Environment keys
The complete list of configuration keys Pocket Homelab reads, with the field titles, whether they are secret, and where to find each value.
iPhoneMacOn this page
Download all keys as a blank env template, then follow the setup and import instructions. Fill only the services you use; every value in the download is empty.
How keys work
Every key is UPPER_SNAKE_CASE and belongs to a service group, one row in Settings → Services, and one slot
on the free plan. The app maps each key to a field with a title, a placeholder, a hint about where to find the
value, and a secret flag that decides whether the field is masked.
- A group counts as configured once its URL is set, or, for key-only groups, once any key is set. An empty URL hides that service everywhere: no Home card, no tab, no search entry, no browser link, no quick action.
- Keys ending in
_URLare normalised: trailing slashes are removed, and the value must have anhttp/httpsscheme and a host. - Keys the app does not recognise are preserved on import and export, so your file round-trips.
- Secret fields (marked below) are masked in the form until you press the eye button beside them to reveal the value. Like every key, they are stored in the Keychain.
- This table does not mark individual keys Required, that depends on the combination you choose (a status page slug or an API key for Kuma, for example). Each service’s own page spells out the minimum.
The env file format
Settings accepts the same format as the Homelab Raycast extension, plain KEY=value lines:
# Lines starting with # are ignored, as are blank lines.
KUMA_URL=https://kuma.example.com
KUMA_API_KEY=uk1234… # trailing comments after " # " are stripped from unquoted values
export NEXTCLOUD_URL="https://cloud.example.com"
NEXTCLOUD_APP_PASSWORD="ABCDE-FGHIJ-KLMNO-PQRST"
- A leading
exportis dropped, and matching single or double quotes around a value are stripped, quoting is optional except where a value itself contains spaces,#or a tab. - Trailing slashes are removed from every
…_URLvalue. - Leaving a service’s URL empty (or removing its line) hides that service everywhere, the same as switching it off in Settings.
See Connect your services for the full import flow (paste vs. Files picker, merge vs. replace).
Server
See the Server page for what this unlocks.
| Key | Field | Required | Secret | Where to get it |
|---|---|---|---|---|
GLANCES_URL | Glances URL | Optional | — | Base URL of your Glances instance. Leave empty to hide Glances features. |
STORAGE_MOUNT | Extra Mount Point | Optional | — | A second filesystem from Glances to show next to / (e.g. a data SSD). Leave empty to show only the root filesystem. |
TEMPS_URL | Temperatures JSON URL | Optional | — | Optional URL of a temps.json published by the companion temps-publish script (server CPU/disk + NAS disk temps). |
Links
See the Links page for what this unlocks.
| Key | Field | Required | Secret | Where to get it |
|---|---|---|---|---|
HOMEPAGE_URL | Dashboard URL | Optional | — | Optional link to your dashboard (Homepage, Dashy…), shown with the other browser links on Home and in the Mac Server page's Open in browser menu. |
TrueNAS
See the TrueNAS page for what this unlocks.
| Key | Field | Required | Secret | Where to get it |
|---|---|---|---|---|
TRUENAS_URL | TrueNAS URL | Optional | — | Base URL of your TrueNAS instance. Leave empty to hide TrueNAS features. |
TRUENAS_API_KEY | TrueNAS API Key | Optional | Secret | Read-only key is enough (pool capacity + health). Leave empty to hide the NAS row. |
qBittorrent
See the qBittorrent page for what this unlocks.
| Key | Field | Required | Secret | Where to get it |
|---|---|---|---|---|
QBIT_URL | qBittorrent URL | Optional | — | Base URL of your qBittorrent instance. Leave empty to hide qBittorrent features. |
QBIT_USERNAME | qBittorrent Username | Optional | — | Web UI username. |
QBIT_PASSWORD | qBittorrent Password | Optional | Secret | Web UI password. Never attempted while empty (qBittorrent IP-bans after 5 failures). |
SABnzbd
See the SABnzbd page for what this unlocks.
