Skip to main content
Never commit .env.local or .dev.vars. Never expose SUPABASE_SERVICE_ROLE_KEY, TENANT_SECRETS_MASTER_KEY, STREAMLY_CRON_SECRET, STREAMLY_INITIAL_ADMIN_EMAIL, or STREAMLY_INITIAL_ADMIN_PASSWORD to the browser.
Copy templates:

Core URLs

Supabase

Server secrets

Operator bootstrap

Email (optional)

Optional product

Cloudflare preview (.dev.vars)

Payments & analytics

Configured through /admin/plugins after install - Stripe / PayPal / bank transfer credentials, analytics measurement IDs, etc. Not core .env.example keys. See Plugins and Payments / Billing.
Cloudflare for SaaS custom-hostname env vars (CLOUDFLARE_ACCOUNT_ID, zone, API token, fallback host) were removed - customer custom domains are not supported.