2024-02-07 09:50:52 +07:00
#=====================================================================#
2026-02-19 19:09:19 -08:00
# Hanzo Chat Configuration #
2024-02-07 09:50:52 +07:00
#=====================================================================#
# Please refer to the reference documentation for assistance #
2026-02-19 19:09:19 -08:00
# with configuring your Hanzo Chat environment. #
2024-05-13 10:15:30 -04:00
# #
2026-02-19 19:09:19 -08:00
# https://hanzo.ai/docs/chat/configuration/dotenv #
2024-02-07 09:50:52 +07:00
#=====================================================================#
2025-02-08 19:29:44 -05:00
2023-12-03 09:52:13 -05:00
#==================================================#
# Server Configuration #
#==================================================#
2023-04-25 04:26:38 -04:00
HOST = localhost
2023-03-06 15:56:25 -05:00
PORT = 3080
2023-03-10 21:05:35 +08:00
2026-02-19 19:09:19 -08:00
MONGO_URI = mongodb://127.0.0.1:27017/HanzoChat
2025-07-25 09:38:35 +05:30
#The maximum number of connections in the connection pool. */
MONGO_MAX_POOL_SIZE =
#The minimum number of connections in the connection pool. */
MONGO_MIN_POOL_SIZE =
#The maximum number of connections that may be in the process of being established concurrently by the connection pool. */
MONGO_MAX_CONNECTING =
#The maximum number of milliseconds that a connection can remain idle in the pool before being removed and closed. */
MONGO_MAX_IDLE_TIME_MS =
#The maximum time in milliseconds that a thread can wait for a connection to become available. */
MONGO_WAIT_QUEUE_TIMEOUT_MS =
# Set to false to disable automatic index creation for all models associated with this connection. */
MONGO_AUTO_INDEX =
# Set to `false` to disable Mongoose automatically calling `createCollection()` on every model created on this connection. */
MONGO_AUTO_CREATE =
2023-10-05 18:34:10 -04:00
2023-12-03 09:52:13 -05:00
DOMAIN_CLIENT = http://localhost:3080
DOMAIN_SERVER = http://localhost:3080
2023-10-05 18:34:10 -04:00
2023-12-30 02:42:04 +01:00
NO_INDEX = true
2025-05-22 14:19:24 +02:00
# Use the address that is at most n number of hops away from the Express application.
# req.socket.remoteAddress is the first hop, and the rest are looked for in the X-Forwarded-For header from right to left.
