Files
QuantDinger/backend_api_python/env.example
T
Dinger 11e0139e2a v3.0.5
Signed-off-by: Dinger <quantdinger@gmail.com>
2026-05-13 14:12:38 +08:00

382 lines
13 KiB
Plaintext

# QuantDinger local configuration (copy to `.env` and edit)
# `run.py` will load `backend_api_python/.env` automatically if present.
#
# This file is organized as:
# 1) first-time deployment settings at the top
# 2) advanced / rarely changed settings at the bottom
# For Docker image source / ports, use the project-root `.env`.
# =========================
# Brand / identity (drives logo, footer, version label, legal modals)
# =========================
# Frontend reads these via /api/settings/brand-config — leave any field empty
# to fall back to the bundled QuantDinger defaults. Change here (or via the
# Settings page) to rebrand a deployment without rebuilding the frontend.
BRAND_APP_NAME=QuantDinger
BRAND_APP_VERSION=3.0.5
BRAND_COPYRIGHT=© 2025-2026 QuantDinger. All rights reserved.
# Logo / favicon URLs (HTTPS recommended; leave empty to use bundled assets)
BRAND_LOGO_LIGHT_URL=
BRAND_LOGO_DARK_URL=
BRAND_LOGO_COLLAPSED_URL=
BRAND_FAVICON_URL=
# Contact & support links surfaced in the sidebar footer.
BRAND_CONTACT_EMAIL=brokermr810@gmail.com
BRAND_CONTACT_SUPPORT_URL=https://t.me/quantdinger
BRAND_CONTACT_LIVE_CHAT_URL=https://t.me/quantdinger
BRAND_CONTACT_FEATURE_REQUEST_URL=https://github.com/brokermr810/QuantDinger/issues
