Skip to content

Historical snapshot archived 2026-09-25. This records an earlier review or plan, not current implementation or live ticket state. For current work, follow root AGENTS.md, the relevant BloxClips skill, and owning repository source/tests. Preserve approved decisions as evidence; verify their present authority before acting.

Environment and Configuration ​

This inventory combines .env.template with actual process.env references. It omits all secret values. “Conditional” means the variable is required only when that subsystem or live mode is used.

Core, URLs, and security ​

VariableRepositoryPurposeRequired?Sensitive?
DATABASE_URLBackend, metric-scraper, backend migrator, frontend E2E runnerPostgreSQL connection for each independently launched process; backend and scraper workers must target the same application databaseYes for database-backed processesYes
NODE_ENVBoth/runtimeEnables production security/cookie/storage behaviorYes in deploymentNo
API_PORTBackendHTTP API port, default 3001NoNo
API_URLBackendPublic backend URL used in generated links/callbacksConditionalNo
FRONTEND_URLBackendCORS origin and OAuth redirectsYes for browser useNo
ALLOWED_PREVIEW_ORIGINSBackendAdditional comma-separated browser originsNoNo
NEXT_PUBLIC_API_URLFrontendBrowser/backend origin and referral rewrite destinationYes outside localhostNo
JWT_SECRETBackendSigns session JWT; import-time validation requires a strong non-placeholder valueYesYes
ENCRYPTION_KEYBackendEncrypts OAuth/TIN data and supports HMAC/signing utilitiesYesYes
TOTP_SECRET, TOTP_SETUP_COMPLETEBackendAdmin second factor for payout/tax-sensitive actionsProduction conditionalYes / No
SIGN_INS_DISABLEDBackendDisables sign-in paths when setNoNo

DATABASE_URL is supplied separately to each launched process; reusing the variable name does not make its target disposable. The migrator uses an owner/direct connection to the intended database, while the API and scraper use their own application/worker connections. prisma migrate deploy does not reset automatically, but committed migration SQL may still change or delete data. The backend database operations guide explains migration, reset, seeding, and disposable test targets in detail.

Identity and administration ​

VariableRepositoryPurposeRequired?Sensitive?
DISCORD_TOKENBackendBot login and API-side Discord clientConditionalYes
CLIENT_ID / DISCORD_CLIENT_IDBackendDiscord application ID; auth accepts either, deploy script uses CLIENT_IDDiscord conditionalNo
CLIENT_SECRET / DISCORD_CLIENT_SECRETBackendDiscord OAuth secret; auth accepts aliasesDiscord loginYes
DISCORD_REDIRECT_URIBackendDiscord OAuth callbackDiscord loginNo
GUILD_IDBackendCommand deployment/default guildBot conditionalNo
ADMIN_DISCORD_IDSBackendBackend-enforced Discord admin allowlistAdmin useSensitive-ish
ADMIN_EMAILSBackendVerified-email admin allowlistAdmin useSensitive-ish
GOOGLE_CLIENT_ID, GOOGLE_CLIENT_SECRET, GOOGLE_REDIRECT_URIBackendGoogle OAuthGoogle loginSecret for client secret

Social scraping, Whop, and Roblox-facing configuration ​

VariableRepositoryPurposeRequired?Sensitive?
YOUTUBE_API_KEYBackendYouTube video/channel metrics and PV syncYouTube flowsYes
APIFY_TOKEN / APIFY_API_KEYBackendTikTok/Instagram scraping; most code prefers APIFY_TOKENTikTok/Instagram flowsYes
APIFY_TIKTOK_ACTOR_ID, APIFY_INSTAGRAM_ACTOR_IDBackendOverride actor identifiersNoNo
COST_PER_1K_TIKTOK, COST_PER_1K_INSTAGRAMBackendScrape-cost accounting estimatesNoNo
WHOP_API_BASE_URLBothOverride Whop API originNoNo
WHOP_API_KEYBackendWhop API key for company count and Support Chat identity/channel/token APIsYes for Support ChatYes
WHOP_COMPANY_API_KEYBothOptional alias used by the public company-count lookupNoYes
WHOP_COMPANY_IDBackendBloxClips Whop account ID (biz_...) for connected accounts, Support Channels, and account-scoped tokens; not the public route slugYes for Support ChatYes
WHOP_COMPANY_ROUTEBothCompany route/ID used for countLive Whop countNo
PUBLIC_CLIPPER_COUNT_FALLBACKBothMember-count fallback, default 25,000NoNo
CLIPPER_COUNT_CACHE_MSBothIn-process Whop count cache, default 10 secondsNoNo