2025-02-20 17:39:12 -05:00
# A value of 0 means that the first untrusted address would be req.socket.remoteAddress, i.e. there is no reverse proxy.
# Defaulted to 1.
TRUST_PROXY = 1
2023-12-30 02:42:04 +01:00
2025-08-27 16:30:56 -04:00
# Minimum password length for user authentication
# Default: 8
# Note: When using LDAP authentication, you may want to set this to 1
# to bypass local password validation, as LDAP servers handle their own
# password policies.
# MIN_PASSWORD_LENGTH=8
2026-02-16 16:47:07 -05:00
# When enabled, the app will continue running after encountering uncaught exceptions
# instead of exiting the process. Not recommended for production unless necessary.
# CONTINUE_ON_UNCAUGHT_EXCEPTION=false
2024-03-27 16:07:04 +02:00
#===============#
# JSON Logging #
#===============#
# Use when process console logs in cloud deployment like GCP/AWS
CONSOLE_JSON = false
2023-12-22 08:36:42 -05:00
#===============#
# Debug Logging #
#===============#
2023-12-30 02:42:04 +01:00
2023-12-22 08:36:42 -05:00
DEBUG_LOGGING = true
DEBUG_CONSOLE = false
2023-12-03 09:52:13 -05:00
#=============#
# Permissions #
#=============#
2023-10-05 18:34:10 -04:00
2023-11-15 19:17:40 -05:00
# UID=1000
# GID=1000
2023-10-13 23:24:27 +02:00
2025-12-25 16:17:17 -05:00
#==============#
# Node Options #
#==============#
# NOTE: NODE_MAX_OLD_SPACE_SIZE is NOT recognized by Node.js directly.
# This variable is used as a build argument for Docker or CI/CD workflows,
# and is NOT used by Node.js to set the heap size at runtime.
# To configure Node.js memory, use NODE_OPTIONS, e.g.:
# NODE_OPTIONS="--max-old-space-size=6144"
# See: https://nodejs.org/api/cli.html#--max-old-space-sizesize-in-mib
NODE_MAX_OLD_SPACE_SIZE = 6144
2024-02-26 19:59:19 +01:00
#===============#
# Configuration #
#===============#
2024-03-11 10:52:54 -04:00
# Use an absolute path, a relative path, or a URL
2024-02-26 19:59:19 +01:00
2026-02-19 19:09:19 -08:00
# CONFIG_PATH="/alternative/path/to/chat.yaml"
2024-02-26 19:59:19 +01:00
2026-02-05 08:50:39 +01:00
#==================#
# Langfuse Tracing #
#==================#
# Get Langfuse API keys for your project from the project settings page: https://cloud.langfuse.com
# LANGFUSE_PUBLIC_KEY=
# LANGFUSE_SECRET_KEY=
# LANGFUSE_BASE_URL=
2023-12-03 09:52:13 -05:00
#===================================================#
# Endpoints #
#===================================================#
2023-03-11 15:03:18 +08:00
2025-06-23 12:39:27 -04:00
# ENDPOINTS=openAI,assistants,azureOpenAI,google,anthropic
2023-03-10 21:05:35 +08:00
2023-12-03 09:52:13 -05:00
PROXY =
2023-04-05 21:21:02 +08:00
2026-02-27 11:00:50 -08:00
#===============================#
# Hanzo API (Zen models) #
#===============================#
# Publishable key for unauthenticated users (rate-limited).
# Authenticated users get their real API key after IAM login (hanzo.id).
# Endpoint: https://api.hanzo.ai/v1
HANZO_API_KEY =
2026-07-02 00:18:02 -07:00
# Canonical Hanzo Cloud agents (/v1/agents). Lets signed-in users run their own
# cloud agents from chat via `/agent <name>` or the @mention picker. The chat
2026-07-03 02:40:16 -07:00
# backend proxies /v1/chat/agents/cloud/* to this host, forwarding the user's
2026-07-02 00:18:02 -07:00
# hanzo.id token server-side (never to the browser); cloud scopes to their org.
# Optional: if unset, derived from OPENAI_BASE_URL (its host, minus /v1).
# HANZO_CLOUD_URL=https://api.hanzo.ai
2026-07-02 13:56:56 -07:00
# A cloud-agent run is a real billable completion; these bound abuse of the proxy.
# CLOUD_AGENT_USER_MAX=30 # max cloud-agent requests per user per window
# CLOUD_AGENT_WINDOW=1 # rate-limit window, minutes
# CLOUD_AGENT_MAX_CONCURRENT=50 # process-wide in-flight ceiling to cloud (503 past it)
2026-07-02 00:18:02 -07:00
2024-02-28 08:46:21 -05:00
#===================================#
2026-02-19 19:09:19 -08:00
# Known Endpoints - chat.yaml #
2024-02-28 08:46:21 -05:00
