Skip to main content
Set secrets once, then restart the stack. Never commit .env.
Treat .env as production secrets. Rotate JWT_SECRET_KEY after any shared or compromised install. Smoke SMTP created by init may let the API start but does not deliver real invite, password-reset, or 2FA email until you configure real SMTP.

Where the file lives

ragsuite init creates and manages env for CLI installs. It regenerates JWT_SECRET_KEY.

Required secrets

Email (SMTP)

Needed for invites, forgot-password, and 2FA email. Smoke SMTP from init may let the API start but does not deliver real mail.
Then:

Frontend / API URLs

Other common flags

Backend settings (database URL, Redis, Chroma, OLLAMA_BASE_URL) live in the backend env template in the Community repository.

After changes

Restart so the API reloads configuration. Rotate secrets after any shared or compromised install — see Security policy.