> For the complete documentation index, see [llms.txt](https://docs.uxwizz.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.uxwizz.com/guides/environment-settings.md).

# Environment settings

UXWizz can read server environment variables for database connections, application security, and optional feature restrictions. These settings need server or hosting-panel access.

For a new Linux installation, use the [interactive installer](/installation/setup-uxwizz-server/ubuntu-20.04.md). You do not need to prepare environment variables first.

### How UXWizz Reads Environment Variables

PHP reads these values through `getenv()`, `$_ENV`, or `$_SERVER`. A variable set in your terminal is not necessarily available to the web server or scheduled tasks.

Only the exact value `1` activates a feature-disable flag. Missing flags keep the normal behavior.

### Setting Environment Variables

Keep credentials in protected server configuration outside the web root. Make the same application settings available to both web requests and scheduled tasks.

#### Linux / Ubuntu

#### 1. Use the installer's protected environment file <a href="#id-1.-add-global-env-variables-to-etc-environment" id="id-1.-add-global-env-variables-to-etc-environment"></a>

The current Linux installer creates `/etc/uxwizz/uxwizz.env`, owned by root with mode `0600`. It configures Apache and the UXWizz task services to use this file.

To change a setting:

1. Back up the file to a protected location.
2. Edit it on the server:

   ```bash
   sudoedit /etc/uxwizz/uxwizz.env
   ```
3. Keep the existing database values and `UXWIZZ_APP_KEY`. Add only the setting you need, for example:

   ```dotenv
   UXWIZZ_DISABLE_AI_CHAT=1
   ```
4. Restart Apache to load the changed environment:

   ```bash
   sudo systemctl restart apache2
   ```

The task services read the file on their next start. Check the dashboard and the next run in **Settings → Scheduled Tasks**.

#### Manual Apache setup

On a server that was not configured by `install.sh`, create a protected environment file for UXWizz:

```bash
sudo install -d -m 0700 /etc/uxwizz
sudo touch /etc/uxwizz/uxwizz.env
sudo chmod 0600 /etc/uxwizz/uxwizz.env
sudoedit /etc/uxwizz/uxwizz.env
```

Add the settings you need, one per line. For example:

```dotenv
UXWIZZ_DISABLE_AI_CHAT=1
```

Run `sudo systemctl edit apache2` and put this block **between the editor's preservation comment lines**:

```ini
[Service]
EnvironmentFile=/etc/uxwizz/uxwizz.env
```

In the virtual host that actually serves UXWizz, pass the configured variables to PHP:

```apache
PassEnv UXWIZZ_DISABLE_AI_CHAT
```

Add other variable names to `PassEnv` only when you set them in the environment file. For database settings these are `UXWIZZ_DB_HOST`, `UXWIZZ_DB_NAME`, `UXWIZZ_DB_USER`, and `UXWIZZ_DB_PASSWORD`; also pass `UXWIZZ_APP_KEY` if configured. Do not paste their values into the virtual host.

For HTTPS this is normally the `*:443` virtual host, often in a `*-le-ssl.conf` file. A port-80 virtual host that only redirects to HTTPS does not serve the PHP application.

```bash
sudo systemctl daemon-reload
sudo apache2ctl configtest
sudo systemctl restart apache2
```

Restart only after the configuration test succeeds. Check the non-secret flag through its effect in UXWizz. [Apache's PassEnv directive](https://httpd.apache.org/docs/2.4/mod/mod_env.html#passenv) passes values inherited by the service; exporting a value in your SSH terminal alone is insufficient.

#### PHP-FPM

For NGINX or Apache with PHP-FPM, add variables to the **pool serving UXWizz**, for example `/etc/php/8.3/fpm/pool.d/www.conf`:

```ini
env[UXWIZZ_DISABLE_AI_CHAT] = 1
```

If PHP-FPM's systemd service reads the protected environment file, forward required values individually:

```ini
env[UXWIZZ_DB_HOST] = $UXWIZZ_DB_HOST
env[UXWIZZ_DB_NAME] = $UXWIZZ_DB_NAME
env[UXWIZZ_DB_USER] = $UXWIZZ_DB_USER
env[UXWIZZ_DB_PASSWORD] = $UXWIZZ_DB_PASSWORD
env[UXWIZZ_APP_KEY] = $UXWIZZ_APP_KEY
```

Use the same `EnvironmentFile` service override above with `sudo systemctl edit php8.3-fpm`. Include only variables you actually configured. Keep the pool's `clear_env` filtering enabled; explicit `env[...]` entries pass the selected values.

```bash
sudo systemctl daemon-reload
sudo php-fpm8.3 -t
sudo systemctl restart php8.3-fpm
```

Replace `8.3` with your installed version. Restart only after the test succeeds. See [PHP-FPM pool configuration](https://www.php.net/manual/en/install.fpm.configuration.php).

These Apache/PHP-FPM steps configure web requests. Configure scheduled-task services to read the same protected file separately; web-server `PassEnv` and FPM pool entries do not configure CLI PHP. Do not store passwords in machine-wide `/etc/environment`.

