Skip to documentation

Self-hosting

Security notes

Protect installation secrets and limit credential access.

Separate public and administrative access

Expose app and required backend origins over HTTPS. Keep the Convex dashboard and deployment admin key private. Use sending-only, domain-scoped API keys for applications that only send mail. To replace a key, create a replacement, deploy it to your application, then remove the old key; removal immediately rejects requests using that token.

Keep secrets recoverable

Protect .env.docker and include its encrypted backup with data backups. Changing BETTER_AUTH_SECRET invalidates old tracking and unsubscribe links. Changing SSO_ENCRYPTION_KEY makes existing SSO and webhook secrets unreadable.

Outbound requests

Webhook destinations require public HTTPS. Requests reject private DNS answers, do not follow redirects, and have bounded response sizes and timeouts. Attachment URLs require public HTTPS with DNS-pinned address checks; each of at most three redirects is revalidated. Disable ALLOW_LOCAL_OIDC before production.

dotenv
ALLOW_LOCAL_OIDC=false

Data retention

Sent and received email content normally expires after 30 days; queued and scheduled work is protected. Webhook payloads remain for 90 days. Export downloads expire after seven days. Backups have the retention you configure.

See background jobs and retention for broadcast, automation, import, SES, and account cleanup windows.