Skip to content

Environment variables ​

The server reads its settings from the environment when it starts. It also reads a .env file (KEY=value lines, no variable expansion) from its working directory and from two directories up (the repo root, when it runs from apps/server as pnpm dev and pnpm start do); real environment variables win over the file. An empty value (KEY=) counts as not set. Docker Compose passes the repo root's .env to the container (see Docker); .env.example at the repo root lists the common ones.

A bad value stops the server at startup with Invalid environment: <VARIABLE>: <problem>.

Bot settings (what the agent says, its voice, its limits) are not environment variables: they live in the admin panel. See Configuration.

Basics ​

Where the server listens, where it keeps its data, and the address the world reaches it at.

VariableTypeDefault
NODE_ENVdevelopment, production, testdevelopmentSet production for any real deployment (the Docker image does). Outside production the server also accepts the widget socket from localhost pages, allows http:// webhook URLs and serves source maps; development also logs every request in a readable format.
HOSTstring0.0.0.0The interface to listen on.
PORTnumber (0 to 65535)8800The port to listen on.
PUBLIC_URLURL(not set)The address visitors' browsers reach this server at, e.g. https://chat.example.com. Used in the embed code, the bot config URLs, invitation links and preview links, and the chat window's WebSocket only accepts connections from this origin. Without it the server uses the address each request came in on, which is wrong behind most proxies. The session cookie is Secure only when it starts with https://.
DATA_DIRstring./dataWhere the server keeps everything: the SQLite database (wireface.db), uploaded files (files/) and the generated master.key. Back this up.
ROOT_REDIRECTstring/admin/Where a visit to / goes: the admin panel, or a product page when the server is a public service.
LOG_LEVELfatal, error, warn, info, debug, trace, silentinfoHow much the server logs. debug helps when looking into a problem.

Security ​

Secrets, and the switches that widen what the server may do.

VariableTypeDefault
WIREFACE_MASTER_KEYstring(not set)Encrypts provider API keys, webhook and identity secrets, tool secrets and MCP headers and environment in the database (AES-256-GCM). 32 bytes as base64 or 64 hex characters, e.g. from openssl rand -base64 32. Without it the server generates one into DATA_DIR/master.key on first run. Lose it and every stored key must be entered again.
WIREFACE_MASTER_KEY_OLDstring(not set)The previous master key, while you change it. At startup the server re-encrypts every stored secret still sealed with it under the new key, and the log says when this variable can be removed. See Backups.
SETUP_TOKENstring (at least 8 characters)(not set)The token the first-run setup at /admin/setup asks for (at least 8 characters). Without it the server makes a random one and prints it in the log until setup is done.
ALLOW_STDIO_MCPboolean (true, 1, yes, on)falseAllow MCP servers that run as commands on this machine (the stdio transport). They get a minimal environment (PATH, HOME and the like) plus the variables the admin sets, never the server's own. Still, only turn it on when everyone with admin access is trusted with a shell.
ALLOW_PRIVATE_NETWORKboolean (true, 1, yes, on)falseLet HTTP tools, MCP servers, webhooks and the knowledge crawler reach private, loopback and link-local addresses. Off, they can only reach the public internet. (One HTTP tool can also be allowed on its own, except in a hosted workspace.)

Behind a proxy ​

VariableTypeDefault
TRUST_PROXYboolean (true, 1, yes, on)falseTrust X-Forwarded-For and X-Forwarded-Proto from a reverse proxy, so rate limits see each visitor's own IP and the server knows the request was https. Set it when the server is behind nginx, Caddy or a load balancer.

Hosted sign-up ​

For running Wireface Chat as a service: people sign in with their wireface.dev account and each gets a workspace of their own, with these limits. The server owner's workspace (made in the setup) has none of them. See Hosted accounts.

