# Environment Variables

> Part of the NocoDB documentation (Self-hosting). Index of all pages: https://nocodb.com/llms.txt. Any docs page is available as Markdown by adding `.md` to its URL.

URL: https://nocodb.com/docs/self-hosting/environment-variables
Last updated: 2026-10-03

Set environment variables to configure a self-hosted NocoDB instance: database, storage, authentication, cache, rate limits and more.

This page lists the NocoDB environment variables by area: database, storage, authentication, cache, rate limits and more.

For a production deployment, set all environment variables that show **"Mandatory"**. These variables affect performance, security and core functions.

## Backward compatibility

NocoDB is fully compatible with legacy environment variable names. If you use an old variable name, it continues to work. We recommend the new names, because they are clearer and more consistent. When a variable has more than one name, NocoDB checks the names in this order:

1. **New recommended name** (for example, `NC_RATE_LIMIT_DATA_API_DURATION`)
2. **Legacy name** (for example, `NC_DATA_API_TTL`)
3. **Default value**

You can change to the new names step by step. Existing deployments continue to work.

## Database

| Variable                    | Mandatory | Description                                                                                                                                                                                                                                                                                     | If Not Set                                                                        |
| --------------------------- | --------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------- |
| `NC_DB`                     | Yes       | The primary database. NocoDB stores all metadata and data in it. Example format: `pg://host.docker.internal:5432?u=username&p=password&d=database_name`.                                                                                                                                        | If `NC_DB` is not set, NocoDB creates a local SQLite database in the root folder. |
| `NC_DB_JSON`                | No        | Sets the database connection with a valid [knex connection JSON string](https://knexjs.org/guide/#configuration-options) instead of `NC_DB`.                                                                                                                                                    |                                                                                   |
| `NC_DB_JSON_FILE`           | No        | The path to a knex connection JSON file that sets the database connection. Use it instead of `NC_DB`.                                                                                                                                                                                           |                                                                                   |
| `DATABASE_URL`              | No        | A [JDBC URL string](https://jdbc.postgresql.org/documentation/use/#connecting-to-the-database) for the database connection. Use it instead of `NC_DB`.                                                                                                                                          |                                                                                   |
| `DATABASE_URL_FILE`         | No        | The path to a file that contains a JDBC URL for the database connection. Use it instead of `NC_DB`.                                                                                                                                                                                             |                                                                                   |
| `NC_CONNECTION_ENCRYPT_KEY` | No        | The key used to encrypt the credentials of external databases. <br /> **Warning:** Do not change this variable directly. A change can break the application. To change it, use the CLI as the [NocoDB Secret CLI documentation](/docs/product/integrations/data-sources/updating-secret) shows. | NocoDB keeps connection credentials as plain text in the database.                |
| `NC_DB_POOL_MAX`            | No        | The maximum number of connections in the database connection pool. This is the number of database connections that NocoDB can keep open at the same time.                                                                                                                                       | Defaults to `10`.                                                                 |

## Authentication

| Variable                       | Mandatory | Description                                                                                                                                                                                                                                                              | If Not Set                                                                        |
| ------------------------------ | --------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | --------------------------------------------------------------------------------- |
| `NC_AUTH_JWT_SECRET`           | Yes       | The JWT secret that NocoDB uses to make authentication tokens.                                                                                                                                                                                                           | NocoDB makes a random secret automatically.                                       |
| `NC_JWT_EXPIRES_IN`            | No        | The expiration time for JWT tokens.                                                                                                                                                                                                                                      | Defaults to `10h`.                                                                |
| `NC_GOOGLE_CLIENT_ID`          | No        | The Google client ID. Necessary for Google authentication.                                                                                                                                                                                                               |                                                                                   |
| `NC_GOOGLE_CLIENT_SECRET`      | No        | The Google client secret. Necessary for Google authentication.                                                                                                                                                                                                           |                                                                                   |
| `NC_ADMIN_EMAIL`               | No        | The super admin email address. Use it to recover your username and password. [See update requirements](#updating-super-admin-credentials).                                                                                                                               | When you open the UI for the first time, NocoDB asks for an email and a password. |
| `NC_ADMIN_PASSWORD`            | No        | The super admin password. It must have at least 8 characters, with one uppercase letter, one number and one special character from `$&+,:;=?@#'.^*()%!_-\"`. Use it to recover your username and password. [See update requirements](#updating-super-admin-credentials). |                                                                                   |
| `NC_DISABLE_EMAIL_AUTH`        | No        | Disables email and password authentication. Use it when you set the Google authentication variables.                                                                                                                                                                     |                                                                                   |
| `NC_REFRESH_TOKEN_EXP_IN_DAYS` | No        | The expiration time for refresh tokens, in days. It must be a positive number. **(On-premise only)**                                                                                                                                                                     | Defaults to `30` days.                                                            |
| `NC_SSO`                       | No        | Enables SSO. Set to `oidc` to activate OpenID Connect or `saml` to activate SAML.                                                                                                                                                                                        | SSO disabled.                                                                     |
| `NC_OIDC_PROVIDER_NAME`        | No        | The name that the login page shows for the OIDC provider.                                                                                                                                                                                                                | Defaults to `OpenID Connect`.                                                     |
| `NC_SSO_SAML_PROVIDER_NAME`    | No        | The name that the login page shows for the SAML provider.                                                                                                                                                                                                                | Defaults to `SAML`.                                                               |

### Updating super admin credentials

To update `NC_ADMIN_EMAIL` **or** `NC_ADMIN_PASSWORD`, set **both** variables together.

