.env file in development or set directly in your hosting platform for production.
Required Variables
These variables must be set for production deployments.SECRET_KEY
Type: StringRequired: Yes Django’s secret key for cryptographic signing. Used for sessions, CSRF tokens, password reset tokens, etc.
django-insecure-641xw29uuar#$5&nj!kxjozc+#2#=f6s+4lmziq&_8hnh$#@6$ (insecure, development only)
DATABASE_URL
Type: Database URLRequired: Yes (for production) PostgreSQL database connection string in URL format.
db.sqlite3 (development only)
Parsed by dj-database-url with connection pooling (conn_max_age=600).
ALLOWED_HOSTS
Type: Comma-separated listRequired: Yes (for production) Domains that Django will serve.
*
CSRF_TRUSTED_ORIGINS
Type: Comma-separated URLsRequired: Yes (for production with HTTPS) Trusted origins for CSRF protection.
https://)
Default: http://127.0.0.1:8000
Authentication Variables
Google OAuth
Required for Google Sign-In functionality.GOOGLE_CLIENT_ID
Type: StringRequired: If using Google OAuth Google OAuth 2.0 client ID from Google Cloud Console.
GOOGLE_CLIENT_SECRET
Type: StringRequired: If using Google OAuth Google OAuth 2.0 client secret.
Email Configuration
RESEND_API_KEY
Type: StringRequired: If sending emails API key for Resend email service.
DEFAULT_FROM_EMAIL
Type: Email addressRequired: If sending emails Default sender email address.
Inventario previously used SMTP (Gmail) but has migrated to Resend. The SMTP configuration is commented out in settings.py:
EMAIL_HOST_USEREMAIL_HOST_PASSWORD
AI Integration
OPENAI_API_KEY
Type: StringRequired: If using AI features OpenAI API key for AI-powered features (likely used in reporting or analytics).
SMS Integration (Twilio)
Required for SMS notifications or two-factor authentication.TWILIO_ACCOUNT_SID
Type: StringRequired: If using Twilio SMS Twilio account identifier.
TWILIO_AUTH_TOKEN
Type: StringRequired: If using Twilio SMS Twilio authentication token.
TWILIO_PHONE_NUMBER
Type: Phone numberRequired: If using Twilio SMS Twilio phone number for sending SMS (E.164 format).
Application Behavior
DEBUG
Type: Boolean stringRequired: No Enables Django debug mode.
True- Enable debug mode (development)False- Disable debug mode (production)
False
Side effects when DEBUG=True:
SESSION_COOKIE_SECUREis disabledCSRF_COOKIE_SECUREis disabled- Detailed error pages are shown
- Static files are served by Django (not WhiteNoise)
Development vs Production
Development .env Example
Production Environment Variables
Security Notes
Loading Environment Variables
Inventario usespython-dotenv to load variables from .env:
- System environment variables (highest priority)
- Variables from
.envfile - Default values in code (lowest priority)