.env.example to .env. The UI and API have separate environments.
API
Root credentials are used for issuance and consent. They cannot authenticate health requests directly. Changing root credentials affects new sign-ins and issuance after the API restarts; revoke existing keys and sessions separately if needed.
Address-based limits use the IP address connecting directly to the API. Requests through one proxy may share a bucket; supplied client-address headers do not change it.
The API derives accepted hosts from
PUBLIC_BASE_URL and fixed loopback readiness addresses. The account timezone is saved in Account Settings → Preferences and defaults to UTC. It controls timestamp display, daily grouping and goal dates across the UI, REST and MCP. Instants remain stored in UTC; date-only records retain their original calendar dates. Changes apply without restarting the API.
Web app
The UI does not need
AUTH_KEY, database credentials or root credentials in its environment. Origin settings are read at runtime, so the same image can serve different installations.
See API keys for issuance and management, and MCP OAuth for client registration, token lifetimes and scopes.
Attachment storage
Set optionalS3_BUCKET, S3_ACCESS_KEY_ID, S3_SECRET_ACCESS_KEY, S3_ENDPOINT, S3_REGION, S3_FORCE_PATH_STYLE and S3_PREFIX on the API. A private bucket enables reusable image/PDF uploads capped at 20 MB per file. See attachments for provider setup, private URLs, backups and cleanup. The web app does not receive these credentials.