Environment Variables

Complete reference for all configuration options.

Authentication

VariableDescriptionDefault
AUTH_SECRETSession and credential encryption secret. Required for production outside DockerDocker: generated on first start and kept in /app/data/.auth-secret; dev: random per start
ADMIN_EMAILPre-configured admin email-
ADMIN_PASSWORDPre-configured admin password-
ADMIN_PASSWORD_RESETSet to true to reset admin passwordfalse
AUTH_TRUSTED_ORIGINSComma-separated list of trusted origins (frontend + backend). Browser requests that change state from another site (Sec-Fetch-Site: same-site or cross-site) are rejected unless their Origin is listed here. Never list the preview gateway origin.http://localhost:5173,http://localhost:5003
AUTH_SECURE_COOKIESUse secure cookies (HTTPS only)Runtime: true in prod, false in dev; Compose: false unless set

OAuth Providers

VariableDescription
GITHUB_CLIENT_IDGitHub OAuth client ID
GITHUB_CLIENT_SECRETGitHub OAuth client secret
GOOGLE_CLIENT_IDGoogle OAuth client ID
GOOGLE_CLIENT_SECRETGoogle OAuth client secret
DISCORD_CLIENT_IDDiscord OAuth client ID
DISCORD_CLIENT_SECRETDiscord OAuth client secret

Passkeys (WebAuthn)

VariableDescriptionDefault
PASSKEY_RP_IDRelying party ID (your domain)localhost
PASSKEY_RP_NAMEDisplay name for passkey promptsOpenCode Manager
PASSKEY_ORIGINOrigin URL for WebAuthn (backend port)http://localhost:5003

Push Notifications (VAPID)

VariableDescriptionRequired
VAPID_PUBLIC_KEYVAPID public key for push notificationsYes
VAPID_PRIVATE_KEYVAPID private key for push notificationsYes
VAPID_SUBJECTContact email for VAPID (MUST use mailto: format)Yes

Generating VAPID Keys

Generate VAPID public/private key pair:

pnpm dlx web-push generate-vapid-keys

Add to .env:

VAPID_PUBLIC_KEY=BMx-1234567890abcdefghijklmnopqrstuv...
VAPID_PRIVATE_KEY=abcd1234567890abcdef...
VAPID_SUBJECT=mailto:you@example.com

When configured, users can enable push notifications in Settings → Notifications to receive background alerts for agent events.

Server

VariableDescriptionDefault
PORTServer port5003
HOSTServer bind address0.0.0.0
NODE_ENVEnvironment (development or production)development
CORS_ORIGINCORS origin for frontendhttp://localhost:5173
LOG_LEVELAccepted but currently unused; debug output is controlled by DEBUGinfo
DEBUGEnable debug loggingfalse

Preview Gateway

The preview gateway serves dev servers through an authenticated, separate origin (see Preview).

VariableDescriptionDefault
PREVIEW_PORTPort for the preview gateway. Set to 0 to disable preview entirely. If the port is already in use, the Manager starts anyway, logs a warning and reports preview as unavailable.5004
PREVIEW_PUBLIC_URLSame-site HTTPS origin that proxies the preview gateway; do not add it to AUTH_TRUSTED_ORIGINS. Set this when the Manager is served over HTTPS or behind a reverse proxy, where mixed content and third-party cookies otherwise block the preview iframe.empty

Database

VariableDescriptionDefault
DATABASE_PATHPath to SQLite database file./data/opencode.db

Workspace

VariableDescriptionDefault
WORKSPACE_PATHPath to workspace directory./workspace (Docker: /workspace)
REPO_BROWSE_ROOTRoot directory the folder browser may browse. When unset, folder browsing is disabledempty (disabled)

OpenCode Server

VariableDescriptionDefault
OPENCODE_SERVER_PORTPort for the OpenCode CLI server5551
OPENCODE_HOSTOpenCode server bind address127.0.0.1
OPENCODE_HEALTH_WATCH_ENABLEDEnable OpenCode health watcher and recoverytrue (false in tests)
OPENCODE_HEALTH_POLL_MSOpenCode health watcher poll interval30000
OPENCODE_HEALTH_FAILURE_THRESHOLDFailed health checks before recovery starts2
OPENCODE_SERVER_PASSWORDBasic Auth password for the managed OpenCode server. OpenCode 2 always requires one: when unset, OpenCode Manager generates and persists a password (override it any time via Settings → OpenCode → Server Auth). DB-stored passwords override this env var. The default docker-compose.yml does not forward this variable from .env; add it to the compose environment: block or set it via Settings → OpenCode → Server Auth.auto-generated
OPENCODE_BINPath to an externally managed OpenCode binary. Overrides binary discovery; while set, in-app upgrade and version install are disabled (HTTP 409)-

Upgrade note: OPENCODE_PUBLIC_URL is no longer used. MCP OAuth redirects now point at the Manager's /api/mcp-oauth-proxy/callback, built from the request: the scheme comes from X-Forwarded-Proto (first value, http or https only), then the Origin header, then http; the host comes from X-Forwarded-Host when present, otherwise Host. Behind a reverse proxy, forward X-Forwarded-Proto and X-Forwarded-Host (or preserve Host) and remove OPENCODE_PUBLIC_URL; the Manager logs a warning at startup while it is still set.