#===================================#
2026-02-19 19:09:19 -08:00
# https://hanzo.ai/docs/chat/configuration/ai_endpoints
2024-02-28 08:46:21 -05:00
# ANYSCALE_API_KEY=
2024-04-24 20:32:18 -04:00
# APIPIE_API_KEY=
2024-06-15 19:01:39 +05:30
# COHERE_API_KEY=
2024-08-25 15:33:03 -04:00
# DEEPSEEK_API_KEY=
2024-06-15 19:01:39 +05:30
# DATABRICKS_API_KEY=
2024-02-28 08:46:21 -05:00
# FIREWORKS_API_KEY=
2024-04-24 20:32:18 -04:00
# GROQ_API_KEY=
2024-05-09 14:26:47 -04:00
# HUGGINGFACE_TOKEN=
2024-04-24 20:32:18 -04:00
# MISTRAL_API_KEY=
# OPENROUTER_KEY=
2024-02-28 08:46:21 -05:00
# PERPLEXITY_API_KEY=
2024-04-24 20:32:18 -04:00
# SHUTTLEAI_API_KEY=
2024-02-28 08:46:21 -05:00
# TOGETHERAI_API_KEY=
2024-08-25 19:10:25 -04:00
# UNIFY_API_KEY=
2024-11-04 16:27:54 -05:00
# XAI_API_KEY=
2024-02-28 08:46:21 -05:00
2023-12-03 09:52:13 -05:00
#============#
# Anthropic #
#============#
2023-03-29 10:17:24 -04:00
2023-12-03 09:52:13 -05:00
ANTHROPIC_API_KEY = user_provided
2026-02-17 15:24:03 -05:00
# ANTHROPIC_MODELS=claude-sonnet-4-6,claude-opus-4-6,claude-opus-4-20250514,claude-sonnet-4-20250514,claude-3-7-sonnet-20250219,claude-3-5-sonnet-20241022,claude-3-5-haiku-20241022,claude-3-opus-20240229,claude-3-sonnet-20240229,claude-3-haiku-20240307
2024-03-15 16:11:31 -04:00
# ANTHROPIC_REVERSE_PROXY=
2023-09-26 21:02:28 -04:00
2025-12-30 18:16:52 -05:00
# Set to true to use Anthropic models through Google Vertex AI instead of direct API
# ANTHROPIC_USE_VERTEX=
# ANTHROPIC_VERTEX_REGION=us-east5
2023-12-03 09:52:13 -05:00
#============#
# Azure #
#============#
2023-05-09 17:42:55 -04:00
2024-02-26 14:12:25 -05:00
# Note: these variables are DEPRECATED
2026-02-19 19:09:19 -08:00
# Use the `chat.yaml` configuration for `azureOpenAI` instead
# You may also continue to use them if you opt out of using the `chat.yaml` configuration
2023-12-03 09:52:13 -05:00
2024-02-26 14:12:25 -05:00
# AZURE_OPENAI_DEFAULT_MODEL=gpt-3.5-turbo # Deprecated
# AZURE_OPENAI_MODELS=gpt-3.5-turbo,gpt-4 # Deprecated
# AZURE_USE_MODEL_AS_DEPLOYMENT_NAME=TRUE # Deprecated
# AZURE_API_KEY= # Deprecated
# AZURE_OPENAI_API_INSTANCE_NAME= # Deprecated
# AZURE_OPENAI_API_DEPLOYMENT_NAME= # Deprecated
# AZURE_OPENAI_API_VERSION= # Deprecated
# AZURE_OPENAI_API_COMPLETIONS_DEPLOYMENT_NAME= # Deprecated
# AZURE_OPENAI_API_EMBEDDINGS_DEPLOYMENT_NAME= # Deprecated
2023-05-09 17:42:55 -04:00
2024-09-09 12:06:59 -04:00
#=================#
# AWS Bedrock #
#=================#
# BEDROCK_AWS_DEFAULT_REGION=us-east-1 # A default region must be provided
# BEDROCK_AWS_ACCESS_KEY_ID=someAccessKey
# BEDROCK_AWS_SECRET_ACCESS_KEY=someSecretAccessKey
2024-12-07 16:53:21 -05:00
# BEDROCK_AWS_SESSION_TOKEN=someSessionToken
2024-09-09 12:06:59 -04:00
# Note: This example list is not meant to be exhaustive. If omitted, all known, supported model IDs will be included for you.
2026-02-17 15:24:03 -05:00
# BEDROCK_AWS_MODELS=anthropic.claude-sonnet-4-6,anthropic.claude-opus-4-6-v1,anthropic.claude-3-5-sonnet-20240620-v1:0,meta.llama3-1-8b-instruct-v1:0
# Cross-region inference model IDs: us.anthropic.claude-sonnet-4-6,us.anthropic.claude-opus-4-6-v1,global.anthropic.claude-opus-4-6-v1
2024-09-09 12:06:59 -04:00
# See all Bedrock model IDs here: https://docs.aws.amazon.com/bedrock/latest/userguide/model-ids.html#model-ids-arns
# Notes on specific models:
2024-09-10 12:56:19 -04:00
# The following models are not support due to not supporting streaming:
# ai21.j2-mid-v1
# The following models are not support due to not supporting conversation history:
# ai21.j2-ultra-v1, cohere.command-text-v14, cohere.command-light-text-v14
2024-09-09 12:06:59 -04:00
2023-12-13 09:45:03 -05:00
#============#
# Google #
#============#
GOOGLE_KEY = user_provided
2024-12-18 12:13:16 -05:00
2023-12-13 09:45:03 -05:00
# GOOGLE_REVERSE_PROXY=
2024-12-18 12:13:16 -05:00
# Some reverse proxies do not support the X-goog-api-key header, uncomment to pass the API key in Authorization header instead.
