Skip to content

All settings

Settings can be environment variables or appsettings.json values. A double underscore in a variable name is a section separator: Auth__JwtSecret is "Auth": { "JwtSecret": … }.

Core

  • DATABASE_URLrequiredAPIAdminSeeder

    PostgreSQL connection. Accepts postgresql://user:pass@host:5432/db or an Npgsql keyword string. The URL form keeps only host, port, database, user and password, so use the keyword form (Host=…;Ssl Mode=Require) when you need SSL options.

  • ASPNETCORE_URLSrequiredAPIAdmin

    Listen address. The API image exposes and health-checks port 3000 but does not set this. Always set http://+:3000 for the API.

    Default: Admin image: http://+:3100

  • ASPNETCORE_ENVIRONMENTAPIAdmin

    Development enables dev defaults (mock notifications, 10s polling) and the Admin Playground, which can wipe the database. Never use Development on a real instance.

    Default: Production

  • ASPNETCORE_FORWARDEDHEADERS_ENABLEDAPIAdmin

    Set to true behind a reverse proxy (Caddy, nginx, Traefik) so the app trusts X-Forwarded-Proto/For/Host and builds correct HTTPS URLs and cookies.

    Default: false

  • CORS_ORIGINSAPI

    Comma-separated origins allowed to call the API from a browser. Only needed when the Web app is served from a different origin than the API. * is ignored.

    Default: (none)

  • PLAYDEX_API_URLWeb

    Web container only. The API base URL baked into appsettings.json at container start. Must end in /api/. Leave unset to use the same origin (/api/ routed to the API by your proxy). Changing it requires recreating the container.

    Default: <web origin>/api/

Auth

  • Auth__JwtSecretrequiredAPI

    HMAC-SHA256 key used to sign user access and refresh tokens. Use a long random value (32+ bytes, e.g. openssl rand -hex 32). Changing it signs everyone out.

  • Auth__AccessTokenTtlAPI

    Access token lifetime as <number><s|m|h|d>. Refresh tokens are fixed at 30 days.

    Default: 15m

  • Admin__CookieLifetimeAdmin

    How long an Admin sign-in lasts (no sliding renewal).

    Default: 08:00:00

Polling

  • Polling__IntervalSecondsAPI

    Seconds between provider poll cycles. Lower values detect sessions faster but use more of each provider's rate limit.

    Default: 60

  • Polling__Steam__BaseUrlAPI

    Steam Web API base URL. Point at WireMock for local testing.

    Default: https://api.steampowered.com

  • Polling__Psn__OAuthAuthorizeUrlAPI

    PSN OAuth authorize endpoint (NPSSO → code).

    Default: https://ca.account.sony.com/api/authz/v3/oauth/authorize

  • Polling__Psn__OAuthTokenUrlAPI

    PSN OAuth token endpoint.

    Default: https://ca.account.sony.com/api/authz/v3/oauth/token

  • Polling__Psn__PresenceBaseUrlAPI

    PSN presence API base URL.

    Default: https://m.np.playstation.com

  • Polling__OpenXbl__BaseUrlAPI

    OpenXBL (unofficial Xbox API) base URL.

    Default: https://api.xbl.io

  • Polling__Igdb__ClientIdAPI

    Twitch application client ID for IGDB game search. If this or the secret is missing, search only covers games already in your database.

  • Polling__Igdb__ClientSecretAPI

    Twitch application client secret for IGDB.

Notifications

  • Apprise__BaseUrlAPI

    Apprise API URL, e.g. http://apprise:8000. If unset, notifications are off and users cannot save a Telegram chat ID.

  • Apprise__TelegramBotTokenAPI

    Telegram bot token from BotFather (123456:ABC…). One bot serves every user.

  • Apprise__UseMockAPI

    Log notifications (APPRISE_MOCK notify …) instead of sending them.

    Default: false (Development: true)

AI drafts

  • AiDrafts__EnabledAPI

    Turns on "create sessions from text or a screenshot". Also requires ApiKey and Model.

    Default: false

  • AiDrafts__ProviderAPI

    openai or openrouter.

    Default: openai

  • AiDrafts__BaseUrlAPI

    Provider endpoint. For OpenRouter use https://openrouter.ai/api/v1/chat/completions.

    Default: https://api.openai.com/v1/responses

  • AiDrafts__ApiKeyAPI

    Provider API key (sent as a Bearer token).

  • AiDrafts__ModelAPI

    Model ID. Must support image input and structured output.

  • AiDrafts__RequestsPerHourAPI

    Per-user hourly limit.

    Default: 10

  • AiDrafts__HistoryRetentionDaysAPI

    Days to keep AI generation history visible in Admin. 0 keeps it until deleted manually.

    Default: 30

  • AiDrafts__MaxTextCharactersAPI

    Maximum pasted text length.

    Default: 10000

  • AiDrafts__MaxImageBytesAPI

    Maximum screenshot size in bytes (10 MB).

    Default: 10485760

  • AiDrafts__MaxImagePixelsAPI

    Maximum screenshot pixel count.

    Default: 20000000

  • AiDrafts__MaxRowsAPI

    Maximum sessions extracted per request (1–50).

    Default: 50

  • AiDrafts__TimeoutSecondsAPI

    Provider request timeout.

    Default: 60

Observability

  • SENTRY_DSNAPIAdmin

    Sentry DSN. Enables API error reporting and trace export. Blank disables Sentry without failing startup.

  • SENTRY_WEB_DSNAPI

    Separate DSN handed to the browser app. Recommended so frontend and backend issues stay apart.

    Default: SENTRY_DSN

  • SENTRY_ENVIRONMENTAPI

    Environment tag on Sentry events.

    Default: ASP.NET environment

  • SENTRY_RELEASEAPI

    Release tag on Sentry events.

  • SENTRY_TRACES_SAMPLE_RATEAPIAdmin

    Fraction of requests traced (0–1).

    Default: 0.2

Playground

  • Playground__WiremockBaseUrlAdmin

    Development only. WireMock URL used by the Admin Playground to switch fake provider states, e.g. http://wiremock:8888.

  • Playground__AppriseBaseUrlAdmin

    Development only. Apprise URL used by the Playground "Send test" button.

  • Playground__TelegramBotTokenAdmin

    Development only. Lets the Playground register a chat with Apprise if the API has not already.