| Key | Field | Required | Secret | Where to get it |
|---|---|---|---|---|
SABNZBD_URL | SABnzbd URL | Optional | — | Base URL of your SABnzbd instance. Leave empty to hide SABnzbd features. |
SABNZBD_API_KEY | SABnzbd API Key | Optional | Secret | Config → General → API Key. |
Nzbget
See the Nzbget page for what this unlocks.
| Key | Field | Required | Secret | Where to get it |
|---|---|---|---|---|
NZBGET_URL | NZBget URL | Optional | — | Base URL of your NZBget instance. Leave empty to hide NZBget features. |
NZBGET_USERNAME | NZBget Username | Optional | — | Settings → Security → ControlUsername. |
NZBGET_PASSWORD | NZBget Password | Optional | Secret | Settings → Security → ControlPassword. |
slskd
See the slskd page for what this unlocks.
| Key | Field | Required | Secret | Where to get it |
|---|---|---|---|---|
SLSKD_URL | slskd URL | Optional | — | Base URL of your slskd instance. Leave empty to hide slskd features. |
SLSKD_API_KEY | slskd API Key | Optional | Secret | Options → Web → Authentication → API keys. |
Jellyfin
See the Jellyfin page for what this unlocks.
| Key | Field | Required | Secret | Where to get it |
|---|---|---|---|---|
JELLYFIN_URL | Jellyfin URL | Optional | — | Base URL of your Jellyfin instance. Leave empty to hide Jellyfin features. |
JELLYFIN_API_KEY | Jellyfin API Key | Optional | Secret | Dashboard → API Keys. |
JELLYFIN_USER_ID | Jellyfin User ID | Optional | — | Optional. Whose Continue Watching / Next Up to show; defaults to the first administrator. |
Jellyseerr
See the Jellyseerr page for what this unlocks.
| Key | Field | Required | Secret | Where to get it |
|---|---|---|---|---|
JELLYSEERR_URL | Jellyseerr URL | Optional | — | Base URL of your Jellyseerr instance. Leave empty to hide Jellyseerr features. |
JELLYSEERR_API_KEY | Jellyseerr API Key | Optional | Secret | Settings → General → API Key (admin). |
Radarr
See the Radarr page for what this unlocks.
| Key | Field | Required | Secret | Where to get it |
|---|---|---|---|---|
RADARR_URL | Radarr URL | Optional | — | Base URL of your Radarr instance. Leave empty to hide Radarr features. |
RADARR_API_KEY | Radarr API Key | Optional | Secret | Settings → General. |
Sonarr
See the Sonarr page for what this unlocks.
| Key | Field | Required | Secret | Where to get it |
|---|---|---|---|---|
SONARR_URL | Sonarr URL | Optional | — | Base URL of your Sonarr instance. Leave empty to hide Sonarr features. |
SONARR_API_KEY | Sonarr API Key | Optional | Secret | Settings → General. |
Lidarr
See the Lidarr page for what this unlocks.
| Key | Field | Required | Secret | Where to get it |
|---|---|---|---|---|
LIDARR_URL | Lidarr URL | Optional | — | Base URL of your Lidarr instance. Leave empty to hide Lidarr features. |
LIDARR_API_KEY | Lidarr API Key | Optional | Secret | Settings → General. |
Chaptarr / Readarr
See the Chaptarr / Readarr page for what this unlocks.
| Key | Field | Required | Secret | Where to get it |
|---|---|---|---|---|
CHAPTARR_URL | Chaptarr / Readarr URL | Optional | — | Base URL of your Chaptarr / Readarr instance. Leave empty to hide Chaptarr / Readarr features. |
CHAPTARR_API_KEY | Chaptarr / Readarr API Key | Optional | Secret | Settings → General (any Readarr-compatible fork). |
Prowlarr
See the Prowlarr page for what this unlocks.
| Key | Field | Required | Secret | Where to get it |
|---|---|---|---|---|
PROWLARR_URL | Prowlarr URL | Optional | — | Base URL of your Prowlarr instance. Leave empty to hide Prowlarr features. |
PROWLARR_API_KEY | Prowlarr API Key | Optional | Secret | Settings → General. |
Subtitles
Covers Bazarr and the Subtitle Sync Server. See the Bazarr and Subtitle Sync Server pages for what this unlocks.