If you set `NC_ADMIN_EMAIL` and `NC_ADMIN_PASSWORD` is empty or missing, NocoDB stops during startup. It shows the error `Missing admin password`. To fix this, do one of these:

* Set the password.
* Unset `NC_ADMIN_EMAIL`. Then create the super admin through the first-signup prompt.

## Storage

| Variable                                   | Mandatory | Description                                                                                                                                                                                                                                                                       | If Not Set                              | Legacy Names (Still Supported) |
| ------------------------------------------ | --------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------- | ------------------------------ |
| `NC_S3_BUCKET_NAME`                        | No        | The name of the AWS S3 bucket for the S3 storage plugin.                                                                                                                                                                                                                          |                                         | -                              |
| `NC_S3_REGION`                             | No        | The AWS S3 region of the S3 storage plugin bucket. If you set `NC_S3_ENDPOINT`, it takes precedence, because the endpoint URL includes the region.                                                                                                                                |                                         | -                              |
| `NC_S3_ENDPOINT`                           | No        | The S3 endpoint for the S3 storage plugin.                                                                                                                                                                                                                                        | Defaults to `s3.<region>.amazonaws.com` | -                              |
| `NC_S3_ACCESS_KEY`                         | No        | The AWS access key ID for the S3 storage plugin. Necessary if you do not use role access.                                                                                                                                                                                         |                                         | -                              |
| `NC_S3_ACCESS_SECRET`                      | No        | The AWS access secret for the S3 storage plugin. Necessary if you do not use role access.                                                                                                                                                                                         |                                         | -                              |
| `NC_S3_FORCE_PATH_STYLE`                   | No        | Forces [path-style requests](https://docs.aws.amazon.com/AmazonS3/latest/userguide/VirtualHosting.html#path-style-access) for the S3 storage plugin.                                                                                                                              |                                         | -                              |
| `NC_S3_ACL`                                | No        | The [ACL](https://docs.aws.amazon.com/AmazonS3/latest/userguide/acl-overview.html) for the objects in S3.                                                                                                                                                                         |                                         | -                              |
| `NC_ATTACHMENT_FIELD_SIZE`                 | No        | The maximum file size for [attachments](/docs/product/tables/fields/field-types/custom-types/attachment) in bytes.                                                                                                                                                                | Defaults to `20971520` (20 MiB).        | -                              |
| `NC_FORM_FIELD_MAX_SIZE`                   | No        | The maximum size in bytes of one form field during multipart uploads in [shared form views](/docs/product/tables/views/share-view). Increase it for large text or JSON fields. This prevents 'Field value too long' errors when people outside your organization submit the form. | Defaults to `10485760` (10 MiB).        | `NC_NON_ATTACHMENT_FIELD_SIZE` |
| `NC_MAX_ATTACHMENTS_ALLOWED`               | No        | The maximum number of attachments in one cell.                                                                                                                                                                                                                                    | Defaults to `10`.                       | -                              |
| `NC_ATTACHMENT_RETENTION_DAYS`             | No        | The number of days that NocoDB keeps an attachment in storage after you delete all references to it. Set `0` to keep it forever.                                                                                                                                                  | Defaults to `10`.                       | -                              |
| `NC_ATTACHMENT_ACCESS_CONTROL_ENABLED`     | No        | Enables access control for attachments through pre-signed URLs. Set to `true` to enable. All other values mean `false`. ⚠ Note: When you enable it, existing links stop working.                                                                                                  | Defaults to `false`.                    | `NC_SECURE_ATTACHMENTS`        |
| `NC_ATTACHMENT_EXPIRE_SECONDS`             | No        | The time in seconds before pre-signed attachment URLs start to expire. The URLs expire 10 minutes after this time. Applies only if you enable `NC_ATTACHMENT_ACCESS_CONTROL_ENABLED`.                                                                                             | Defaults to `7200` (2 hours).           | -                              |
| `NC_THUMBNAIL_MAX_SIZE`                    | No        | The maximum size in bytes of an image file that gets a thumbnail. Larger images get no thumbnail.                                                                                                                                                                                 | Defaults to `3145728` (3 MiB).          | -                              |
| `NC_THUMBNAIL_MAX_INPUT_PIXELS`            | No        | The maximum image resolution for thumbnails, in pixels (width times height). NocoDB skips larger images, so that it does not run out of memory.                                                                                                                                   | Defaults to `24000000` (24 MP).         | -                              |
| `NC_THUMBNAIL_MAX_INPUT_PIXELS_SHRINKABLE` | No        | The upper limit in pixels for thumbnails. Above this limit, NocoDB makes no thumbnail, also for formats that support shrink-on-load decoding.                                                                                                                                     | Defaults to `100000000` (100 MP).       | -                              |
| `NC_DATA_IMPORT_FILE_SIZE`                 | No        | The maximum file size in bytes for the data import upload endpoint. NocoDB uses this endpoint when you import CSV, Excel or JSON files into a base.                                                                                                                               | Defaults to `104857600` (100 MiB).      | -                              |

