> Source: https://www.gitdash.info/docs/configuration · GitDash v4.7.1

# Configuration

Everything is configured with environment variables. `.env.local.example` in the repository lists them all with comments; the tables below explain what each one is for.

## Core

| Variable |  | Purpose |
| --- | --- | --- |
| `SESSION_SECRET` | Required | At least 32 characters; encrypts the session cookie. The app refuses to start in production without it. |
| `MODE` | Optional | `standalone` (default) or `organization`. |
| `NEXT_PUBLIC_APP_URL` | Optional | Public URL; used for OAuth redirects, same-origin checks, and the canonical and social-card URLs of public pages. Static pages read it at build time, so pass it to the image build as well when those URLs matter. |

## Organization mode and access control

| Variable |  | Purpose |
| --- | --- | --- |
| `GITHUB_CLIENT_ID` | Organization | OAuth App client id (Continue with GitHub). |
| `GITHUB_CLIENT_SECRET` | Organization | OAuth App client secret. |
| `DATABASE_URL` | Organization | Postgres connection string: users, groups, grants, audit, alerts, reports, shared cache. |
| `GITDASH_ADMIN_GITHUB_IDS` | Organization | Comma-separated numeric GitHub ids that are always admins. |
| `GITDASH_ALLOWED_ORGS` | Optional | Comma-separated orgs whose active members may sign in; empty means any GitHub account (it lands on /pending). |
| `GITDASH_RBAC_ENFORCE` | Optional | `true` enforces group permissions; `false` (default) keeps everyone's access during rollout. |
| `GITDASH_LANDING_PAGE` | Optional | `true` shows the /welcome product page to signed-out visitors at /, with Sign in leading to /login. For the public product site; leave unset when self-hosting. |

## Sync, webhooks and caching

| Variable |  | Purpose |
| --- | --- | --- |
| `GITHUB_TOKEN` | Optional | Server token for the nightly sync crons, which run without a user session. |
| `CRON_SECRET` | Optional | Bearer token for /api/cron/*; the routes answer 401 without it. |
| `GITHUB_WEBHOOK_SECRET` | Optional | Verifies /api/webhooks/github signatures; without it every webhook is rejected. |
| `GITDASH_L2_CACHE` | Optional | `0` keeps the API cache in memory only (default: shared Postgres cache when a database is set). |
| `GITDASH_GH_LOG` | Optional | `1` logs every GitHub call with its route and remaining budget. |

## Email

| Variable |  | Purpose |
| --- | --- | --- |
| `RESEND_API_KEY`, `RESEND_FROM` | Optional | Email delivery through Resend (preferred). |
| `SMTP_HOST`, `SMTP_USER`, `SMTP_PASS`, `SMTP_FROM` | Optional | Generic SMTP instead of Resend (or `SENDGRID_API_KEY`). Admins can also set email in Settings → Email and digests. |

## AI insights

Optional. Without a key every AI surface is hidden. Providers are tried in this order and any without a key is skipped; in organization mode an admin can also set a provider in Settings → AI provider.

| Variable | Purpose |
| --- | --- |
| `BAILIAN_API_KEY`, `BAILIAN_MODEL`, `BAILIAN_BASE_URL` | Alibaba Cloud Bailian (Anthropic Messages API). |
| `GEMINI_API_KEY`, `GEMINI_MODEL` | Google Gemini. |
| `QWEN_API_KEY`, `QWEN_MODEL` | Qwen via DashScope. |
| `AI_DISABLED` | `true` turns every AI surface off regardless of keys. |
| `AI_TIMEOUT_MS`, `AI_TOTAL_BUDGET_MS`, `AI_DAILY_TOKEN_BUDGET` | Per-attempt timeout, per-request time budget and a per-instance daily token cap. |

## Demo data

`NEXT_PUBLIC_DEMO_MODE=true` (or `?demo=1` on a page) replaces GitHub data with a fictional organization, for screenshots and trials. You still sign in.
