Environment Variables
Configuration reference
Security & Database
| Variable | Required | Description | Example |
|---|---|---|---|
BETTER_AUTH_SECRET | Yes | Signing/encryption secret for sessions and for the secret-reveal key (HKDF-derived from it). Must be at least 32 characters. Generate with openssl rand -base64 32. | s3cr3t... |
DB_PASSWORD | Yes | PostgreSQL database password. Used by the Docker Compose setup. | changeme123 |
DATABASE_URL | Yes | Full PostgreSQL connection string. Auto-configured in Docker. | postgresql://sendly:password@postgres:5432/sendly |
REDIS_URL | Yes | Redis connection string. | redis://redis:6379 |
PORT | No | Port the API server listens on. | 8080 (default) |
URLs & Domains
Set your subdomains here. The application automatically derives all internal and client-side URLs from these at container startup — you don't need to set *_URI or NEXT_PUBLIC_* variables manually.
| Variable | Required | Description | Example |
|---|---|---|---|
API_DOMAIN | Yes | Subdomain for the API server. | api.yourdomain.com |
DASHBOARD_DOMAIN | Yes | Subdomain for the dashboard app. | app.yourdomain.com |
LANDING_DOMAIN | Yes | Subdomain for the landing page. | www.yourdomain.com |
WIKI_DOMAIN | Yes | Subdomain for the documentation site. | docs.yourdomain.com |
USE_HTTPS | No | Set to true when running behind a TLS-terminating reverse proxy. Used to construct URLs with the correct protocol. | false (default) |
AWS SES
| Variable | Required | Description | Example |
|---|---|---|---|
AWS_SES_REGION | Yes | AWS region where SES is configured. | us-east-1 |
AWS_SES_ACCESS_KEY_ID | Yes | AWS access key ID with SES send permissions. | AKIA... |
AWS_SES_SECRET_ACCESS_KEY | Yes | AWS secret access key for SES. | wJalr... |
SES_CONFIGURATION_SET | No | SES configuration set name used for open/click tracking. | sendly-configuration-set (default) |
SES_CONFIGURATION_SET_NO_TRACKING | No | A second SES configuration set without tracking. When set, projects can toggle email tracking on/off. If omitted, the tracking toggle is hidden. | sendly-no-tracking-configuration-set (default) |
Storage (Minio)
The bundled Docker setup includes Minio with defaults that work out of the box. Only change these when connecting to an external S3-compatible bucket.
| Variable | Required | Description | Default |
|---|---|---|---|
MINIO_ROOT_USER | No | Minio root username (Docker Compose only). | sendly |
MINIO_ROOT_PASSWORD | No | Minio root password (Docker Compose only). | sendlyminiopass |
MINIO_API_PORT | No | Port for the Minio API (Docker Compose only). | 9000 |
MINIO_CONSOLE_PORT | No | Port for the Minio console UI (Docker Compose only). | 9001 |
S3_ENDPOINT | No | S3 or Minio endpoint URL. | http://minio:9000 |
S3_ACCESS_KEY_ID | No | S3 or Minio access key. | — |
S3_ACCESS_KEY_SECRET | No | S3 or Minio secret key. | — |
S3_BUCKET | No | Bucket name for file uploads. | uploads |
S3_PUBLIC_URL | No | Publicly accessible base URL for stored files. | — |
S3_FORCE_PATH_STYLE | No | Use path-style URLs instead of virtual-hosted. Required for Minio. | true |
SMTP Server
The optional SMTP relay lets you send emails through Sendly via the SMTP protocol.
| Variable | Required | Description | Default |
|---|---|---|---|
SMTP_DOMAIN | No | SMTP relay domain. Required when using Traefik's acme.json with multiple certificates so the correct cert can be selected. | localhost |
SMTP_ENABLED | No | Explicitly enable SMTP features in the UI. Automatically enabled when SMTP_DOMAIN is set to a non-localhost value in production. | false |
PORT_SECURE | No | SMTPS port (implicit TLS). | 465 |
PORT_SUBMISSION | No | SMTP submission port (STARTTLS). | 587 |
MAX_RECIPIENTS | No | Maximum number of recipients per email. | 5 |
OAuth
Enables social login. Register an OAuth app with each provider and add the credentials here.
| Variable | Required | Description |
|---|---|---|
GITHUB_OAUTH_CLIENT | No | GitHub OAuth app client ID. |
GITHUB_OAUTH_SECRET | No | GitHub OAuth app client secret. |
GOOGLE_OAUTH_CLIENT | No | Google OAuth app client ID. |
GOOGLE_OAUTH_SECRET | No | Google OAuth app client secret. |
Stripe
All four are required, and there is no "billing disabled" mode. While they were optional the
app derived a STRIPE_ENABLED flag from their presence, which made the monthly usage cap, the
pre-send campaign billing check and usage metering into silent no-ops on any install that had
not configured Stripe — enforcement became a function of how completely someone had filled in
their environment. A missing value now fails boot instead.
