Skip to main content

Configuration

One .env file, read at container start. Real environment variables always win, so a hosting platform's own configuration takes precedence. Required variables have no default — the app refuses to start without them. Optional ones can be left empty to disable a feature.

Database — required​

Variable
SPRING_DATASOURCE_URLJDBC URL of the tenant database (jdbc:postgresql://hrida-postgres:5432/hridaone in the bundled compose)
DB_USERNAME / DB_PASSWORDCredentials
SPRING_JPA_HIBERNATE_DDL_AUTOupdate for first deploy / dev; validate in production

App URL & CORS​

Variable
APP_BASE_URL / APP_FRONTEND_URLPublic origin — https://one.hrida.ai in production, http://localhost:8080 locally
CORS_ALLOWED_ORIGINSComma-separated allow-list of browser origins
FILE_UPLOAD_DIRWhere uploads land (/app/uploads, a Docker volume)

Secrets — required​

VariableGenerateNotes
JWT_SECRETopenssl rand -hex 6464+ chars, never reused
GLOBAL_ADMIN_SECRETopenssl rand -hex 32Global Admin bootstrap; must differ from JWT_SECRET
SECURITY_KEYWORD_ENC_KEYopenssl rand -hex 32AES key for the security keyword; must differ from both above

Email — required​

Variable
MAIL_HOST / MAIL_PORTSMTP server (smtp.gmail.com / 587)
MAIL_USERNAME / MAIL_PASSWORDCredentials — Gmail requires an App Password with 2-Step Verification
ADMIN_EMAIL / MAIL_FROMDefault sender identity (fall back to MAIL_USERNAME)

Per-company branded sending over SES is configured in-app, not here.

Optional integrations​

FeatureVariables
Cloudinary mediaCLOUDINARY_NAME, CLOUDINARY_KEY, CLOUDINARY_SECRET
OpenAI document OCROPENAI_API_KEY, OPENAI_RESPONSES_URL, OPENAI_OCR_MODEL (gpt-4.1-mini)
Razorpay paymentsRAZORPAY_KEY_ID, RAZORPAY_KEY_SECRET, RAZORPAY_WEBHOOK_SECRET

Keycloak SSO — optional​

Leave all blank for native auth. See Authentication → Keycloak SSO.

KEYCLOAK_ISSUER_URI · KEYCLOAK_CLIENT_ID · KEYCLOAK_CLIENT_SECRET · KEYCLOAK_SSO_CALLBACK_URL · KEYCLOAK_SSO_COOKIE_SECURE · KEYCLOAK_ALLOWED_CLIENT_IDS · KEYCLOAK_ADMIN_CLIENT_ID · KEYCLOAK_ADMIN_CLIENT_SECRET · KEYCLOAK_SYNC_INTERVAL_MS · KEYCLOAK_SYNC_INITIAL_DELAY_MS

LDAP — optional​

The shared provisioning directory this app owns. See Authentication → LDAP.

LDAP_PROVISIONING_ENABLED · LDAP_URL · LDAP_BASE_DN (dc=hrida,dc=local) · LDAP_ADMIN_DN · LDAP_ADMIN_PASSWORD

A tenant's own LDAP / AD federation is configured per company in-app, not here.

Hrida.ai is proprietary software of Zlabs Innovation. See the license for terms. © 2026 Zlabs Innovation.