# Database # # Local dev (Nest on your machine + Postgres via docker-compose.postgres.yml): # Use host "localhost" — hostname "postgres" only works inside Docker networks. DATABASE_URL=postgresql://dyolink_user:password@localhost:5432/dyolink_db POSTGRES_HOST=localhost POSTGRES_PORT=5432 POSTGRES_USER=dyolink_user POSTGRES_PASSWORD=password POSTGRES_DB=dyolink_db # # If you run the API inside the same Compose stack as Postgres, use instead: # DATABASE_URL=postgresql://dyolink_user:password@postgres:5432/dyolink_db # POSTGRES_HOST=postgres # JWT (required for register/login) JWT_SECRET=CHANGE_ME_TO_A_STRONG_SECRET_32_CHARS_MIN JWT_EXPIRES_IN=7d JWT_REFRESH_SECRET=CHANGE_ME_TO_ANOTHER_STRONG_SECRET JWT_REFRESH_EXPIRES_IN=30d # Application PORT=3000 NODE_ENV=development API_PREFIX=/api # CORS and invite links — must match the URL where the Next.js app runs FRONTEND_URL=http://localhost:3001 # Set true when the app is served over HTTPS (required for Secure auth cookies) COOKIE_SECURE=false # OAuth (optional — uncomment when configured) # GOOGLE_CLIENT_ID=your-google-client-id # GOOGLE_CLIENT_SECRET=your-google-client-secret # GOOGLE_CALLBACK_URL=http://localhost:3000/auth/google/callback # FACEBOOK_CLIENT_ID=your-facebook-app-id # FACEBOOK_CLIENT_SECRET=your-facebook-app-secret # FACEBOOK_CALLBACK_URL=http://localhost:3000/auth/facebook/callback # Email (configure for production) SMTP_HOST=smtp.gmail.com SMTP_PORT=587 SMTP_USER=your_email@gmail.com SMTP_PASSWORD=your_app_password # SMS (sms.ir — use Sandbox API key for development) # SMS_IR_API_KEY=4QKMiSU4Kh7tWPLCdRMV0QpDh8WgF33YkWRS18BcG3vf4QHi SMS_IR_API_KEY=lwbK7hxmjimNjFS4g5DWahh75EKCgJUfcUIinUQzfQXwXkSp SMS_IR_TEMPLATE_ID=123456 # ── Voice treatment entry ────────────────────────────────────────────────────── # Without OPENROUTER_API_KEY the microphone button does not render at all. OPENROUTER_API_KEY= # OPENROUTER_BASE_URL=https://openrouter.ai/api/v1 # Locales the microphone is offered in. An unknown locale here fails at boot. # VOICE_ENABLED_LOCALES=fa,en,nl # Models, overridable per locale (VOICE_ASR_MODEL_FA, VOICE_LLM_MODEL_NL, ...). # All locales share these today; the per-locale override exists so Persian can be # repointed at a specialist ASR vendor without a code change. # VOICE_ASR_MODEL=openai/whisper-1 # VOICE_LLM_MODEL=google/gemini-3.7-flash # VOICE_ASR_PROVIDER_FA=openrouter # VOICE_LLM_PROVIDER_FA=openrouter # Recording cap in ms (0 = uncapped). 2 minutes bounds worst-case vendor spend at # about 1.3 cents per recording. # VOICE_MAX_RECORDING_MS=120000 # Per-user rate limit on the extract endpoint. Unreachable by a human — a recording # plus processing takes ten seconds at minimum — so it is purely an abuse guard. # VOICE_THROTTLE_TTL=60 # VOICE_THROTTLE_LIMIT=6