## Email notifications

* NocoDB uses these SMTP variables to send email notifications to users, for example invites.

| Variable                      | Mandatory | Description                                                                                                                                                                                                                                                                                                                           | If Not Set           |
| ----------------------------- | --------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------- |
| `NC_SMTP_FROM`                | Yes       | The sender email address for the SMTP plugin.                                                                                                                                                                                                                                                                                         |                      |
| `NC_SMTP_HOST`                | Yes       | The hostname of the email server for the SMTP plugin.                                                                                                                                                                                                                                                                                 |                      |
| `NC_SMTP_PORT`                | Yes       | The network port of the email server for the SMTP plugin.                                                                                                                                                                                                                                                                             |                      |
| `NC_SMTP_USERNAME`            | Yes       | The username for authentication with the SMTP plugin.                                                                                                                                                                                                                                                                                 |                      |
| `NC_SMTP_PASSWORD`            | Yes       | The password for authentication with the SMTP plugin.                                                                                                                                                                                                                                                                                 |                      |
| `NC_SMTP_SECURE`              | No        | Enables secure authentication for the SMTP plugin. Set to `true` to enable. All other values mean `false`.                                                                                                                                                                                                                            | Defaults to `false`. |
| `NC_SMTP_IGNORE_TLS`          | No        | Ignores TLS for the SMTP plugin. This disables STARTTLS, also when the SMTP server supports it. Set to `true` to ignore TLS. All other values mean `false`. This setting can decrease security. For more details, see [Nodemailer's SMTP documentation](https://nodemailer.com/smtp/).                                                | Defaults to `false`. |
| `NC_SMTP_REJECT_UNAUTHORIZED` | No        | Rejects connections to SMTP servers with invalid (self-signed) TLS certificates. Set to `true` to reject. All other values mean `false`. This setting gives more protection against man-in-the-middle attacks. For more details, see [Nodemailer's SMTP documentation](https://nodemailer.com/smtp/#3-allow-selfsigned-certificates). | Defaults to `false`. |

## Backend

| Variable       | Mandatory | Description                                                                                  | If Not Set          |
| -------------- | --------- | -------------------------------------------------------------------------------------------- | ------------------- |
| `PORT`         | No        | The network port that NocoDB runs on.                                                        | Defaults to `8080`. |
| `NODE_OPTIONS` | No        | The Node.js [options](https://nodejs.org/api/cli.html#node_optionsoptions) for the instance. |                     |

## Frontend

| Variable                     | Mandatory                                                                                                                                                                                           | Description                                                                                                                                                                                                                                                                                                                | If Not Set                                                                                                      | Legacy Names (Still Supported) |
| ---------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------- | ------------------------------ |
| `NC_SITE_URL`                | <span title="Required for sending emails (invitations, password resets). Can be skipped if email functionality is not needed.">Yes <label style={{ color:"var(--color-red-500)"}}>\*</label></span> | **Required for outbound emails to work.** Invitation and password-reset emails make their links from this URL. If you do not set it, these links point to the wrong host. NocoDB also uses it for the Swagger docs URL and other backend URLs. Set it to your public NocoDB URL, for example `https://nocodb.example.com`. | The backend gets the URL from the incoming request. If the server is behind a proxy, the URLs can be incorrect. | `NC_PUBLIC_URL`                |
| `NC_DASHBOARD_URL`           | No                                                                                                                                                                                                  | A custom dashboard URL path.                                                                                                                                                                                                                                                                                               | Defaults to `/dashboard`.                                                                                       |                                |
| `NUXT_PUBLIC_NC_BACKEND_URL` | No                                                                                                                                                                                                  | A custom backend URL.                                                                                                                                                                                                                                                                                                      | Defaults to `http://localhost:8080`.                                                                            |                                |

## Cache

| Variable                  | Mandatory | Description                                                                                                                                                         | If Not Set                            | Legacy Names (Still Supported) |
| ------------------------- | --------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------- | ------------------------------ |
| `NC_CACHE_REDIS_URL`      | Yes       | The Redis URL for the cache. <br /> Example: `redis://:authpassword@127.0.0.1:6380/4`                                                                               | Caching layer of backend              | `NC_REDIS_URL`                 |
| `NC_JOBS_REDIS_URL`       | No        | A separate Redis URL for the job queue. Falls back to `NC_REDIS_JOB_URL`. Use it to keep the job queue workload apart from cache operations. **(On-premise only)**  | Required if using job queue features. | `NC_REDIS_JOB_URL`             |
| `NC_RATE_LIMIT_REDIS_URL` | No        | A separate Redis URL for rate limits. Falls back to `NC_THROTTLER_REDIS`. Use it to keep rate limit operations apart from the cache and jobs. **(On-premise only)** | NocoDB keeps rate limits in memory.   | `NC_THROTTLER_REDIS`           |