OpenCode Import

VariableDescriptionDefault
OPENCODE_IMPORT_CONFIG_PATHExisting standalone OpenCode config file to import on first startup. When set to a single file, only that file is imported. When unset, the host's opencode.json, opencode.jsonc, and legacy config.json are mirrored into the workspace, workspace copies absent on the host are removed, and the mirrored legacy file is folded into the workspace config-
OPENCODE_IMPORT_STATE_PATHExisting standalone OpenCode state directory to import on first startup-

Agent Sandboxing

Sandboxed agent commands run inside a microVM managed by msb (see Agent Sandboxing). Requires a Linux host with /dev/kvm and the sandbox compose overlay.

VariableDescriptionDefault
MSB_PATHPath to the msb executablemsb
MSB_LIBKRUNFW_PATHPath to the libkrunfw firmware library used by msb (set in the container image)/opt/microsandbox/lib/libkrunfw.so
MSB_BACKENDBackend the microsandbox client useslocal
MSB_HOMEMicrosandbox home directory for state~/.microsandbox
MSB_PROFILEMicrosandbox profile passed through to the client-
MSB_API_URLMicrosandbox API URL passed through to the client-
MSB_API_KEYMicrosandbox API key passed through to the client-
SANDBOX_IMAGEOCI image the microVM boots from. Digest-pinned by default so a rebuilt guest image is actually adopted; see Sandbox Guest Image for what the default ships and how to build your owndocker.io/cstechdev/ocm-sandbox@sha256:9df035cf…
SANDBOX_MEMORYMicroVM memory (e.g. 4G)4G
SANDBOX_CPUSMicroVM CPU count2
SANDBOX_EXEC_USERGuest identity sandboxed commands run as: a numeric uid, a numeric uid:gid, or a guest username. A numeric uid must match the Manager's effective uid (PUID); the compose overlay defaults it to ${PUID:-1000}. A guest username is resolved to the Manager's effective uid:gid so writes to the mounted project roots always succeed. When a configured numeric identity cannot write the workspace, enforcement is reported unavailable${PUID:-1000} via the overlay, otherwise node
SANDBOX_NETNetwork mode for the microVM: public, private, or host, or a comma-separated composition (for example public,host). Passed to msb run --net and attested against the profile's canonical network policypublic
SANDBOX_START_TIMEOUT_MSTimeout for microVM startup, in milliseconds300000
SANDBOX_EXEC_TIMEOUT_MSTimeout for a single sandboxed command, in milliseconds600000

Timeouts

VariableDescriptionDefault
PROCESS_START_WAIT_MSWait time for OpenCode process to start2000
PROCESS_VERIFY_WAIT_MSWait time for process health verification1000
HEALTH_CHECK_TIMEOUT_MSOpenCode liveness probe timeout30000

File Limits

VariableDescriptionDefault
MAX_FILE_SIZE_MBMaximum file size for reading/preview50
MAX_UPLOAD_SIZE_MBMaximum upload file size50

Frontend (Vite)

VariableDescriptionDefault
VITE_API_URLBackend API URL for frontend. Empty (the default) means same-origin requests; the Vite dev server proxies /api to the backendempty (same origin)
VITE_SERVER_PORTBackend port hint for frontend5003
VITE_OPENCODE_PORTOpenCode server port hint5551
VITE_MAX_FILE_SIZE_MBFile size limit for frontend50
VITE_MAX_UPLOAD_SIZE_MBUpload size limit for frontend50

Example .env File

# Server
PORT=5003
HOST=0.0.0.0
NODE_ENV=production

# Required for production outside Docker (Docker generates one when unset)
AUTH_SECRET=generate-with-openssl-rand-base64-32

# Pre-configured admin (optional)
ADMIN_EMAIL=admin@example.com
ADMIN_PASSWORD=your-secure-password

# Remote access (optional - include both frontend and backend ports)
AUTH_TRUSTED_ORIGINS=http://localhost:5173,http://localhost:5003,http://192.168.1.244:5003
AUTH_SECURE_COOKIES=false

# OAuth providers (optional)
GITHUB_CLIENT_ID=your-client-id
GITHUB_CLIENT_SECRET=your-client-secret

# Passkeys (optional - use BACKEND port)
PASSKEY_RP_ID=localhost
PASSKEY_RP_NAME=OpenCode Manager
PASSKEY_ORIGIN=http://localhost:5003

# Push notifications (optional)
VAPID_PUBLIC_KEY=BMx-1234567890abcdefghijklmnopqrstuv...
VAPID_PRIVATE_KEY=abcd1234567890abcdef...
VAPID_SUBJECT=mailto:you@example.com

Generating Secrets

AUTH_SECRET

Docker generates and persists one automatically, so this is only needed outside Docker or to manage the secret yourself. Generate a secure random secret:

openssl rand -base64 32

Output example:

K7gNU3sdo+OL0wNhqoVWhr3g6s1xYv72ol/pe/Unols=

VAPID Keys

Generate VAPID public/private key pair for push notifications:

pnpm dlx web-push generate-vapid-keys

Output example:

=======================================
Public Key:
BMx-1234567890abcdefghijklmnopqrstuv...

Private Key:
abcd1234567890abcdef...

Subject:
mailto:you@example.com
===========================================

Environment Precedence

Local runtime loads .env from the project root with dotenv without overriding variables that are already present in the process environment. Docker Compose reads .env for interpolation, then passes the explicit environment entries from docker-compose.yml into the container.