Backend Environment (.env) Reference
A comprehensive specification of every accepted environment variable, its purpose, valid value types, default behaviors, and concrete production examples for VibeMatch.
⚙️ Overview & Location
VibeMatch backend loads configuration from an environment file located at the root of the backend folder: code/.env. When deploying to a production VPS or cPanel/GadoHost server, create a .env file in the directory where server.js (or server.ts) is executed.
.env file is protected with strict filesystem permissions (chmod 600 .env) so other non-root system users cannot read your database credentials or cryptographic secrets.
📋 Accepted Environment Keys Summary
| Variable Key | Requirement | Valid Values / Type | Purpose & Description |
|---|---|---|---|
| MONGODB_URI | Strictly Required | String URI (mongodb:// or mongodb+srv://) |
Full MongoDB connection string. Connects Mongoose to your database cluster for storing users, chat logs, transactions, settings, and gifts. |
| JWT_SECRET | Strictly Required | String (≥ 32 chars) | Cryptographic secret key used to sign and verify HMAC-SHA256 authentication tokens for mobile app and admin dashboard sessions. |
| PORT | Optional | Integer (1024 - 65535) | Network port for the HTTP/Socket.IO server. Defaults to 3000 if omitted. When running on cPanel/GadoHost, this is automatically managed. |
| NODE_ENV | Recommended | production | development |
Specifies runtime environment mode. When set to production, Vite dev server is disabled and optimized build bundles are served. |
| DEMO_MODE | Optional | true | false |
When set to true, demo account passwords cannot be changed and destructive administrative actions are disabled. Defaults to false. |
| GOOGLE_SERVICE_ACCOUNT_JSON | IAP Only | Minified JSON String | Google Cloud Service Account JSON credentials with Android Publisher permissions. Used for server-side cryptographic validation of Google Play In-App Purchases (Fail-closed). |
| APPLE_SHARED_SECRET | IAP Only | 32-character Hex String | Apple App Store Connect Shared Secret used to verify auto-renewable VIP subscriptions and diamond consumable receipts for iOS users. |
| DISABLE_HMR | Optional | true | false |
Disables Vite Hot Module Replacement in development mode if running behind specific reverse proxies. Defaults to false. |
🔍 Detailed Variable Specifications
1. MONGODB_URI
Specifies the database connection string. VibeMatch supports both local standalone MongoDB instances and MongoDB Atlas Cloud clusters with replica sets.
2. JWT_SECRET
The secret string used by jsonwebtoken to sign user auth tokens upon login or registration. Never use default or predictable strings in production.
3. GOOGLE_SERVICE_ACCOUNT_JSON
Required if you sell Diamond coins on Google Play Store via In-App Purchases. The server directly queries the Google Play Developer API (androidpublisher.googleapis.com) to cryptographically verify purchase tokens. If this key is missing, all Google Play purchases are rejected automatically (fail-closed security).
4. APPLE_SHARED_SECRET
The master secret key from App Store Connect. Required for validating StoreKit purchases on iOS devices.
📄 Production Ready .env Template
You can copy this complete template directly into your production .env file: