API (api-v2)

Integrations & environment

Every third-party service is optional in development and degrades predictably. Mailgun is the exception: production refuses to boot without it. All configuration goes through src/config/env.ts.


Third-party services

ServicePurposeEnv varsIf missing
PostgreSQL (Stackhero in prod)Primary databaseDATABASE_URL, TEST_DATABASE_URL, DBMATE_*Required
Mailgun (EU region)OTP emailsMAILGUN_API_KEY, MAILGUN_DOMAIN, MAILGUN_BASE_URL, MAIL_FROMProduction exits. Dev logs the codes.
Redis (Redis Cloud in prod)Read-through cacheREDIS_URL (REDISCLOUD_URL also on prod), CACHE_PREFIXNo cache; every read goes to Postgres
RabbitMQ / CloudAMQPLedger postings, search reindexRABBITMQ_URL, CLOUDAMQP_URL, RABBITMQ_EXCHANGE, WEB_CONSUMES_QUEUEEvents dispatched in-process
AlgoliaSearch rollback backendALGOLIA_APP_ID, ALGOLIA_API_KEY, ALGOLIA_INDEX_PREFIX, SEARCH_BACKENDNo-op
CloudinaryProduct and section media; catalogue XLSX as raw uploadsCLOUDINARY_CLOUD_NAME, CLOUDINARY_API_KEY, CLOUDINARY_API_SECRET, MEDIA_MAX_IMAGE_BYTES, MEDIA_MAX_VIDEO_BYTESUploads return 503
Google Maps (Places, Geocoding, Time Zone)Address lookupGOOGLE_MAPS_API_KEY, PLACES_BIAS_CENTER, PLACES_BIAS_RADIUS_MEmpty results
Apple App StoreIn-app purchase verificationAPPLE_BUNDLE_ID, APPLE_ROOT_CA_PEM, APPLE_ENVIRONMENT503
Google PlayIn-app purchase verificationGOOGLE_PLAY_PACKAGE_NAME, GOOGLE_PLAY_SERVICE_ACCOUNT_JSON, GOOGLE_PLAY_ENVIRONMENT503
BetterStack (Logtail)Request logs: never bodies, auth headers or cookiesBETTERSTACK_SOURCE_TOKEN, BETTERSTACK_INGEST_URLstdout
open.er-api.com (in progress)Daily FX ratesFX_SYNC_URL, FX_SYNC_TIMEOUT_MSDefault feed
GitHub PackagesContract packagesNPM_TOKENnpm install fails

Core settings

VariableNotes
JWT_SECRET≥ 32 characters. Also the key discount PIN HMACs are derived from, so rotating it invalidates every PIN.
ACCESS_TOKEN_TTL, REFRESH_TOKEN_TTL_DAYSDefaults: 15 minutes and 30 days
COOKIE_SECURECookie flag
CORS_ORIGINSAllowed origins. Locally, the apps run on 5173 / 5273.
OPS_TOKENMounts /internal/ops/*
INTERNAL_SECRET_KEYMounts /internal/*
PORT, NODE_ENVNODE_ENV ∈ development, test, production

Front-end variables

AppVariableNotes
DashboardVITE_API_BASE_URLEmpty means same-origin (expected in production)
DashboardVITE_API_PROXY_TARGETDev proxy target, default http://localhost:3000
DashboardVITE_POS_URL, VITE_ACCOUNTING_URLLaunch targets; defaults https://pos.totlob.com, https://accounting.totlob.com
DashboardVITE_MAP_STYLE_URLDefaults to OpenFreeMap (keyless)
DashboardVITE_ASSISTANT_ENABLEDExactly true enables the assistant panel
POSVITE_API_BASE_URLBaked into the bundle
POSVITE_API_PROXY_TARGETDev proxy, default http://localhost:3000
BothNPM_TOKENInstall-time only

Not integrated

  • Live courier labels and rates (Wakilni). Deferred.
  • Stripe
  • Push, websocket or email notifications
  • An online card gateway, for both the storefront and the POS card terminal
Previous
Storefront, internal & ops