.env.local, and Docker deployments use .env.production. On Vercel, you set them in your project under Settings → Environment Variables.
Environment variables
Set at least one of
DEEPSEEK_API_KEY and GEMINI_API_KEY. If you set neither, visitors must enter their own key in Settings to use the app, and the sentence of the day on the home page falls back to built-in backup sentences..env.production
Model providers
The app calls models through the OpenAI-compatible Chat Completions API.
The server adjusts request parameters automatically for each provider:
- DeepSeek: Returns structured results in
json_objectformat, with thinking mode turned off. - Gemini: Returns structured results with a strict JSON Schema.
gemini-flash-latestuses thelowreasoning level, andgemini-flash-lite-latestuses theminimalreasoning level.
Use a custom API URL
If you reach a model provider through a proxy or a compatible gateway, setDEEPSEEK_API_URL or GEMINI_API_URL. The URL must be the full Chat Completions endpoint, not a base URL.
Request timeouts
Access password
When you setCODE, visitors must enter the access password before they can use the site.
- After successful verification, the server sets an HttpOnly session cookie,
ja_session, valid for 7 days. - The session token is signed with HMAC-SHA256, using
CODEas the key. When you changeCODE, all existing sessions become invalid immediately. - Without verification, the analysis, translation, definition, image recognition, text-to-speech, chat, and sentence-of-the-day endpoints all return
401. - In production, the cookie has the
Secureflag, so you must access the site over HTTPS.
CODE suits simple private deployments and keeps strangers from using up your API quota. It does not replace a full account and permission system.