# Telegram Bot Token and Admin IDs BOT_TOKEN=your_bot_token_here # Telegram bot token ADMIN_IDS=comma_separated_admin_ids # Your telegram ID # PostgreSQL Database Connection Settings POSTGRES_USER= # Required: database user name POSTGRES_PASSWORD= # Required: database password POSTGRES_HOST=remnawave-minishop-db # Database container name POSTGRES_PORT=5432 # Port POSTGRES_DB=postgres # Database name # Localization and Display DEFAULT_LANGUAGE="ru" # or "en" DEFAULT_CURRENCY_SYMBOL="RUB" # e.g., RUB, USD, EUR # External Links SUPPORT_LINK=https://t.me/your_support_link # Link to the support chat SERVER_STATUS_URL=https://status.yourdomain.tld/status/your_service # Link to the server status page TERMS_OF_SERVICE_URL=https://example.com/tos # Link to the terms of service PRIVACY_POLICY_URL=https://example.com/privacy # Link to the privacy policy USER_AGREEMENT_URL=https://example.com/user-agreement # Link to the user agreement SUBSCRIPTION_MINI_APP_URL= # Public URL of the subscription Mini App, e.g. https://app.yourdomain.tld/ START_COMMAND_DESCRIPTION= # Description of the /start command DISABLE_WELCOME_MESSAGE= # Disable the welcome message MY_DEVICES_SECTION_ENABLED=False # Enable the My Devices section in the subscription menu USER_HWID_DEVICE_LIMIT=0 # Default HWID/device limit for panel users (0 = unlimited) # Required channel subscription REQUIRED_CHANNEL_ID= # Telegram channel ID (e.g. -1001234567890) the user must join REQUIRED_CHANNEL_LINK=https://t.me/your_channel # Optional: public link/invite button text opens # Webhook Base URL (used for Telegram and payment providers) WEBHOOK_BASE_URL=https://webhooks.yourdomain.tld TRUSTED_PROXIES=127.0.0.1,::1 # Reverse proxies trusted for X-Forwarded-For # Subscription Mini App (same container, separate port) WEBAPP_ENABLED=True # Run Mini App HTTP server WEBAPP_SERVER_HOST=0.0.0.0 # Internal listen host WEBAPP_SERVER_PORT=8081 # Internal/published Mini App port WEBAPP_TITLE="/minishop" # Mini App title WEBAPP_PRIMARY_COLOR="#00fe7a" # Main UI color WEBAPP_LOGO_URL=https://em-content.zobj.net/source/animated-noto-color-emoji/427/dotted-line-face_1fae5.gif # Optional logo URL; shown in the header and login screen, leave empty to hide WEBAPP_SESSION_SECRET= # Optional: HMAC secret for webapp sessions; generated if empty WEBHOOK_SECRET_TOKEN= # Optional: Telegram webhook secret token; generated if empty WEBAPP_SESSION_TTL_SECONDS=86400 # Web App session lifetime (24h) WEBAPP_AUTH_MAX_AGE_SECONDS=86400 # Max Telegram initData age WEBAPP_LOGIN_TOKEN_TTL_SECONDS=600 # External browser login link lifetime # Email login and account linking via SMTP (Brevo SMTP relay defaults) SMTP_HOST=smtp-relay.brevo.com # SMTP server SMTP_PORT=587 # Brevo recommends 587 with STARTTLS SMTP_FALLBACK_PORTS=2525,465 # Tried after SMTP_PORT; 465 uses SSL automatically SMTP_TIMEOUT_SECONDS=30 # Per SMTP connection/send attempt timeout SMTP_USERNAME= # Brevo SMTP login SMTP_PASSWORD= # Brevo SMTP key/password SMTP_FROM_EMAIL= # Verified sender email SMTP_FROM_NAME= # Optional sender name SMTP_STARTTLS=True # Use STARTTLS on SMTP_PORT SMTP_USE_SSL=False # Use SSL wrapper, usually only for port 465 EMAIL_CODE_TTL_SECONDS=600 # Email verification code lifetime EMAIL_CODE_RESEND_SECONDS=60 # Minimum delay between code sends EMAIL_CODE_MAX_ATTEMPTS=5 # Max attempts per code BRUTE_FORCE_MAX_FAILURES=5 # Max failed code attempts in the throttle window BRUTE_FORCE_WINDOW_SECONDS=900 # Rolling window used to count failures BRUTE_FORCE_LOCK_SECONDS=1800 # Temporary lockout duration after too many failures # Payment Method