Skip to content
Keel
Dashboard

Environment variables reference

Every environment variable used to deploy and operate the Keel server and CLI, with format, sensitivity and where each is read.

Last updated

These are the variables for running Keel itself, not for your applications. Examples use clearly fake placeholders.

Server variables#

NameRequiredSensitivePurpose
NEXT_PUBLIC_CLERK_PUBLISHABLE_KEYYesNo (public)Clerk publishable key used by the browser and server SDK
CLERK_SECRET_KEYYesYesClerk secret key used by the server to verify sessions
MONGODB_URIYesYes (can embed a password)MongoDB connection string. The database name is taken from the path.
SECRETS_ENCRYPTION_KEYYesYesAES-256 key that encrypts every secret value
SECRETS_ENCRYPTION_KEY_V<N>NoYesKey for encryption key version N, where N is 2 or higher
NEXT_PUBLIC_SITE_URLNoNoPublic origin used for canonical and social URLs
GOOGLE_SITE_VERIFICATIONNoNoSearch Console HTML tag token
NEXT_PUBLIC_FORMAS_API_KEYNoNo (public)Form key for the contact page
KEEL_SYNC_DEBOUNCE_MSNoNoDelay before an automatic Vercel sync, default 3000
VERCEL_RETRY_DELAY_MSNoNoBase backoff for Vercel API retries, default 500

Details and examples#

#### NEXT_PUBLIC_CLERK_PUBLISHABLE_KEY and CLERK_SECRET_KEY

Both come from your Clerk application. They are read by @clerk/nextjs, which app/layout.tsx and proxy.ts use, and by the API routes that call auth().

.env
NEXT_PUBLIC_CLERK_PUBLISHABLE_KEY=pk_test_placeholder
CLERK_SECRET_KEY=sk_test_placeholder

#### MONGODB_URI

Read in lib/db.ts. The server throws on first database use if it is not set. Indexes are created on connection.

.env
MONGODB_URI=mongodb://127.0.0.1:27017/keel

#### SECRETS_ENCRYPTION_KEY

Base64 of exactly 32 random bytes, 44 characters ending in =. It is validated in lib/crypto.ts, and instrumentation.ts checks it when the server starts, so a missing or malformed key stops the server immediately. A key made of one repeated byte is rejected.

Generate one:

Shell
node -e "console.log(require('crypto').randomBytes(32).toString('base64'))"
.env
SECRETS_ENCRYPTION_KEY=<44-character-base64-value>

#### SECRETS_ENCRYPTION_KEY_V<N>

Key for version N of the key scheme. Keys are looked up by the version recorded in each encrypted payload. New writes always use version 1, so additional versions are only needed to read data encrypted under them.

#### NEXT_PUBLIC_SITE_URL

Defaults to https://keel.hoardspace.in. Set it for preview and self-hosted deployments so canonical links, the sitemap and social previews use the right origin. Read in lib/site.ts.

.env
NEXT_PUBLIC_SITE_URL=https://keel.example.com

#### KEEL_SYNC_DEBOUNCE_MS and VERCEL_RETRY_DELAY_MS

Tuning values for the Vercel integration, read in lib/vercel-sync.ts and lib/vercel.ts. Defaults suit normal use.

#### NODE_ENV

Standard Node variable. In production, invitation links are not returned by the invitations API. See Members API.

CLI variables#

NamePurpose
KEEL_API_URLServer URL used by keel login when --api-url and .keel.json do not provide one
KEEL_CONFIG_DIRDirectory for stored credentials
KEEL_CREDENTIAL_STORESet to file to force the user-only file store
KEEL_DEBUGSet to 1 to print the type of an unexpected error

The CLI also reads APPDATA on Windows and XDG_CONFIG_HOME on Linux to locate its default config directory. See CLI authentication.

Next steps#

Review the Glossary.