metrics, and /v1/logs. Leave empty to disable export. | | OTEL_EXPORTER_OTLP_HEADERS | Optional comma-separated key=value headers sent with each OTLP request. For PostHog, use Authorization=Bearer your_posthog_project_token_here. |
An empty OTLP endpoint does not disable container stdout logs, application health endpoints, direct product analytics, or direct voice-gateway error reporting.
Providers
| Variable group | Purpose | | --- | --- | | TWILIO_* | Voice, verification, number provisioning, and webhook authentication. | | OPENAI_API_KEY | Realtime voice and fallback key for compatible AI providers. | | AI_CHAT_API_KEY, AI_CHAT_BASE_URL, AI_CHAT_MODEL, AI_CHAT_PROVIDER_NAME | OpenAI-compatible chat generation. | | AI_EMBEDDING_API_KEY, AI_EMBEDDING_BASE_URL, AI_EMBEDDING_MODEL, AI_EMBEDDING_PROVIDER_NAME, AI_EMBEDDING_REVISION | OpenAI-compatible 1536-dimensional embeddings. | | WIDGET_SESSION_SECRET | Signs cross-origin website-widget sessions. | | WEB_CALL_ALLOWED_ORIGINS | Origins allowed to reach the voice gateway transport; the signed widget token still controls the customer parent origin. | | FIRECRAWL_* | Website knowledge ingestion. | | GOOGLE_* | Google Calendar OAuth. | | SMTP_*, EMAIL_* | Transactional email. | | POLAR_* | Hosted billing and usage meters. | | POSTHOG_* | Direct product analytics and error reporting. |
Never place secrets in
NEXT_PUBLIC_*variables. Next.js includes those values in browser bundles.
Marketing site (apps/landing)
The marketing site is built separately (for example on Cloudflare Pages) and reads its own environment.
| Variable | Purpose | | --- | --- | | PUBLIC_SITE_URL | Origin of the marketing site, used for canonical URLs, the sitemap, Open Graph and JSON-LD. Required for astro build. | | PUBLIC_APP_URL | Origin of this app (APP_BASE_URL), used for Log in, Sign up, Docs and Affiliate links. Required for astro build. | | LANDING_LOCAL_BUILD | Set to 1 only for local or CI builds without real domains. The build then uses http://localhost:4321 and http://127.0.0.1:13000. |
A production build fails if PUBLIC_SITE_URL or PUBLIC_APP_URL is missing or points at localhost.