# --------------------------------------------------------------------------- # PIG — environment # Copy to .env and fill in. Never commit .env. # --------------------------------------------------------------------------- # --- Database --------------------------------------------------------------- # PIG owns this database exclusively. Do not point it at a database shared with # another application. DATABASE_URL=postgres://pig:CHANGEME@localhost:5432/pig # --- Auth (Supabase) -------------------------------------------------------- # PIG uses Supabase for authentication ONLY. It stores no passwords and issues # no sessions of its own; it verifies incoming JWTs against the project JWKS. # # IMPORTANT: authorization does NOT follow from having a Supabase account. # A user must also have a row in PIG's `users` table. If this Supabase project # is shared with another application, that application's users get nothing here # until they are explicitly invited. SUPABASE_URL=https://YOUR_PROJECT_REF.supabase.co SUPABASE_ANON_KEY= # Service key is only needed for administrative user provisioning. Omit it and # PIG runs fine in invite-only mode. Treat it as the most powerful secret here. SUPABASE_SERVICE_KEY= # --- Auth: on-premises (OIDC) --------------------------------------------- # Set PIG_OIDC_ISSUER to authenticate against your own identity provider — # Okta, Entra, Keycloak, Auth0, Authentik, Google Workspace, anything # standards-compliant. It TAKES PRECEDENCE over the Supabase values above, so # an on-prem install can leave those in place. # # PIG never sees a password. It verifies the token your provider issued and # reads two things: a stable subject, and an email. Everything else — teams, # roles, capabilities — is PIG's own data keyed on that subject, so users are # provisioned in PIG by invite, not by your directory. PIG_OIDC_ISSUER= # Optional. Discovered from the issuer's /.well-known/openid-configuration when # omitted. Set it to skip discovery entirely on an air-gapped network. PIG_OIDC_JWKS_URI= # STRONGLY recommended. Without it, a token your provider issued for ANY other # application in the same tenant is accepted here as a PIG session. PIG_OIDC_AUDIENCE= # Comma-separated, in preference order. Defaults to email,preferred_username,upn # which covers most providers; Entra sometimes needs upn first. PIG_OIDC_EMAIL_CLAIMS= # --- Application ------------------------------------------------------------ PIG_PORT=8920 PIG_PUBLIC_URL=http://localhost:8920 NODE_ENV=development # Comma-separated emails granted platform-admin rights. # Every address listed here MUST already have an account. An address listed but # unregistered is a standing offer of admin to whoever claims it first. PIG_ADMIN_EMAILS= # Invite code gating self-serve profile creation. Rotate freely. PIG_INVITE_CODE= # --- Prime Intellect compute API ------------------------------------------- # Used to sync GPU availability into `inventory_listings`. # Mint a key at https://app.primeintellect.ai/dashboard/tokens with the # NARROWEST scope that works: `Availability -> Read`. PIG never provisions # infrastructure and must not hold a key that could. Set an expiry. PRIME_API_KEY= PRIME_API_BASE=https://api.primeintellect.ai # Rate limits are undocumented upstream; the sync backs off empirically. PRIME_SYNC_ENABLED=false PRIME_SYNC_INTERVAL_MINUTES=30 # --- Piggy (the in-app agent) ---------------------------------------------- # Piggy drains a leased queue and serves chat on an authenticated internal # listener. Generate one internal token and give the same value to API + Piggy. # Never publish the Piggy listener or put this token in a URL. PIGGY_INFERENCE_API_KEY= PIGGY_ENABLED=false PIGGY_MODEL=nvidia/nemotron-3-nano-30b-a3b PIGGY_INFERENCE_BASE=https://api.pinference.ai/api/v1 PIGGY_LEASE_SECONDS=300 PIGGY_INTERNAL_URL=http://127.0.0.1:8931 PIGGY_INTERNAL_TOKEN= PIGGY_CHAT_HOST=127.0.0.1 PIGGY_CHAT_PORT=8931 # Only containers on a private network need this; never combine it with a # published Piggy port. PIGGY_CHAT_ALLOW_NON_LOOPBACK=false # --- Slack ------------------------------------------------------------------ SLACK_BOT_TOKEN= SLACK_SIGNING_SECRET= SLACK_APP_TOKEN= # --- Buzz (https://github.com/block/buzz) ----------------------------------- # Buzz agents reach PIG through the MCP server, so no PIG-specific credential is # required. These are only for PIG pushing notifications into a Buzz relay. BUZZ_RELAY_URL= NOTION_CLIENT_ID= NOTION_CLIENT_SECRET= NOTION_REDIRECT_URI=http://localhost:8920/api/imports/notion/oauth/callback GOOGLE_CLIENT_ID= GOOGLE_CLIENT_SECRET= # Must use the PIG_PUBLIC_URL origin and exact /oauth/google/callback path. GOOGLE_REDIRECT_URI=http://localhost:8920/oauth/google/callback BUZZ_PRIVATE_KEY= # Optional NIP-OA owner attestation JSON for an agent identity. BUZZ_AUTH_TAG=