Toggles YOOKASSA_ENABLED=True # Turn on YOOKASSA FREEKASSA_ENABLED=True # Turn on FreeKassa STARS_ENABLED=True # Turn on STARS CRYPTOPAY_ENABLED=True # Turn on CRYPTOPAY PLATEGA_ENABLED=False # Turn on PLATEGA SEVERPAY_ENABLED=False # Turn on SeverPay # Order of payment methods (top to bottom). Supported: severpay, freekassa, platega, yookassa, stars, cryptopay PAYMENT_METHODS_ORDER=severpay,yookassa,cryptopay,freekassa,platega,stars # YooKassa Payment Gateway Configuration YOOKASSA_SHOP_ID=your_shop_id # Your store ID in YooKassa YOOKASSA_SECRET_KEY=your_secret_key # Your secret key for YooKassa YOOKASSA_RETURN_URL=https://t.me/your_bot # URL to which the user will be returned after payment YOOKASSA_DEFAULT_RECEIPT_EMAIL=your_email@example.com # Default email for sending receipts YOOKASSA_VAT_CODE=1 # VAT code YOOKASSA_AUTOPAYMENTS_ENABLED=False # Auto-renew toggle YOOKASSA_AUTOPAYMENTS_REQUIRE_CARD_BINDING=True # Force automatic card binding when autopay is enabled (set to False to show the save-card checkbox) # Nalogo (self-employed receipts) NALOGO_INN=your_inn # INN for nalog.ru NALOGO_PASSWORD=your_nalogo_password # Password for nalog.ru NALOGO_RECEIPT_NAME_SUBSCRIPTION=subscription {months} months # Receipt name for time-based subscriptions ({months} = duration) NALOGO_RECEIPT_NAME_TRAFFIC=traffic package {gb} GB # Receipt name for traffic packages ({gb} = traffic amount) # FreeKassa Payment Gateway Configuration FREEKASSA_MERCHANT_ID=your_shop_id # Your shop ID in FreeKassa FREEKASSA_API_KEY=your_api_key # API key for REST requests FREEKASSA_SECOND_SECRET=your_second_secret # Secret word #2 (used to verify notifications) FREEKASSA_PAYMENT_IP= # Public IP address reported to FreeKassa FREEKASSA_PAYMENT_METHOD_ID=44 # Payment method ID, you can get it from https://merchant.freekassa.net/settings/currencies FREEKASSA_TRUSTED_IPS=168.119.157.136,168.119.60.227,178.154.197.79,51.250.54.238 # FreeKassa webhook source IP allowlist # CryptoBot Payment Gateway Configuration CRYPTOPAY_TOKEN= # API token for CryptoPay CRYPTOPAY_NETWORK=mainnet # Network (mainnet or testnet) CRYPTOPAY_CURRENCY_TYPE=fiat # Currency type (fiat or crypto) CRYPTOPAY_ASSET=RUB # Asset, e.g., RUB, BTC, USDT # Platega Payment Gateway Configuration PLATEGA_BASE_URL=https://app.platega.io # Base API URL PLATEGA_MERCHANT_ID= # Your MerchantId from Platega PLATEGA_SECRET= # API secret from Platega PLATEGA_PAYMENT_METHOD=2 # Legacy method ID; fallback for the SBP button when PLATEGA_SBP_METHOD stays default PLATEGA_SBP_ENABLED=False # Show a separate "Pay via SBP" Platega button PLATEGA_CRYPTO_ENABLED=False # Show a separate "Pay with crypto" Platega button PLATEGA_SBP_METHOD=2 # Platega method ID for SBP QR (default 2) PLATEGA_CRYPTO_METHOD=13 # Platega method ID for crypto (default 13) PLATEGA_RETURN_URL= # Optional: redirect after successful payment (defaults to bot link) PLATEGA_FAILED_URL= # Optional: redirect after failed/cancelled payment (defaults to return URL) # SeverPay Payment Gateway Configuration SEVERPAY_BASE_URL=https://severpay.io/api/merchant # Base API URL SEVERPAY_MID= # Your MID from SeverPay SEVERPAY_TOKEN= # API token/secret for signing requests SEVERPAY_RETURN_URL= # Optional: redirect URL after payment (defaults to bot link) SEVERPAY_LIFETIME_MINUTES= # Optional: payment link lifetime in minutes (30-4320, leave empty for default) # Subscription Options. Specify cost parameters or payment links here. 1_MONTH_ENABLED=True RUB_PRICE_1_MONTH=150 STARS_PRICE_1_MONTH=0 3_MONTHS_ENABLED=True RUB_PRICE_3_MONTHS=300 STARS_PRICE_3_MONTHS=0 