## Rate limiting

**(On-premise only)** NocoDB sets rate limits for each API type. Rate limits prevent abuse and keep usage fair. Each API type has three parameters:

| Parameter       | What it sets                                                                   |
| --------------- | ------------------------------------------------------------------------------ |
| DURATION        | The time window, in milliseconds                                               |
| MAX\_REQUESTS   | The maximum number of requests in that window                                  |
| BLOCK\_DURATION | How long NocoDB blocks requests after they go above the limit, in milliseconds |

### REST API with auth token

Rate limits for authenticated API requests that use auth tokens.

| Variable                                | Mandatory | Description                                                           | If Not Set                 | Legacy Names (Still Supported) |
| --------------------------------------- | --------- | --------------------------------------------------------------------- | -------------------------- | ------------------------------ |
| `NC_RATE_LIMIT_DATA_API_DURATION`       | No        | The time window in milliseconds for data API rate limits.             | Defaults to `1000` (1s).   | `NC_DATA_API_TTL`              |
| `NC_RATE_LIMIT_DATA_API_MAX_REQUESTS`   | No        | The maximum number of data API requests in one duration window.       | Defaults to `5`.           | `NC_DATA_COUNT`                |
| `NC_RATE_LIMIT_DATA_API_BLOCK_DURATION` | No        | Duration in milliseconds to block requests after exceeding the limit. | Defaults to `30000` (30s). | `NC_DATA_BLOCK_DURATION`       |

### REST API with auth token (metadata operations)

Rate limits for metadata operations (base, table and field management) that use auth tokens.

| Variable                                | Mandatory | Description                                                           | If Not Set                 | Legacy Names (Still Supported) |
| --------------------------------------- | --------- | --------------------------------------------------------------------- | -------------------------- | ------------------------------ |
| `NC_RATE_LIMIT_META_API_DURATION`       | No        | The time window in milliseconds for meta API rate limits.             | Defaults to `60000` (60s). | `NC_META_API_TTL`              |
| `NC_RATE_LIMIT_META_API_MAX_REQUESTS`   | No        | The maximum number of meta API requests in one duration window.       | Defaults to `60`.          | `NC_META_COUNT`                |
| `NC_RATE_LIMIT_META_API_BLOCK_DURATION` | No        | Duration in milliseconds to block requests after exceeding the limit. | Defaults to `30000` (30s). | `NC_META_BLOCK_DURATION`       |

### Web UI - data operations

Rate limits for data operations in the web interface (browser sessions).

| Variable                                | Mandatory | Description                                                            | If Not Set                  | Legacy Names (Still Supported) |
| --------------------------------------- | --------- | ---------------------------------------------------------------------- | --------------------------- | ------------------------------ |
| `NC_RATE_LIMIT_DATA_GUI_DURATION`       | No        | The time window in milliseconds for web UI data operation rate limits. | Defaults to `1000` (1s).    | `NC_DATA_GUI_API_TTL`          |
| `NC_RATE_LIMIT_DATA_GUI_MAX_REQUESTS`   | No        | The maximum number of web UI data requests in one duration window.     | Defaults to `30000`.        | `NC_DATA_GUI_COUNT`            |
| `NC_RATE_LIMIT_DATA_GUI_BLOCK_DURATION` | No        | Duration in milliseconds to block requests after exceeding the limit.  | Defaults to `0` (no block). | `NC_DATA_GUI_BLOCK_DURATION`   |

### Web UI - metadata operations

Rate limits for metadata operations (base, table and field management) in the web interface (browser sessions).

| Variable                                | Mandatory | Description                                                                | If Not Set                  | Legacy Names (Still Supported) |
| --------------------------------------- | --------- | -------------------------------------------------------------------------- | --------------------------- | ------------------------------ |
| `NC_RATE_LIMIT_META_GUI_DURATION`       | No        | The time window in milliseconds for web UI metadata operation rate limits. | Defaults to `1000` (1s).    | `NC_META_GUI_API_TTL`          |
| `NC_RATE_LIMIT_META_GUI_MAX_REQUESTS`   | No        | The maximum number of web UI metadata requests in one duration window.     | Defaults to `1000`.         | `NC_META_GUI_COUNT`            |
| `NC_RATE_LIMIT_META_GUI_BLOCK_DURATION` | No        | Duration in milliseconds to block requests after exceeding the limit.      | Defaults to `0` (no block). | `NC_META_GUI_BLOCK_DURATION`   |

### Shared views & forms (public access)

Rate limits for public shared views and forms. These need no authentication.

| Variable                                  | Mandatory | Description                                                           | If Not Set                  | Legacy Names (Still Supported) |
| ----------------------------------------- | --------- | --------------------------------------------------------------------- | --------------------------- | ------------------------------ |
| `NC_RATE_LIMIT_PUBLIC_API_DURATION`       | No        | The time window in milliseconds for public API rate limits.           | Defaults to `1000` (1s).    | `NC_PUBLIC_API_TTL`            |
| `NC_RATE_LIMIT_PUBLIC_API_MAX_REQUESTS`   | No        | The maximum number of public API requests in one duration window.     | Defaults to `10`.           | `NC_PUBLIC_COUNT`              |
| `NC_RATE_LIMIT_PUBLIC_API_BLOCK_DURATION` | No        | Duration in milliseconds to block requests after exceeding the limit. | Defaults to `0` (no block). | `NC_PUBLIC_BLOCK_DURATION`     |

