Developer reference
Environment variables
Separate browser-visible configuration from server credentials and configure canonical origins deliberately.
Public variables are embedded in browser assets. Server secrets belong in an ignored local environment file or the deployment provider’s secret store. Changes to embedded public configuration require a new build.
Application configuration
| Variable | Purpose |
|---|---|
NEXT_PUBLIC_SUPABASE_URL | Supabase project URL. |
NEXT_PUBLIC_SUPABASE_ANON_KEY | Public project key used with user authentication. |
SUPABASE_SERVICE_ROLE_KEY | Server-only privileged client credential. |
NEXT_PUBLIC_SITE_URL | Exact canonical application origin used for public links and auth destinations. |
NEXT_PUBLIC_HELM_DOCS_URL | Exact documentation origin for reciprocal public links. |
HELM_SIGNUP_MODE | Registration mode: open, closed or allowlist. The default is closed. |
HELM_SIGNUP_ALLOWLIST | Comma-separated registration choices when allowlist mode is used. |
HELM_AUTH_EXPLICIT_DUPLICATE_TESTING | Keep false outside a controlled test. |
HELM_IMPORT_WORKER_SECRET | Server-only worker authorization. |
HELM_HOUSEKEEPING_SECRET | Server-only housekeeping authorization. |
Never prefix a service credential with NEXT_PUBLIC_. Public project keys do not replace authentication or ownership enforcement.
Public origins
Production uses https://helm.neuroom.io for the app and https://helm-docs.neuroom.io for documentation. Configure an origin without credentials, path, query or fragment. Local development can explicitly use localhost HTTP origins.
The docs package needs only NEXT_PUBLIC_HELM_APP_URL and NEXT_PUBLIC_HELM_DOCS_URL. It does not need Supabase credentials.
Registration and mail
Reviewer-facing registration is open on the public product. Other installations can choose a different mode. Allowlist registration requires confirmed email and provider confirmation settings. Recovery and confirmation messages require configured email transport; an accepted request does not establish delivery.
After changing provider URLs, origins or mail configuration, exercise the affected flow from its public UI. See deployment.