System

Platform status

Whether each variable is set and whether it is structurally valid, and where each configurable value actually resolves from — the environment, the Integration Hub, or a managed key file. Values are never read into this page — not masked, not truncated, not prefixed.

This screen is read-only. It never restarts, deploys, migrates, backs up or restores anything — those are YELLOW/RED actions under the security model and run from a shell through ops/. Where an action would help, the exact command to run is shown instead of a button.

Presence and validity only

Configuration

OK
OK

All required configuration present

26 optional variables not set.

Values are never read into this page — only whether each variable is set and whether it is structurally valid.

Deployment

  • DATABASE_URL

    Real PostgreSQL connection string. Unset means the file-backed PGlite store, which is a single-process, single-host database.

    optionalSet
  • PAXX_DB_MODE

    `memory` forces an ephemeral in-memory store. Used by tests; never set in production.

    optionalNot set (optional)
  • PAXX_PUBLIC_URL

    Public base URL of this deployment. OAuth redirect URIs are built from it; without it they are guessed from the request's forwarded origin.

    Set
  • PAXX_SERVICE_UNIT

    systemd user unit name, used to read this service's own journal. Defaults to `paxx-web`.

    optionalSet
  • PAXX_LOG_LEVEL

    Minimum level this process logs. Defaults to `info` in production, `debug` otherwise.

    optionalNot set (optional)
  • PAXX_LOG_FILE

    Optional log file to tail when journald is unavailable.

    optionalNot set (optional)
  • PAXX_STATE_DIR

    Where the ops scripts write the deployment and backup journals. Defaults to ~/.paxx/state.

    optionalSet
  • PAXX_BACKUP_MAX_AGE_HOURS

    Age after which the newest successful database backup counts as stale. Defaults to 48.

    optionalNot set (optional)
  • PAXX_BUILD_COMMIT

    Set by the deploy script so the running process reports the commit it deployed.

    optionalSet
  • PAXX_RELEASE_ID

    Set by the deploy script to identify the release directory this process runs from.

    optionalSet
  • PAXX_DISABLE_CONNECTOR_READ_CACHE

    Turns off the per-request connector read cache, so every read reaches its provider. An escape hatch, not a tuning knob — set only if a provider's data looks stale within a single page render, which would be a bug in the read allowlist.

    optionalNot set (optional)
  • PAXX_CONNECTOR_READ_STATS

    Logs one line per connector read (HIT/MISS/PASSTHROUGH/UNKEYED). Diagnostic only, and deliberately noisy — it exists to count provider reads per render.

    optionalNot set (optional)

Security

  • PAXX_SECRET_KEY

    Seals integration credentials at rest. Without it no Connect flow can store anything — sealing fails rather than writing plaintext.

    Set
  • PAXX_TOKEN_ENCRYPTION_KEY

    Seals Google OAuth tokens and PKCE verifiers. Without it the real Google connector is never selected and both account slots run the mock.

    Set
  • PAXX_KEY_DIR

    Where the two managed encryption keys are written when they are created from the Integration Hub rather than set above. Defaults to `packages/db/.paxx-keys`, which is inside the release directory a deploy replaces — so it becomes required once PAXX_RELEASE_ID shows this process runs from a release, unless both keys come from the environment. Losing it loses every credential sealed with those keys, and nothing software-side can repair that.

    optionalSet

Integrations

  • GITHUB_TOKEN

    Read-only PAT, and an override: since M10 this can also be stored from the Integration Hub, so `unset` here does not by itself mean the connector is on mock data — the Hub is authoritative for that.

    optionalNot set (optional)
  • CLICKUP_TOKEN

    Read-only API token, and an override — like GITHUB_TOKEN, it can instead be stored from the Integration Hub.

    optionalNot set (optional)
  • PAPERCLIP_API_KEY

    Paperclip read credentials. Both this and PAPERCLIP_COMPANY_ID are needed before the real, read-only connector is selected.

    optionalNot set (optional)
  • PAPERCLIP_COMPANY_ID

    Paperclip company scope. Pairs with PAPERCLIP_API_KEY.

    optionalNot set (optional)
  • PAPERCLIP_API_BASE

    Overrides Paperclip's API base URL. Defaults to its local API on this host.

    optionalNot set (optional)
  • OBSIDIAN_API_URL

    Headless alternative to connecting Obsidian from the browser. A stored credential overrides it.

