Repository navigation
Expand file tree
/
Copy path.env.example
More file actions
76 lines (65 loc) · 3.83 KB
/
Copy path.env.example
File metadata and controls
76 lines (65 loc) · 3.83 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
# =============================================================================
# Client configuration (exposed to the browser via the VITE_ prefix)
# =============================================================================
# SimplePDF company identifier: the subdomain piece of
# <companyIdentifier>.<baseDomain> that serves the embedded editor. Exposed to
# the browser because the iframe src is built client-side.
# REQUIRED: the app throws at startup if unset.
#
# `spdf-copilot` is the public demo workspace and whitelists
# `http://localhost:3001`, so the iframe loads as-is for local dev. To host this
# on your own domain, set this to your own SimplePDF Premium company identifier
# and whitelist your serving origin in the SimplePDF dashboard.
VITE_SIMPLEPDF_COMPANY_IDENTIFIER=spdf-copilot
# Base domain the editor is served from. OPTIONAL: defaults to
# https://simplepdf.com (production). The editor origin is built as
# https://<companyIdentifier>.<host of this URL>. Point it elsewhere to test
# against another environment (e.g. https://simplepdf.us for staging, or a local
# editor). Leave unset to run against production.
# VITE_SIMPLEPDF_BASE_DOMAIN=https://simplepdf.com
# Gates the TanStack Router devtools panel + chatty monitoring logs. OPTIONAL:
# leave unset in production / CI; set to "true" for local dev.
# VITE_ENABLE_DEVTOOLS=true
# =============================================================================
# Demo mode (server, OPTIONAL)
# =============================================================================
#
# Leave the four DEMO_* vars unset and the app runs BYOK-only: every visitor
# brings their own provider key via the in-app Model Picker, and the stream goes
# browser-direct (never through this server). Easiest setup for personal use.
#
# Set ALL of DEMO_CHAT_API_KEY + DEMO_CHAT_MODEL + DEMO_RATE_LIMIT_TURNS +
# DEMO_STT_OPENAI_API_KEY to enable "demo mode": visitors chat (and use voice)
# on YOUR keys without pasting one, rate-limited per IP. If the chat config is
# set but the transcription key is missing, the deployment silently falls back
# to BYOK-only (and logs an error), since voice would otherwise be broken. BYOK
# still overrides demo mode per capability.
# Provider API key the shared demo chat runs on.
# DEMO_CHAT_API_KEY=
# Model handle the demo runs on: anthropic_haiku_4_5 | deepseek_v4_flash.
# DEMO_CHAT_MODEL=anthropic_haiku_4_5
# Total demo chat turns a single IP may ever spend (positive integer).
# DEMO_RATE_LIMIT_TURNS=20
# OpenAI API key for speech-to-text (voice input). Required alongside the chat
# config above for demo mode.
# DEMO_STT_OPENAI_API_KEY=
# =============================================================================
# Rate-limit storage (server, OPTIONAL; only relevant in demo mode)
# =============================================================================
# Connection URL to a Redis-protocol-compatible instance (Valkey, Redis, KeyDB,
# etc.). Required for hosted demo deployments where the per-IP lifetime counters
# (Redis key `rl:__default__:<ipHash>`) must survive restarts AND be shared
# across containers. Without it, counters live in memory per container (fine for
# local dev, single-instance hosts, or BYOK-only deployments).
#
# DO Managed Caching for Valkey: $15/mo single-node, drop-in protocol-
# compatible. The dashboard returns a `rediss://default:<password>@<host>:25061/0`
# URL. The password is INSIDE the URL, so this value is a secret.
# REDIS_URL=rediss://default:<password>@<host>:25061/0
# REQUIRED when REDIS_URL is set (the server refuses to boot otherwise). Salts
# the SHA-256 IP hash used in the Redis key. Without a salt, a leak of the Redis
# snapshot lets anyone brute-force the ~4B IPv4 space in minutes; with a salt,
# the brute force needs this server-side secret too. Unused in BYOK-only mode.
#
# Generate with: openssl rand -hex 32
# IP_HASH_SALT=