Appearance
Historical snapshot archived 2026-09-25. This records an earlier review or plan, not current implementation or live ticket state. For current work, follow root AGENTS.md, the relevant BloxClips skill, and owning repository source/tests. Preserve approved decisions as evidence; verify their present authority before acting.
Environment and Configuration
This inventory combines .env.template with actual process.env references. It omits all secret values. “Conditional” means the variable is required only when that subsystem or live mode is used.
Core, URLs, and security
| Variable | Repository | Purpose | Required? | Sensitive? |
|---|---|---|---|---|
DATABASE_URL | Backend, metric-scraper, backend migrator, frontend E2E runner | PostgreSQL connection for each independently launched process; backend and scraper workers must target the same application database | Yes for database-backed processes | Yes |
NODE_ENV | Both/runtime | Enables production security/cookie/storage behavior | Yes in deployment | No |
API_PORT | Backend | HTTP API port, default 3001 | No | No |
API_URL | Backend | Public backend URL used in generated links/callbacks | Conditional | No |
FRONTEND_URL | Backend | CORS origin and OAuth redirects | Yes for browser use | No |
ALLOWED_PREVIEW_ORIGINS | Backend | Additional comma-separated browser origins | No | No |
NEXT_PUBLIC_API_URL | Frontend | Browser/backend origin and referral rewrite destination | Yes outside localhost | No |
JWT_SECRET | Backend | Signs session JWT; import-time validation requires a strong non-placeholder value | Yes | Yes |
ENCRYPTION_KEY | Backend | Encrypts OAuth/TIN data and supports HMAC/signing utilities | Yes | Yes |
TOTP_SECRET, TOTP_SETUP_COMPLETE | Backend | Admin second factor for payout/tax-sensitive actions | Production conditional | Yes / No |
SIGN_INS_DISABLED | Backend | Disables sign-in paths when set | No | No |
DATABASE_URL is supplied separately to each launched process; reusing the variable name does not make its target disposable. The migrator uses an owner/direct connection to the intended database, while the API and scraper use their own application/worker connections. prisma migrate deploy does not reset automatically, but committed migration SQL may still change or delete data. The backend database operations guide explains migration, reset, seeding, and disposable test targets in detail.
Identity and administration
| Variable | Repository | Purpose | Required? | Sensitive? |
|---|---|---|---|---|
DISCORD_TOKEN | Backend | Bot login and API-side Discord client | Conditional | Yes |
CLIENT_ID / DISCORD_CLIENT_ID | Backend | Discord application ID; auth accepts either, deploy script uses CLIENT_ID | Discord conditional | No |
CLIENT_SECRET / DISCORD_CLIENT_SECRET | Backend | Discord OAuth secret; auth accepts aliases | Discord login | Yes |
DISCORD_REDIRECT_URI | Backend | Discord OAuth callback | Discord login | No |
GUILD_ID | Backend | Command deployment/default guild | Bot conditional | No |
ADMIN_DISCORD_IDS | Backend | Backend-enforced Discord admin allowlist | Admin use | Sensitive-ish |
ADMIN_EMAILS | Backend | Verified-email admin allowlist | Admin use | Sensitive-ish |
GOOGLE_CLIENT_ID, GOOGLE_CLIENT_SECRET, GOOGLE_REDIRECT_URI | Backend | Google OAuth | Google login | Secret for client secret |
Social scraping, Whop, and Roblox-facing configuration
| Variable | Repository | Purpose | Required? | Sensitive? |
|---|---|---|---|---|
YOUTUBE_API_KEY | Backend | YouTube video/channel metrics and PV sync | YouTube flows | Yes |
APIFY_TOKEN / APIFY_API_KEY | Backend | TikTok/Instagram scraping; most code prefers APIFY_TOKEN | TikTok/Instagram flows | Yes |
APIFY_TIKTOK_ACTOR_ID, APIFY_INSTAGRAM_ACTOR_ID | Backend | Override actor identifiers | No | No |
