Skip to content

Environment variables ​

.env sits in the project root, one level above public/. It holds the things that must not live in the database: the database password itself, the key that signs every session cookie, and high-value API keys.

.env is the most sensitive file on your server

Anyone who reads it can forge session cookies, decrypt your payment gateway credentials and connect to your database. Verify it is unreachable with System → System → Check exposure.

Most day-to-day configuration is not here — it is in the database, editable under Settings. This page covers what is not.

After editing .env, clear the caches: System → Maintenance, or php artisan optimize:clear.

Application ​

VariableDefaultNotes
APP_NAMERadiusUsed in emails and page titles
APP_ENVproductionlocal enables development behaviour
APP_KEYgeneratedSee the warning below
APP_DEBUGfalseNever true on a live site
APP_URLyour domainUsed to build absolute URLs in emails
APP_LOCALEen
TRUSTED_PROXIES—Set when behind Cloudflare or a load balancer

APP_KEY decrypts your gateway credentials

It also signs every session cookie. Regenerating it signs everybody out and makes every encrypted value unreadable — payment gateway credentials, two-factor secrets, recovery codes. After a deliberate key:generate you must re-enter every gateway's credentials and every admin must re-enrol their second factor.

Back up .env before touching it. Never commit it.

The key is generated on your server at first run, never shipped. A key baked into a download would be identical on every site that installed it, and anyone holding it could forge session cookies for all of them.

Database ​

VariableDefaultNotes
DB_CONNECTIONmysql
DB_HOST127.0.0.1
DB_PORT3306
DB_DATABASE—
DB_USERNAME—
DB_PASSWORD—

Radius-specific ​

VariableDefaultNotes
CMS_ADMIN_PREFIXadminMoves the admin panel off the predictable path
CMS_API_PREFIXapiWhere the Mobile API answers. Change it only if the site already uses /api
CMS_MEDIA_DISKpublicWhere uploads go
CMS_DOWNLOADS_DISKprivateWhere paid files go — keep it private
CMS_DOWNLOADS_MAX_KB262144256 MB default limit for sold files
SEARCH_INDEX_PATHstorage/app/search-indexWhere index search keeps its files. Must be writable
CMS_UPDATE_URLGitHub releases endpointUnset to disable update checks
CMS_UPDATE_CHECK_HOURS24How often to check
CMS_UPDATE_REQUIRE_CHECKSUMtrueLeave this alone
CMS_UPDATE_REQUIRE_HTTPStrueLeave this alone

The two update switches are load-bearing

A release archive becomes program code running on your server. Turning off the checksum requirement means installing a download nobody verified; turning off the HTTPS requirement means fetching it over a channel anybody on the path can rewrite. They exist for testing a local manifest, not for production.

After changing CMS_ADMIN_PREFIX, clear the route cache or the old path keeps working and the new one 404s.

Theme directory ​

VariableDefaultNotes
CMS_MARKETPLACE_ENABLEDtruefalse removes Browse themes and every request it makes
CMS_MARKETPLACE_URLhttps://www.insertcart.com/marketplace/themes.jsonPoint a fork at its own catalogue
CMS_MARKETPLACE_CACHE_HOURS12How long the catalogue is remembered
CMS_MARKETPLACE_REQUIRE_CHECKSUMtrueLeave this alone
CMS_MARKETPLACE_REQUIRE_HTTPStrueLeave this alone
CMS_MARKETPLACE_REMOTE_IMAGEStruefalse stops screenshots loading from the directory's server

The two REQUIRE_ switches matter for the same reason as the update ones: an installed theme is code on your server. See Theme directory.

Sessions, cache and queue ​

VariableDefaultNotes
SESSION_DRIVERfileThe installer needs a session before a database exists
SESSION_LIFETIME120Minutes
SESSION_ENCRYPTfalse
CACHE_STOREfile
QUEUE_CONNECTIONsyncsync runs jobs immediately, in-request
FILESYSTEM_DISKlocal

sync is the right default for shared hosting, where nothing is going to run a queue worker. It means a slow email send happens inside the request that triggered it.

Mail ​

SMTP settings are normally set in Settings → Email. These exist for the providers whose keys should not sit in a database backup:

VariableFor
MAIL_MAILEROverrides the provider chosen in Settings
RESEND_KEYResend
POSTMARK_TOKENPostmark
AWS_ACCESS_KEY_IDAmazon SES
AWS_SECRET_ACCESS_KEYAmazon SES
AWS_DEFAULT_REGIONAmazon SES — us-east-1 by default

Each provider also needs its Composer package. See Settings → Email.

Firebase ​

VariableNotes
FIREBASE_CREDENTIALSPath to your service-account JSON

Defaults to storage/app/firebase/service-account.json if unset. The public web config goes in Settings → Firebase; only the service-account file belongs here.

S3 and object storage ​

VariableNotes
AWS_BUCKET
AWS_USE_PATH_STYLE_ENDPOINTtrue for MinIO and some S3-compatible hosts

If you move downloads to S3, keep the bucket private

CMS_DOWNLOADS_DISK pointing at a public bucket undoes every access check on paid files. See Digital products.

A minimal production .env ​

ini
APP_NAME="My Site"
APP_ENV=production
APP_KEY=base64:...        # generated, do not copy from another site
APP_DEBUG=false
APP_URL=https://example.com

DB_CONNECTION=mysql
DB_HOST=127.0.0.1
DB_PORT=3306
DB_DATABASE=mysite
DB_USERNAME=mysite
DB_PASSWORD=...

CMS_ADMIN_PREFIX=my-private-path

Everything else can stay at its default.

Never copy APP_KEY between sites

Two sites sharing a key means a session cookie from one is valid on the other. Each install generates its own.

Radius is open source under the MIT licence. Security issues go to the address in SECURITY.md, not the public issue tracker.