InboxorcistInboxorcist

Configuration

Complete reference for all environment variables and configuration options.

Security Variables

VariableDescriptionFormat
JWT_SECRETSecret for signing authentication tokensMinimum 32 characters
ENCRYPTION_KEYKey for encrypting OAuth tokens at restExactly 64 hexadecimal characters

Binary installation: These are auto-generated on first run. No manual configuration needed.

Docker/Cloud deployment: You must generate and set these manually.

Generate these securely:

# Generate JWT_SECRET
openssl rand -base64 32

# Generate ENCRYPTION_KEY
openssl rand -hex 32

Never commit these secrets to version control. Use environment variables or secrets management.

Google OAuth

VariableDescriptionExample
GOOGLE_CLIENT_IDOAuth client ID from Google Cloud Console123456789.apps.googleusercontent.com
GOOGLE_CLIENT_SECRETOAuth client secretGOCSPX-xxxxxxxxxxxxx

These are optional in .env. If not set, you can configure them via the web UI at /setup on first run.

See Google OAuth Setup for instructions on obtaining these credentials.

The OAuth redirect URI is automatically derived from APP_URL as ${APP_URL}/auth/google/callback. You don't need to configure it separately.

Optional Variables

Application URLs

VariableDefaultDescription
APP_URLhttp://localhost:6616Public URL where app is accessible. Used for OAuth redirect URI and CORS.
PORT6616Port for the API server

Database

VariableDefaultDescription
DATABASE_URL(none)PostgreSQL connection string
SQLITE_PATH./data/inboxorcist.dbPath to SQLite database file
DATA_DIR./dataDirectory for per-account email databases

If DATABASE_URL is not set, Inboxorcist uses SQLite automatically.

Binary Installer: During installation, the binary installer prompts you to choose between SQLite and PostgreSQL. If you choose PostgreSQL, it writes DATABASE_URL to your .env file automatically.

In Docker, DATA_DIR is automatically set to /usr/src/app/data to ensure email data persists across container restarts.

PostgreSQL Connection String Format

DATABASE_URL=postgres://username:password@host:port/database

Examples:

# Local PostgreSQL
DATABASE_URL=postgres://inboxorcist:secret@localhost:5432/inboxorcist

# Docker network
DATABASE_URL=postgres://inboxorcist:secret@postgres:5432/inboxorcist

# Cloud managed (with SSL)
DATABASE_URL=postgres://user:pass@db.example.com:5432/inboxorcist?sslmode=require

JWT Expiry

VariableDefaultDescription
JWT_ACCESS_EXPIRY1hAccess token lifetime
JWT_REFRESH_EXPIRY7dRefresh token lifetime

Supported formats: 15m, 1h, 24h, 7d, 30d

Debugging

VariableDefaultDescription
ENABLE_LOGGINGfalseEnable verbose debug logging in production

Debug logs are always enabled in development mode. Set ENABLE_LOGGING=true to enable verbose logging in production for troubleshooting.

Docker Compose Specific

VariableDefaultDescription
POSTGRES_PASSWORDinboxorcist_secretPassword for PostgreSQL container

Environment File Examples

Minimal (Local Development)

# .env
GOOGLE_CLIENT_ID=your-client-id.apps.googleusercontent.com
GOOGLE_CLIENT_SECRET=GOCSPX-your-secret
JWT_SECRET=your-local-dev-secret-at-least-32-characters
ENCRYPTION_KEY=0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef

Production with PostgreSQL

# .env
GOOGLE_CLIENT_ID=your-client-id.apps.googleusercontent.com
GOOGLE_CLIENT_SECRET=GOCSPX-your-secret
JWT_SECRET=generated-secure-random-string-at-least-32-chars
ENCRYPTION_KEY=generated-64-hex-character-encryption-key

APP_URL=https://inboxorcist.yourdomain.com
DATABASE_URL=postgres://inboxorcist:secure-password@postgres:5432/inboxorcist

Validation

On startup, Inboxorcist validates all required environment variables:

ValidationRequirement
GOOGLE_CLIENT_IDMust be set, typically ends with .apps.googleusercontent.com
GOOGLE_CLIENT_SECRETMust be set, typically starts with GOCSPX-
JWT_SECRETMust be at least 32 characters
ENCRYPTION_KEYMust be exactly 64 hexadecimal characters
APP_URL (optional)If set, must be a valid URL starting with http:// or https://

If validation fails, the application will not start and will log the specific error.

Platform-Specific Configuration

Docker

Environment variables can be set in:

  • .env file (loaded by Docker Compose)
  • docker-compose.yml environment section
  • docker run -e VAR=value flags

Railway

Set in the Variables tab of your service settings.

Render

Set in Environment > Environment Variables. Mark secrets with the lock icon.

Fly.io

Use fly secrets set:

fly secrets set JWT_SECRET=your-secret

DigitalOcean

Set in App Settings > Environment Variables. Use SECRET type for sensitive values.

Security Best Practices

  1. Never commit secrets - Use .env files (gitignored) or platform secret management
  2. Rotate secrets periodically - Especially if you suspect a breach
  3. Use strong secrets - Generate with openssl rand rather than creating manually
  4. Limit access - Restrict who can view environment variables in production
  5. Different secrets per environment - Don't reuse development secrets in production

On this page