Skip to Content
Local developmentEnvironment variables

Developer reference

Environment variables

Separate browser-visible configuration from server credentials and configure canonical origins deliberately.

Public variables are embedded in browser assets. Server secrets belong in an ignored local environment file or the deployment provider’s secret store. Changes to embedded public configuration require a new build.

Application configuration

VariablePurpose
NEXT_PUBLIC_SUPABASE_URLSupabase project URL.
NEXT_PUBLIC_SUPABASE_ANON_KEYPublic project key used with user authentication.
SUPABASE_SERVICE_ROLE_KEYServer-only privileged client credential.
NEXT_PUBLIC_SITE_URLExact canonical application origin used for public links and auth destinations.
NEXT_PUBLIC_HELM_DOCS_URLExact documentation origin for reciprocal public links.
HELM_SIGNUP_MODERegistration mode: open, closed or allowlist. The default is closed.
HELM_SIGNUP_ALLOWLISTComma-separated registration choices when allowlist mode is used.
HELM_AUTH_EXPLICIT_DUPLICATE_TESTINGKeep false outside a controlled test.
HELM_IMPORT_WORKER_SECRETServer-only worker authorization.
HELM_HOUSEKEEPING_SECRETServer-only housekeeping authorization.

Never prefix a service credential with NEXT_PUBLIC_. Public project keys do not replace authentication or ownership enforcement.

Public origins

Production uses https://helm.neuroom.io  for the app and https://helm-docs.neuroom.io  for documentation. Configure an origin without credentials, path, query or fragment. Local development can explicitly use localhost HTTP origins.

The docs package needs only NEXT_PUBLIC_HELM_APP_URL and NEXT_PUBLIC_HELM_DOCS_URL. It does not need Supabase credentials.

Registration and mail

Reviewer-facing registration is open on the public product. Other installations can choose a different mode. Allowlist registration requires confirmed email and provider confirmation settings. Recovery and confirmation messages require configured email transport; an accepted request does not establish delivery.

After changing provider URLs, origins or mail configuration, exercise the affected flow from its public UI. See deployment.