Accounts & access
Configure the built-in Better Auth accounts, public origins, and optional social sign-in.
Required account configuration
The app uses Better Auth with its PostgreSQL database. Generate a stable BETTER_AUTH_SECRET and set BETTER_AUTH_URL to the actual public product origin, particularly behind a reverse proxy.
BETTER_AUTH_SECRET=replace-with-a-random-secret
BETTER_AUTH_URL=https://workspace.example.com
APP_PUBLIC_URL=https://workspace.example.com
DEPLOYMENT_MODE=self-hostedKeep the landing origin separate from the authenticated app origin. The public site's NEXT_PUBLIC_APP_URL must be set during its build.
Optional social sign-in
AUTH_GOOGLE_CLIENT_ID / AUTH_GOOGLE_CLIENT_SECRET enable Google sign-in. AUTH_GITHUB_CLIENT_ID / AUTH_GITHUB_CLIENT_SECRET enable GitHub sign-in. Register the callback URLs required by the configured Better Auth provider on your public origin.
Sign-in OAuth and workspace connections use different configuration names. A working Google login does not configure a Google Drive connection.
Deployment mode
self-hosted is the default mode. cloud enables the hosted product's metering path and requires INNGEST_EVENT_KEY. Use self-hosted for an instance you operate, and configure workspace memberships and roles in the product.
Keep development preview routes disabled on public instances. ENABLE_DEV_ROUTES is for isolated development previews.