Skip to content

Environment variables

Kosmos is configured through config/.env, the only file it reads. This page lists every variable. How to create the file is covered in Configuration.

Required means there is no default and the application will not start without a value. A default of empty means the feature the variable belongs to stays off or falls back until it is set.

Core

Variable Default Description
SECRET_KEY Required Django's secret key. Generate one with: python3 -c 'import secrets; print(secrets.token_urlsafe(50))'
DEBUG False Django debug mode. Always False in production. (boolean)
ENV Required Name of this environment: prod or dev. dev keeps login sessions in files under .dev-sessions/ and marks the interface as a development instance.
ALLOWED_HOSTS Required Comma-separated host names the application answers to. (comma-separated list)
CSRF_TRUSTED_ORIGINS empty Comma-separated full origins (scheme, host and port when not the default) trusted for form posts. Needed behind a reverse proxy. (comma-separated list)
PUBLIC_BASE_URL empty Scheme and host used to build absolute links outside a web request, such as payment links in emails sent by the background worker. Blank falls back to the host of the request that triggered the send, when there is one.
TIME_ZONE America/New_York The firm's time zone, as a tz database name (for example America/Chicago). Dates shown in the app, the times scheduled jobs run, and the zone events are written to Google Calendar in all follow it.

Database

Variable Default Description
DB_NAME Required PostgreSQL database name.
DB_USER Required PostgreSQL role. It must own the database.
DB_PASSWORD Required Password for that role.
DB_HOST localhost Database host.
DB_PORT 5432 Database port.

Email

Variable Default Description
EMAIL_BACKEND 'console' if DEBUG else 'smtp' How outgoing mail is delivered: console (print to the process log, no credentials needed), smtp, or locmem (tests). Defaults to console when DEBUG is on and smtp when it is off.
EMAIL_HOST empty SMTP server host.
EMAIL_PORT 587 SMTP server port. (integer)
EMAIL_USE_TLS True Use STARTTLS on the SMTP connection. (boolean)
EMAIL_TIMEOUT 10 Seconds before a stalled SMTP connection is abandoned. Login codes are sent during the request, so a hung connection would otherwise hang the login page. (integer)
EMAIL_HOST_USER empty SMTP user name.
EMAIL_HOST_PASSWORD empty SMTP password.
SERVER_EMAIL webmaster@localhost From address for error reports sent to ADMINS.
DEFAULT_FROM_EMAIL the value of SERVER_EMAIL From address for mail the application sends. Defaults to SERVER_EMAIL.
BILLING_FROM_EMAIL the value of DEFAULT_FROM_EMAIL From address for client-facing billing mail (invoices and payment requests). Defaults to DEFAULT_FROM_EMAIL.
ADMINS empty People who receive error emails, as a Python list of (name, address) tuples.

File storage

Variable Default Description
STORAGE_BACKEND local Where uploaded files are kept: local (the media/ directory) or s3 (an S3-compatible object store). With local storage, never serve media/ directly from the web server: it holds confidential client documents, and the application streams them only to signed-in users.
DIGITAL_OCEAN_REGION_NAME Required when STORAGE_BACKEND == 's3' Object store region. Required when STORAGE_BACKEND=s3, as are the four settings below. The names say DigitalOcean; any S3-compatible store works.
DIGITAL_OCEAN_ENDPOINT_URL Required when STORAGE_BACKEND == 's3' Object store endpoint URL.
DIGITAL_OCEAN_BUCKET_NAME Required when STORAGE_BACKEND == 's3' Bucket name.
DIGITAL_OCEAN_ACCESS_KEY_ID Required when STORAGE_BACKEND == 's3' Access key id.
DIGITAL_OCEAN_SECRET_ACCESS_KEY Required when STORAGE_BACKEND == 's3' Secret access key.

Google Workspace

Variable Default Description
GOOGLE_DATA_DIR google/ in the repository Directory holding the Google OAuth client file (google_tokens.json) and the tokens generated when an integration is connected. A relative path is resolved from the repository root.
CALENDAR_ID empty Id of the Google Calendar that events sync with.
DRIVE_NOTES_ROOT Matters - Open Name of the Drive folder that holds one subfolder per matter.
DRIVE_SHARED_DRIVE_ID empty Shared Drive id. Set only when the root folder lives in a Shared Drive.
GMAIL_LABEL_ROOT Matters - Open Parent Gmail label whose child labels can be linked to matters. Blank offers every user label in the mailbox.