# GOOGLE_AUTH_HEADER=true
2023-12-13 09:45:03 -05:00
2024-08-04 20:08:57 +02:00
# Gemini API (AI Studio)
2026-02-20 16:21:32 -05:00
# GOOGLE_MODELS=gemini-3.1-pro-preview,gemini-3.1-pro-preview-customtools,gemini-2.5-pro,gemini-2.5-flash,gemini-2.5-flash-lite,gemini-2.0-flash,gemini-2.0-flash-lite
2024-04-28 04:06:54 +05:30
# Vertex AI
2026-02-20 16:21:32 -05:00
# GOOGLE_MODELS=gemini-3.1-pro-preview,gemini-3.1-pro-preview-customtools,gemini-2.5-pro,gemini-2.5-flash,gemini-2.5-flash-lite,gemini-2.0-flash-001,gemini-2.0-flash-lite-001
2024-04-28 04:06:54 +05:30
2025-05-07 17:19:06 +02:00
# GOOGLE_TITLE_MODEL=gemini-2.0-flash-lite-001
2024-06-22 08:42:51 -07:00
2026-01-03 11:26:46 -05:00
# Google Cloud region for Vertex AI (used by both chat and image generation)
2024-10-16 00:10:48 +02:00
# GOOGLE_LOC=us-central1
2026-01-03 11:26:46 -05:00
# Alternative region env var for Gemini Image Generation
# GOOGLE_CLOUD_LOCATION=global
# Vertex AI Service Account Configuration
# Path to your Google Cloud service account JSON file
# GOOGLE_SERVICE_KEY_FILE=/path/to/service-account.json
2024-08-04 20:08:57 +02:00
# Google Safety Settings
# NOTE: These settings apply to both Vertex AI and Gemini API (AI Studio)
2024-05-08 21:32:23 -04:00
#
2024-08-04 20:08:57 +02:00
# For Vertex AI:
# To use the BLOCK_NONE setting, you need either:
# (a) Access through an allowlist via your Google account team, or
# (b) Switch to monthly invoiced billing: https://cloud.google.com/billing/docs/how-to/invoiced-billing
#
# For Gemini API (AI Studio):
# BLOCK_NONE is available by default, no special account requirements.
#
# Available options: BLOCK_NONE, BLOCK_ONLY_HIGH, BLOCK_MEDIUM_AND_ABOVE, BLOCK_LOW_AND_ABOVE
2024-05-08 21:32:23 -04:00
#
# GOOGLE_SAFETY_SEXUALLY_EXPLICIT=BLOCK_ONLY_HIGH
# GOOGLE_SAFETY_HATE_SPEECH=BLOCK_ONLY_HIGH
# GOOGLE_SAFETY_HARASSMENT=BLOCK_ONLY_HIGH
# GOOGLE_SAFETY_DANGEROUS_CONTENT=BLOCK_ONLY_HIGH
2024-12-18 12:13:16 -05:00
# GOOGLE_SAFETY_CIVIC_INTEGRITY=BLOCK_ONLY_HIGH
2024-05-08 21:32:23 -04:00
2026-01-03 11:26:46 -05:00
#========================#
# Gemini Image Generation #
#========================#
# Gemini Image Generation Tool (for Agents)
# Supports multiple authentication methods in priority order:
# 1. User-provided API key (via GUI)
# 2. GEMINI_API_KEY env var (admin-configured)
# 3. GOOGLE_KEY env var (shared with Google chat endpoint)
# 4. Vertex AI service account (via GOOGLE_SERVICE_KEY_FILE)
# Option A: Use dedicated Gemini API key for image generation
# GEMINI_API_KEY=your-gemini-api-key
# Option B: Use Vertex AI (no API key needed, uses service account)
# Set this to enable Vertex AI and allow tool without requiring API keys
# GEMINI_VERTEX_ENABLED=true
# Vertex AI model for image generation (defaults to gemini-2.5-flash-image)
# GEMINI_IMAGE_MODEL=gemini-2.5-flash-image
2023-12-03 09:52:13 -05:00
#============#
# OpenAI #
#============#
OPENAI_API_KEY = user_provided
2025-10-12 10:13:17 +02:00
# OPENAI_MODELS=gpt-5,gpt-5-codex,gpt-5-mini,gpt-5-nano,o3-pro,o3,o4-mini,gpt-4.1,gpt-4.1-mini,gpt-4.1-nano,o3-mini,o1-pro,o1,gpt-4o,gpt-4o-mini
2023-12-03 09:52:13 -05:00
DEBUG_OPENAI = false
# TITLE_CONVO=false
2024-12-04 15:48:13 -05:00
# OPENAI_TITLE_MODEL=gpt-4o-mini
2023-12-03 09:52:13 -05:00
# OPENAI_SUMMARIZE=true
2024-12-04 15:48:13 -05:00
# OPENAI_SUMMARY_MODEL=gpt-4o-mini
2023-12-03 09:52:13 -05:00
# OPENAI_FORCE_PROMPT=true
# OPENAI_REVERSE_PROXY=
2024-03-27 16:07:04 +02:00
# OPENAI_ORGANIZATION=
2024-01-18 20:39:30 -05:00
2024-02-13 20:42:27 -05:00
#====================#
# Assistants API #
#====================#
2024-03-07 08:11:32 -05:00
ASSISTANTS_API_KEY = user_provided
2024-02-13 20:42:27 -05:00
# ASSISTANTS_BASE_URL=
2024-07-19 13:59:07 +02:00
# ASSISTANTS_MODELS=gpt-4o,gpt-4o-mini,gpt-3.5-turbo-0125,gpt-3.5-turbo-16k-0613,gpt-3.5-turbo-16k,gpt-3.5-turbo,gpt-4,gpt-4-0314,gpt-4-32k-0314,gpt-4-0613,gpt-3.5-turbo-0613,gpt-3.5-turbo-1106,gpt-4-0125-preview,gpt-4-turbo-preview,gpt-4-1106-preview