| Key | Field | Required | Secret | Where to get it |
|---|---|---|---|---|
BAZARR_URL | Bazarr URL | Optional | — | Base URL of your Bazarr instance. Leave empty to hide Bazarr features. |
BAZARR_API_KEY | Bazarr API Key | Optional | Secret | Settings → General. |
SUBSYNC_URL | Subtitle Sync Server URL | Optional | — | Base URL of your Subtitle Sync Server instance. Leave empty to hide Subtitle Sync Server features. |
Audiobookshelf
See the Audiobookshelf page for what this unlocks.
| Key | Field | Required | Secret | Where to get it |
|---|---|---|---|---|
ABS_URL | Audiobookshelf URL | Optional | — | Base URL of your Audiobookshelf instance. Leave empty to hide Audiobookshelf features. |
ABS_TOKEN | Audiobookshelf API Token | Optional | Secret | Settings → Users → your user → API token. |
Navidrome
See the Navidrome page for what this unlocks.
| Key | Field | Required | Secret | Where to get it |
|---|---|---|---|---|
NAVIDROME_URL | Navidrome URL | Optional | — | Base URL of your Navidrome instance. Leave empty to hide Navidrome features. |
NAVIDROME_USER | Navidrome Username | Optional | — | Any user; Subsonic token auth is used. |
NAVIDROME_PASSWORD | Navidrome Password | Optional | Secret | Password of that user. |
Immich
See the Immich page for what this unlocks.
| Key | Field | Required | Secret | Where to get it |
|---|---|---|---|---|
IMMICH_URL | Immich URL | Optional | — | Base URL of your Immich instance. Leave empty to hide Immich features. |
IMMICH_API_KEY | Immich API Key | Optional | Secret | Account Settings → API Keys. |
Calibre-Web
See the Calibre-Web page for what this unlocks.
| Key | Field | Required | Secret | Where to get it |
|---|---|---|---|---|
CALIBRE_URL | Calibre-Web URL | Optional | — | Base URL of your Calibre-Web instance. Leave empty to hide Calibre-Web features. |
CALIBRE_USER | Calibre-Web Username | Optional | — | Used for OPDS + Send-to-Kindle. |
CALIBRE_PASSWORD | Calibre-Web Password | Optional | Secret | Password of that user. |
Paperless
See the Paperless page for what this unlocks.
| Key | Field | Required | Secret | Where to get it |
|---|---|---|---|---|
PAPERLESS_URL | Paperless URL | Optional | — | Base URL of your Paperless-ngx instance. Leave empty to hide Paperless features. |
PAPERLESS_TOKEN | Paperless API Token | Optional | Secret | Your Paperless profile → API Auth Token. Documents must be visible to this user. |
MeTube
See the MeTube page for what this unlocks.
| Key | Field | Required | Secret | Where to get it |
|---|---|---|---|---|
METUBE_URL | MeTube URL | Optional | — | Base URL of your MeTube instance. Leave empty to hide MeTube features. |
METUBE_FOLDERS | MeTube Destinations | Optional | — | Comma-separated extra folders as folder|Label[|video]. Add |video to download video instead of opus audio. Example: music|Music,clips|Clips|video |
Uptime Kuma
See the Uptime Kuma page for what this unlocks.
| Key | Field | Required | Secret | Where to get it |
|---|---|---|---|---|
KUMA_URL | Uptime Kuma URL | Optional | — | Base URL of your Uptime Kuma instance. Leave empty to hide Uptime Kuma features. |
KUMA_STATUS_SLUG | Uptime Kuma Status Page Slug | Optional | — | Slug of a public status page (used when no API key is set). |
KUMA_API_KEY | Uptime Kuma API Key | Optional | Secret | Settings → API Keys. With a key every monitor is read from /metrics, not just the status page. |
ntfy
See the ntfy page for what this unlocks.
