This is what an AI/RAG pipeline sees when it indexes this page — the same output served at https://camelmind-docs.vercel.app/api/llms/deployment/environment-variables.Back to doc

Rendered doc

Environment variables

Configure CamelMind with environment variables for local development, production, authentication, and integrations.

Use environment variables to configure CamelMind at runtime. This page explains which variables you need, when to set them, and where to configure them.

You typically configure environment variables in one of these places:

  • Local development: .env.local
  • Production: Your hosting platform's environment variable settings

You do not need to configure every variable on this page. Start with the variables required for your setup, then add optional variables when you enable features such as authentication, Last Updated information, offline exports, or the feedback widget.

Configure environment variables for local development

For local development, create .env.local from the example file included with your CamelMind project:

bash
cp .env.example .env.local

Open .env.local and set the values required for your site.

Important

Never commit .env.local or any file containing secrets to version control. The .gitignore in the starter template already excludes .env.local.


Configure environment variables for production

For production deployments, configure environment variables in your hosting platform instead of committing an .env file to your repository.

For example, on Vercel, go to Project Settings → Environment Variables. Vercel makes the variables available to your application at build time and runtime.

The variables you need depend on which CamelMind features you use:

If you want toConfigure
Set your site's public URLCAMELMIND_URL
Enable authenticationCAMELMIND_AUTH_ENABLED, CAMELMIND_AUTH_REQUIRE_LOGIN, CAMELMIND_AUTH_PROVIDER, SESSION_SECRET
Connect an OIDC/SSO providerOIDC_ISSUER, OIDC_CLIENT_ID, OIDC_CLIENT_SECRET, OIDC_ROLES_CLAIM
Show the correct Last Updated date and authorGITHUB_TOKEN or GITLAB_TOKEN when required
Build an offline/static version of the siteOFFLINE_MODE
Send feedback widget submissions by emailRESEND_API_KEY, FEEDBACK_EMAIL_TO, and optionally FEEDBACK_EMAIL_FROM

Site configuration environment variables and public URL settings

Configure general site configuration options, canonical domain settings, and base public URLs by setting the CAMELMIND_URL environment variable for your CamelMind documentation site:

VariableDefaultDescription
CAMELMIND_URLhttp://localhost:3000Public-facing URL of your site. Used in auth callbacks and <meta> tags. Must not have a trailing slash.

For local development, use the default:

bash
CAMELMIND_URL=http://localhost:3000

For production, replace it with your site's public URL:

bash
CAMELMIND_URL=https://docs.example.com

Authentication environment variables and access control

Set these authentication environment variables when you enable CamelMind authentication to manage user sessions and control access to your documentation site:

VariableDefaultDescription
CAMELMIND_AUTH_ENABLEDfalseSet "true" to enable the authentication layer.
CAMELMIND_AUTH_REQUIRE_LOGINfalseSet "true" to require a valid session on all pages except publicPaths.
CAMELMIND_AUTH_PROVIDERdev-mockAuthentication provider: "dev-mock" or "oidc".
SESSION_SECRET—Random string used to sign and encrypt session cookies. Required when you enable authentication is. Must be at least 32 characters. Generate one with openssl rand -base64 32.

For example, to enable authentication with the development mock provider:

bash
CAMELMIND_AUTH_ENABLED=true
CAMELMIND_AUTH_REQUIRE_LOGIN=true
CAMELMIND_AUTH_PROVIDER=dev-mock
SESSION_SECRET=your-random-32-character-secret

For the complete authentication setup, see Authentication and RBAC.


OIDC and SSO identity provider environment variables

Configure these OpenID Connect (OIDC) and Single Sign-On (SSO) environment variables when CAMELMIND_AUTH_PROVIDER=oidc to integrate your identity provider with CamelMind:

VariableDescription
OIDC_ISSUEROIDC issuer URL, such as https://keycloak.example.com/realms/my-realm.
OIDC_CLIENT_IDClient ID registered with your identity provider.
OIDC_CLIENT_SECRETClient secret from your identity provider. Keep this secret.
OIDC_ROLES_CLAIMJWT claim path containing user roles. Default: realm_access.roles (Keycloak format).

