Skip to content

Environment variables ​

Configure Masir at runtime. Restart the application after a value changes.

Copy .env.example and edit it. Masir validates critical values at boot and stops with a named error when they are invalid.

Required values ​

VariableDefaultRule
NUXT_SESSION_PASSWORDnoneAt least 32 characters
NUXT_DATABASE_URLlocal development URLPostgres 18 connection
NUXT_ROOT_DOMAINhttp://localhost:3000Full HTTP or HTTPS origin
NUXT_PUBLIC_SHORT_DOMAINhttp://localhost:3000Origin printed in short links

The production Compose files construct the database URL and require POSTGRES_PASSWORD.

Changing the session password signs every user out. Set a separate visitor hash secret so this does not also reset daily unique counts.

Database and session ​

VariableDefaultPurpose
NUXT_SESSION_PASSWORDnoneSeals session cookies
NUXT_VISITOR_HASH_SECRETsession passwordSalts daily visitor hashes
NUXT_DATABASE_URLpostgres://masir:masir@127.0.0.1:5432/masirRuntime database
NUXT_DATABASE_POOL_MAX10Connections per app instance
NUXT_MIGRATE_ON_BOOTtrueApplies pending migrations at startup
TEST_DATABASE_URLpostgres://masir:masir@127.0.0.1:5432/masir_testTest-only database source

On serverless, set the pool to one or two, turn off boot migration, and run bun run db:migrate during deployment.

Deployment and domains ​

VariableDefaultPurpose
NUXT_DEPLOYMENT_MODESELF_HOSTEDSELF_HOSTED or CLOUD
NUXT_ROOT_DOMAINhttp://localhost:3000Root host boundary
NUXT_APP_DOMAINemptyOptional sign-in and dashboard origin
NUXT_PUBLIC_SHORT_DOMAINhttp://localhost:3000Displayed short-link origin
NUXT_MULTI_WORKSPACEfalseEnables workspace subdomains
NUXT_SESSION_COOKIE_DOMAINemptyRequired parent domain in multi mode
NUXT_SESSION_COOKIE_SECUREtrueSends the session only over HTTPS
NUXT_ALLOW_REGISTRATIONfalseEnables public registration
NUXT_SERVERLESSbuild targetMarks hosts without durable disk or process
NUXT_DEMO_ENABLEDfalseEnables 24-hour seeded demo workspaces

Multi-workspace mode needs a dotted root hostname and a cookie domain such as .example.com. It does not support localhost, an IP address, or a bare local hostname.

Mail ​

VariableDefaultPurpose
NUXT_MAIL_DRIVERautomaticsmtp, resend, outbox, or log
NUXT_MAIL_FROMMasir <no-reply@localhost>Sender header
NUXT_MAIL_SMTP_HOSTemptyEnables SMTP
NUXT_MAIL_SMTP_PORT587SMTP port
NUXT_MAIL_SMTP_USERemptyOptional SMTP user
NUXT_MAIL_SMTP_PASSWORDemptyOptional SMTP password
NUXT_MAIL_SMTP_SECUREfalseImplicit TLS, usually on port 465
NUXT_MAIL_SMTP_POOL_MAX5Open SMTP connections
NUXT_MAIL_API_KEYemptyEnables Resend

Automatic selection tries SMTP, then Resend, then the log driver. The outbox driver is for tests.

Storage ​

VariableDefaultPurpose
NUXT_STORAGE_DRIVERautomaticfile or s3
NUXT_STORAGE_LOCAL_ROOT./data/uploadsFile storage root
NUXT_STORAGE_PUBLIC_BASE_URLhttp://localhost:3000/uploadsPublic object prefix
NUXT_STORAGE_ACCESS_KEY_IDemptyS3-compatible access key
NUXT_STORAGE_SECRET_ACCESS_KEYemptyS3-compatible secret
NUXT_STORAGE_BUCKETemptyEnables S3 selection
NUXT_STORAGE_ENDPOINTemptyR2 or custom S3 endpoint
NUXT_STORAGE_MAX_UPLOAD_BYTES2097152Maximum workspace logo size

Automatic selection prefers S3 when a bucket is set, then file storage. Serverless mode rejects file storage.

OAuth and bot checks ​

VariableDefault
NUXT_OAUTH_GOOGLE_CLIENT_IDempty
NUXT_OAUTH_GOOGLE_CLIENT_SECRETempty
NUXT_OAUTH_MICROSOFT_CLIENT_IDempty
NUXT_OAUTH_MICROSOFT_CLIENT_SECRETempty
NUXT_OAUTH_MICROSOFT_TENANTcommon
NUXT_PUBLIC_TURNSTILE_SITE_KEYempty
NUXT_TURNSTILE_SECRET_KEYempty

A provider button appears when its client ID is set. Cloud mode requires a specific Microsoft tenant.

Turnstile runs only when both keys are set.

