Documentation
Production Setup
Environment and integration checklist before deploying Motoko Base to production.
Use this checklist before your first production deploy. Required vars boot the app; optional integrations can be enabled one at a time.
Full env reference: Environment Variables.
Required
These four variables are the minimum for a working production app:
| Variable | Production value |
|---|---|
DATABASE_URL | Postgres connection string — prefer Supabase transaction pooler (port 6543) for runtime |
BETTER_AUTH_SECRET | Long random secret — generate with openssl rand -base64 32; never reuse the dev secret |
BETTER_AUTH_URL | Public HTTPS origin, e.g. https://app.example.com |
NEXT_PUBLIC_APP_URL | Same public origin — used for short links and redirects |
Keep BETTER_AUTH_URL and NEXT_PUBLIC_APP_URL aligned with the URL users actually visit.
Run migrations against production before or during the first deploy:
pnpm db:migrateIf DDL fails through the pooler, temporarily use a direct connection (port 5432). See Migrations.
Database
| Check | Action |
|---|---|
| Postgres running | Supabase, Neon, RDS, or self-hosted — any Postgres works |
| Migrations applied | pnpm db:migrate against production |
| Pooler for runtime | Use transaction pooler URL in DATABASE_URL for serverless/multi-instance hosts |
| RLS (Supabase) | Starter ships RLS enabled — app connects via pooler role, not anon key |
Details: Database.
Better Auth & secrets
| Check | Action |
|---|---|
| New production secret | Generate a fresh BETTER_AUTH_SECRET — do not copy from .env.local |
| HTTPS origin | BETTER_AUTH_URL must match your live domain (cookies + callbacks depend on it) |
| Trusted origins (optional) | BETTER_AUTH_TRUSTED_ORIGINS for preview/staging hosts |
Details: Better Auth.
OAuth callbacks
If you use Google or GitHub sign-in, update both the provider console and .env:
| Provider | Production callback URL |
|---|---|
{BETTER_AUTH_URL}/api/auth/callback/google | |
| GitHub | {BETTER_AUTH_URL}/api/auth/callback/github |
Set production GOOGLE_* / GITHUB_* credentials — sandbox/dev OAuth apps will not work on your live domain.
Details: OAuth Setup.
Resend
Required for signup verification and password reset in production.
| Variable | Notes |
|---|---|
RESEND_API_KEY | Production API key |
EMAIL_FROM | Verified domain sender, e.g. My App <noreply@yourdomain.com> |
Verify your domain in Resend (SPF/DKIM) before go-live.
Details: Email (Resend).
Polar
Switch from sandbox to production when billing goes live.
| Variable | Notes |
|---|---|
POLAR_SERVER | production |
POLAR_ACCESS_TOKEN | Production organization token |
POLAR_PRO_MONTHLY_PRODUCT_ID | Production product ID |
POLAR_WEBHOOK_SECRET | From production webhook config |
Webhook URL: {NEXT_PUBLIC_APP_URL}/api/billing/webhooks/polar
Test checkout in sandbox first. Details: Payments (Polar).
Cloudflare R2
| Variable | Notes |
|---|---|
R2_ACCOUNT_ID | Cloudflare account |
R2_ACCESS_KEY_ID / R2_SECRET_ACCESS_KEY | Production API token |
R2_BUCKET_NAME | Private bucket |
Configure bucket CORS for your production origin if browser uploads fail.
Details: Storage (R2).
PostHog
| Variable | Scope | Notes |
|---|---|---|
NEXT_PUBLIC_POSTHOG_PROJECT_TOKEN | Client | Production project token |
NEXT_PUBLIC_POSTHOG_HOST | Client | Match your PostHog region (US/EU) |
POSTHOG_PERSONAL_API_KEY | Server | For /dashboard/analytics HogQL |
POSTHOG_PROJECT_ID | Server | Production project ID |
POSTHOG_HOST | Server | API host (not ingest host) |
Details: Analytics (PostHog).
Sentry
| Variable | Notes |
|---|---|
NEXT_PUBLIC_SENTRY_DSN | Production project DSN |
SENTRY_AUTH_TOKEN | CI/build — source map upload |
SENTRY_ORG / SENTRY_PROJECT | CI/build — org and project slugs |
Set Sentry env vars in your build environment (CI), not only runtime, so source maps upload during pnpm build.
Sentry is disabled during next dev — verify with pnpm build && pnpm start or on the deployed host.
Details: Monitoring (Sentry).
Pre-launch checklist
- Production env vars set on the host (never commit secrets)
- Fresh
BETTER_AUTH_SECRETgenerated -
BETTER_AUTH_URLandNEXT_PUBLIC_APP_URLpoint to live HTTPS domain - Migrations applied to production database
- Resend domain verified; test verification email
- OAuth callback URLs updated (if using social sign-in)
- Polar webhook points to production URL (if using billing)
-
pnpm buildsucceeds locally or in CI - Smoke test: sign up → verify → dashboard → key integrations
Deployment — Deploy to any Next.js-compatible platform + Vercel example.