Reference

Environment Variables

Common environment variables used by Federation.

VariablePurpose
DOWNCITY_FEDERATION_TOKEN_SIGNING_KEYLets Federation issue and validate user_token internally
DOWNCITY_CITY_DATABASE_URLOptional. Specifies the database URL used by Federation
OPENAI_API_KEYExample provider key; recommended to write it into the Federation database through Admin env
OPENAI_BASE_URLExample provider base URL; recommended to write it into the Federation database through Admin env

fed deploy interactively provisions the administrator ID and password. The password is stored as a PBKDF2 digest and administrator sessions are stored server-side; there is no administrator key environment variable. DOWNCITY_FEDERATION_TOKEN_SIGNING_KEY and BETTER_AUTH_SECRET are generated automatically on first boot and stored in Federation's env table.

If DOWNCITY_CITY_DATABASE_URL is omitted, the default database path is:

.base/downcity.sqlite

How provider env is used

The model handler reads directly from input.env:

import {
  AIChannel,
  stream_openai_compatible_model,
  type AIChannelStreamInput,
  type AIChannelStreamResult,
} from "@downcity/federation";

class DeepSeekChannel extends AIChannel {
  constructor() {
    super({
      id: "deepseek",
      env: { DEEPSEEK_API_KEY: "DeepSeek API Key" },
      base_url: "https://api.deepseek.com",
    });
  }

  protected async stream(
    input: AIChannelStreamInput,
  ): Promise<AIChannelStreamResult> {
    const api_key = input.env("DEEPSEEK_API_KEY");
    if (!api_key) throw new Error("DEEPSEEK_API_KEY is required");
    return stream_openai_compatible_model(input, {
      api_key,
      base_url: this.base_url ?? "https://api.deepseek.com/v1",
    });
  }
}

const deepseek = new DeepSeekChannel();

So the practical rules are simple:

  • you choose the env key names yourself
  • uppercase snake case is recommended
  • read values through input.env(key) inside stream()

Write values into the database

A trusted backend can write provider keys through Embassy Admin:

await embassy.admin.env.upsert({
  key: "DEEPSEEK_API_KEY",
  value: "sk-xxx",
});

These values are stored in the env table inside the Federation database. Business runtime reads only from that Federation-managed env table and no longer falls back to .env or process environment variables.

See also AIChannel environment variables.