Payments, tax, and storage ​

VariableRepositoryPurposeRequired?Sensitive?
MINIMUM_PAYOUT_AMOUNTBackendPayout threshold (source defaults vary historically; configure explicitly)RecommendedNo
STRIPE_SECRET_KEY, STRIPE_WEBHOOK_SECRETBackendStripe Connect dispatch and webhook verificationStripe useYes
STRIPE_PAYOUT_SURCHARGE_BPSBackendAdditional Stripe rail surcharge, default 250 bpsNoNo
PAYPAL_MODEBackendmock, sandbox, or liveNo; defaults mockNo
PAYPAL_CLIENT_ID, PAYPAL_CLIENT_SECRET, PAYPAL_WEBHOOK_IDBackendPayPal verification/payout/webhookNon-mock PayPalYes
PAYPAL_PAYOUT_VOLUME_CAP_USD, PAYPAL_CIRCUIT_TRIP_THRESHOLDBackendOperational payout guardsNoNo
NOWPAYMENTS_MODEBackendmock, sandbox, or liveNo; defaults mockNo
NOWPAYMENTS_API_KEY, NOWPAYMENTS_IPN_SECRETBackendUSDT payout and webhook signatureNon-mock USDTYes
TAX1099_MODEBackendTIN matching modeNo; defaults mockNo
TAX1099_API_KEY, TAX1099_USER_TOKENBackendTIN matching credentialsNon-mock matchingYes
IRS_1099_NEC_THRESHOLD, TAX_FORM_COLLECTION_THRESHOLDBackendReporting/form gatesNoNo
TAX_FORM_W8BEN_VALIDITY_YEARS, TAX_FORM_RETENTION_YEARSBackendexpiry/retention calculationsNoNo
TAX_FORM_SIGNED_URL_TTL_SECONDSBackendPDF download URL validityNoNo
R2_ACCOUNT_ID, R2_ACCESS_KEY_ID, R2_SECRET_ACCESS_KEY, R2_BUCKET_TAX_FORMSBackendPrivate tax-PDF storageRequired in productionYes except bucket name

R2_PUBLIC_URL_BASE and STRIPE_PUBLISHABLE_KEY appear in the template/local environment but are not material runtime inputs in the traced server source.

Contact, email, booking, and SMS ​

VariableRepositoryPurposeRequired?Sensitive?
NEXT_PUBLIC_TURNSTILE_SITE_KEYFrontendContact widget site keyContact formNo
TURNSTILE_SECRET_KEYBoth server runtimesVerify contact form challengeContact formYes
RESEND_API_KEY, RESEND_FROM_EMAIL, CONTACT_FORM_TO_EMAILBoth server runtimesTransactional/contact emailEmail flowsAPI key yes
CONTACT_ATTEMPT_WINDOW_MSBackendWindow for persisted contact-attempt checksNoNo
CONTACT_DUPLICATE_TTL_MSBackendDuplicate-content retention windowNoNo
CONTACT_RATE_LIMIT_WINDOW_MSBackendExpress contact limiter windowNoNo
CONTACT_RATE_LIMIT_MAXBackendExpress contact limiter maximumNoNo
CONTACT_EMAIL_WINDOW_MAXBackendPer-email attempts allowed in the persisted window, default 3NoNo
CONTACT_IP_WINDOW_MAXBackendPer-IP attempts allowed in the persisted window, default 5NoNo
CONTACT_MAX_URLSBackendMaximum URLs accepted in a contact message, default 1NoNo
GOOGLE_REFRESH_TOKEN / GOOGLE_BOOKING_REFRESH_TOKENBackendCalendar OAuth refresh token (aliases)Backend bookingYes
GOOGLE_BOOKING_CALENDAR_ID / GOOGLE_CALENDAR_IDBackendBooking calendar (aliases)Backend bookingSensitive-ish
BOOKING_TIMEZONEBackendDefault booking timezoneNoNo
BOOKING_DAYS_AHEADBackendAvailability horizonNoNo
BOOKING_CALL_MINUTESBackendCalendar event durationNoNo
BOOKING_SLOT_MINUTESBackendSlot spacingNoNo
BOOKING_START_HOUR, BOOKING_END_HOURBackendDefault daily business-hour boundsNoNo
BOOKING_WEEKDAYSBackendDefault enabled weekdaysNoNo
BOOKING_MIN_LEAD_HOURSBackendRequired lead timeNoNo
BOOKING_RATE_LIMIT_WINDOW_MSBackendBooking limiter windowNoNo
BOOKING_RATE_LIMIT_MAXBackendBooking limiter maximumNoNo
BOOKING_ALERT_EMAILS, BOOKING_ALERT_PHONE_NUMBERSBackendAdmin booking recipientsNoYes
TWILIO_ACCOUNT_SID, TWILIO_AUTH_TOKEN, TWILIO_FROM_NUMBERBackendOptional booking SMS alertsSMS onlyYes