6_MONTHS_ENABLED=True RUB_PRICE_6_MONTHS=500 STARS_PRICE_6_MONTHS=0 12_MONTHS_ENABLED=True RUB_PRICE_12_MONTHS=900 STARS_PRICE_12_MONTHS=0 # Traffic Packages (enables traffic sale mode when set) TRAFFIC_PACKAGES=10:199,50:799 # Format: ":", comma-separated STARS_TRAFFIC_PACKAGES=10:2500 # Optional: traffic packages priced in Stars TARIFFS_CONFIG_PATH=config/tariffs.json # Optional Tariffs 2.0 JSON config. If missing, legacy .env pricing is used. # Subscription Notifications SUBSCRIPTION_NOTIFICATIONS_ENABLED=True # Enable subscription SUBSCRIPTION_NOTIFY_ON_EXPIRE=True # Notify on subscription SUBSCRIPTION_NOTIFY_AFTER_EXPIRE=True # Notify after SUBSCRIPTION_NOTIFY_DAYS_BEFORE=3 # Days before expiration to notify REFERRAL_ONE_BONUS_PER_REFEREE=False # Give a bonus only once per referee REFERRAL_WELCOME_BONUS_DAYS=3 # Welcome bonus for newly registered user from referral link LEGACY_REFS=true # Allow ref_ links. Leave unset/true unless you want to disable old links # Referral Bonus Days # Bonus for the inviting user REFERRAL_BONUS_DAYS_1_MONTH=3 REFERRAL_BONUS_DAYS_3_MONTHS=7 REFERRAL_BONUS_DAYS_6_MONTHS=15 REFERRAL_BONUS_DAYS_12_MONTHS=30 # Invited User Bonus REFEREE_BONUS_DAYS_1_MONTH=1 REFEREE_BONUS_DAYS_3_MONTHS=3 REFEREE_BONUS_DAYS_6_MONTHS=7 REFEREE_BONUS_DAYS_12_MONTHS=15 # Panel API Configuration PANEL_API_URL=http://your_panel_api_url/api # URL of the panel API PANEL_API_KEY=your_panel_api_key # Panel API key PANEL_WEBHOOK_SECRET= # secret used to verify panel webhook signatures # User traffic limits (applied for all users) # 0 means unlimited USER_TRAFFIC_LIMIT_GB=0 # Traffic limit for users (0 unlimited) USER_TRAFFIC_STRATEGY="NO_RESET" # Traffic reset strategy (NO_RESET, WEEK, MONTH) # Default Internal Squads for Users (Optional, comma-separated UUIDs) USER_SQUAD_UUIDS=uuid1,uuid2,uuid3 # Default External Squad for Users (Optional, single UUID) USER_EXTERNAL_SQUAD_UUID= # Optional: UUID from Remnawave External Squads to auto-link new panel users # Trial Settings TRIAL_ENABLED=True # Enable the trial period TRIAL_DURATION_DAYS=5 # Duration of the trial period in days TRIAL_TRAFFIC_LIMIT_GB=0 # Traffic limit for the trial period (0 = unlimited) TRIAL_TRAFFIC_STRATEGY="NO_RESET" # Traffic reset strategy for the trial period (NO_RESET, WEEK, MONTH) # Connection link handling (happ crypt4) CRYPT4_ENABLED=False # Enable happ crypt4 encryption for subscription URLs CRYPT4_REDIRECT_URL= # Base redirect to wrap the connect button, e.g. https://redir.example.com?url= # Web Server Settings (for handling webhooks) WEB_SERVER_HOST="0.0.0.0" WEB_SERVER_PORT=8080 # Admin Panel Log Pagination LOGS_PAGE_SIZE=10 # Number of events in the log LOG_LEVEL=INFO # Global log level (DEBUG, INFO, WARNING, ERROR, CRITICAL) # Admin Logging Configuration LOG_CHAT_ID=-1001234567890 # Telegram chat/group ID for admin notifications LOG_THREAD_ID= # Optional: Thread ID for supergroup messages LOG_NEW_USERS=True # Log new user registrations LOG_PAYMENTS=True # Log payments LOG_PROMO_ACTIVATIONS=True # Log promo code activations LOG_TRIAL_ACTIVATIONS=True # Log trial activations LOG_SUSPICIOUS_ACTIVITY=True # Log suspicious activity # Embedded mode thumbnails. Please don't touch this if you don't know what it is. INLINE_REFERRAL_THUMBNAIL_URL=https://cdn-icons-png.flaticon.com/512/1077/1077114.png INLINE_USER_STATS_THUMBNAIL_URL=https://cdn-icons-png.flaticon.com/512/681/681494.png INLINE_FINANCIAL_STATS_THUMBNAIL_URL=https://cdn-icons-png.flaticon.com/512/2769/2769339.png INLINE_SYSTEM_STATS_THUMBNAIL_URL=https://cdn-icons-png.flaticon.com/512/2920/2920277.png