2024-02-13 20:42:27 -05:00
2024-05-19 12:56:55 -04:00
#==========================#
# Azure Assistants API #
#==========================#
# Note: You should map your credentials with custom variables according to your Azure OpenAI Configuration
# The models for Azure Assistants are also determined by your Azure OpenAI configuration.
# More info, including how to enable use of Assistants with Azure here:
2026-02-19 19:09:19 -08:00
# https://hanzo.ai/docs/chat/configuration/ai_endpoints/azure#using-assistants-with-azure
2024-05-19 12:56:55 -04:00
2023-11-30 15:50:28 -03:00
# Azure AI Search
2023-12-03 09:52:13 -05:00
#-----------------
2023-11-30 15:50:28 -03:00
AZURE_AI_SEARCH_SERVICE_ENDPOINT =
AZURE_AI_SEARCH_INDEX_NAME =
AZURE_AI_SEARCH_API_KEY =
2023-08-19 20:11:31 +09:00
2023-11-30 15:50:28 -03:00
AZURE_AI_SEARCH_API_VERSION =
AZURE_AI_SEARCH_SEARCH_OPTION_QUERY_TYPE =
AZURE_AI_SEARCH_SEARCH_OPTION_TOP =
AZURE_AI_SEARCH_SEARCH_OPTION_SELECT =
2023-08-19 20:11:31 +09:00
2025-04-26 04:30:58 -04:00
# OpenAI Image Tools Customization
#----------------
2025-11-04 15:52:47 -03:00
# IMAGE_GEN_OAI_API_KEY= # Create or reuse OpenAI API key for image generation tool
# IMAGE_GEN_OAI_BASEURL= # Custom OpenAI base URL for image generation tool
# IMAGE_GEN_OAI_AZURE_API_VERSION= # Custom Azure OpenAI deployments
2025-12-25 09:45:38 -08:00
# IMAGE_GEN_OAI_MODEL=gpt-image-1 # OpenAI image model (e.g., gpt-image-1, gpt-image-1.5)
2025-11-04 15:52:47 -03:00
# IMAGE_GEN_OAI_DESCRIPTION=
2025-04-26 04:30:58 -04:00
# IMAGE_GEN_OAI_DESCRIPTION_WITH_FILES=Custom description for image generation tool when files are present
# IMAGE_GEN_OAI_DESCRIPTION_NO_FILES=Custom description for image generation tool when no files are present
# IMAGE_EDIT_OAI_DESCRIPTION=Custom description for image editing tool
# IMAGE_GEN_OAI_PROMPT_DESCRIPTION=Custom prompt description for image generation tool
# IMAGE_EDIT_OAI_PROMPT_DESCRIPTION=Custom prompt description for image editing tool
2024-01-18 19:39:27 -05:00
# DALL·E
2023-12-03 09:52:13 -05:00
#----------------
2024-01-31 08:20:07 -05:00
# DALLE_API_KEY=
# DALLE3_API_KEY=
# DALLE2_API_KEY=
# DALLE3_SYSTEM_PROMPT=
# DALLE2_SYSTEM_PROMPT=
# DALLE_REVERSE_PROXY=
# DALLE3_BASEURL=
# DALLE2_BASEURL=
2024-01-18 19:39:27 -05:00
# DALL·E (via Azure OpenAI)
# Note: requires some of the variables above to be set
#----------------
2024-01-31 08:20:07 -05:00
# DALLE3_AZURE_API_VERSION=
# DALLE2_AZURE_API_VERSION=
2023-05-13 16:29:06 -04:00
2025-03-02 13:19:53 -05:00
# Flux
#-----------------
FLUX_API_BASE_URL = https://api.us1.bfl.ai
# FLUX_API_BASE_URL = 'https://api.bfl.ml';
# Get your API key at https://api.us1.bfl.ai/auth/profile
# FLUX_API_KEY=
2025-01-10 08:54:08 -05:00
2023-12-03 09:52:13 -05:00
# Google
#-----------------
2024-04-16 08:32:40 -04:00
GOOGLE_SEARCH_API_KEY =
2023-12-03 09:52:13 -05:00
GOOGLE_CSE_ID =
2023-05-13 16:29:06 -04:00
2023-12-03 09:52:13 -05:00
# Stable Diffusion
#-----------------
SD_WEBUI_URL = http://host.docker.internal:7860
2023-05-13 16:29:06 -04:00
2024-02-23 10:08:49 -05:00
# Tavily
#-----------------
TAVILY_API_KEY =
2024-03-06 16:52:42 -05:00
# Traversaal
#-----------------
TRAVERSAAL_API_KEY =
2023-12-03 09:52:13 -05:00
# WolframAlpha
#-----------------
WOLFRAM_APP_ID =
2023-09-13 17:02:22 +02:00
2023-12-03 09:52:13 -05:00
# Zapier
#-----------------
ZAPIER_NLA_API_KEY =
2023-11-21 04:12:53 +03:00
2023-12-03 09:52:13 -05:00
#==================================================#
# Search #
#==================================================#
2023-11-21 04:12:53 +03:00
2023-06-22 20:12:25 -04:00
SEARCH = true
2023-07-15 08:23:34 -04:00
MEILI_NO_ANALYTICS = true
2023-04-25 04:26:38 -04:00
MEILI_HOST = http://0.0.0.0:7700
2026-02-27 10:56:21 -08:00
MEILI_MASTER_KEY =
2023-03-23 13:30:55 -04:00
2025-02-20 17:39:12 -05:00
# Optional: Disable indexing, useful in a multi-node setup
# where only one instance should perform an index sync.
# MEILI_NO_SYNC=true
2024-05-22 17:19:55 -04:00
#==================================================#
# Speech to Text & Text to Speech #
#==================================================#
STT_API_KEY =
TTS_API_KEY =
2024-08-05 08:54:51 +08:00
#==================================================#
# RAG #
#==================================================#
2026-02-19 19:09:19 -08:00
# More info: https://hanzo.ai/docs/chat/configuration/rag_api
2024-08-05 08:54:51 +08:00
# RAG_OPENAI_BASEURL=
# RAG_OPENAI_API_KEY=
2024-10-31 09:57:33 -04:00
# RAG_USE_FULL_CONTEXT=
2024-08-05 08:54:51 +08:00
# EMBEDDINGS_PROVIDER=openai
# EMBEDDINGS_MODEL=text-embedding-3-small
2023-12-03 09:52:13 -05:00
#===================================================#
# User System #
#===================================================#
#========================#
# Moderation #
#========================#
2024-01-01 21:08:02 +01:00
OPENAI_MODERATION = false
OPENAI_MODERATION_API_KEY =
2024-01-31 08:20:07 -05:00
# OPENAI_MODERATION_REVERSE_PROXY=
2024-01-01 21:08:02 +01:00
2023-12-03 09:52:13 -05:00
BAN_VIOLATIONS = true
BAN_DURATION = 1000 * 60 * 60 * 2
BAN_INTERVAL = 20
LOGIN_VIOLATION_SCORE = 1
REGISTRATION_VIOLATION_SCORE = 1
CONCURRENT_VIOLATION_SCORE = 1
MESSAGE_VIOLATION_SCORE = 1
NON_BROWSER_VIOLATION_SCORE = 20
2025-07-07 17:08:40 -04:00
TTS_VIOLATION_SCORE = 0
STT_VIOLATION_SCORE = 0
FORK_VIOLATION_SCORE = 0
IMPORT_VIOLATION_SCORE = 0
FILE_UPLOAD_VIOLATION_SCORE = 0
2023-12-03 09:52:13 -05:00
LOGIN_MAX = 7
LOGIN_WINDOW = 5
REGISTER_MAX = 5