The public /book-call page currently embeds Calendly and does not use these backend booking variables. They remain relevant to backend booking routes and the admin bookings UI.

Timers, limits, and PV tracker ​

VariableRepositoryPurposeRequired?Sensitive?
GLOBAL_RATE_LIMIT_PER_MINUTEBackendGlobal API request maximum per minute, default 300NoNo
ACTIVE_BAN_CACHE_TTL_MSBackendIn-process active-ban cache lifetime, default 30 secondsNoNo
LIVE_EVENT_POLL_MSBackendCreator live-event database poll interval, default 15 secondsNoNo
LIVE_EVENT_HEARTBEAT_MSBackendCreator live-event SSE heartbeat, default 30 secondsNoNo
LIVE_RESTRICTION_CHECK_MSBackendLive-session restriction refresh, default 60 secondsNoNo
PV_TRACKER_AUTO_SYNC_ENABLEDBackendEnables PV autosync; defaults trueNoNo
PV_TRACKER_AUTO_SYNC_INITIAL_DELAY_MSBackendInitial autosync delay; minimum 10 seconds, default 5 minutesNoNo
PV_TRACKER_AUTO_SYNC_INTERVAL_HOURSBackendAutosync period; minimum 1 hour, default 24NoNo
PV_TRACKER_DATA_PATHBackendOverride JSON state-file locationNoSensitive-ish
PV_TRACKER_INACTIVE_AFTER_DAYSBackendInactivity classification, default 7 daysNoNo
PV_TRACKER_STALE_AFTER_HOURSBackendStaleness threshold, default 12 hoursNoNo
VIDEOS_PER_ACCOUNTBackendGeneral per-account PV discovery limit, default 15NoNo
YOUTUBE_VIDEOS_PER_ACCOUNTBackendYouTube-specific limit; defaults to general limitNoNo
TRACK_MAX_AGE_DAYSBackendMaximum age considered by PV tracking, default 30 daysNoNo

Present in environment material but not active source inputs ​

The checked-in ignored .env was inspected by key name only. AFFILIATE_PROGRAM_MODE, REVENUE_SHARE_PAUSED, REQUIRED_GUILD_ID, TIKTOK_FETCH_DELAY_MS, and TIKTOK_REQUEST_TIMEOUT_MS appear there but are not referenced through process.env in current TypeScript source. STRIPE_PUBLISHABLE_KEY and R2_PUBLIC_URL_BASE appear in .env.template but likewise have no material traced runtime consumer. Treat these as legacy/anticipated until the prior team confirms an external consumer.

Environment-specific behavior ​

  • Production enables secure cookies and strict no-Origin rejection for state-changing API requests, except verified payment webhooks.
  • Production requires R2 tax-form storage; development can use local disk.
  • API startup uses HTTPS/443 when origin certificate files are present, independent of NODE_ENV; otherwise it uses HTTP and API_PORT.
  • PayPal, NowPayments, and Tax1099 default to mock modes unless explicitly configured. This protects local startup but makes an unset production mode dangerous operationally.
  • Frontend public variables are bundled into client code; never put secrets in NEXT_PUBLIC_* variables.