Example:

bash
CAMELMIND_AUTH_PROVIDER=oidc
OIDC_ISSUER=https://keycloak.example.com/realms/my-realm
OIDC_CLIENT_ID=my-docs
OIDC_CLIENT_SECRET=your-client-secret
OIDC_ROLES_CLAIM=realm_access.roles

Only configure these variables if you are using an OIDC provider. You do not need them when using the default dev-mock provider.


Configure Git access for Last Updated information

CamelMind can show the date and author of the most recent documentation change in the Last Updated footer.

To determine this information, CamelMind queries the GitHub or GitLab REST API. It checks public repositories without a token, subject to unauthenticated API rate limits. Private repositories require an API token.

This access is separate from your hosting provider's repository access. For example, Vercel may have permission to clone a private GitHub repository, but CamelMind still needs its own token to make an authenticated GitHub API request.

GitHub repositories environment variables

Configure GITHUB_TOKEN environment variables when your GitHub documentation repository is private or when you want to avoid unauthenticated GitHub API rate limits for Last Updated data:

VariableDefaultDescription
GITHUB_TOKEN—Token with read access to your repository. Required for CamelMind to look up Last Updated information for a private GitHub repository. Recommended for public repositories to avoid API rate limits.

GitLab repositories environment variables

Configure GITLAB_TOKEN environment variables when your GitLab documentation repository is private or when you want to avoid unauthenticated GitLab API rate limits for Last Updated data:

VariableDefaultDescription
GITLAB_TOKEN—Token with read access to your repository. Required for CamelMind to look up Last Updated information for a private GitLab repository. Recommended for public repositories to avoid API rate limits.

For more information about how CamelMind determines the date and author, see Last Updated.


Configure offline and static builds

Set OFFLINE_MODE when you want to generate a static version of your CamelMind site for offline use.

VariableDescription
OFFLINE_MODESet "true" to enable static export mode (output: export). Bypasses authentication and hides server-only UI. Used by build-offline.sh.

For example:

bash
OFFLINE_MODE=true

You do not need to set this variable for a normal CamelMind deployment.


Configure the feedback widget

Set these variables when you want the CamelMind feedback widget to send visitor feedback by email through Resend.

VariableDefaultDescription
RESEND_API_KEY—API key for Resend. When set along with FEEDBACK_EMAIL_TO, the feedback widget emails submissions. If unset, the feedback API returns a 503 and submissions are not recorded.
FEEDBACK_EMAIL_TO—Address that receives feedback submissions.
FEEDBACK_EMAIL_FROMDoc Feedback <onboarding@resend.dev>The From address used when sending feedback emails. For anything other than the default onboarding@resend.dev, the address must use a verified domain or sender in your Resend account.

At minimum, configure:

bash
RESEND_API_KEY=your-resend-api-key
FEEDBACK_EMAIL_TO=feedback@example.com

Example .env.local development environment file

For local development, use the following .env.local configuration. The example uses the default development mock provider, so it comments out the OIDC environment variables:

bash
# Site
CAMELMIND_URL=http://localhost:3000

# Authentication
CAMELMIND_AUTH_ENABLED=false
CAMELMIND_AUTH_REQUIRE_LOGIN=false
CAMELMIND_AUTH_PROVIDER=dev-mock
SESSION_SECRET=change-me-to-a-random-32-character-string

# OIDC — only needed when AUTH_PROVIDER=oidc
# OIDC_ISSUER=https://keycloak.example.com/realms/my-realm
# OIDC_CLIENT_ID=my-docs
# OIDC_CLIENT_SECRET=
# OIDC_ROLES_CLAIM=realm_access.roles

You can add other variables from this page as you enable the corresponding features.


Example production environment variables

The following example shows a production configuration using OIDC authentication:

bash
CAMELMIND_URL=https://docs.example.com

# Authentication
CAMELMIND_AUTH_ENABLED=true
CAMELMIND_AUTH_REQUIRE_LOGIN=true
CAMELMIND_AUTH_PROVIDER=oidc
SESSION_SECRET=a-truly-random-32-character-secret

# OIDC
OIDC_ISSUER=https://keycloak.example.com/realms/prod
OIDC_CLIENT_ID=docs-prod
OIDC_CLIENT_SECRET=prod-secret-from-your-idp
OIDC_ROLES_CLAIM=realm_access.roles

Add GITHUB_TOKEN or GITLAB_TOKEN if your repository requires authentication to retrieve Last Updated information.