There is no flat-monthly price. Checkout sells one metered line item, and
STRIPE_PRICE_PRO_FLAT_MONTHLY (formerly STRIPE_PRICE_ONBOARDING) is a retired name that
fails boot if it is still set.
| Variable | Required | Description |
| -------------------------- | -------- | --------------------------------------------------------------------- | ------------------ |
| STRIPE_SK | Yes | Stripe secret key. |
| STRIPE_WEBHOOK_SECRET | Yes | Stripe webhook signing secret for verifying events. |
| STRIPE_PRICE_EMAIL_USAGE | Yes | Stripe price ID for the metered, graduated pay-per-email usage price. |
| STRIPE_METER_EVENT_NAME | Yes | Stripe meter event name. | emails (default) |
Platform Emails
When configured, Sendly will send email notifications to users for critical events (e.g. project disabled, billing limits reached). Without these, only ntfy notifications are sent.
| Variable | Required | Description | Example |
|---|---|---|---|
SENDLY_PLATFORM_SEND_API_KEY | Yes | API key Sendly sends its OWN platform mail with. | pk_... |
SENDLY_FROM_ADDRESS | Yes | From address used for platform notification emails. | noreply@yourdomain.com |
Notifications (ntfy)
Sendly bundles a self-hosted ntfy server for internal system notifications.
| Variable | Required | Description | Default |
|---|---|---|---|
NTFY_PORT | No | Port for the ntfy web UI (Docker Compose only). | 8080 |
NTFY_URL | No | ntfy topic URL. Change this to use an external ntfy.sh server or your own instance. | http://ntfy/sendly-notifications |
Security
| Variable | Required | Description | Default |
|---|---|---|---|
EMAIL_RATE_LIMIT_PER_SECOND | No | Override the email sending rate limit, in emails per second. If not set, Sendly automatically fetches the quota from your AWS SES account. When set it is a hard ceiling — it applies whether the SES quota is higher or lower. Fractional values below 1 are supported for deliberately slow sending: 0.16 paces roughly one email every 6.25 seconds (~48 per 5 minutes), which is useful while warming up a new SES account or rebuilding sender reputation. Must be greater than 0. | — |
Phishing Detection
Sendly uses AI to detect and block phishing emails before they're sent. This requires an OpenRouter API key — the app fails at startup without one, so that content scanning can never be silently disabled.
| Variable | Required | Description | Default |
|---|---|---|---|
OPENROUTER_API_KEY | Yes | OpenRouter API key. Powers outbound phishing detection and inbound spam classification. | — |
OPENROUTER_ASSISTANT_MODEL | No | LLM model for the AI assistant. See OpenRouter models. | anthropic/claude-3-haiku |
OPENROUTER_MODERATION_MODEL | No | Classification model for phishing/spam scanning. Avoid reasoning models (they can return empty content). | deepseek/deepseek-v4-flash |
PHISHING_SAMPLE_RATE_DEFAULT | No | Percentage of emails to check (0.0-1.0). For example, 0.1 means 10% of emails are analyzed. | 0.1 (10%) |
PHISHING_CONFIDENCE_THRESHOLD | No | Minimum confidence percentage (0-100) required to auto-disable a project from a single detection. | 85 |
PHISHING_CUMULATIVE_THRESHOLD | No | Number of phishing detections within the time window required to auto-disable a project. | 3 |
PHISHING_CUMULATIVE_WINDOW_MS | No | Time window in milliseconds for cumulative phishing tracking. | 3600000 (1 hour) |
How it works:
- A random sample of emails (controlled by
PHISHING_SAMPLE_RATE_DEFAULT) are analyzed by the LLM for phishing content. - Projects are automatically disabled if either:
- A single email is detected with confidence ≥
PHISHING_CONFIDENCE_THRESHOLD, or PHISHING_CUMULATIVE_THRESHOLDor more emails are flagged within thePHISHING_CUMULATIVE_WINDOW_MStime window.
- A single email is detected with confidence ≥
- Detection history is stored in Redis and shared across all worker instances.