Configuration
Everything is configured with environment variables. .env.local.example in the repository lists them all with comments; the tables below explain what each one is for.
Core
| Variable | Purpose | |
|---|---|---|
SESSION_SECRET | Required | At least 32 characters; encrypts the session cookie. The app refuses to start in production without it. |
MODE | Optional | standalone (default) or organization. |
NEXT_PUBLIC_APP_URL | Optional | Public URL; used for OAuth redirects, same-origin checks, and the canonical and social-card URLs of public pages. Static pages read it at build time, so pass it to the image build as well when those URLs matter. |
Organization mode and access control
| Variable | Purpose | |
|---|---|---|
GITHUB_CLIENT_ID | Organization | OAuth App client id (Continue with GitHub). |
GITHUB_CLIENT_SECRET | Organization | OAuth App client secret. |
DATABASE_URL | Organization | Postgres connection string: users, groups, grants, audit, alerts, reports, shared cache. |
GITDASH_ADMIN_GITHUB_IDS | Organization | Comma-separated numeric GitHub ids that are always admins. |
GITDASH_ALLOWED_ORGS | Optional | Comma-separated orgs whose active members may sign in; empty means any GitHub account (it lands on /pending). |
GITDASH_RBAC_ENFORCE | Optional | true enforces group permissions; false (default) keeps everyone's access during rollout. |
GITDASH_LANDING_PAGE | Optional | true shows the /welcome product page to signed-out visitors at /, with Sign in leading to /login. For the public product site; leave unset when self-hosting. |
Sync, webhooks and caching
| Variable | Purpose | |
|---|---|---|
GITHUB_TOKEN | Optional | Server token for the nightly sync crons, which run without a user session. |
CRON_SECRET | Optional | Bearer token for /api/cron/*; the routes answer 401 without it. |
GITHUB_WEBHOOK_SECRET | Optional | Verifies /api/webhooks/github signatures; without it every webhook is rejected. |
GITDASH_L2_CACHE | Optional | 0 keeps the API cache in memory only (default: shared Postgres cache when a database is set). |
GITDASH_GH_LOG | Optional | 1 logs every GitHub call with its route and remaining budget. |
| Variable | Purpose | |
|---|---|---|
RESEND_API_KEY, RESEND_FROM | Optional | Email delivery through Resend (preferred). |
SMTP_HOST, SMTP_USER, SMTP_PASS, SMTP_FROM | Optional | Generic SMTP instead of Resend (or SENDGRID_API_KEY). Admins can also set email in Settings → Email and digests. |
AI insights
Optional. Without a key every AI surface is hidden. Providers are tried in this order and any without a key is skipped; in organization mode an admin can also set a provider in Settings → AI provider.
| Variable | Purpose |
|---|---|
BAILIAN_API_KEY, BAILIAN_MODEL, BAILIAN_BASE_URL | Alibaba Cloud Bailian (Anthropic Messages API). |
GEMINI_API_KEY, GEMINI_MODEL | Google Gemini. |
QWEN_API_KEY, QWEN_MODEL | Qwen via DashScope. |
AI_DISABLED | true turns every AI surface off regardless of keys. |
AI_TIMEOUT_MS, AI_TOTAL_BUDGET_MS, AI_DAILY_TOKEN_BUDGET | Per-attempt timeout, per-request time budget and a per-instance daily token cap. |
Demo data
NEXT_PUBLIC_DEMO_MODE=true (or ?demo=1 on a page) replaces GitHub data with a fictional organization, for screenshots and trials. You still sign in.