| Key | Field | Required | Secret | Where to get it |
|---|---|---|---|---|
NTFY_URL | ntfy URL | Optional | — | Base URL of your ntfy instance. Leave empty to hide ntfy features. |
NTFY_TOPICS | ntfy Topics | Optional | — | Comma-separated topics to read. |
AdGuard Home
See the AdGuard Home page for what this unlocks.
| Key | Field | Required | Secret | Where to get it |
|---|---|---|---|---|
ADGUARD_URL | AdGuard Home URL | Optional | — | Base URL of your AdGuard Home instance. Leave empty to hide AdGuard Home features. |
ADGUARD_USERNAME | AdGuard Home Username | Optional | — | Web UI username. |
ADGUARD_PASSWORD | AdGuard Home Password | Optional | Secret | Web UI password. |
Komodo
See the Komodo page for what this unlocks.
| Key | Field | Required | Secret | Where to get it |
|---|---|---|---|---|
KOMODO_URL | Komodo URL | Optional | — | Base URL of your Komodo instance. Leave empty to hide Komodo features. |
KOMODO_API_KEY | Komodo API Key | Optional | Secret | Settings → Profile → API keys. |
KOMODO_API_SECRET | Komodo API Secret | Optional | Secret | Shown once when the key is created. |
Services & Jobs (SSH)
Mac only, not shown in the iPhone Services list. See the Services & Jobs over SSH page for what this unlocks.
| Key | Field | Required | Secret | Where to get it |
|---|---|---|---|---|
SERVICES_SSH_HOST | Services SSH Host | Optional | — | SSH destination for Services & Jobs: user@host or an alias from ~/.ssh/config. Uses noninteractive key or agent authentication and a previously trusted host key. Leave empty to disable. |
SERVICES_SSH_PORT | Services SSH Port | Optional | — | Optional SSH port (1–65535). Leave empty to use your SSH configuration or port 22. |
SERVICES_SSH_IDENTITY_FILE | Services SSH Identity File | Optional | — | Optional path to your local SSH private key; ~/ is supported. Leave empty to use your SSH configuration or agent. Enter a file path, never the key itself. |
Backrest
See the Backrest page for what this unlocks.
| Key | Field | Required | Secret | Where to get it |
|---|---|---|---|---|
BACKREST_URL | Backrest URL | Optional | — | Base URL of your Backrest instance. Leave empty to hide Backrest features. |
BACKREST_USERNAME | Backrest Username | Optional | — | Web UI username. |
BACKREST_PASSWORD | Backrest Password | Optional | Secret | Web UI password. |
BACKREST_GRACE_HOURS | Backup Freshness Grace (Hours) | Optional | — | Extra time beyond each backup/check schedule before it is overdue. Defaults to 2 hours. Manual plans have no deadline. |
Scrutiny
See the Scrutiny page for what this unlocks.
| Key | Field | Required | Secret | Where to get it |
|---|---|---|---|---|
SCRUTINY_URL | Scrutiny URL | Optional | — | Base URL of your Scrutiny instance. Leave empty to hide Scrutiny features. |
Speedtest Tracker
See the Speedtest Tracker page for what this unlocks.
| Key | Field | Required | Secret | Where to get it |
|---|---|---|---|---|
SPEEDTEST_URL | Speedtest Tracker URL | Optional | — | Base URL of your Speedtest Tracker instance. Leave empty to hide Speedtest Tracker features. |
Money
Covers Firefly III, Firefly Pico and the subscriptions summary. See the Firefly III and Firefly Pico pages for what this unlocks.
| Key | Field | Required | Secret | Where to get it |
|---|---|---|---|---|
FIREFLY_URL | Firefly III URL | Optional | — | Base URL of your Firefly III instance. Leave empty to hide Firefly III features. |
FIREFLY_TOKEN | Firefly III Personal Access Token | Optional | Secret | Options → Profile → OAuth → Personal Access Tokens. |
PICO_URL | Firefly Pico URL | Optional | — | Base URL of your Firefly Pico instance. Leave empty to hide Firefly Pico features. |
SUBSCRIPTIONS_URL | Subscriptions JSON URL | Optional | — | Optional URL of a subscriptions.json published by the companion firefly-sub-publish script (upcoming bills summary). |
Forgejo
See the Forgejo page for what this unlocks.