    optionalNot set (optional)
  • OBSIDIAN_API_KEY

    Obsidian Local REST API key, for the headless path only.

    optionalNot set (optional)
  • OBSIDIAN_VAULT_SCOPES

    Operator ceiling on vault paths. Every grant the app issues is capped by it; unset means the whole vault.

    optionalNot set (optional)
  • SPOTIFY_CLIENT_ID

    Operator-provisioned OAuth client. Without it the Spotify Connect button is not offered.

    optionalNot set (optional)
  • SPOTIFY_CLIENT_SECRET

    Pairs with SPOTIFY_CLIENT_ID.

    optionalNot set (optional)
  • SPOTIFY_REDIRECT_URI

    Overrides the derived Spotify callback URL. Spotify matches it byte-for-byte.

    optionalNot set (optional)
  • WEATHER_PROVIDER

    `open-meteo` (keyless, the default) or `mock` to force fixtures.

    optionalNot set (optional)
  • WEATHER_CACHE_TTL_SECONDS

    Weather snapshot cache TTL. Defaults to 600.

    optionalNot set (optional)
  • GOOGLE_OAUTH_CLIENT_ID

    Operator-provisioned OAuth client. Needed, with its secret and PAXX_TOKEN_ENCRYPTION_KEY, before the real Google connector is selected.

    optionalNot set (optional)
  • GOOGLE_OAUTH_CLIENT_SECRET

    Pairs with GOOGLE_OAUTH_CLIENT_ID.

    optionalNot set (optional)
  • GOOGLE_OAUTH_REDIRECT_URI

    Overrides the derived Google callback URL. Google matches it exactly; a mismatch is the usual reason consent fails.

    optionalNot set (optional)

Provisioning

  • PAPERCLIP_WRITE_ENABLED

    Separate opt-in for Paperclip writes. Without `true` the provisioning pipeline can plan and dry-run but never execute.

    optionalNot set (optional)
  • PAXX_PROJECTS_ROOT

    The only directory provisioning may create or remove anything in. Must exist, be writable, and not be a symlink; the executor never creates it.

    optionalNot set (optional)
  • PAPERCLIP_ENVIRONMENT_ID

    Pins provisioned projects to a Paperclip environment. Unset means Paperclip picks.

    optionalNot set (optional)
  • PAPERCLIP_WORKTREE_PARENT_DIR

    Overrides where Paperclip puts per-task worktrees. Leave unset to use its own default.

    optionalNot set (optional)

Persistence

Database

OK

Reachable in 4ms

23 tables

Driver
PostgreSQL
Store
postgres://paxx@127.0.0.1:55432/paxx_dev
Reachable
yes4ms
Migrations
up to date11 applied / 11 shipped
Tables
23

Environment, Hub, key file — never a value

Where each value resolves from

OK
OK

2 values resolve, 12 unset

2 from the environment, 0 from the Integration Hub, 0 from a managed key file. 4 belong to providers with no implementation to configure.

Configuration resolves from three tiers, environment first: the server environment, then operator configuration written in the Integration Hub, then nothing. The environment always wins, so a value it owns cannot be changed from the Hub.

GitHub

Paperclip

Google Workspace (primary)

ClickUp

Obsidian

Spotify

Xentral

  • Credential

    This provider has no client code, so there is nothing to configure — it is fixture-only by declaration, not by a missing variable.

    secretNot implemented

Shopify

  • Credential

    This provider has no client code, so there is nothing to configure — it is fixture-only by declaration, not by a missing variable.

    secretNot implemented

PAXX P1

  • Credential

    This provider has no client code, so there is nothing to configure — it is fixture-only by declaration, not by a missing variable.

    secretNot implemented

Carrier network

  • Credential

    This provider has no client code, so there is nothing to configure — it is fixture-only by declaration, not by a missing variable.

    secretNot implemented

Weather

Encryption keys

  • PAXX_SECRET_KEY

    PAXX_SECRET_KEY

    Resolved from the server environment. The environment always wins, so the Hub shows this read-only and refuses a write to it.

    secretEnvironment
  • PAXX_TOKEN_ENCRYPTION_KEY

    PAXX_TOKEN_ENCRYPTION_KEY

    Resolved from the server environment. The environment always wins, so the Hub shows this read-only and refuses a write to it.

    secretEnvironment

Status collected (just now)