Skip to main content
This page is for the self-hoster and for developers looking a variable up. It lists what the orchestrator, the site SDK, the editor and the command-line tools actually read, grouped by what each variable configures.
Which process reads what. In library mode the site and the orchestrator are the same process, so the site and orchestrator variables land in one .env.local. In a standalone deployment they are separate environments, and each variable goes where the table says. Most variables are read when they are first needed rather than once at boot. Provider keys are the exception that matters: change a key and restart the process.
Boolean flags accept 1/true/yes/on and 0/false/no/off.

Model providers

At least one key is required for chat. Everything else in the editor works without one: the preview, the property panel and click-to-select. With several keys set, a request that names no provider goes to OpenAI, then Anthropic, then Gemini, in that order. The editor names Anthropic on every request when that key is present. CHAT_PLANNER_FORCE_SONNET=1 pins provider-less requests to Anthropic when its key is set.

Model selection, per tier

Each provider resolves four tiers. Override any of them by name:
Leave these unset unless you mean to pin a model. A pinned id stays pinned when Avocado’s defaults move to a newer generation, which is why .env.example no longer sets them.
Also read: See AI providers.

Images

Voice input

POST /audio/transcribe tries OpenAI first. It falls back to Gemini when OpenAI fails or is over quota. With neither provider key set, /status/planner reports features.audioTranscription: false and the editor hides the microphone button.

Access and security

The full picture, including what is open and what is closed by default, is on security and access. The variables:
Library mode refuses every request under NODE_ENV=production when none of ACCESS_PASSWORD_HASH, ORCHESTRATOR_ACCESS_TOKEN or a code-level auth hook is configured. That is deliberate. See security and access.

The site

Read by your app through the SDK or the Astro integration. A mismatch between the editor’s draft secret and the site’s DRAFT_MODE_SECRET degrades to “the preview shows published content” rather than to an error, which is why it goes unnoticed. avocado-register checks the secret against the orchestrator’s and stops, writing nothing, when they differ.

Publishing

See publishing.

Persistence

Full detail on state and backups.

Operations

Telemetry

See telemetry events and token usage.

Chat pipeline flags

These tune the planner rather than configure it. Defaults are tuned for responsiveness. Turn flags off one at a time when debugging, not as a matter of course.

Jira

Only read when the Jira channel is configured. JIRA_BASE_URL · JIRA_USER_EMAIL · JIRA_API_TOKEN · JIRA_WEBHOOK_SECRET · JIRA_SITE_ID · JIRA_SESSION · JIRA_AGENT_ACCOUNT_ID · JIRA_TRIGGER_STATUS · JIRA_EXECUTE_STATUS · JIRA_PREVIEW_STATUS · JIRA_REVIEW_STATUS · JIRA_DONE_STATUS · JIRA_FAILED_STATUS · JIRA_AUTO_PUBLISH · JIRA_MAX_REVIEW_PASSES · JIRA_POLL_ENABLED · JIRA_POLL_INTERVAL_MS · JIRA_POLL_JQL

MCP server

See MCP server.

The editor

avocado-studio start writes the editor’s configuration into the page it serves. The CLI reads these as an alternative to its flags. See CLI and packages. AVOCADO_ORCHESTRATOR_URL · AVOCADO_SITE_ORIGIN · AVOCADO_PUBLISH_TOKEN · AVOCADO_SITE_DRAFT_SECRET (then DRAFT_MODE_SECRET) · PORT · HOST When you build apps/editor from source instead, Vite reads VITE_* variables at build time and inlines them into the JavaScript bundle:
Every VITE_* value is readable by anyone who can load the editor. Do not build VITE_SITE_DRAFT_SECRET or VITE_PUBLISH_TOKEN into an editor served on a public URL. Give the orchestrator DRAFT_MODE_SECRET, PUBLISH_TOKEN and an access password instead. The editor then fetches them from GET /editor/credentials after sign-in.