Request handling ​

VariableDefaultPurpose
NUXT_ALLOW_PRIVATE_DESTINATIONSfalseAllows private-network link targets
NUXT_GEO_COUNTRY_HEADERemptyTrusted country-code header
NUXT_TRUSTED_PROXY_DEPTH0Trusted proxies before the app

Keep private destinations off on a public deployment. Set proxy depth to the exact network chain.

Rate limits ​

VariableDefault
NUXT_REDIS_URLempty
NUXT_RATE_LIMIT_LOGIN_PER_MINUTE10
NUXT_RATE_LIMIT_WORKSPACE_PER_DAY5
NUXT_RATE_LIMIT_REDIRECT_PER_MINUTE120
NUXT_RATE_LIMIT_CREATE_PER_HOUR30
NUXT_RATE_LIMIT_UPDATE_PER_MINUTE60
NUXT_RATE_LIMIT_PASSWORD_PER_MINUTE10
NUXT_RATE_LIMIT_SLUG_CHECK_PER_MINUTE30
NUXT_RATE_LIMIT_INVITE_PER_HOUR30

Without Redis, each process has its own counters. Use a rediss:// endpoint before you run several instances.

VariableDefaultPurpose
NUXT_LINK_CACHE_TTL_SECONDS60Positive link cache lifetime in seconds; zero disables
NUXT_LINK_CACHE_MISS_TTL_SECONDS15Negative link cache lifetime in seconds; zero disables
NUXT_LINK_CACHE_SHARED_INVALIDATIONfalseEnables Redis pub/sub invalidation across instances

Alerts and jobs ​

VariableDefaultPurpose
NUXT_ALERTS_INTERVAL_MINUTES15In-process sweep interval; zero disables it
NUXT_JOBS_SECRETemptyBearer secret for POST /api/jobs/alerts
NUXT_OPERATOR_EMAILSemptyComma-separated user emails allowed to access operator routes

The maximum interval is 35,000 minutes. Serverless deployments use zero and an external scheduler.

Application analytics ​

VariableDefaultPurpose
NUXT_PUBLIC_SCRIPTS_GOOGLE_ANALYTICS_IDemptyGA4 measurement ID
NUXT_PUBLIC_SCRIPTS_UMAMI_ANALYTICS_WEBSITE_IDemptyUmami website ID
NUXT_PUBLIC_SCRIPTS_UMAMI_ANALYTICS_HOST_URLemptySelf-hosted Umami origin
NUXT_PUBLIC_SCRIPTS_UMAMI_ANALYTICS_REPLAYSfalseLoads the Umami recorder

Each tool turns on when its ID is set. You can use both at the same time.

For Umami Cloud, set only the website ID. For a self-hosted Umami, also set the host URL. The browser then loads script.js from that host and sends events to it. A host that renames the tracker with TRACKER_SCRIPT_NAME is not supported.

Replays and heatmaps need Umami 3.1.0 or later. Set the replay variable to true, then turn on Replays & Heatmaps in the Umami website settings. The sample rate, mask level, and block selector are set in Umami. The default mask level masks only input fields, and the dashboard shows emails and link destinations. Use the strict mask level to mask all text. The heatmap page preview does not load, because Masir blocks framing and the preview has no session.

This tracks application page views. It does not run on short-link visitor responses.

Sentry ​

VariableDefaultPurpose
NUXT_PUBLIC_SENTRY_DSNemptyEnables error reporting
NUXT_PUBLIC_SENTRY_ENVIRONMENTemptyEnvironment label
NUXT_PUBLIC_SENTRY_TRACES_SAMPLE_RATE0Trace fraction from zero to one
NUXT_PUBLIC_SENTRY_RELEASEimage version in DockerRelease name
SENTRY_AUTH_TOKENemptyAuthorizes source-map upload
SENTRY_ORGemptyOrganization slug
SENTRY_PROJECTemptyProject slug
SENTRY_URLhttps://sentry.io/Custom Sentry origin
SENTRY_BUILDfalseBuild-only module switch

The Docker image sets SENTRY_BUILD=true, includes hidden source maps, and keeps reporting off until a DSN exists. With upload credentials, the container creates the release and uploads its maps at startup.

The build also accepts SENTRY_DSN, SENTRY_ENVIRONMENT, SENTRY_RELEASE, and SENTRY_TRACES_SAMPLE_RATE as server-side aliases.

Seed script ​

VariableDefaultPurpose
ADMIN_EMAILadmin@example.comInitial owner email
ADMIN_PASSWORDnoneInitial owner password

The server does not read these values. Only bun run db:seed:admin uses them.

Docker Compose ​

VariableDefaultPurpose
POSTGRES_PASSWORDnoneRequired database password
MASIR_APP_PORT3000Host application port
MASIR_VERSIONlatestPublished image tag
MASIR_DB_PORT5432Development database port
MASIR_MAIL_SMTP_PORT1025Development Mailpit SMTP port
MASIR_MAIL_UI_PORT8025Development Mailpit web port

Compose passes the database password through PGPASSWORD, outside the connection URL. Changing POSTGRES_PASSWORD does not change an existing Postgres volume password.

Open source link management for teams. Released under the MIT License.