Skip to main content
Every variable the API reads, its default, and what happens when it is wrong. Read at boot by apps/api/src/config/env.ts; the process refuses to start on an invalid value rather than failing later inside an adapter.

Server

The API version is not an environment variable: API_VERSION in packages/contracts/src/http/version.ts is the single constant that versions the URL prefix, the client, the response header and the generated specification. It changes when the API version changes, in one place. See versioning.

Database

Authentication

Rotating either secret invalidates the tokens signed with it. Refresh tokens are additionally revoked in the database on rotation, so a stolen token is usable at most once. See sessions.

Model provider

Timeouts and retries

A generation is a network call to someone else’s server, so it is bounded and repeated rather than left to hang. Only a transient failure is repeated: a dropped connection, a 429, a 5xx, or a timeout. A rejected key or a malformed request is not, because repeating it cannot succeed. The wait grows exponentially with the attempt number and is randomised across 0–delay (full jitter), so several requests that fail together do not all return at the same instant. Retries repeat the same provider. They never fall back to another one or to the local generator: silently answering from a different model would hand back a campaign that does not match what was asked for. When every attempt fails the caller gets 503 with llm_unavailable. See the generative pipeline. With no key at all, the deterministic local generator answers, and the boot log says so. Asking for a provider whose key is missing resolves to the generator and logs the mismatch rather than binding an adapter that would fail on every call:

Web app

Copying the example file

.env is not committed. The example file must stay in step with the schema above; a variable added to env.ts belongs in it.
Last modified on October 6, 2026