Add the Resend variables if you want to enable the feedback widget.


Environment variable checklist

Before deploying your CamelMind site, check which of these apply to your setup:

  • Set CAMELMIND_URL to your production site URL.
  • Set authentication variables if your site requires user login.
  • Set OIDC variables if you use an OIDC identity provider.
  • Set GITHUB_TOKEN or GITLAB_TOKEN if your repository is private or you want authenticated Git API access.
  • Set OFFLINE_MODE=true only if you are generating a static offline build.
  • Set Resend variables if you want to receive feedback widget submissions.
  • Store secrets in your hosting platform's environment variable settings rather than in your repository.
  • Never commit .env.local or files containing secrets to Git.

What the AI sees

1> For a complete documentation index, see /llms.txt. To read any public page as Markdown, append .md to the URL.
2 
3Use environment variables to configure CamelMind at runtime. This page explains **which variables you need, when to set them, and where to configure them**.
4 
5You typically configure environment variables in one of these places:
6 
7- **Local development:** `.env.local`
8- **Production:** Your hosting platform's environment variable settings
9 
10You do not need to configure every variable on this page. Start with the variables required for your setup, then add optional variables when you enable features such as authentication, Last Updated information, offline exports, or the feedback widget.
11 
12## Configure environment variables for local development
13 
14For local development, create `.env.local` from the example file included with your CamelMind project:
15 
16```bash
17cp .env.example .env.local
18```
19 
20Open `.env.local` and set the values required for your site.
21 
22<Callout type="important">
23Never commit `.env.local` or any file containing secrets to version control. The `.gitignore` in the starter template already excludes `.env.local`.
24</Callout>
25 
26---
27 
28## Configure environment variables for production
29 
30For production deployments, configure environment variables in your hosting platform instead of committing an `.env` file to your repository.
31 
32For example, on Vercel, go to **Project Settings → Environment Variables**. Vercel makes the variables available to your application at build time and runtime.
33 
34The variables you need depend on which CamelMind features you use:
35 
36| If you want to | Configure |
37| --- | --- |
38| Set your site's public URL | `CAMELMIND_URL` |
39| Enable authentication | `CAMELMIND_AUTH_ENABLED`, `CAMELMIND_AUTH_REQUIRE_LOGIN`, `CAMELMIND_AUTH_PROVIDER`, `SESSION_SECRET` |
40| Connect an OIDC/SSO provider | `OIDC_ISSUER`, `OIDC_CLIENT_ID`, `OIDC_CLIENT_SECRET`, `OIDC_ROLES_CLAIM` |
41| Show the correct Last Updated date and author | `GITHUB_TOKEN` or `GITLAB_TOKEN` when required |
42| Build an offline/static version of the site | `OFFLINE_MODE` |
43| Send feedback widget submissions by email | `RESEND_API_KEY`, `FEEDBACK_EMAIL_TO`, and optionally `FEEDBACK_EMAIL_FROM` |
44 
45---
46 
47## Site configuration environment variables and public URL settings
48 
49Configure general site configuration options, canonical domain settings, and base public URLs by setting the `CAMELMIND_URL` environment variable for your CamelMind documentation site:
50 
51| Variable | Default | Description |
52| --- | --- | --- |
53| `CAMELMIND_URL` | `http://localhost:3000` | Public-facing URL of your site. Used in auth callbacks and `<meta>` tags. Must not have a trailing slash. |
54 
55For local development, use the default:
56 
57```bash
58CAMELMIND_URL=http://localhost:3000
59```
60 
61For production, replace it with your site's public URL:
62 
63```bash
64CAMELMIND_URL=https://docs.example.com
65```
66 
67---
68 
69## Authentication environment variables and access control
70 