## Product configuration

| Variable                                   | Mandatory | Description                                                                                                                                                                                                                                                                                             | If Not Set                                                                     | Legacy Names (Still Supported)   |
| ------------------------------------------ | --------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------ | -------------------------------- |
| `NC_DB_QUERY_LIMIT_DEFAULT`                | No        | The default pagination limit for data tables.                                                                                                                                                                                                                                                           | Defaults to `25`. Maximum is `100`                                             | `DB_QUERY_LIMIT_DEFAULT`         |
| `NC_DB_QUERY_LIMIT_GROUP_BY_GROUP`         | No        | The number of groups on one page.                                                                                                                                                                                                                                                                       | Defaults to `10`.                                                              | `DB_QUERY_LIMIT_GROUP_BY_GROUP`  |
| `NC_DB_QUERY_LIMIT_GROUP_BY_RECORD`        | No        | The number of records in one group.                                                                                                                                                                                                                                                                     | Defaults to `10`.                                                              | `DB_QUERY_LIMIT_GROUP_BY_RECORD` |
| `NC_DB_QUERY_LIMIT_MAX`                    | No        | The maximum pagination limit.                                                                                                                                                                                                                                                                           | Defaults to `1000`.                                                            | `DB_QUERY_LIMIT_MAX`             |
| `NC_DB_QUERY_LIMIT_MIN`                    | No        | The minimum pagination limit.                                                                                                                                                                                                                                                                           | Defaults to `10`                                                               | `DB_QUERY_LIMIT_MIN`             |
| `NC_CONNECT_TO_EXTERNAL_DB_DISABLED`       | No        | Stops users from creating bases on external databases.                                                                                                                                                                                                                                                  |                                                                                | -                                |
| `NC_INVITE_ONLY_SIGNUP`                    | No        | Disables public signup. Users can sign up only through invitations. Since version 0.99.0, this setting is also in the [super admin settings menu](/docs/product/account-settings/oss-specific-details#enable--disable-signup).                                                                          |                                                                                | -                                |
| `NC_REQUEST_BODY_SIZE`                     | No        | The maximum number of bytes in the request body, based on [ExpressJS limits](https://expressjs.com/en/resources/middleware/body-parser.html#limit).                                                                                                                                                     | Defaults to `1048576` (1 MB).                                                  | -                                |
| `NC_WEBHOOK_MAX_BODY_SIZE`                 | No        | The maximum size in bytes of an outgoing webhook request or response body that NocoDB buffers. This limits memory use from large webhook payloads.                                                                                                                                                      | Defaults to `10485760` (10 MB).                                                | -                                |
| `NC_FORMULA_MAX_OUTPUT_LENGTH`             | No        | The maximum number of characters in the string output of a formula field. NocoDB truncates longer output.                                                                                                                                                                                               | Falls back to `NC_MAX_TEXT_LENGTH` (default `100000`).                         | -                                |
| `NC_WEBHOOK_ALLOW_PRIVATE_NETWORK`         | No        | Lets webhooks call private network addresses (localhost, RFC1918 ranges). Set to `true` to enable. All other values mean `false`. ⚠ Security risk.                                                                                                                                                      | Defaults to `false`.                                                           | `NC_ALLOW_LOCAL_HOOKS`           |
| `NC_ALLOW_LOCAL_EXTERNAL_DBS`              | No        | Lets NocoDB connect to external databases on local network addresses. This can be a security risk. Set to `true` to enable. All other values mean `false`.                                                                                                                                              | Defaults to `false`.                                                           | -                                |
| `NC_ALLOW_LOCAL_DATA_IMPORT`               | No        | Lets the **Add from URL** data import get files from local or private network addresses (localhost, RFC1918 ranges). Set to `true` to enable. All other values mean `false`. ⚠ Security risk.                                                                                                           | Defaults to `false`.                                                           | -                                |
| `NC_DATABASE_COLUMN_NAME_SANITIZE_ENABLED` | No        | Sanitizes column names when you create them, to prevent SQL injection. Set to `false` to disable it.                                                                                                                                                                                                    | Defaults to `true` (enabled).                                                  | `NC_SANITIZE_COLUMN_NAME`        |
| `NC_APP_DATA_DIR`                          | No        | The directory for metadata and app files. In Docker setups, this is `/usr/app/data/`, where you mount volumes.                                                                                                                                                                                          | Defaults to the current working directory.                                     | `NC_TOOL_DIR`                    |
| `NC_DISABLE_PG_DATA_REFLECTION`            | No        | Stops NocoDB from creating a schema for each base in Postgres.  [Click here for more detail](#postgres-data-reflection)                                                                                                                                                                                 | Defaults to `false`.                                                           | -                                |
| `NC_MIGRATIONS_DISABLED`                   | No        | Disables NocoDB migrations.                                                                                                                                                                                                                                                                             |                                                                                | -                                |
| `NC_DISABLE_AUDIT`                         | No        | Disables the audit log feature.                                                                                                                                                                                                                                                                         | Defaults to `false`.                                                           | -                                |
| `NC_DISABLE_TOURS`                         | No        | Disables in-app product tours. Product tours are guided walkthroughs that highlight parts of the interface. They can start on their own, for example when a new user first opens their workspace. Set to `true` to disable.                                                                             | Defaults to `false`. Product tours are currently inactive by default.          | -                                |
| `NC_WEBHOOK_LOG_LEVEL`                     | No        | Sets the log level for webhook runs. Possible values: `OFF`, `ERROR`, `ALL`. For more details, refer to [Webhooks](/docs/product/tables/table-operations/webhook/create-webhook).                                                                                                                       | Defaults to `OFF`.                                                             | `NC_AUTOMATION_LOG_LEVEL`        |
| `NC_IFRAME_ALLOWED_DOMAINS`                | No        | A comma-separated list of domains that you can embed in iframes. **(On-premise only)** Example: `*.nocodb.com,*.mycompany.com`                                                                                                                                                                          |                                                                                | `NC_IFRAME_WHITELIST_DOMAINS`    |
| `NC_API_BULK_OPERATION_MAX_RECORDS`        | No        | The maximum number of records that one v3 API request can insert, update or delete. This prevents memory problems with large bulk operations. **(On-premise only)**                                                                                                                                     | Defaults to `10` for v3 APIs.                                                  | `NC_DATA_PAYLOAD_LIMIT`          |
| `NC_WORKER_MODE_ENABLED`                   | No        | Set to `true` to make this instance a background job processor. The instance then only processes jobs. It does not serve HTTP requests. **(On-premise only)**                                                                                                                                           | Defaults to `false`.                                                           | `NC_WORKER_CONTAINER`            |
| `NC_WORKER_CONCURRENCY`                    | No        | The number of jobs that each worker processes at the same time. **(On-premise only)**                                                                                                                                                                                                                   | NocoDB default.                                                                | -                                |
| `NC_ALLOW_LEGACY_API_TOKENS`               | No        | Lets you create legacy (not fine-grained) [API tokens](/docs/product/account-settings/api-tokens#legacy-api-tokens) through the API again on a licensed instance. Set to `true` to enable. Legacy tokens never expire, and fine-grained scopes do not apply to them. ⚠ Security risk.                   | Defaults to `false`. Licensed deployments block the creation of legacy tokens. | -                                |
| `NC_MCP_DATA_PAYLOAD_LIMIT`                | No        | The maximum number of records that the [MCP](/docs/apis-and-mcp/mcp) record tools accept in one call. `NC_API_BULK_OPERATION_MAX_RECORDS` caps this value. This variable does not change the limit for v3 API requests.                                                                                 | Defaults to `100`.                                                             | -                                |
| `NC_MCP_BUDGET_BASES_PER_DAY`              | No        | The maximum number of bases that one [MCP connection](/docs/apis-and-mcp/mcp#connection-tools-and-access) can create in one day. Set `-1` for no limit. Set `0` to block base creation over MCP. NocoDB counts each connection separately. The limit applies only when you configure a [cache](#cache). | Defaults to `25`.                                                              | -                                |