Drafting (LibreOffice)

Variable Default Description
SOFFICE_BIN soffice Headless LibreOffice binary for the server-side redline module (apps/drive/redline.py). Drafting does not currently use that module: edits are applied by the companion extension in the user's LibreOffice.
UNO_PYTHON /usr/bin/python3 A Python interpreter that has the UNO bindings (the system python3 with the python3-uno package), not the project virtualenv. Used only by the same server-side redline module.

AI and research

Variable Default Description
ANTHROPIC_API_KEY empty Anthropic API key, for the Claude models.
GEMINI_API_KEY empty Google Gemini API key, for the Gemini models and for the embeddings behind semantic search (the one feature only Gemini provides).
SEMANTIC_AUTO_INDEX True Re-embed a record for semantic search whenever it is saved. The built-in default is True; nothing is queued while no Gemini key is set. After setting one, run manage.py build_semantic_index once. (boolean)
COURTLISTENER_API_KEY empty CourtListener API token, for case law search and citation checking. While it is blank, the AI is not offered the case law search tools.
CHAT_RETENTION_DAYS 180 Days after a matter closes before the weekly purge deletes its AI chats. 0 keeps them indefinitely. (integer)

Intakes

Variable Default Description
KOSMOS_SEAM_KEY empty Shared secret for the intake API used by a connected website or intake application (the X-Seam-Key header). While blank, that API refuses every request.
MAILGUN_WEBHOOK_SIGNING_KEY empty Mailgun HTTP webhook signing key, verifying inbound mail posted to /api/inbound-email/. While blank, that webhook refuses every request.
INTAKE_INBOUND_RECIPIENT kosmos-intakes The part before the @ of the address this instance accepts forwarded intake mail on. Mail for any other address is dropped, which lets several instances share one Mailgun route.
INTAKE_FORM_LINK_MAX_AGE 2592000 Seconds a client intake-form link stays valid. Defaults to 30 days. (integer)

Billing and payments

Variable Default Description
LAW_FIRM_ID empty The firm's id in LEDES invoice exports. While it is blank, the Download Ledes action is hidden.
PAYMENT_PROCESSOR fake Which processor collects online payments: none (online payment off; the emailed link still shows the invoice), lawpay, stripe, confido, or fake. fake is for development: it records a payment although no money moves, so never run it where real clients receive invoices. The built-in default is fake; the installer sets none for a production install.
INVOICE_PAY_LINK_MAX_AGE 7776000 Seconds an emailed payment link stays valid. Defaults to 90 days. Resending the invoice issues a fresh link. (integer)
LAWPAY_PUBLIC_KEY empty LawPay (AffiniPay) public key, used in the browser by the hosted card fields. Test keys reach only test accounts.
LAWPAY_SECRET_KEY empty LawPay secret key, used by the server.
LAWPAY_OPERATING_CARD_ACCOUNT_ID empty LawPay deposit account for card payments to the operating account. List the account ids with manage.py lawpay_accounts. Blank lets the gateway pick its primary account; the same applies to the three settings below.
LAWPAY_OPERATING_ECHECK_ACCOUNT_ID empty LawPay deposit account for eCheck payments to the operating account.
LAWPAY_TRUST_CARD_ACCOUNT_ID empty LawPay deposit account for card payments to the trust account. Required before a trust deposit request can be sent: a trust charge is never left to the gateway's choice of account.
LAWPAY_TRUST_ECHECK_ACCOUNT_ID empty LawPay deposit account for eCheck payments to the trust account.
LAWPAY_API_BASE https://api.8am.com LawPay API host. Change only if AffiniPay moves it.
STRIPE_PUBLISHABLE_KEY empty Stripe publishable key, used in the browser. The firm supplies keys for its own Stripe account.
STRIPE_SECRET_KEY empty Stripe secret key, used by the server.
STRIPE_WEBHOOK_SECRET empty Stripe webhook signing secret for the /webhooks/stripe/ endpoint.
CONFIDO_API_KEY empty Confido Legal (Gravity Legal) API key.
CONFIDO_WEBHOOK_SECRET empty Confido webhook signing secret for the /webhooks/confido/ endpoint.
CONFIDO_OPERATING_BANK_ACCOUNT_ID empty Confido bank account id that invoice payments are deposited to. Confido has no default account, so both account ids are required.
CONFIDO_TRUST_BANK_ACCOUNT_ID empty Confido bank account id that trust deposits go to.
CONFIDO_API_BASE https://api.sandbox.gravity-legal.com/v2 Confido API endpoint. The default is the sandbox; for live payments set https://api.gravity-legal.com/v2
CONFIDO_HOSTED_FIELDS_URL https://js.sandbox.gravity-legal.com/hosted-fields.js Confido hosted-fields script. The default is the sandbox; for live payments set https://js.gravity-legal.com/hosted-fields.js