infra/relay/.env.example

# Required: Relay API and managed tunnel domains
# Production adopts retained DNS zones in your Cloudflare account. The API
# zone serves relay.<zone> in production and relay-<stage>.<zone> for personal
# stages. Managed environment endpoints are provisioned below the tunnel zone.
RELAY_API_ZONE_NAME=example.com
RELAY_TUNNEL_ZONE_NAME=tunnels.example.com

# Optional: inactive tunnel cleanup. Start with dry-run, verify the cleanup
# logs, then set enabled. Unset and off both disable cleanup.
# RELAY_TUNNEL_CLEANUP_MODE=off

# Optional: Relay domain override
# Set this only when the derived relay hostname should not be used.
# RELAY_DOMAIN=relay.example.com

# Required: Clerk
# Get the keys from the Clerk Dashboard under API keys. Set the JWT audience to
# the `aud` claim configured on the `t3-relay` JWT template.
CLERK_PUBLISHABLE_KEY=pk_test_...
CLERK_SECRET_KEY=sk_test_...
CLERK_JWT_AUDIENCE=t3-code-relay

# Apple Push Notification service (required unless APNS_ENABLED=false)
# Set APNS_ENABLED=false for an Android-only development relay.
# Get these values from your Apple Developer account. Use `sandbox` for
# development APNs credentials and `production` for production credentials.
APNS_ENVIRONMENT=sandbox
APNS_TEAM_ID=...
APNS_KEY_ID=...
APNS_BUNDLE_ID=...
APNS_PRIVATE_KEY=...

# Optional: Android push. Set this secret to the service account JSON from
# Firebase Project settings > Service accounts. Never put it in an app build.
# FCM_SERVICE_ACCOUNT={...}