REGISTER_WINDOW = 60
LIMIT_CONCURRENT_MESSAGES = true
CONCURRENT_MESSAGE_MAX = 2
LIMIT_MESSAGE_IP = true
MESSAGE_IP_MAX = 40
MESSAGE_IP_WINDOW = 1
LIMIT_MESSAGE_USER = false
MESSAGE_USER_MAX = 40
MESSAGE_USER_WINDOW = 1
2024-02-19 22:47:39 -05:00
ILLEGAL_MODEL_REQ_SCORE = 5
2023-12-03 09:52:13 -05:00
#========================#
# Balance #
#========================#
2025-03-21 22:48:11 +01:00
# CHECK_BALANCE=false
2024-11-16 19:17:17 +04:00
# START_BALANCE=20000 # note: the number of tokens that will be credited after registration.
2023-12-03 09:52:13 -05:00
#========================#
# Registration and Login #
#========================#
2023-04-05 21:21:02 +08:00
2023-12-06 13:08:49 +01:00
ALLOW_EMAIL_LOGIN = true
2023-06-15 09:36:34 -07:00
ALLOW_REGISTRATION = true
2023-07-11 23:17:58 +02:00
ALLOW_SOCIAL_LOGIN = false
2023-08-18 16:11:00 +02:00
ALLOW_SOCIAL_REGISTRATION = false
2024-06-06 17:39:36 +02:00
ALLOW_PASSWORD_RESET = false
2026-06-21 12:46:56 -07:00
#=====================================================#
# Guest Chat (anonymous preview) #
#=====================================================#
# Off by default. When enabled, unauthenticated visitors get a small free
# quota on the free Zen model routed through api.hanzo.ai. After the quota is
# spent the UI surfaces the existing OpenID/hanzo.id login. Guests are scoped
# server-side to the free model only and rejected from every other route.
ALLOW_GUEST_CHAT = false
# GUEST_MESSAGE_MAX=3 # free messages per IP before login is required
2026-07-14 10:41:50 -07:00
# GUEST_ENDPOINT=Hanzo # custom endpoint name from chat.yaml (api.hanzo.ai)
2026-06-21 12:46:56 -07:00
# GUEST_MODEL=zen3-nano # free Zen model id guests are pinned to
# GUEST_TOKEN_EXPIRY=3600000 # guest JWT lifetime in ms (default 1h)
# GUEST_TOKEN_MAX=20 # max guest sessions issued per IP per window
# GUEST_TOKEN_WINDOW=60 # guest-session issuance window in minutes
2024-06-06 01:35:12 +02:00
# ALLOW_ACCOUNT_DELETION=true # note: enabled by default if omitted/commented out
2024-06-07 21:06:47 +02:00
ALLOW_UNVERIFIED_EMAIL_LOGIN = true
2023-08-18 16:11:00 +02:00
2023-12-03 09:52:13 -05:00
SESSION_EXPIRY = 1000 * 60 * 15
REFRESH_TOKEN_EXPIRY =( 1000 * 60 * 60 * 24) * 7
2026-02-27 11:16:07 -08:00
JWT_SECRET =
JWT_REFRESH_SECRET =
2023-06-10 19:10:03 -04:00
2023-12-03 09:52:13 -05:00
# Discord
2023-12-11 17:23:38 -05:00
DISCORD_CLIENT_ID =
DISCORD_CLIENT_SECRET =
2023-12-03 09:52:13 -05:00
DISCORD_CALLBACK_URL = /oauth/discord/callback
2023-05-07 10:04:51 -07:00
2023-12-03 09:52:13 -05:00
# Facebook
2023-08-25 02:10:48 +02:00
FACEBOOK_CLIENT_ID =
FACEBOOK_CLIENT_SECRET =
FACEBOOK_CALLBACK_URL = /oauth/facebook/callback
2023-12-03 09:52:13 -05:00
# GitHub
2023-12-11 17:23:38 -05:00
GITHUB_CLIENT_ID =
GITHUB_CLIENT_SECRET =
2023-12-03 09:52:13 -05:00
GITHUB_CALLBACK_URL = /oauth/github/callback
2025-02-15 18:52:29 -05:00
# GitHub Enterprise
2025-02-03 21:30:02 +01:00
# GITHUB_ENTERPRISE_BASE_URL=
# GITHUB_ENTERPRISE_USER_AGENT=
2023-12-03 09:52:13 -05:00
# Google
GOOGLE_CLIENT_ID =
GOOGLE_CLIENT_SECRET =
GOOGLE_CALLBACK_URL = /oauth/google/callback
2025-01-31 15:49:09 +01:00
# Apple
APPLE_CLIENT_ID =
APPLE_TEAM_ID =
APPLE_KEY_ID =
APPLE_PRIVATE_KEY_PATH =
APPLE_CALLBACK_URL = /oauth/apple/callback
2023-12-03 09:52:13 -05:00
# OpenID
2023-06-24 21:45:52 -05:00
OPENID_CLIENT_ID =
OPENID_CLIENT_SECRET =
OPENID_ISSUER =
OPENID_SESSION_SECRET =
OPENID_SCOPE = "openid profile email"
OPENID_CALLBACK_URL = /oauth/openid/callback
2024-04-02 03:08:17 -04:00
OPENID_REQUIRED_ROLE =
OPENID_REQUIRED_ROLE_TOKEN_KIND =
OPENID_REQUIRED_ROLE_PARAMETER_PATH =
2025-10-09 08:35:22 +01:00
OPENID_ADMIN_ROLE =
OPENID_ADMIN_ROLE_PARAMETER_PATH =
OPENID_ADMIN_ROLE_TOKEN_KIND =
2024-10-27 11:41:48 -04:00
# Set to determine which user info property returned from OpenID Provider to store as the User's username
OPENID_USERNAME_CLAIM =
# Set to determine which user info property returned from OpenID Provider to store as the User's name
OPENID_NAME_CLAIM =
2025-08-05 02:49:36 +08:00
# Optional audience parameter for OpenID authorization requests
OPENID_AUDIENCE =
2023-12-03 09:52:13 -05:00
2023-06-25 12:40:31 -07:00
OPENID_BUTTON_LABEL =
2023-07-01 19:10:53 -05:00
OPENID_IMAGE_URL =
2025-03-19 14:51:56 +01:00
# Set to true to automatically redirect to the OpenID provider when a user visits the login page
# This will bypass the login form completely for users, only use this if OpenID is your only authentication method
OPENID_AUTO_REDIRECT = false
2025-05-22 14:19:24 +02:00
# Set to true to use PKCE (Proof Key for Code Exchange) for OpenID authentication
OPENID_USE_PKCE = false
#Set to true to reuse openid tokens for authentication management instead of using the mongodb session and the custom refresh token.
OPENID_REUSE_TOKENS =
#By default, signing key verification results are cached in order to prevent excessive HTTP requests to the JWKS endpoint.
#If a signing key matching the kid is found, this will be cached and the next time this kid is requested the signing key will be served from the cache.
#Default is true.
OPENID_JWKS_URL_CACHE_ENABLED =
OPENID_JWKS_URL_CACHE_TIME = # 600000 ms eq to 10 minutes leave empty to disable caching
#Set to true to trigger token exchange flow to acquire access token for the userinfo endpoint.
2025-06-26 19:10:21 -04:00
OPENID_ON_BEHALF_FLOW_FOR_USERINFO_REQUIRED =
OPENID_ON_BEHALF_FLOW_USERINFO_SCOPE = "user.read" # example for Scope Needed for Microsoft Graph API