COST_PER_1K_TIKTOK, COST_PER_1K_INSTAGRAM | Backend | Scrape-cost accounting estimates | No | No |
WHOP_API_BASE_URL | Both | Override Whop API origin | No | No |
WHOP_API_KEY | Backend | Whop API key for company count and Support Chat identity/channel/token APIs | Yes for Support Chat | Yes |
WHOP_COMPANY_API_KEY | Both | Optional alias used by the public company-count lookup | No | Yes |
WHOP_COMPANY_ID | Backend | BloxClips Whop account ID (biz_...) for connected accounts, Support Channels, and account-scoped tokens; not the public route slug | Yes for Support Chat | Yes |
WHOP_COMPANY_ROUTE | Both | Company route/ID used for count | Live Whop count | No |
PUBLIC_CLIPPER_COUNT_FALLBACK | Both | Member-count fallback, default 25,000 | No | No |
CLIPPER_COUNT_CACHE_MS | Both | In-process Whop count cache, default 10 seconds | No | No |
Payments, tax, and storage
| Variable | Repository | Purpose | Required? | Sensitive? |
|---|---|---|---|---|
MINIMUM_PAYOUT_AMOUNT | Backend | Payout threshold (source defaults vary historically; configure explicitly) | Recommended | No |
STRIPE_SECRET_KEY, STRIPE_WEBHOOK_SECRET | Backend | Stripe Connect dispatch and webhook verification | Stripe use | Yes |
STRIPE_PAYOUT_SURCHARGE_BPS | Backend | Additional Stripe rail surcharge, default 250 bps | No | No |
PAYPAL_MODE | Backend | mock, sandbox, or live | No; defaults mock | No |
PAYPAL_CLIENT_ID, PAYPAL_CLIENT_SECRET, PAYPAL_WEBHOOK_ID | Backend | PayPal verification/payout/webhook | Non-mock PayPal | Yes |
PAYPAL_PAYOUT_VOLUME_CAP_USD, PAYPAL_CIRCUIT_TRIP_THRESHOLD | Backend | Operational payout guards | No | No |
NOWPAYMENTS_MODE | Backend | mock, sandbox, or live | No; defaults mock | No |
NOWPAYMENTS_API_KEY, NOWPAYMENTS_IPN_SECRET | Backend | USDT payout and webhook signature | Non-mock USDT | Yes |
TAX1099_MODE | Backend | TIN matching mode | No; defaults mock | No |
TAX1099_API_KEY, TAX1099_USER_TOKEN | Backend | TIN matching credentials | Non-mock matching | Yes |
IRS_1099_NEC_THRESHOLD, TAX_FORM_COLLECTION_THRESHOLD | Backend | Reporting/form gates | No | No |
TAX_FORM_W8BEN_VALIDITY_YEARS, TAX_FORM_RETENTION_YEARS | Backend | expiry/retention calculations | No | No |
TAX_FORM_SIGNED_URL_TTL_SECONDS | Backend | PDF download URL validity | No | No |
R2_ACCOUNT_ID, R2_ACCESS_KEY_ID, R2_SECRET_ACCESS_KEY, R2_BUCKET_TAX_FORMS | Backend | Private tax-PDF storage | Required in production | Yes except bucket name |
R2_PUBLIC_URL_BASE and STRIPE_PUBLISHABLE_KEY appear in the template/local environment but are not material runtime inputs in the traced server source.
Contact, email, booking, and SMS
| Variable | Repository | Purpose | Required? | Sensitive? |
|---|---|---|---|---|
NEXT_PUBLIC_TURNSTILE_SITE_KEY | Frontend | Contact widget site key | Contact form | No |
TURNSTILE_SECRET_KEY | Both server runtimes | Verify contact form challenge | Contact form | Yes |
RESEND_API_KEY, RESEND_FROM_EMAIL, CONTACT_FORM_TO_EMAIL | Both server runtimes | Transactional/contact email | Email flows | API key yes |
CONTACT_ATTEMPT_WINDOW_MS | Backend | Window for persisted contact-attempt checks | No | No |
CONTACT_DUPLICATE_TTL_MS | Backend | Duplicate-content retention window | No | No |
CONTACT_RATE_LIMIT_WINDOW_MS | Backend | Express contact limiter window | No | No |
CONTACT_RATE_LIMIT_MAX | Backend | Express contact limiter maximum | No | No |
CONTACT_EMAIL_WINDOW_MAX | Backend | Per-email attempts allowed in the persisted window, default 3 | No | No |
CONTACT_IP_WINDOW_MAX | Backend | Per-IP attempts allowed in the persisted window, default 5 | No | No |
CONTACT_MAX_URLS | Backend | Maximum URLs accepted in a contact message, default 1 | No | No |
GOOGLE_REFRESH_TOKEN / GOOGLE_BOOKING_REFRESH_TOKEN | Backend | Calendar OAuth refresh token (aliases) | Backend booking | Yes |
