# API Server configuration # Copy to .env and adjust. The server also reads plain environment variables. # Never commit the real .env file. # Address the API Server listens on. A bare port (8080) is accepted too. API_ADDR=:8080 # PocketBase base URL (no trailing slash). The API Server is the only thing that # talks to PocketBase; it proxies /api/auth/* to this address, which is never # exposed to clients. Editable at runtime from the panel (PocketBase section), # which writes the change back into this file. POCKETBASE_URL=http://10.2.1.10:8027 # PocketBase superuser service account. Every privileged flow runs through it: # user/organization management and all car-domain database access. Leave unset # and the server still starts — a superadmin can log in to the panel and # configure it there; management endpoints return 503 until then. POCKETBASE_ADMIN_EMAIL= POCKETBASE_ADMIN_PASSWORD= # CORS allowed origins for browser clients (comma separated, or * for any). # Native mobile apps are not subject to CORS. Editable at runtime from the panel # (Web App section), which writes the change back into this file. CORS_ALLOW_ORIGINS=http://localhost:5173 # Web App address, probed by GET /api/status and shown on the panel. Editable at # runtime from the panel (Web App section). WEBAPP_URL=http://localhost:5173 # PocketBase auth collection holding app users (default: users). AUTH_USERS_COLLECTION=users # Local JSON store for plugin enable-state + config (default: plugins.json). PLUGINS_FILE=plugins.json # --- Legacy names ----------------------------------------------------------- # PB_URL, PB_ADMIN_EMAIL, PB_ADMIN_PASSWORD, PORT and CORS_ORIGINS are still # honoured for older deployments; the POCKETBASE_*/API_ADDR names above win when # both are set. AUTH_SECRET is gone — the server no longer mints its own JWTs.