<Callout type="warn">
  **Behavior change for URL-based data import.**

   Previously, setting 

  `NC_ALLOW_LOCAL_HOOKS=true`

   (now 

  `NC_WEBHOOK_ALLOW_PRIVATE_NETWORK=true`

  ) also disabled SSRF protection for the 

  **Add from URL**

   data import. It no longer does. To let the URL-based data import reach local or private network hosts, you must now additionally set 

  `NC_ALLOW_LOCAL_DATA_IMPORT=true`

  . Default deployments are unaffected by this change.
</Callout>

### Postgres data reflection

The NocoDB UI mirrors your Postgres database schema, with the same tables and the same columns. To do this, NocoDB creates a schema for each base in Postgres. This feature is on by default if the user has the necessary permissions. To disable it, set the `NC_DISABLE_PG_DATA_REFLECTION` environment variable to `true`.

## AI & script execution

### Code execution sandbox

> [E2B](https://e2b.dev/) gives the sandboxed cloud environments that NocoDB uses to run untrusted code: the [Webhook Run Script](/docs/product/tables/table-operations/webhook/create-webhook#run-script-action-) action, the [Workflow Run Script](/docs/workflows/nodes/action-nodes/run-script) node, and the AI assistant's code-analysis tools.

| Variable                            | Mandatory | Description                                                                                                                                                         | If Not Set                                                              |
| ----------------------------------- | --------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------- |
| `NC_COMPUTE_E2B_API_KEY`            | No        | The API key for the E2B service. Necessary for all code-execution features.                                                                                         | Script execution and AI code-analysis features are off.                 |
| `NC_COMPUTE_E2B_TEMPLATE_SCRIPT`    | No        | The E2B sandbox template ID for webhook and workflow scripts.                                                                                                       | Defaults to NocoDB's script-execution template, `yah8ggzfy44fpdop51ai`. |
| `NC_COMPUTE_E2B_TEMPLATE_CHAT`      | No        | The E2B sandbox template ID for the analysis sandbox of the AI assistant. The default NocoDB image includes a document toolchain (LaTeX, pandoc, LibreOffice, OCR). | Defaults to NocoDB's chat-analyst template, `hefmkx6afen2dhjf3i0u`.     |
| `NC_CHAT_CODE_EXECUTION_TIMEOUT_MS` | No        | The maximum wall-clock time in milliseconds for one AI assistant code run. After this time, NocoDB stops the run.                                                   | Defaults to `60000` (60s).                                              |
| `NC_CHAT_COMPUTE_TIMEOUT_MS`        | No        | The idle lifetime in milliseconds of the AI assistant sandbox. Each chat turn resets it. It is only a safety limit.                                                 | Defaults to `120000` (120s).                                            |