71Set these authentication environment variables when you enable CamelMind authentication to manage user sessions and control access to your documentation site:
72 
73| Variable | Default | Description |
74| --- | --- | --- |
75| `CAMELMIND_AUTH_ENABLED` | `false` | Set `"true"` to enable the authentication layer. |
76| `CAMELMIND_AUTH_REQUIRE_LOGIN` | `false` | Set `"true"` to require a valid session on all pages except `publicPaths`. |
77| `CAMELMIND_AUTH_PROVIDER` | `dev-mock` | Authentication provider: "dev-mock" or "oidc". |
78| `SESSION_SECRET` | — | Random string used to sign and encrypt session cookies. **Required when you enable authentication is.** Must be at least 32 characters. Generate one with `openssl rand -base64 32`. |
79 
80For example, to enable authentication with the development mock provider:
81 
82```bash
83CAMELMIND_AUTH_ENABLED=true
84CAMELMIND_AUTH_REQUIRE_LOGIN=true
85CAMELMIND_AUTH_PROVIDER=dev-mock
86SESSION_SECRET=your-random-32-character-secret
87```
88 
89For the complete authentication setup, see [Authentication and RBAC](/features/auth-rbac).
90 
91---
92 
93## OIDC and SSO identity provider environment variables
94 
95Configure these OpenID Connect (OIDC) and Single Sign-On (SSO) environment variables when `CAMELMIND_AUTH_PROVIDER=oidc` to integrate your identity provider with CamelMind:
96 
97| Variable | Description |
98| --- | --- |
99| `OIDC_ISSUER` | OIDC issuer URL, such as `https://keycloak.example.com/realms/my-realm`. |
100| `OIDC_CLIENT_ID` | Client ID registered with your identity provider. |
101| `OIDC_CLIENT_SECRET` | Client secret from your identity provider. Keep this secret. |
102| `OIDC_ROLES_CLAIM` | JWT claim path containing user roles. Default: `realm_access.roles` (Keycloak format). |
103 
104Example:
105 
106```bash
107CAMELMIND_AUTH_PROVIDER=oidc
108OIDC_ISSUER=https://keycloak.example.com/realms/my-realm
109OIDC_CLIENT_ID=my-docs
110OIDC_CLIENT_SECRET=your-client-secret
111OIDC_ROLES_CLAIM=realm_access.roles
112```
113 
114Only configure these variables if you are using an OIDC provider. You do not need them when using the default `dev-mock` provider.
115 
116---
117 
118## Configure Git access for Last Updated information
119 
120CamelMind can show the date and author of the most recent documentation change in the **Last Updated** footer.
121 
122To determine this information, CamelMind queries the GitHub or GitLab REST API. It checks public repositories without a token, subject to unauthenticated API rate limits. Private repositories require an API token.
123 
124This access is separate from your hosting provider's repository access. For example, Vercel may have permission to clone a private GitHub repository, but CamelMind still needs its own token to make an authenticated GitHub API request.
125 
126### GitHub repositories environment variables
127 
128Configure `GITHUB_TOKEN` environment variables when your GitHub documentation repository is private or when you want to avoid unauthenticated GitHub API rate limits for Last Updated data:
129 
130| Variable | Default | Description |
131| --- | --- | --- |
132| `GITHUB_TOKEN` | — | Token with read access to your repository. Required for CamelMind to look up Last Updated information for a private GitHub repository. Recommended for public repositories to avoid API rate limits. |
133 
134### GitLab repositories environment variables
135 
136Configure `GITLAB_TOKEN` environment variables when your GitLab documentation repository is private or when you want to avoid unauthenticated GitLab API rate limits for Last Updated data:
137 
138| Variable | Default | Description |
139| --- | --- | --- |
140| `GITLAB_TOKEN` | — | Token with read access to your repository. Required for CamelMind to look up Last Updated information for a private GitLab repository. Recommended for public repositories to avoid API rate limits. |
141 
142For more information about how CamelMind determines the date and author, see [Last Updated](/features/last-updated).
