Environment variables
Local boots with no env. Production uses --main / NETWORK=main.
cargo run and bun run dev are local/dev. The API is production with --main. Next is production when NODE_ENV=production (Vercel). Stacks is testnet in dev and mainnet on main — there is no separate STACKS_NETWORK.
Local hardcodes Compose URLs, Clarinet + Solana fixtures, and INTERNAL_API_SECRET=sw-dev-internal. Wars keys never go on laptops.
Production
API (--main): DATABASE_URL, REDIS_URL, APP_URL, INTERNAL_API_SECRET, STACKS_VAULT, HIRO_API_KEY, HELIUS_API_KEY.
Next (Vercel secrets only): DATABASE_URL, BETTER_AUTH_SECRET, INTERNAL_API_SECRET, STACKS_KEY (was STACKS_WARS_KEY), SOLANA_KEY (was SOLANA_WARS_KEY), HIRO_API_KEY, HELIUS_API_KEY, GOOGLE_SERVICE_ACCOUNT_KEY.
Site origin, API/WS URLs, and vault/token ids are hardcoded.
Railway image CMD is ["/app/sw-server", "--main"].
Optional locally
| Variable | Purpose |
|---|---|
HIRO_API_KEY | Higher Hiro rate limits |
HELIUS_API_KEY | Helius RPC instead of public devnet |
GOOGLE_CLIENT_ID / GOOGLE_CLIENT_SECRET | Google sign-in |
RESEND_API_KEY | Auth email |
DISABLE_VERIFICATION=false | Turn email OTP back on |
VAPID_* | Web push |
Telegram enables only when both TELEGRAM_BOT_TOKEN and TELEGRAM_CHAT_ID are set.
Production encrypts custodial mnemonics with Google Cloud KMS, not CUSTODIAL_DEV_SECRET.