Environment variables
Set these in your host’s environment settings (on Vercel: Project Settings →
Environment Variables). For local development, put them in
apps/app/.env.local; apps/app/.env.local.example is a commented starting
point. For which Vercel scope each variable goes in, see
Deploying to Vercel.
Generate secrets with openssl rand -hex 32. Every variable has its own link:
hover its row and copy the #.
Required is Yes when every deployment needs it, Optional when it has a working default, and If … when only that setup needs it.
Quick start
The minimum for a working deployment with the default backends:
# Auth
BETTER_AUTH_URL=https://screenplay.example.com # production only
BETTER_AUTH_PRODUCTION_URL=https://screenplay.example.com
BETTER_AUTH_SECRET=<openssl rand -hex 32>
GITHUB_CLIENT_ID=...
GITHUB_CLIENT_SECRET=...
# Data
DATABASE_URL=postgres://...
LIVEBLOCKS_SECRET_KEY=sk_...
PUBLIC_BLOB_READ_WRITE_TOKEN=... # a public Blob store for thumbnails
PRIVATE_BLOB_READ_WRITE_TOKEN=... # a second, private Blob store for canvas files
# Agent
ANTHROPIC_API_KEY=sk-ant-...
AGENT_DEFAULT_MODEL=anthropic:claude-sonnet-5-5
# Secrets
ENCRYPTION_KEY=<openssl rand -hex 32>
TERMINAL_AUTH_SECRET=<openssl rand -hex 32>Auth
Data
Agent
At least one model provider must be configured. Each provider enables itself when its variables are set. See Model providers.
Terminal access
Choose TERMINAL_AUTH based on who uses the deployment:
bearer(default, no extra setup). The terminal is reached through a random, unguessable sandbox URL, and that URL is the whole credential. URLs can leak through browser history,Refererheaders, proxy logs, and screen shares, and anyone holding one gets a writable shell until the sandbox is gone. Use it only when every user is trusted.ttyd-credential(no extra infrastructure). The terminal daemon requires a per-sandbox secret derived fromTERMINAL_AUTH_SECRET, which is sent over the WebSocket handshake instead of in the URL, so a leaked URL alone isn’t enough. The secret is shared by the sandbox’s members and lasts as long as the sandbox, so it can’t be revoked per user mid-session. Deleting the chat invalidates it.
Neither mode offers per-user revocation. For a deployment shared with
people you don’t fully trust, use ttyd-credential and keep canvas
membership tight. Design notes are in
apps/app/docs/adr/0002-byo-harness-terminal.md.
Sandbox
Scheduled jobs
Serving
Build switches
These select alternative backends. The desktop app sets them together; see Local build and Desktop app. A hosted deployment leaves them all unset.
Desktop build
The desktop shell sets these for the app it launches (see Desktop app). You only set them yourself when running the local build by hand.