Skip to main content
You configure everything on the server side through environment variables. Local development uses .env.local, and Docker deployments use .env.production. On Vercel, you set them in your project under Settings → Environment Variables.

Environment variables

Set at least one of DEEPSEEK_API_KEY and GEMINI_API_KEY. If you set neither, visitors must enter their own key in Settings to use the app, and the sentence of the day on the home page falls back to built-in backup sentences.
Full example:
.env.production

Model providers

The app calls models through the OpenAI-compatible Chat Completions API. The server adjusts request parameters automatically for each provider:
  • DeepSeek: Returns structured results in json_object format, with thinking mode turned off.
  • Gemini: Returns structured results with a strict JSON Schema. gemini-flash-latest uses the low reasoning level, and gemini-flash-lite-latest uses the minimal reasoning level.

Use a custom API URL

If you reach a model provider through a proxy or a compatible gateway, set DEEPSEEK_API_URL or GEMINI_API_URL. The URL must be the full Chat Completions endpoint, not a base URL.
You can only set API URLs in the server’s environment variables. If a browser request includes a custom API URL, the server rejects it. This prevents the app from being used as a proxy to arbitrary addresses.

Request timeouts

Access password

When you set CODE, visitors must enter the access password before they can use the site.
  • After successful verification, the server sets an HttpOnly session cookie, ja_session, valid for 7 days.
  • The session token is signed with HMAC-SHA256, using CODE as the key. When you change CODE, all existing sessions become invalid immediately.
  • Without verification, the analysis, translation, definition, image recognition, text-to-speech, chat, and sentence-of-the-day endpoints all return 401.
  • In production, the cookie has the Secure flag, so you must access the site over HTTPS.
CODE suits simple private deployments and keeps strangers from using up your API quota. It does not replace a full account and permission system.

Umami analytics

When you set both of the following variables, the app loads the Umami tracking script:
If either one is empty, the app doesn’t load Umami. The server reads both variables at runtime, so you only need to restart the service after changing them. Docker deployments don’t need to rebuild the image. Analytics only records feature usage, never content. For details, see Keys and privacy.