<Callout type="warn">
  **Renamed variables: old names no longer work.**

   

  `E2B_API_KEY`

  , 

  `E2B_TEMPLATE_ID`

  , and 

  `E2B_CHAT_TEMPLATE_ID`

   were renamed to 

  `NC_COMPUTE_E2B_API_KEY`

  , 

  `NC_COMPUTE_E2B_TEMPLATE_SCRIPT`

  , and 

  `NC_COMPUTE_E2B_TEMPLATE_CHAT`

  . Unlike the variables covered under 

  [Backward compatibility](#backward-compatibility)

  , the old names are no longer read at all. If your deployment still sets only the old names after upgrading, script execution and AI code-analysis features are silently disabled. Update the variable names when you upgrade. The template variables are now optional: each workload falls back to NocoDB's own template if unset.
</Callout>

### AI web search

> [Exa](https://exa.ai/) runs the web search and web page fetch tools of the AI assistant.

| Variable             | Mandatory | Description                                                                                               | If Not Set                             |
| -------------------- | --------- | --------------------------------------------------------------------------------------------------------- | -------------------------------------- |
| `NC_WEB_EXA_API_KEY` | No        | The API key for the Exa service. It replaces the old `EXA_API_KEY`. NocoDB no longer reads `EXA_API_KEY`. | AI web search and fetch tools are off. |

## Logging & monitoring

| Variable                 | Mandatory | Description                                                               | If Not Set |
| ------------------------ | --------- | ------------------------------------------------------------------------- | ---------- |
| `NC_SENTRY_DSN`          | No        | The Data Source Name (DSN) for Sentry, for monitoring and error tracking. |            |
| `NC_DISABLE_ERR_REPORTS` | No        | Disables the default Sentry error reports.                                | TRUE       |

## Debugging only

| Variable                          | Mandatory | Description                                                                                                                                             | If Not Set           |
| --------------------------------- | --------- | ------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------- |
| `DEBUG`                           | No        | Enables levels of debug logs. Set to `nc:*` to enable all NocoDB debug logs. Set to `nc:*,knex:*` to also log database queries. Use only for debugging. | Unset by default.    |
| `NC_ENABLE_ALL_API_ERROR_LOGGING` | No        | Enables more detailed API error logs. Use only for debugging.                                                                                           | Defaults to `false`. |
| `NC_DISABLE_CACHE`                | No        | Disables the cache. NocoDB then gets metadata directly from the database, not from Redis or the cache. Use only for debugging.                          | Defaults to `false`. |

## Telemetry

| Variable          | Mandatory | Description                                                                                                                                                                  | If Not Set |
| ----------------- | --------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------- |
| `NC_DISABLE_TELE` | No        | Disables telemetry, so NocoDB sends no anonymous usage data. Keep telemetry on. It helps us understand how people use the product and how a breaking change can affect them. |            |

## Support chat

| Variable                  | Mandatory | Description                                                                                              | If Not Set |
| ------------------------- | --------- | -------------------------------------------------------------------------------------------------------- | ---------- |
| `NC_DISABLE_SUPPORT_CHAT` | No        | Disables the support chat in the product. The support chat uses Chatwoot, an open source support system. | FALSE      |

## Litestream

> NocoDB uses Litestream **only** when `NC_DB` is set to SQLite. Litestream backs up the SQLite database to S3.

