.env file beside your Compose file and recreate the container after changes:
Server and access
With
AUTH_TOKEN set, open https://host/?token=THE_TOKEN once to establish an access cookie. The health endpoint remains open.
For DEVICE_ALLOWLIST, copy full fingerprints from QR code → Connection details or Known devices. Devices must prove they hold the matching key. Remove a fingerprint and restart to revoke access.
If direct connections fail across networks or firewalls, configure TURN. Encrypted server relay remains the fallback.
HTTPS reverse proxies
SetTRUST_PROXY=1 only behind a proxy you control.
- Keep the backend port private.
- Preserve the public
Hostheader or sendX-Forwarded-Host, including any non-default port. - Account changes require an HTTPS Origin matching that host. Account cookies are Secure.
ALLOWED_ORIGINSaffects WebSockets, not the account origin check.
Device and room limits
Replacing a device connection does not need another slot. Each account can own two rooms; creating a third replaces its oldest. Rooms switch to server relay above six members.
File and text budgets
Byte limits include encrypted content and envelopes. Accepted uploads reserve their declared size.
The smaller global budgets take precedence over per-chat ceilings. Files cannot consume the text budget.
At capacity, older completed pending items of the same kind may be removed. Active uploads and downloads are protected from capacity eviction. Online participants receive warnings and removal notices.
Relay expiry
Rooms are exempt from the one-device expiry rule. Self-chat has a 24-hour offline window and a maximum age of three days. See relay lifetimes.
Storage paths
Keep accounts in their separate named volume. Do not mount a persistent relay volume.
Local Node accounts are disabled unless
ACCOUNTS_DB is set. Local relay data defaults to evakage-blobs under the OS temporary directory.