143 
144---
145 
146## Configure offline and static builds
147 
148Set `OFFLINE_MODE` when you want to generate a static version of your CamelMind site for offline use.
149 
150| Variable | Description |
151| --- | --- |
152| `OFFLINE_MODE` | Set `"true"` to enable static export mode (`output: export`). Bypasses authentication and hides server-only UI. Used by `build-offline.sh`. |
153 
154For example:
155 
156```bash
157OFFLINE_MODE=true
158```
159 
160You do not need to set this variable for a normal CamelMind deployment.
161 
162---
163 
164## Configure the feedback widget
165 
166Set these variables when you want the CamelMind feedback widget to send visitor feedback by email through Resend.
167 
168| Variable | Default | Description |
169| --- | --- | --- |
170| `RESEND_API_KEY` | — | API key for [Resend](https://resend.com/). When set along with `FEEDBACK_EMAIL_TO`, the feedback widget emails submissions. If unset, the feedback API returns a 503 and submissions are not recorded. |
171| `FEEDBACK_EMAIL_TO` | — | Address that receives feedback submissions. |
172| `FEEDBACK_EMAIL_FROM` | `Doc Feedback <onboarding@resend.dev>` | The `From` address used when sending feedback emails. For anything other than the default `onboarding@resend.dev`, the address must use a verified domain or sender in your Resend account. |
173 
174At minimum, configure:
175 
176```bash
177RESEND_API_KEY=your-resend-api-key
178FEEDBACK_EMAIL_TO=feedback@example.com
179```
180 
181---
182 
183## Example .env.local development environment file
184 
185For local development, use the following `.env.local` configuration. The example uses the default development mock provider, so it comments out the OIDC environment variables:
186 
187```bash
188# Site
189CAMELMIND_URL=http://localhost:3000
190 
191# Authentication
192CAMELMIND_AUTH_ENABLED=false
193CAMELMIND_AUTH_REQUIRE_LOGIN=false
194CAMELMIND_AUTH_PROVIDER=dev-mock
195SESSION_SECRET=change-me-to-a-random-32-character-string
196 
197# OIDC — only needed when AUTH_PROVIDER=oidc
198# OIDC_ISSUER=https://keycloak.example.com/realms/my-realm
199# OIDC_CLIENT_ID=my-docs
200# OIDC_CLIENT_SECRET=
201# OIDC_ROLES_CLAIM=realm_access.roles
202```
203 
204You can add other variables from this page as you enable the corresponding features.
205 
206---
207 
208## Example production environment variables
209 
210The following example shows a production configuration using OIDC authentication:
211 
212```bash
213CAMELMIND_URL=https://docs.example.com
214 
215# Authentication
216CAMELMIND_AUTH_ENABLED=true
217CAMELMIND_AUTH_REQUIRE_LOGIN=true
218CAMELMIND_AUTH_PROVIDER=oidc
219SESSION_SECRET=a-truly-random-32-character-secret
220 
221# OIDC
222OIDC_ISSUER=https://keycloak.example.com/realms/prod
223OIDC_CLIENT_ID=docs-prod
224OIDC_CLIENT_SECRET=prod-secret-from-your-idp
225OIDC_ROLES_CLAIM=realm_access.roles
226```
227 
228Add `GITHUB_TOKEN` or `GITLAB_TOKEN` if your repository requires authentication to retrieve Last Updated information.
229 
230Add the Resend variables if you want to enable the feedback widget.
231 
232---
233 
234## Environment variable checklist
235 
236Before deploying your CamelMind site, check which of these apply to your setup:
237 
238- [ ] Set `CAMELMIND_URL` to your production site URL.
239- [ ] Set authentication variables if your site requires user login.
240- [ ] Set OIDC variables if you use an OIDC identity provider.
241- [ ] Set `GITHUB_TOKEN` or `GITLAB_TOKEN` if your repository is private or you want authenticated Git API access.
242- [ ] Set `OFFLINE_MODE=true` only if you are generating a static offline build.
243- [ ] Set Resend variables if you want to receive feedback widget submissions.
244- [ ] Store secrets in your hosting platform's environment variable settings rather than in your repository.
245- [ ] Never commit `.env.local` or files containing secrets to Git.

Issues (0)

No AI-friendliness issues found.