| Variable                              | Mandatory | Description                                                                                                                                                                                                                                                                                                         | If Not Set                                                                                                                       |
| ------------------------------------- | --------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------- |
| `LITESTREAM_S3_ENDPOINT`              | No        | The endpoint URL of an S3-compatible object storage service. [Litestream](https://litestream.io/) replicates the default NocoDB SQLite database to it. Example: `s3.eu-central-1.amazonaws.com`.                                                                                                                    | Defaults to [AWS S3](https://aws.amazon.com/s3/).                                                                                |
| `LITESTREAM_S3_REGION`                | No        | The AWS region of the Litestream replication bucket. If you set `LITESTREAM_S3_ENDPOINT`, it takes precedence, because the endpoint URL includes the region.                                                                                                                                                        | Defaults to the [default region configured in AWS](https://docs.aws.amazon.com/emr/latest/ManagementGuide/emr-plan-region.html). |
| `LITESTREAM_S3_BUCKET`                | No        | The name of the object storage bucket for the Litestream replication.                                                                                                                                                                                                                                               | *Litestream replication is disabled if this variable is not set.*                                                                |
| `LITESTREAM_S3_PATH`                  | No        | The directory path in the Litestream replication bucket.                                                                                                                                                                                                                                                            | Defaults to `nocodb`.                                                                                                            |
| `LITESTREAM_S3_ACCESS_KEY_ID`         | No        | The authentication key ID for the Litestream replication bucket.                                                                                                                                                                                                                                                    | *Litestream replication is disabled if this variable is not set.*                                                                |
| `LITESTREAM_S3_SECRET_ACCESS_KEY`     | No        | The authentication secret for the Litestream replication bucket.                                                                                                                                                                                                                                                    | *Litestream replication is disabled if this variable is not set.*                                                                |
| `LITESTREAM_S3_SKIP_VERIFY`           | No        | Disables TLS verification for the Litestream replication storage service. Use it when you test with a local node, such as MinIO, that has self-signed certificates.                                                                                                                                                 | Defaults to `false`.                                                                                                             |
| `LITESTREAM_RETENTION`                | No        | How long Litestream keeps snapshot and WAL files. After this period, Litestream creates a new snapshot and removes the old one. It also removes WAL files that are older than the oldest snapshot.                                                                                                                  | Defaults to `1440h` (60 days).                                                                                                   |
| `LITESTREAM_RETENTION_CHECK_INTERVAL` | No        | How often Litestream checks if it must apply the retention period.                                                                                                                                                                                                                                                  | Defaults to `72h` (3 days).                                                                                                      |
| `LITESTREAM_SNAPSHOT_INTERVAL`        | No        | How often Litestream creates a new snapshot. More frequent snapshots make restores faster, because newer snapshots have fewer WAL frames to apply. The retention period also applies to these snapshots.                                                                                                            | Defaults to `24h` (1 day).                                                                                                       |
| `LITESTREAM_SYNC_INTERVAL`            | No        | How often Litestream sends frames to the replica. More frequent syncs can increase object storage costs by a large amount.                                                                                                                                                                                          | Defaults to `60s` (1 minute).                                                                                                    |
| `LITESTREAM_AGE_PUBLIC_KEY`           | No        | [age](https://age-encryption.org/) public key generated by `age-keygen` (`age1...`) or SSH public key (`ssh-ed25519 AAAA...`, `ssh-rsa AAAA...`) that Litestream uses to encrypt the replication. Refer to the relevant [Litestream documentation](https://litestream.io/reference/config/#encryption) for details. | *Litestream replication is unencrypted if this variable is not set.*                                                             |
| `LITESTREAM_AGE_SECRET_KEY`           | No        | [age](https://age-encryption.org/) secret key (`AGE-SECRET-KEY-1...`) that Litestream uses to encrypt the replication. Refer to the relevant [Litestream documentation](https://litestream.io/reference/config/#encryption) for details.                                                                            | *Litestream replication is unencrypted if this variable is not set.*                                                             |
| `AWS_ACCESS_KEY_ID`                   | No        | ***Deprecated***. Use `LITESTREAM_S3_ACCESS_KEY_ID` instead.                                                                                                                                                                                                                                                        |                                                                                                                                  |
| `AWS_SECRET_ACCESS_KEY`               | No        | ***Deprecated***. Use `LITESTREAM_S3_SECRET_ACCESS_KEY` instead.                                                                                                                                                                                                                                                    |                                                                                                                                  |
| `AWS_BUCKET`                          | No        | ***Deprecated***. Use `LITESTREAM_S3_BUCKET` instead.                                                                                                                                                                                                                                                               |                                                                                                                                  |
| `AWS_BUCKET_PATH`                     | No        | ***Deprecated***. Use `LITESTREAM_S3_PATH` instead.                                                                                                                                                                                                                                                                 |                                                                                                                                  |

---

## Related pages

- [Self-Hosting](https://nocodb.com/docs/self-hosting.md): Self-host NocoDB on your own infrastructure and keep full control of your data.
- [Purchasing a License](https://nocodb.com/docs/self-hosting/purchase-license.md): Purchase a Business or Scale plan license for your self-hosted NocoDB instance through NocoDB Cloud.
- [Activating a License](https://nocodb.com/docs/self-hosting/license-activation.md): Activate a self-hosted NocoDB license with the standard, airgapped or fully offline method.
- [White Label](https://nocodb.com/docs/self-hosting/white-label.md): Replace the NocoDB branding on your self-hosted instance with your own product name, logos, favicon, brand color, email branding and support contact.
- [Troubleshooting](https://nocodb.com/docs/self-hosting/troubleshooting.md): Find and fix common problems with self-hosted NocoDB: startup, network, SSL, database, attachments and login.
- [Migration Guide](https://nocodb.com/docs/self-hosting/migration-guide.md): Migrate a self-hosted NocoDB instance from a non-Postgres database to PostgreSQL so you can activate a paid license without losing data.
- [License](https://nocodb.com/docs/self-hosting/license.md): The NocoDB Sustainable Use License (SUL), its Fair-Code principles, and when you need a commercial license.
- [FAQs](https://nocodb.com/docs/self-hosting/FAQs.md): Answers to common questions about self-hosted NocoDB: what the Community Edition includes, upgrades, shifted timestamps and instance details.