GOOGLE_BOOKING_CALENDAR_ID / GOOGLE_CALENDAR_ID | Backend | Booking calendar (aliases) | Backend booking | Sensitive-ish |
BOOKING_TIMEZONE | Backend | Default booking timezone | No | No |
BOOKING_DAYS_AHEAD | Backend | Availability horizon | No | No |
BOOKING_CALL_MINUTES | Backend | Calendar event duration | No | No |
BOOKING_SLOT_MINUTES | Backend | Slot spacing | No | No |
BOOKING_START_HOUR, BOOKING_END_HOUR | Backend | Default daily business-hour bounds | No | No |
BOOKING_WEEKDAYS | Backend | Default enabled weekdays | No | No |
BOOKING_MIN_LEAD_HOURS | Backend | Required lead time | No | No |
BOOKING_RATE_LIMIT_WINDOW_MS | Backend | Booking limiter window | No | No |
BOOKING_RATE_LIMIT_MAX | Backend | Booking limiter maximum | No | No |
BOOKING_ALERT_EMAILS, BOOKING_ALERT_PHONE_NUMBERS | Backend | Admin booking recipients | No | Yes |
TWILIO_ACCOUNT_SID, TWILIO_AUTH_TOKEN, TWILIO_FROM_NUMBER | Backend | Optional booking SMS alerts | SMS only | Yes |
The public /book-call page currently embeds Calendly and does not use these backend booking variables. They remain relevant to backend booking routes and the admin bookings UI.
Timers, limits, and PV tracker
| Variable | Repository | Purpose | Required? | Sensitive? |
|---|---|---|---|---|
GLOBAL_RATE_LIMIT_PER_MINUTE | Backend | Global API request maximum per minute, default 300 | No | No |
ACTIVE_BAN_CACHE_TTL_MS | Backend | In-process active-ban cache lifetime, default 30 seconds | No | No |
LIVE_EVENT_POLL_MS | Backend | Creator live-event database poll interval, default 15 seconds | No | No |
LIVE_EVENT_HEARTBEAT_MS | Backend | Creator live-event SSE heartbeat, default 30 seconds | No | No |
LIVE_RESTRICTION_CHECK_MS | Backend | Live-session restriction refresh, default 60 seconds | No | No |
PV_TRACKER_AUTO_SYNC_ENABLED | Backend | Enables PV autosync; defaults true | No | No |
PV_TRACKER_AUTO_SYNC_INITIAL_DELAY_MS | Backend | Initial autosync delay; minimum 10 seconds, default 5 minutes | No | No |
PV_TRACKER_AUTO_SYNC_INTERVAL_HOURS | Backend | Autosync period; minimum 1 hour, default 24 | No | No |
PV_TRACKER_DATA_PATH | Backend | Override JSON state-file location | No | Sensitive-ish |
PV_TRACKER_INACTIVE_AFTER_DAYS | Backend | Inactivity classification, default 7 days | No | No |
PV_TRACKER_STALE_AFTER_HOURS | Backend | Staleness threshold, default 12 hours | No | No |
VIDEOS_PER_ACCOUNT | Backend | General per-account PV discovery limit, default 15 | No | No |
YOUTUBE_VIDEOS_PER_ACCOUNT | Backend | YouTube-specific limit; defaults to general limit | No | No |
TRACK_MAX_AGE_DAYS | Backend | Maximum age considered by PV tracking, default 30 days | No | No |
Present in environment material but not active source inputs
The checked-in ignored .env was inspected by key name only. AFFILIATE_PROGRAM_MODE, REVENUE_SHARE_PAUSED, REQUIRED_GUILD_ID, TIKTOK_FETCH_DELAY_MS, and TIKTOK_REQUEST_TIMEOUT_MS appear there but are not referenced through process.env in current TypeScript source. STRIPE_PUBLISHABLE_KEY and R2_PUBLIC_URL_BASE appear in .env.template but likewise have no material traced runtime consumer. Treat these as legacy/anticipated until the prior team confirms an external consumer.
Environment-specific behavior
- Production enables secure cookies and strict no-Origin rejection for state-changing API requests, except verified payment webhooks.
- Production requires R2 tax-form storage; development can use local disk.
- API startup uses HTTPS/443 when origin certificate files are present, independent of
NODE_ENV; otherwise it uses HTTP andAPI_PORT. - PayPal, NowPayments, and Tax1099 default to mock modes unless explicitly configured. This protects local startup but makes an unset production mode dangerous operationally.
- Frontend public variables are bundled into client code; never put secrets in
NEXT_PUBLIC_*variables.