Skip to content

Configuration ​

The server is configured with environment variables (in Docker, the repo root's .env), read at startup: restart after changing them. The full list is in Environment variables. Everything about your bots, keys, team and data retention is set in the admin panel instead, and stored in the database.

The ones that matter ​

VariableSet it toWhy
PUBLIC_URLThe address visitors reach the server at, e.g. https://chat.example.comThe embed code, the chat's own URLs, invitation and preview links. The chat window's WebSocket only accepts its own origin, worked out from this.
TRUST_PROXYtrue behind a reverse proxySo the server sees visitors' real IPs (rate limits) and that requests came over https.
NODE_ENVproduction (the Docker image sets it)Development mode relaxes several checks.
WIREFACE_MASTER_KEY32 random bytes, base64 (optional)Encrypts stored keys and secrets. Without it a key is generated into DATA_DIR/master.key.
SETUP_TOKENA long random string (optional)The token for the first-run setup. Without it one is printed in the log.
LOG_LEVELinfo (default), debug when investigating

Two switches widen what the server may do. Leave them off unless you need them:

  • ALLOW_PRIVATE_NETWORK=true lets tools, MCP servers, webhooks and the knowledge crawler reach addresses inside your network. See Security.
  • ALLOW_STDIO_MCP=true lets admins add MCP servers that run as commands on the server.

Before going live ​

  • [ ] HTTPS in front of the server (reverse proxy, TLS), with WebSocket upgrades passed through.
  • [ ] PUBLIC_URL set to the https:// address, and TRUST_PROXY=true.
  • [ ] The port published only to the proxy (127.0.0.1:8800:8800), not to the internet.
  • [ ] Each bot's allowed origins list your sites (an empty list allows any site).
  • [ ] Spending caps on each bot (security.caps), and rate limits that suit your traffic.
  • [ ] A backup of /data, and a copy of the master key kept somewhere else (Backups).
  • [ ] A retention period, if your privacy policy needs one (Settings in the admin panel).
  • [ ] Team members invited with the least role they need (agent for people who answer chats).

Behind a path, or another port ​

The server must be the root of its own host name (https://chat.example.com/): the widget, the chat window and the APIs use fixed paths such as /widget.js and /v1/widget/ws, so it can't live under a path like https://example.com/chat/. Any port works as long as PUBLIC_URL includes it.

Wireface Chat 0.1.0. These docs are served by your own server.