#### Docker

Use the protected `.env` file and shared application environment in the [Docker Compose guide](/installation/docker/via-docker-compose.md). Add feature flags to the shared environment block so both `webserver` and `scheduler` receive them.

Apply a change with:

```bash
docker compose config --quiet
docker compose up -d
```

A simple restart does not load new Compose environment values. Changing the database password in `.env` also does not change the password inside an existing database.

#### Windows / WAMP

For a non-secret feature flag, open PowerShell **as Administrator** and run:

```powershell
[Environment]::SetEnvironmentVariable("UXWIZZ_DISABLE_AI_CHAT", "1", "Machine")
```

Restart WAMP/Apache and open a new terminal for scheduled-task checks. Existing processes keep their previous environment. If a Windows service still sees the old value, arrange a Windows restart with your administrator. For Apache/mod\_php, add `PassEnv UXWIZZ_DISABLE_AI_CHAT` to the UXWizz virtual host as above.

To remove this override:

```powershell
[Environment]::SetEnvironmentVariable("UXWIZZ_DISABLE_AI_CHAT", $null, "Machine")
```

Restart the affected processes again. Machine variables apply beyond one application: use them for non-secret flags only. Keep database passwords in protected application/service configuration, and do not expose them in a public `phpinfo()` page.

### Feature Disable Flags

#### Disable AI Chat

```dotenv
UXWIZZ_DISABLE_AI_CHAT=1
```

Blocks AI questions and AI query execution. Users can still open **Ask AI** and manage permitted provider settings, but the server rejects chat requests. This flag controls the UXWizz AI workflow; it is not a server-wide network firewall.

#### Disable Self-Update

```dotenv
UXWIZZ_DISABLE_SELFUPDATE=1
```

Blocks the built-in file updater. Version checks and license checks remain available. Use this when your administrator manages application updates separately.

#### Disable Scheduled Task Execution

```dotenv
UXWIZZ_DISABLE_SCHEDULED_TASKS_EXECUTION=1
```

Blocks manual and automatic task execution. Administrators can still edit task definitions and view history. Existing schedules remain stored.

### Database Credentials From Environment Variables

In standalone UXWizz, a defined environment value **takes priority over the matching value in `server/dbconfig.php`**. This also applies to an empty environment value. Unset a variable to use the file value again.

Changing `dbconfig.php` cannot repair an incorrect environment override. Check the settings received by PHP and the task runner, without printing their secrets.

### Updates and Env-Based Database Credentials

The updater preserves file-based database settings. For values loaded from the environment, it keeps the corresponding fields empty in the updated `dbconfig.php`, so it does not copy those secrets into application files.

Keep the environment file when updating or migrating. Preserve `UXWIZZ_APP_KEY`: replacing it is a security-key rotation, not a password-reset step.

### WordPress Installations

The WordPress package uses database constants from `wp-config.php`. The standalone `UXWIZZ_DB_HOST`, `UXWIZZ_DB_NAME`, `UXWIZZ_DB_USER`, and `UXWIZZ_DB_PASSWORD` variables do not replace those WordPress settings.

### Security Notes

* Keep environment files outside the web root with access limited to the responsible administrator and service.
* Do not include credentials in commands, screenshots, support messages, or debug output.
* Back up secrets separately from application files and restrict access to those backups.
* Test the web process and scheduled tasks after a configuration change.

### Reference

| Variable                                   | Purpose                                                                                         |
| ------------------------------------------ | ----------------------------------------------------------------------------------------------- |
| `UXWIZZ_DISABLE_AI_CHAT`                   | Set to `1` to block AI questions and query execution.                                           |
| `UXWIZZ_DISABLE_SELFUPDATE`                | Set to `1` to block the built-in file updater.                                                  |
| `UXWIZZ_DISABLE_SCHEDULED_TASKS_EXECUTION` | Set to `1` to block manual and automatic task execution.                                        |
| `UXWIZZ_DB_HOST`                           | Standalone database host; overrides the file value when defined.                                |
| `UXWIZZ_DB_NAME`                           | Standalone database name; overrides the file value when defined.                                |
| `UXWIZZ_DB_USER`                           | Standalone database user; overrides the file value when defined.                                |
| `UXWIZZ_DB_PASSWORD`                       | Standalone database password; overrides the file value when defined.                            |
| `UXWIZZ_MYSQL_SSL_CA_PATH`                 | Database TLS CA certificate path; overrides the file value when defined.                        |
| `UXWIZZ_APP_KEY`                           | Persistent application encryption key. Keep it private and preserve it across updates.          |
| `UXWIZZ_PUBLIC_SERVER_URL`                 | Public HTTPS URL of the `server` directory, for example `https://analytics.example.com/server`. |
| `UXWIZZ_TRUST_PROXY`                       | Set to `1` only behind a trusted proxy that controls forwarded headers.                         |