2025-05-22 14:19:24 +02:00
# Set to true to use the OpenID Connect end session endpoint for logout
OPENID_USE_END_SESSION_ENDPOINT =
2026-01-06 15:22:10 -05:00
# URL to redirect to after OpenID logout (defaults to ${DOMAIN_CLIENT}/login)
OPENID_POST_LOGOUT_REDIRECT_URI =
2025-05-22 14:19:24 +02:00
2025-07-25 00:03:23 -04:00
#========================#
# SharePoint Integration #
#========================#
# Requires Entra ID (OpenID) authentication to be configured
# Enable SharePoint file picker in chat and agent panels
# ENABLE_SHAREPOINT_FILEPICKER=true
# SharePoint tenant base URL (e.g., https://yourtenant.sharepoint.com)
# SHAREPOINT_BASE_URL=https://yourtenant.sharepoint.com
# Microsoft Graph API And SharePoint scopes for file picker
# SHAREPOINT_PICKER_SHAREPOINT_SCOPE==https://yourtenant.sharepoint.com/AllSites.Read
# SHAREPOINT_PICKER_GRAPH_SCOPE=Files.Read.All
#========================#
2025-05-30 00:00:58 +09:00
# SAML
# Note: If OpenID is enabled, SAML authentication will be automatically disabled.
SAML_ENTRY_POINT =
SAML_ISSUER =
SAML_CERT =
SAML_CALLBACK_URL = /oauth/saml/callback
SAML_SESSION_SECRET =
# Attribute mappings (optional)
SAML_EMAIL_CLAIM =
SAML_USERNAME_CLAIM =
SAML_GIVEN_NAME_CLAIM =
SAML_FAMILY_NAME_CLAIM =
SAML_PICTURE_CLAIM =
SAML_NAME_CLAIM =
# Logint buttion settings (optional)
SAML_BUTTON_LABEL =
SAML_IMAGE_URL =
# Whether the SAML Response should be signed.
# - If "true", the entire `SAML Response` will be signed.
# - If "false" or unset, only the `SAML Assertion` will be signed (default behavior).
# SAML_USE_AUTHN_RESPONSE_SIGNED=
2025-06-23 10:22:27 -04:00
#===============================================#
# Microsoft Graph API / Entra ID Integration #
#===============================================#
# Enable Entra ID people search integration in permissions/sharing system
# When enabled, the people picker will search both local database and Entra ID
USE_ENTRA_ID_FOR_PEOPLE_SEARCH = false
# When enabled, entra id groups owners will be considered as members of the group
ENTRA_ID_INCLUDE_OWNERS_AS_MEMBERS = false
# Microsoft Graph API scopes needed for people/group search
# Default scopes provide access to user profiles and group memberships
OPENID_GRAPH_SCOPES = User.Read,People.Read,GroupMember.Read.All
2024-05-29 14:46:20 -07:00
# LDAP
LDAP_URL =
LDAP_BIND_DN =
LDAP_BIND_CREDENTIALS =
LDAP_USER_SEARCH_BASE =
2025-03-21 16:47:03 +01:00
#LDAP_SEARCH_FILTER="mail="
2024-05-29 14:46:20 -07:00
LDAP_CA_CERT_PATH =
2024-07-28 01:16:39 +05:30
# LDAP_TLS_REJECT_UNAUTHORIZED=
2025-03-21 12:55:09 +01:00
# LDAP_STARTTLS=
2024-07-27 15:42:18 -04:00
# LDAP_LOGIN_USES_USERNAME=true
2024-06-21 07:14:53 -07:00
# LDAP_ID=
# LDAP_USERNAME=
2024-09-21 10:44:27 -04:00
# LDAP_EMAIL=
2024-06-21 07:14:53 -07:00
# LDAP_FULL_NAME=
2024-05-29 14:46:20 -07:00
2023-12-03 09:52:13 -05:00
#========================#
# Email Password Reset #
#========================#
2023-05-07 10:04:51 -07:00
2024-03-27 16:07:04 +02:00
EMAIL_SERVICE =
EMAIL_HOST =
EMAIL_PORT = 25
EMAIL_ENCRYPTION =
EMAIL_ENCRYPTION_HOSTNAME =
EMAIL_ALLOW_SELFSIGNED =
EMAIL_USERNAME =
EMAIL_PASSWORD =
EMAIL_FROM_NAME =
2026-02-19 19:09:19 -08:00
EMAIL_FROM = noreply@hanzo.ai
2023-07-11 23:17:58 +02:00
2025-06-04 13:12:37 -04:00
#========================#
# Mailgun API #
#========================#
# MAILGUN_API_KEY=your-mailgun-api-key
# MAILGUN_DOMAIN=mg.yourdomain.com
# EMAIL_FROM=noreply@yourdomain.com
2026-02-19 19:09:19 -08:00
# EMAIL_FROM_NAME="Hanzo Chat"
2025-06-04 13:12:37 -04:00
# # Optional: For EU region
# MAILGUN_HOST=https://api.eu.mailgun.net
2023-12-30 03:42:19 +01:00
#========================#
# Firebase CDN #
#========================#
FIREBASE_API_KEY =
FIREBASE_AUTH_DOMAIN =
FIREBASE_PROJECT_ID =
FIREBASE_STORAGE_BUCKET =
FIREBASE_MESSAGING_SENDER_ID =
FIREBASE_APP_ID =
2025-03-19 07:04:45 +01:00
#========================#
# S3 AWS Bucket #
#========================#
2025-03-20 14:00:59 +01:00
AWS_ENDPOINT_URL =
2025-03-19 07:04:45 +01:00
AWS_ACCESS_KEY_ID =
AWS_SECRET_ACCESS_KEY =
AWS_REGION =
AWS_BUCKET_NAME =
2026-02-21 18:36:48 -05:00
# Required for path-style S3-compatible providers (MinIO, Hetzner, Backblaze B2, etc.)
# that don't support virtual-hosted-style URLs (bucket.endpoint). Not needed for AWS S3.
# AWS_FORCE_PATH_STYLE=false
2025-03-19 07:04:45 +01:00
2025-03-19 15:45:52 +01:00
#========================#
# Azure Blob Storage #
#========================#
AZURE_STORAGE_CONNECTION_STRING =
AZURE_STORAGE_PUBLIC_ACCESS = false
AZURE_CONTAINER_NAME = files
2024-06-15 08:12:03 -07:00
#========================#
# Shared Links #
#========================#
ALLOW_SHARED_LINKS = true
ALLOW_SHARED_LINKS_PUBLIC = true
2024-08-04 21:17:59 -04:00
#==============================#
# Static File Cache Control #
#==============================#
2024-08-26 15:34:46 -04:00
# Leave commented out to use defaults: 1 day (86400 seconds) for s-maxage and 2 days (172800 seconds) for max-age
2024-08-04 21:17:59 -04:00
# NODE_ENV must be set to production for these to take effect
2024-08-26 15:34:46 -04:00
# STATIC_CACHE_MAX_AGE=172800
# STATIC_CACHE_S_MAX_AGE=86400
2024-08-04 21:17:59 -04:00
2026-02-19 19:09:19 -08:00
# If you have another service in front of your Hanzo Chat doing compression, disable express based compression here
2024-08-04 21:17:59 -04:00
# DISABLE_COMPRESSION=true
2025-07-12 05:51:53 +09:00
# If you have gzipped version of uploaded image images in the same folder, this will enable gzip scan and serving of these images
# Note: The images folder will be scanned on startup and a ma kept in memory. Be careful for large number of images.
# ENABLE_IMAGE_OUTPUT_GZIP_SCAN=true
2024-02-27 23:59:56 +01:00
#===================================================#
# UI #
#===================================================#
2026-02-19 19:09:19 -08:00
APP_TITLE = Hanzo Chat
2024-03-06 16:52:42 -05:00
# CUSTOM_FOOTER="My custom footer"
2026-02-19 19:09:19 -08:00
HELP_AND_FAQ_URL = https://hanzo.ai/chat
2024-02-27 23:59:56 +01:00
# SHOW_BIRTHDAY_ICON=true
2024-06-15 14:09:18 +02:00
# Google tag manager id
#ANALYTICS_GTM_ID=user provided google tag manager id
2025-10-07 14:47:21 -04:00
# limit conversation file imports to a certain number of bytes in size to avoid the container
# maxing out memory limitations by unremarking this line and supplying a file size in bytes
# such as the below example of 250 mib
# CONVERSATION_IMPORT_MAX_FILE_SIZE_BYTES=262144000
2025-02-20 17:39:12 -05:00