VariableTypeDefault
WIREFACE_ACCOUNTS_URLURL(not set)The wireface.dev accounts site (https://wireface.dev). Set it, with the secret, to offer "Sign in with your wireface.dev account" on the sign-in page: anyone with an account gets a workspace of their own on first sign-in. Only once this server's own setup is done.
WIREFACE_ACCOUNTS_SECRETstring (at least 32 characters)(not set)The secret the accounts service signs sign-in tokens with (the same value as its CHAT_SSO_SECRET), at least 32 characters, e.g. from openssl rand -base64 48.
HOSTED_SIGNUPS_PER_DAYnumber50New hosted workspaces a day, in all.
HOSTED_MAX_BOTSnumber3Bots in a hosted workspace.
HOSTED_MAX_MEMBERSnumber3People in a hosted workspace, counting invitations.
HOSTED_MAX_KB_SOURCESnumber10Knowledge sources in a hosted workspace.
HOSTED_MAX_KB_PAGESnumber50Pages one website or sitemap source may read.
HOSTED_MAX_KB_FILE_MBnumber5The largest knowledge file, in MB.
HOSTED_MAX_TOOLSnumber10HTTP tools and MCP servers in a hosted workspace, together.
HOSTED_MAX_WEBHOOKSnumber3Webhooks in a hosted workspace.
HOSTED_MAX_FACESnumber10Custom faces (from photos) in a hosted workspace.
HOSTED_MAX_RETENTION_DAYSnumber90The longest a hosted workspace may keep conversations; they start at this.
DEMO_SANDBOXboolean (true, 1, yes, on)falseOffer "Try the demo" on the sign-in page: one click makes a visitor a sandbox workspace with a sample bot, conversations and leads, without signing in. They can change the bot and talk to it, but not connect keys, add tools or publish; signing in with a wireface.dev account keeps what they made. Needs DEMO_SANDBOX_GEMINI_KEY and this server's own setup done. See Hosted accounts.
DEMO_SANDBOX_GEMINI_KEYstring(not set)The Gemini API key the sandboxes' sample bots run on. It's stored encrypted in each sandbox like any key, and never shown; it's removed when a sandbox is kept by signing in.
DEMO_SANDBOXES_PER_DAYnumber200New sandboxes a day, in all (and three an hour from one address).
DEMO_SANDBOX_HOURSnumber (1 to 168)24How long a sandbox lasts before it and everything in it is deleted.
DEMO_DAILY_USDnumber3What all sandboxes together may spend on the demo key in a day (estimated, USD). Past it, their bots stop answering until midnight UTC.
DEMO_BOT_DAILY_USDnumber0.25A sandbox bot's daily spending cap (its own caps can only be lower).
DEMO_BOT_DAILY_MESSAGESnumber40A sandbox bot's daily message cap.
DEMO_BOT_VOICE_MINUTESnumber3A sandbox bot's daily voice minutes (one voice conversation at a time).

AI providers ​

Keys to connect on first run, and other addresses for the providers (proxies, gateways, test mocks).

VariableTypeDefault
PROVIDER_BASE_URL_ANTHROPICstring(not set)Send Anthropic API calls somewhere else, e.g. a corporate gateway. Default https://api.anthropic.com. (Server-side refusal fallback is only used with the default.)
PROVIDER_BASE_URL_OPENAIstring(not set)Default https://api.openai.com/v1.
PROVIDER_BASE_URL_GEMINIstring(not set)Default https://generativelanguage.googleapis.com.
PROVIDER_BASE_URL_ELEVENLABSstring(not set)Default https://api.elevenlabs.io.
PROVIDER_WS_URL_OPENAIstring(not set)WebSocket base for the Realtime API and transcription. Default wss://api.openai.com/v1.
PROVIDER_WS_URL_GEMINIstring(not set)WebSocket base for the Live API. Default wss://generativelanguage.googleapis.com.
PROVIDER_WS_URL_ELEVENLABSstring(not set)WebSocket base for Agents and Scribe. Default wss://api.elevenlabs.io.
ANTHROPIC_API_KEYstring(not set)If set when the first-run setup completes, an Anthropic connection is made from it. After that, manage keys in the admin panel.
OPENAI_API_KEYstring(not set)The same, for OpenAI.
GEMINI_API_KEYstring(not set)The same, for Google Gemini.
ELEVENLABS_API_KEYstring(not set)The same, for ElevenLabs.

Static files ​

Only needed when the built files are not in the usual places of the repo (the Docker image keeps them there).

VariableTypeDefault
ADMIN_DISTstring(not set)Where the built admin panel is. Defaults to apps/admin/dist in the repo.
WIDGET_DISTstring(not set)Where the built widget is. Defaults to packages/widget/dist.
WIDGET_RELEASESstring(not set)Every released widget@x.y.z.js, so pages pinned to an older version keep loading after an upgrade. Defaults to packages/widget/releases.
DOCS_DISTstring(not set)Where these docs are built. Defaults to docs/.vitepress/dist.
CORE_DIRstring(not set)Where the Wireface face engine is. Defaults to vendor/wireface-core.

Wireface Chat 0.1.0. These docs are served by your own server.