Configuration

Upvora is configured entirely through environment variables. The essentials are below; anything not set falls back to a sensible default.

Core

VariableDescription
BASE_URLPublic URL, e.g. https://feedback.example.com.
DATABASE_URLPostgres connection string.
JWT_SECRETLong random secret used to sign sessions.
EMAIL_NOREPLYThe "from" address for outgoing mail.

Email providers

Choose one provider with EMAIL (or it is inferred from whichever keys are set). EMAIL_NOREPLY must be an address on a domain your provider is allowed to send from.

ProviderVariables
SMTPEMAIL=smtp, EMAIL_SMTP_HOST, EMAIL_SMTP_PORT, EMAIL_SMTP_USERNAME, EMAIL_SMTP_PASSWORD, EMAIL_SMTP_ENABLE_STARTTLS
MailgunEMAIL=mailgun, EMAIL_MAILGUN_API, EMAIL_MAILGUN_DOMAIN, EMAIL_MAILGUN_REGION
Amazon SESEMAIL=awsses, EMAIL_AWSSES_REGION, EMAIL_AWSSES_ACCESS_KEY_ID, EMAIL_AWSSES_SECRET_ACCESS_KEY
ResendEMAIL=resend, EMAIL_RESEND_API_KEY

Resend: set EMAIL_RESEND_API_KEY and make sure EMAIL_NOREPLY is on a domain you've verified in Resend. Upvora sends one request per recipient and retries briefly on rate limits.

Social sign-in

Google and GitHub are two env vars each; any other OAuth2/OIDC provider (Microsoft, Authentik, Keycloak…) is added from Admin → Authentication.

VariableDescription
OAUTH_GOOGLE_CLIENTID / OAUTH_GOOGLE_SECRETGoogle sign-in.
OAUTH_GITHUB_CLIENTID / OAUTH_GITHUB_SECRETGitHub sign-in.

OAuth callback URLs follow BASE_URL/oauth/<provider>/callback.

Other

Upvora is open source under AGPL-3.0 — a friendly fork of Fider, not affiliated with it.  ·  Built & maintained by HODY