| Key | Field | Required | Secret | Where to get it |
|---|---|---|---|---|
FORGEJO_URL | Forgejo / Gitea URL | Optional | — | Base URL of your Forgejo / Gitea instance. Leave empty to hide Forgejo / Gitea features. |
FORGEJO_TOKEN | Forgejo / Gitea Access Token | Optional | Secret | Settings → Applications → Generate token, with read/write on repository, issue and notification. Unlocks the Code screen (repos, pull requests, reviews, Actions). |
Nextcloud
See the Nextcloud page for what this unlocks.
| Key | Field | Required | Secret | Where to get it |
|---|---|---|---|---|
NEXTCLOUD_URL | Nextcloud URL | Optional | — | Base URL of Nextcloud, including its subpath if any. |
NEXTCLOUD_USERNAME | Nextcloud Username | Optional | — | Your Nextcloud user ID (not display name). |
NEXTCLOUD_APP_PASSWORD | Nextcloud App Password | Optional | Secret | Create an app password in Nextcloud → Personal settings → Security. |
LubeLogger
See the LubeLogger page for what this unlocks.
| Key | Field | Required | Secret | Where to get it |
|---|---|---|---|---|
LUBELOGGER_URL | LubeLogger URL | Optional | — | Base URL of your LubeLogger instance, e.g. https://lubelogger.example.org |
LUBELOGGER_USERNAME | LubeLogger Username | Optional | — | Only needed if your LubeLogger requires a login (basic auth) |
LUBELOGGER_PASSWORD | LubeLogger Password | Optional | Secret | Only needed if your LubeLogger requires a login (basic auth) |
LUBELOGGER_CURRENCY | Vehicle Currency | Optional | — | Currency used for vehicle costs and linked payments. Defaults to BAM. Changing it does not convert existing amounts. |
LUBELOGGER_DISTANCE_UNIT | Distance Unit Label | Optional | — | Defaults to km |
LUBELOGGER_VOLUME_UNIT | Fuel Volume Unit Label | Optional | — | Defaults to L |
LUBELOGGER_VEHICLE_ID | Default Vehicle ID | Optional | — | Which vehicle the Home row summarises when you have several |
LUBELOGGER_DECIMAL | LubeLogger Decimal Separator | Optional | — | How LubeLogger's server locale parses numbers. Auto-detects from its own data. |
SearXNG
See the SearXNG page for what this unlocks.
| Key | Field | Required | Secret | Where to get it |
|---|---|---|---|---|
SEARXNG_URL | SearXNG URL | Optional | — | Base URL of your SearXNG instance (JSON API enabled). Leave empty to hide web search. |
Jellystat
See the Jellystat page for what this unlocks.
| Key | Field | Required | Secret | Where to get it |
|---|---|---|---|---|
JELLYSTAT_URL | Jellystat URL | Optional | — | Base URL of your Jellystat instance. Leave empty to hide watch statistics. |
JELLYSTAT_API_KEY | Jellystat API Key | Optional | Secret | Jellystat → Settings → API Keys. |
PinePods
See the PinePods page for what this unlocks.
| Key | Field | Required | Secret | Where to get it |
|---|---|---|---|---|
PINEPODS_URL | PinePods URL | Optional | — | Base address of your PinePods server. |
PINEPODS_API_KEY | PinePods API key | Optional | Secret | Your user API key from PinePods settings. Stored in the Keychain. |
Exporting
The app never writes a plain env file. Its only export is Move to another device (iPhone: Settings → Move &
restore; Mac: Settings → Move & Restore), which seals every key above in the same KEY=value format behind a
passphrase you choose. Import configuration on the other device opens it with that passphrase. See
Move to another device.