#===============#
# REDIS Options #
#===============#
2025-07-15 16:24:31 -06:00
# Enable Redis for caching and session storage
2025-02-20 17:39:12 -05:00
# USE_REDIS=true
2025-12-19 10:12:39 -05:00
# Enable Redis for resumable LLM streams (defaults to USE_REDIS value if not set)
# Set to false to use in-memory storage for streams while keeping Redis for other caches
# USE_REDIS_STREAMS=true
2025-02-20 17:39:12 -05:00
2025-07-15 16:24:31 -06:00
# Single Redis instance
# REDIS_URI=redis://127.0.0.1:6379
# Redis cluster (multiple nodes)
# REDIS_URI=redis://127.0.0.1:7001,redis://127.0.0.1:7002,redis://127.0.0.1:7003
# Redis with TLS/SSL encryption and CA certificate
# REDIS_URI=rediss://127.0.0.1:6380
# REDIS_CA=/path/to/ca-cert.pem
2025-08-27 16:09:07 -04:00
# Elasticache may need to use an alternate dnsLookup for TLS connections. see "Special Note: Aws Elasticache Clusters with TLS" on this webpage: https://www.npmjs.com/package/ioredis
# Enable alternative dnsLookup for redis
# REDIS_USE_ALTERNATIVE_DNS_LOOKUP=true
2025-07-15 16:24:31 -06:00
# Redis authentication (if required)
# REDIS_USERNAME=your_redis_username
# REDIS_PASSWORD=your_redis_password
# Redis key prefix configuration
# Use environment variable name for dynamic prefix (recommended for cloud deployments)
# REDIS_KEY_PREFIX_VAR=K_REVISION
# Or use static prefix directly
2026-07-14 10:41:50 -07:00
# REDIS_KEY_PREFIX=chat
2025-07-15 16:24:31 -06:00
# Redis connection limits
# REDIS_MAX_LISTENERS=40
2025-02-20 17:39:12 -05:00
2025-07-25 09:00:02 -06:00
# Redis ping interval in seconds (0 = disabled, >0 = enabled)
# When set to a positive integer, Redis clients will ping the server at this interval to keep connections alive
# When unset or 0, no pinging is performed (recommended for most use cases)
# REDIS_PING_INTERVAL=300
2025-07-25 08:23:36 -06:00
# Force specific cache namespaces to use in-memory storage even when Redis is enabled
2026-02-11 22:20:43 -05:00
# Comma-separated list of CacheKeys
# Defaults to CONFIG_STORE,APP_CONFIG so YAML-derived config stays per-container (safe for blue/green deployments)
# Set to empty string to force all namespaces through Redis: FORCED_IN_MEMORY_CACHE_NAMESPACES=
# FORCED_IN_MEMORY_CACHE_NAMESPACES=CONFIG_STORE,APP_CONFIG
2025-07-25 08:23:36 -06:00
2025-10-30 15:08:04 -06:00
# Leader Election Configuration (for multi-instance deployments with Redis)
# Duration in seconds that the leader lease is valid before it expires (default: 25)
# LEADER_LEASE_DURATION=25
# Interval in seconds at which the leader renews its lease (default: 10)
# LEADER_RENEW_INTERVAL=10
# Maximum number of retry attempts when renewing the lease fails (default: 3)
# LEADER_RENEW_ATTEMPTS=3
# Delay in seconds between retry attempts when renewing the lease (default: 0.5)
# LEADER_RENEW_RETRY_DELAY=0.5
2023-12-03 09:52:13 -05:00
#==================================================#
# Others #
#==================================================#
# You should leave the following commented out #
2023-07-11 23:17:58 +02:00
2023-12-03 09:52:13 -05:00
# NODE_ENV=
2023-07-04 21:23:42 +02:00
2023-12-03 09:52:13 -05:00
# E2E_USER_EMAIL=
2024-03-19 13:54:35 -04:00
# E2E_USER_PASSWORD=
2024-10-28 11:01:31 -04:00
#=====================================================#
# Cache Headers #
#=====================================================#
# Headers that control caching of the index.html #
# Default configuration prevents caching to ensure #
# users always get the latest version. Customize #
# only if you understand caching implications. #
2025-05-16 23:18:52 +09:00
# INDEX_CACHE_CONTROL=no-cache, no-store, must-revalidate
# INDEX_PRAGMA=no-cache
# INDEX_EXPIRES=0
2024-10-28 11:01:31 -04:00
# no-cache: Forces validation with server before using cached version
# no-store: Prevents storing the response entirely
2025-01-10 08:54:08 -05:00
# must-revalidate: Prevents using stale content when offline
#=====================================================#
# OpenWeather #
#=====================================================#
2025-02-15 18:52:29 -05:00
OPENWEATHER_API_KEY =
2025-05-24 10:23:17 -04:00
#====================================#
2026-02-19 19:09:19 -08:00
# Hanzo Chat Code Interpreter API #
2025-05-24 10:23:17 -04:00
#====================================#
2026-06-30 18:39:33 -07:00
# "Run Code" routes through the Hanzo unified backend (api.hanzo.ai/v1/exec),
# which executes in a Hanzo sandbox. execute_code POSTs {BASEURL}/exec with
# X-API-Key. https://hanzo.ai/docs/chat/code-interpreter
2026-07-14 10:41:50 -07:00
# CHAT_CODE_BASEURL=https://api.hanzo.ai/v1
# CHAT_CODE_API_KEY=your-key # prod: KMS chat-secrets/CHAT_CODE_API_KEY
2025-05-24 10:23:17 -04:00
#======================#
# Web Search #
#======================#
2026-06-30 18:39:33 -07:00
# Web Search routes through the Hanzo unified backend ONLY — no external SaaS.
# The searxng provider + firecrawl scraper both point at api.hanzo.ai/v1/websearch
2026-07-14 10:41:50 -07:00
# (Hanzo metasearch + Hanzo Crawl). See chat.yaml `webSearch`.
2026-02-19 19:09:19 -08:00
# https://hanzo.ai/docs/chat/features/web_search
2026-06-30 18:39:33 -07:00
# SEARXNG_INSTANCE_URL=https://api.hanzo.ai/v1/websearch
# FIRECRAWL_API_URL=https://api.hanzo.ai/v1/websearch
# WEBSEARCH_API_KEY=your-key # prod: KMS chat-secrets/WEBSEARCH_API_KEY
#
# Do NOT set SERPER_API_KEY / TAVILY_API_KEY / JINA_API_KEY / COHERE_API_KEY:
# external providers are intentionally disabled (one way, unified backend).
2025-08-13 09:45:06 -06:00
#======================#
# MCP Configuration #
#======================#
# Treat 401/403 responses as OAuth requirement when no oauth metadata found
# MCP_OAUTH_ON_AUTH_ERROR=true
# Timeout for OAuth detection requests in milliseconds
# MCP_OAUTH_DETECTION_TIMEOUT=5000
# Cache connection status checks for this many milliseconds to avoid expensive verification
# MCP_CONNECTION_CHECK_TTL=60000
2025-11-21 14:44:52 +00:00
# Skip code challenge method validation (e.g., for AWS Cognito that supports S256 but doesn't advertise it)
# When set to true, forces S256 code challenge even if not advertised in .well-known/openid-configuration
# MCP_SKIP_CODE_CHALLENGE_CHECK=false