Documentação

Variáveis de ambiente

Variáveis de ambiente obrigatórias e opcionais do Motoko Base — banco de dados, auth, cobrança, e-mail, armazenamento, analytics, monitoramento e IA.

Abrir emChatGPT (abre em uma nova aba)Claude (abre em uma nova aba)Cursor (abre em uma nova aba)Variáveis de ambiente obrigatórias e opcionais do Motoko Base — banco de dados, auth, cobrança, e-mail, armazenamento, analytics, monitoramento e IA.

O Motoko Base lê a configuração a partir de variáveis de ambiente. Copie .env.example para .env ou .env.local e preencha os valores:

cp .env.example .env

Nunca faça commit de segredos reais. .env* está no gitignore, exceto .env.example. Nunca coloque segredos só de servidor em NEXT_PUBLIC_* — eles são expostos ao navegador.

Integrações opcionais falham de forma suave quando não definidas: o app sobe, rotas não relacionadas continuam funcionando e as páginas de feature mostram uma mensagem clara de configuração em vez de quebrar.

Obrigatórias

Essas três variáveis bastam para iniciar o servidor de desenvolvimento e rodar migrations:

VariableRequiredPurpose
DATABASE_URLYesPostgreSQL connection string (server-only)
BETTER_AUTH_SECRETYesSigning secret for sessions and tokens
BETTER_AUTH_URLYesPublic origin for auth callbacks — use http://localhost:3000 locally

Gere um segredo:

openssl rand -base64 32

Fortemente recomendadas

A verificação de e-mail é obrigatória antes do acesso ao dashboard. Sem o Resend configurado, você consegue iniciar o app, mas não receberá e-mails de verificação após o cadastro.

VariableRequiredPurpose
RESEND_API_KEYRecommendedResend API key for transactional email
EMAIL_FROMRecommendedSender address, e.g. Motoko Base <onboarding@resend.dev> for Resend onboarding tests

Aplicação

VariableRequiredPurpose
NEXT_PUBLIC_APP_URLNoPublic app origin for short links (/r/{slug}) and password-reset redirects. Falls back to the request origin when unset. Keep aligned with BETTER_AUTH_URL in production.

Autenticação

VariableRequiredPurpose
BETTER_AUTH_SECRETYesSession and token signing secret
BETTER_AUTH_URLYesCanonical auth origin (must match the URL users hit for callbacks)
BETTER_AUTH_TRUSTED_ORIGINSNoComma-separated extra origins for preview/staging hosts
GOOGLE_CLIENT_IDNoGoogle OAuth client ID — leave unset to disable Google sign-in
GOOGLE_CLIENT_SECRETNoGoogle OAuth client secret
GITHUB_CLIENT_IDNoGitHub OAuth app client ID — leave unset to disable GitHub sign-in
GITHUB_CLIENT_SECRETNoGitHub OAuth app client secret

As callback URLs do OAuth devem corresponder a BETTER_AUTH_URL:

  • Google: {BETTER_AUTH_URL}/api/auth/callback/google
  • GitHub: {BETTER_AUTH_URL}/api/auth/callback/github

Banco de dados

VariableRequiredPurpose
DATABASE_URLYesPostgreSQL connection string (Supabase or local). Never NEXT_PUBLIC_*.

Para o Supabase em runtime, prefira o transaction pooler (muitas vezes a porta 6543). Se as migrations falharem pelo pooler, aponte temporariamente DATABASE_URL para a conexão direta (muitas vezes a porta 5432). Veja src/lib/db/README.md.

Cobrança

VariableRequiredPurpose
BILLING_PROVIDERNoBilling provider selection (polar in v1). Defaults to polar.
POLAR_ACCESS_TOKENNoPolar Organization Access Token — leave unset to stay on Free
POLAR_WEBHOOK_SECRETNoWebhook secret from Polar → Settings → Webhooks
POLAR_PRO_MONTHLY_PRODUCT_IDNoPro monthly product ID from Polar Dashboard
POLAR_PRO_YEARLY_PRODUCT_IDNoPro yearly product ID (optional)
POLAR_SERVERNosandbox or production (tokens and products are environment-specific)

Endpoint de webhook: {APP_URL}/api/billing/webhooks/polar

E-mail

VariableRequiredPurpose
RESEND_API_KEYNo*Resend API key (server-only)
EMAIL_FROMNo*Single sender identity, e.g. Motoko Base <noreply@yourdomain.com>

* Ambas são necessárias para a entrega de e-mail. O app sobe sem elas, mas a verificação de cadastro não funcionará.

Armazenamento

O Cloudflare R2 alimenta a demo File Storage e os uploads de avatar. Deixe indefinido para iniciar sem Storage.

VariableRequiredPurpose
R2_ACCOUNT_IDNoCloudflare account ID (used to build the S3 API endpoint)
R2_ACCESS_KEY_IDNoR2 API token access key
R2_SECRET_ACCESS_KEYNoR2 API token secret
R2_BUCKET_NAMENoPrivate bucket name. A slash is treated as an object-key prefix: my-bucket/demo → bucket my-bucket, prefix demo/
R2_PREFIXNoOptional explicit object-key prefix (overrides a slash suffix on the bucket name)
R2_ENDPOINTNoOptional S3 API endpoint override (defaults from R2_ACCOUNT_ID)

Analytics

O PostHog se divide em captura no cliente (project token) e consultas HogQL no servidor (personal API key).

VariableRequiredPurpose
NEXT_PUBLIC_POSTHOG_PROJECT_TOKENNoPostHog project API key for client capture
NEXT_PUBLIC_POSTHOG_HOSTNoIngest host (US default: https://us.i.posthog.com, EU: https://eu.i.posthog.com)
POSTHOG_PERSONAL_API_KEYNoPersonal API key with Query Read — used by /dashboard/analytics
POSTHOG_PROJECT_IDNoPostHog project ID for HogQL queries
POSTHOG_HOSTNoApp API host for Query API (US: https://us.posthog.com, EU: https://eu.posthog.com)

Monitoramento

VariableRequiredPurpose
NEXT_PUBLIC_SENTRY_DSNNoPublic Sentry DSN — leave unset to disable monitoring
SENTRY_AUTH_TOKENNoAuth token for source map upload during next build
SENTRY_ORGNoSentry organization slug
SENTRY_PROJECTNoSentry project slug

O Sentry também é desativado automaticamente durante next dev (mesmo com DSN definido) para evitar ruído de listeners do webpack.

IA

VariableRequiredPurpose
OPENAI_API_KEYNoOpenAI or compatible API key — leave unset to disable AI Email demo
OPENAI_BASE_URLNoOptional OpenAI-compatible API base URL
OPENAI_MODELNoModel ID (defaults to gpt-4o-mini)

Referência rápida por requisito de boot

CategoryMinimal bootFull feature set
DatabaseDATABASE_URLDATABASE_URL
AuthenticationBETTER_AUTH_SECRET, BETTER_AUTH_URL+ optional OAuth vars
Email—RESEND_API_KEY, EMAIL_FROM
Billing—POLAR_* vars
Storage—R2_* vars
Analytics—PostHog vars
Monitoring—Sentry vars
AI—OPENAI_API_KEY

Veja .env.example para comentários inline de cada variável.


Próximos passos

Configuração — Onde os arquivos de config ficam e como alterar navegação, planos de cobrança, metadata e integrações.