Skip to main content

Environment Variables

0DIN Scanner uses environment variables for two purposes:

  1. System configuration: set in your .env file (read by Docker Compose)
  2. AI provider API keys: managed via the 0DIN Scanner UI and stored encrypted per-target

System Configuration​

Set these in your root .env file before starting 0DIN Scanner.

Required​

VariableDescription
SECRET_KEY_BASESecret key for sessions and encryption. Generate with openssl rand -hex 64.
POSTGRES_PASSWORDPostgreSQL database password.
ADMIN_INITIAL_PASSWORDInitial admin password used only when creating the first admin account. Generate with openssl rand -base64 24.

Network & Port​

VariableDefaultDescription
PORT80Host port 0DIN Scanner is accessible on. Change if port 80 is unavailable.
ASSUME_SSLfalseSet to true when running behind a TLS-terminating proxy.
SESSION_COOKIE_DOMAIN—Required when ACTION_CABLE_URL uses a different subdomain (e.g., .scanner.example.com).
ACTION_CABLE_URL—WebSocket URL when WebSockets are on a different host (e.g., wss://ws.scanner.example.com/cable).

Database​

VariableDefaultDescription
POSTGRES_USERscannerDatabase username.
POSTGRES_HOSTpostgresHostname (only needed for external PostgreSQL).
POSTGRES_PORT5432Port number.
DATABASE_URL—Full PostgreSQL URL. Overrides individual POSTGRES_* vars.

See Database Configuration for DATABASE_URL format and managed PostgreSQL setup.

Scanning Behavior​

VariableDefaultDescription
EVALUATION_THRESHOLD0.2Controls vulnerability detection strictness. Lower = stricter.
RETENTION_DAYS90Days to keep reports before automatic deletion.
DEBUG_LOG_TAIL_BYTES131072Maximum bytes synced into live report execution-log tails. Set to 0 to disable live-tail reads. Blank, non-integer, or negative values fall back to the default. This is read by the Python runner at startup, applies globally, and requires restarting 0DIN Scanner after changes.

Logging​

VariableDefaultDescription
RAILS_LOG_LEVELinfoLog verbosity: debug, info, warn, error.

Admin Seed Account​

VariableDefaultDescription
ADMIN_EMAILadmin@example.comInitial admin email (used only on first boot).
ADMIN_INITIAL_PASSWORD—Required outside development/test; initial admin password used only on first boot.

AI Provider API Keys (via UI)​

API keys for AI providers are configured through the 0DIN Scanner UI, not in .env. This keeps secrets scoped per-tenant and encrypted at rest.

How to Configure API Keys​

  1. Log in to 0DIN Scanner
  2. Navigate to Configuration → Environment Variables
  3. Click New Environment Variable
  4. Set:
    • Target: leave blank for global, or select a specific target
    • Name: the variable name (see table below)
    • Value: your API key

Supported API Key Variables​

OpenAI​

OpenRouter​

Azure OpenAI​

  • AZURE_API_KEY
  • AZURE_ENDPOINT: Your Azure resource endpoint URL
  • AZURE_MODEL_NAME: Deployment name

Anthropic​

Groq​

Replicate​

Hugging Face​

Cohere​

Global vs. Target-Specific Variables​

Global variables (no target selected) apply to all scans. Target-specific variables override globals for that target only.

Use target-specific keys to:

  • Use different credentials for production vs. test targets
  • Limit credential exposure if a key is compromised
  • Test the same model with different API plans

Priority: target-specific → global (target-specific always wins)

Evaluation Threshold Tuning​

EnvironmentRecommended EVALUATION_THRESHOLD
Production (strict)0.1 – 0.15
Development / testing0.2 – 0.3
Initial exploration0.3 – 0.5