Environment variables
This page describes environment and deployment-related configuration for the monorepo.
Next.js app (site-nextjs) — official full stack
The production implementation in this monorepo today is primarily the Next.js app under site-nextjs/, with Convex, Better Auth, Square, and Radar. Most variables and file layout below are Next.js–specific (NEXT_*, App Router, Vercel).
Local development
For local development, we use .env and .env.local files.
Variable file overview
-
.env: Contains non-sensitive development defaults. Shared across some tools but overridden by.env.localin Next.js. -
.env.local: Contains your personal API keys and secrets. This file is ignored by git. -
.env.example: A template for the.envfile. -
.env.local.example: A template for the.env.localfile.
Next.js encourages use of .env.local to store all personal secrets. While .env will work, it is less accurate for local overrides. Variables in .env.local override variables in .env, which is useful if you are testing a function locally and you don’t want to replace shared information in .env.
Because most software developers are unaware of the difference, they might drop sensitive information into .env instead of .env.local. To be safe, both are excluded from git via .gitignore. Other non-local versions (like .env.development) are also typically ignored to prevent hardcoded secrets in project history.
CI/CD pipeline
If you are trying to deploy this code via CI/CD pipelines on GitHub, Vercel, or other deployment platforms, do not use .env files to store variables. Environment variables for staging or production environments should be managed by secret managers or injected directly into the deployment pipeline.
Setup
To get started, copy the template files in the site-nextjs directory:
cd site-nextjs
cp .env.example .env
cp .env.local.example .env.local
Variable reference
| Variable | Description | Source |
|---|---|---|
|
Base URL for the API (server-side calls) |
Internal / Zuplo |
|
Base URL for API calls from the frontend |
Internal / Vercel Domain |
|
Tile provider for Find map. OpenFreeMap via MapLibre ( |
Internal (Default: |
|
Publishable key for Radar geocoding / autocomplete only (not required for map tiles) |
|
|
Optional Convex CLI target ( |
|
|
Convex HTTP URL the Next.js app queries. Until release, local + Vercel Preview/Development use the same production URL as |
|
|
Deploy key so Vercel production builds can |
|
Optional. Reference Convex URL for |
|
|
Optional. Deploy/admin key for the reference deployment in schema parity. Falls back to |
|
|
Optional. Personal/dev Convex URL for schema parity. Falls back to |
|
|
Optional. Deploy/admin key for the personal/dev deployment in schema parity. Falls back to |
|
|
Square Application ID |
|
|
Square Access Token (Sandbox/Production) |
|
|
Square Webhook Signature Key |
|
|
Random string for NextAuth.js encryption |
Generate with |
|
32-character key for data encryption (Local) |
Any random 32-character string |
|
32-character key for sensitive token encryption (Vercel) |
Any random 32-character string |
|
Secret for Better Auth session signing (use a long random string in production) |
Generate with |
|
Public origin of the Next.js app as seen by the auth server (no trailing path). Better Auth stores sessions in SQLite: |
e.g. |
|
Same origin as |
Must match deployment URL (include |
|
Optional store listing URLs for homepage badges. Empty → Coming soon (do not invent links). |
Play Console / App Store Connect / Partner Center when listings exist |
|
Optional. GitHub repo whose latest release assets feed the homepage Download button. Defaults to |
GitHub |
|
Comma-separated list of sign-in emails granted the Convex |
e.g. |
|
Comma-separated list of sign-in emails granted |
e.g. |
|
Inbox that receives “new host request” notifications. Defaults to |
e.g. |
|
Optional. When set, host-request and approval emails send via Resend. Without the key, emails are logged server-side only. Transactional / app only — use sending host |
Resend dashboard; DNS in org |
Customer.io / Twilio (planned) |
Fan sends (including owner-paid follower campaigns) are not wired yet. Customer.io is the marketing + multi-channel orchestration platform (US data center; Email, SMS, Push, In-app). Owner requests use existing Resend transactional mail to PR. Twilio is the planned SMS transport. Add site/API and Twilio secrets here when provisioned; never ship write keys to browsers. See Messaging & marketing (Customer.io) and Follower marketing. |
|
|
Optional. Yoti Age Verification credentials for affiliated host age + liveness checks. Leave unset in local/dev to use the stub verification path documented in Community events. |
|
|
Adapty public SDK key for mobile ( |
|
|
Adapty secret API key for Next.js server-side profile and access-level checks ( |
Adapty Dashboard → App Settings → API keys |
|
Google OAuth credentials for Better Auth social sign-in |
|
|
Convex deployment only (not Next.js). Google AI Studio / Gemini API key for menu photo parsing ( |
Google AI Studio or Cloud Console → APIs & Services → Credentials |
|
Optional. Convex-only model id for menu vision parse (default |
e.g. |
|
Optional. Convex-only model id for listing logo/cover/gallery auto-review (falls back to |
e.g. |
|
Meta (Facebook) OAuth credentials for Better Auth social sign-in. In the Meta app, add a Valid OAuth Redirect URI that matches your deployment: the app origin (same as |
|
Vercel deployment
For production deployments on Vercel, variables are managed in the Vercel Dashboard under Settings > Environment Variables.
Important notes
-
CONVEX_DEPLOY_KEY is required on Vercel Production only. Preview and Development skip
convex deployand must setNEXT_PUBLIC_CONVEX_URLto the production Convex URL (shared data until release). -
NEXT_PUBLIC_CONVEX_URL is set explicitly for Preview/Development. Production builds still let
pnpm convex deploy --cmdinject it; keeping the same URL in the dashboard is fine. -
Square variables are only needed if you’re using Square POS integration. Get credentials from the Square Developer Portal.
-
Radar variables are needed for place search / geocoding (typeahead, reverse geocode). Find map tiles use MapLibre + OpenFreeMap and do not require a Radar key.
-
Map tiles: MapLibre GL JS loads OpenFreeMap styles directly. Mapbox is deferred. Radar is not used for the map shell.
-
TOKEN_ENCRYPTION_KEY should be a strong random string (at least 32 characters). Use it to encrypt sensitive data like Square access tokens.
-
NEXT_PUBLIC_* variables are exposed to the browser. Never put secrets in these variables.
-
Do not pull environment variables via Vercel CLI. If prompted by
vercel --prodto download variables, select NO. This prevents Vercel from overwriting your local setup or creating redundant.envfiles. -
Social login: Set
BETTER_AUTH_URLandNEXT_PUBLIC_APP_URLto the production site origin. For Facebook, register the matching/api/auth/callback/facebookredirect URI in the Meta app. -
Square: Use one Square application for both POS linking and seller sign-in. Register two redirect URIs in the Square app: the POS link URL (
SQUARE_REDIRECT_URI, path/api/auth/callback/square) and the Better Auth URL with path/api/auth/oauth2/callback/squareon the same origin asBETTER_AUTH_URL.
For more details, see the Deployment guide in the Next.js section.