Documentation
Variables d’environnement
Variables d’environnement requises et optionnelles pour Motoko Base — base de données, auth, facturation, e-mail, stockage, analytics, monitoring et IA.
Motoko Base lit la configuration depuis les variables d’environnement. Copiez .env.example vers .env ou .env.local et renseignez les valeurs :
cp .env.example .envNe committez jamais de vrais secrets. .env* est gitignoré sauf .env.example. Ne placez jamais de secrets serveur-only sur NEXT_PUBLIC_* — ils sont exposés au navigateur.
Les intégrations optionnelles échouent soft lorsqu’elles ne sont pas définies : l’app démarre, les routes non liées continuent de fonctionner, et les pages de feature affichent un message de configuration clair au lieu de planter.
Requises
Ces trois variables suffisent pour démarrer le serveur de développement et lancer les migrations :
| Variable | Required | Purpose |
|---|---|---|
DATABASE_URL | Yes | PostgreSQL connection string (server-only) |
BETTER_AUTH_SECRET | Yes | Signing secret for sessions and tokens |
BETTER_AUTH_URL | Yes | Public origin for auth callbacks — use http://localhost:3000 locally |
Générer un secret :
openssl rand -base64 32Fortement recommandées
La vérification e-mail est obligatoire avant l’accès au dashboard. Sans Resend configuré, vous pouvez démarrer l’app mais vous ne recevrez pas d’e-mails de vérification après l’inscription.
| Variable | Required | Purpose |
|---|---|---|
RESEND_API_KEY | Recommended | Resend API key for transactional email |
EMAIL_FROM | Recommended | Sender address, e.g. Motoko Base <onboarding@resend.dev> for Resend onboarding tests |
Application
| Variable | Required | Purpose |
|---|---|---|
NEXT_PUBLIC_APP_URL | No | Public app origin for short links (/r/{slug}) and password-reset redirects. Falls back to the request origin when unset. Keep aligned with BETTER_AUTH_URL in production. |
Authentification
| Variable | Required | Purpose |
|---|---|---|
BETTER_AUTH_SECRET | Yes | Session and token signing secret |
BETTER_AUTH_URL | Yes | Canonical auth origin (must match the URL users hit for callbacks) |
BETTER_AUTH_TRUSTED_ORIGINS | No | Comma-separated extra origins for preview/staging hosts |
GOOGLE_CLIENT_ID | No | Google OAuth client ID — leave unset to disable Google sign-in |
GOOGLE_CLIENT_SECRET | No | Google OAuth client secret |
GITHUB_CLIENT_ID | No | GitHub OAuth app client ID — leave unset to disable GitHub sign-in |
GITHUB_CLIENT_SECRET | No | GitHub OAuth app client secret |
Les callback URLs OAuth doivent correspondre à BETTER_AUTH_URL :
- Google:
{BETTER_AUTH_URL}/api/auth/callback/google - GitHub:
{BETTER_AUTH_URL}/api/auth/callback/github
Base de données
| Variable | Required | Purpose |
|---|---|---|
DATABASE_URL | Yes | PostgreSQL connection string (Supabase or local). Never NEXT_PUBLIC_*. |
Pour Supabase au runtime, préférez le transaction pooler (souvent le port 6543). Si les migrations échouent via le pooler, pointez temporairement DATABASE_URL vers la connexion directe (souvent le port 5432). Voir src/lib/db/README.md.
Facturation
| Variable | Required | Purpose |
|---|---|---|
BILLING_PROVIDER | No | Billing provider selection (polar in v1). Defaults to polar. |
POLAR_ACCESS_TOKEN | No | Polar Organization Access Token — leave unset to stay on Free |
POLAR_WEBHOOK_SECRET | No | Webhook secret from Polar → Settings → Webhooks |
POLAR_PRO_MONTHLY_PRODUCT_ID | No | Pro monthly product ID from Polar Dashboard |
POLAR_PRO_YEARLY_PRODUCT_ID | No | Pro yearly product ID (optional) |
POLAR_SERVER | No | sandbox or production (tokens and products are environment-specific) |
Endpoint webhook : {APP_URL}/api/billing/webhooks/polar
| Variable | Required | Purpose |
|---|---|---|
RESEND_API_KEY | No* | Resend API key (server-only) |
EMAIL_FROM | No* | Single sender identity, e.g. Motoko Base <noreply@yourdomain.com> |
* Les deux sont nécessaires pour la livraison d’e-mails. L’app démarre sans elles, mais la vérification d’inscription ne fonctionnera pas.
Stockage
Cloudflare R2 alimente la démo File Storage et les uploads d’avatar. Laissez non défini pour démarrer sans Storage.
| Variable | Required | Purpose |
|---|---|---|
R2_ACCOUNT_ID | No | Cloudflare account ID (used to build the S3 API endpoint) |
R2_ACCESS_KEY_ID | No | R2 API token access key |
R2_SECRET_ACCESS_KEY | No | R2 API token secret |
R2_BUCKET_NAME | No | Private bucket name. A slash is treated as an object-key prefix: my-bucket/demo → bucket my-bucket, prefix demo/ |
R2_PREFIX | No | Optional explicit object-key prefix (overrides a slash suffix on the bucket name) |
R2_ENDPOINT | No | Optional S3 API endpoint override (defaults from R2_ACCOUNT_ID) |
Analytics
PostHog est divisé en capture client (project token) et requêtes HogQL serveur (personal API key).
| Variable | Required | Purpose |
|---|---|---|
NEXT_PUBLIC_POSTHOG_PROJECT_TOKEN | No | PostHog project API key for client capture |
NEXT_PUBLIC_POSTHOG_HOST | No | Ingest host (US default: https://us.i.posthog.com, EU: https://eu.i.posthog.com) |
POSTHOG_PERSONAL_API_KEY | No | Personal API key with Query Read — used by /dashboard/analytics |
POSTHOG_PROJECT_ID | No | PostHog project ID for HogQL queries |
POSTHOG_HOST | No | App API host for Query API (US: https://us.posthog.com, EU: https://eu.posthog.com) |
Monitoring
| Variable | Required | Purpose |
|---|---|---|
NEXT_PUBLIC_SENTRY_DSN | No | Public Sentry DSN — leave unset to disable monitoring |
SENTRY_AUTH_TOKEN | No | Auth token for source map upload during next build |
SENTRY_ORG | No | Sentry organization slug |
SENTRY_PROJECT | No | Sentry project slug |
Sentry est aussi désactivé automatiquement pendant next dev (même si le DSN est défini) pour éviter le bruit des listeners webpack.
IA
| Variable | Required | Purpose |
|---|---|---|
OPENAI_API_KEY | No | OpenAI or compatible API key — leave unset to disable AI Email demo |
OPENAI_BASE_URL | No | Optional OpenAI-compatible API base URL |
OPENAI_MODEL | No | Model ID (defaults to gpt-4o-mini) |
Référence rapide par exigence de démarrage
| Category | Minimal boot | Full feature set |
|---|---|---|
| Database | DATABASE_URL | DATABASE_URL |
| Authentication | BETTER_AUTH_SECRET, BETTER_AUTH_URL | + optional OAuth vars |
| — | RESEND_API_KEY, EMAIL_FROM | |
| Billing | — | POLAR_* vars |
| Storage | — | R2_* vars |
| Analytics | — | PostHog vars |
| Monitoring | — | Sentry vars |
| AI | — | OPENAI_API_KEY |
Voir .env.example pour les commentaires inline de chaque variable.
Prochaines étapes
Configuration — Où vivent les fichiers de config et comment modifier navigation, plans de facturation, metadata et intégrations.