# Social accounts shown as icons in the sidebar footer. Leave any single
# entry empty to hide that icon.
BRAND_SOCIAL_GITHUB=https://github.com/brokermr810/QuantDinger
BRAND_SOCIAL_X=https://x.com/quantdinger_en
BRAND_SOCIAL_DISCORD=https://discord.com/invite/tyx5B6TChr
BRAND_SOCIAL_TELEGRAM=https://t.me/quantdinger
BRAND_SOCIAL_YOUTUBE=https://youtube.com/@quantdinger
# Legal: external URL takes priority; if both URL and inline text are empty,
# the frontend falls back to the built-in i18n copy.
BRAND_LEGAL_USER_AGREEMENT_URL=
BRAND_LEGAL_USER_AGREEMENT_TEXT=
BRAND_LEGAL_PRIVACY_POLICY_URL=
BRAND_LEGAL_PRIVACY_POLICY_TEXT=
# =========================
# Auth (required)
# =========================
# Also derives Fernet key for encrypting qd_exchange_credentials.encrypted_config (do not rotate casually).
SECRET_KEY=quantdinger-secret-key-change-me
ADMIN_USER=quantdinger
ADMIN_PASSWORD=123456
ADMIN_EMAIL=
# =========================
# Core app
# =========================
DATABASE_URL=postgresql://quantdinger:quantdinger123@postgres:5432/quantdinger
FRONTEND_URL=http://localhost:8888
# Extra front-end origins allowed as OAuth post-login redirect targets.
# Comma-separated, scheme + host (+ optional port). Used when multiple clients
# (e.g. PC web + mobile web) share the same backend. FRONTEND_URL is always
# allowed implicitly; list every additional front-end here.
# Example: OAUTH_ALLOWED_REDIRECTS=https://m.quantdinger.com,https://app.quantdinger.com
OAUTH_ALLOWED_REDIRECTS=
# OAuth CSRF state TTL (minutes); stored in Postgres for multi-worker. Default 20, clamped [5,120].
OAUTH_STATE_TTL_MINUTES=20
ENABLE_REGISTRATION=true
# =========================
# Mobile app (in-app version check)
# =========================
# Semver-like string shown to clients; leave empty to avoid "new version" prompts.
MOBILE_APP_LATEST_VERSION=
# APK / install page URL for one-tap update on Android (HTTPS recommended).
MOBILE_APP_DOWNLOAD_URL=https://www.quantdinger.com/download/app.apk
# =========================
# Database bootstrap behaviour
# =========================
# On every backend startup we auto-apply `migrations/init.sql` so a fresh
# install (especially bare-metal / Windows local PG) gets the full schema
# without anyone remembering to `psql -f` first. The file uses
# `CREATE TABLE IF NOT EXISTS` everywhere so re-running is a no-op.
# Set to `true` if you manage schema externally (Flyway, Liquibase, etc.)
# and don't want the backend touching DDL on boot. Permission probing on
# critical tables still runs either way.
SKIP_AUTO_MIGRATE=false
# =========================
# Database connection pool (psycopg2 ThreadedConnectionPool)
# =========================
# Tune these if you see `psycopg2.pool.PoolError: connection pool exhausted`
# or if you run many trading bots / portfolios concurrently.
# Make sure PG `max_connections` (docker-compose: PG_MAX_CONNECTIONS) is
# comfortably larger than DB_POOL_MAX.
DB_POOL_MIN=5
DB_POOL_MAX=50
DB_POOL_ACQUIRE_TIMEOUT=10
DB_POOL_HEALTH_CHECK=true
# Route-level parallel fetch executors. Each worker may hold one DB
# connection, so keep MARKET_EXECUTOR_WORKERS + PORTFOLIO_EXECUTOR_WORKERS
# well below DB_POOL_MAX.
MARKET_EXECUTOR_WORKERS=6
PORTFOLIO_EXECUTOR_WORKERS=3
# Gunicorn worker/thread model
GUNICORN_WORKERS=1
GUNICORN_THREADS=8
# =========================
# AI / LLM (choose one provider)
# =========================
LLM_PROVIDER=openrouter
OPENROUTER_API_KEY=
OPENROUTER_MODEL=openai/gpt-4o
# Optional: dedicated model for AI code generation (fallback to provider default if empty)
AI_CODE_GEN_MODEL=
OPENAI_API_KEY=
OPENAI_MODEL=gpt-4o
GOOGLE_API_KEY=
GOOGLE_MODEL=gemini-1.5-flash
DEEPSEEK_API_KEY=
DEEPSEEK_MODEL=deepseek-chat
GROK_API_KEY=
GROK_MODEL=grok-beta
# OpenAI-compatible third-party API (set LLM_PROVIDER=custom)
# Local Ollama example (backend must reach this host; Docker Desktop: http://host.docker.internal:11434/v1):
# CUSTOM_API_URL=http://127.0.0.1:11434/v1
# CUSTOM_MODEL=llama3.2
# Ollama usually needs no key — leave CUSTOM_API_KEY empty.
CUSTOM_API_URL=
CUSTOM_API_KEY=
CUSTOM_MODEL=
# MiniMax (set LLM_PROVIDER=minimax)
MINIMAX_API_KEY=
MINIMAX_MODEL=MiniMax-M2.7
MINIMAX_BASE_URL=https://api.minimax.io/v1
# =========================
# Common background jobs
# =========================
ENABLE_PENDING_ORDER_WORKER=true
ENABLE_PORTFOLIO_MONITOR=true
DISABLE_RESTORE_RUNNING_STRATEGIES=false
# =========================
# Agent Gateway (/api/agent/v1) — see docs/agent/AI_INTEGRATION_DESIGN.md
# =========================
# Thread pool size for async agent jobs (backtests, experiment pipelines).
AGENT_JOBS_MAX_WORKERS=4
# Hard kill switch for live trading from agent tokens. Even when a token is
# issued with paper_only=false, live order routing remains disabled until this
# flag is true AND a live executor implementation is wired in. Until then,
# `T`-class agent calls always record paper orders in qd_agent_paper_orders.
AGENT_LIVE_TRADING_ENABLED=false
# Deployment topology hint for the Agent Gateway.
# (unset) — single-tenant / self-hosted; admins keep full control of
# paper_only and the T (Trading) scope.
# saas / hosted — multi-tenant hosted instance (e.g. ai.quantdinger.com):
# `paper_only` is force-pinned to true and any attempt to
# issue a T-scope agent token returns 403. Use this on every
# deployment that serves more than one operator's data, so a
# misconfigured token can never route real-money orders.
QUANTDINGER_DEPLOYMENT_MODE=
# =========================
# Email / SMTP (optional)
# =========================
SMTP_HOST=
SMTP_PORT=587
SMTP_USER=
SMTP_PASSWORD=
SMTP_FROM=
SMTP_USE_TLS=true
SMTP_USE_SSL=false
# =========================
# Proxy (optional)
# =========================
# PROXY_URL=socks5h://127.0.0.1:10808 # local
# PROXY_URL=socks5h://host.docker.internal:10808 # Docker
PROXY_URL=
# Outbound HTTPS to exchanges when using PROXY_URL (especially SOCKS). If you see
# SSLCertVerificationError / "unable to get local issuer certificate":
# - Prefer: install OS ca-certificates in the image, or point to a PEM bundle:
# LIVE_TRADING_CA_BUNDLE=/path/to/ca-bundle.pem
# (REQUESTS_CA_BUNDLE / SSL_CERT_FILE are also honored.)
# - Last resort only: LIVE_TRADING_SSL_VERIFY=false # disables TLS verify — insecure
#LIVE_TRADING_CA_BUNDLE=
#LIVE_TRADING_SSL_VERIFY=
# =========================
# Local desktop brokers (IBKR / MT5)
# =========================
# Interactive Brokers and MetaTrader 5 need TWS/IB Gateway or the MT5 terminal on a
# machine reachable from this API (typically your own PC or a VPS with those apps).
# On a public multi-tenant cloud deployment, set to false so users see a clear message
# instead of broken flows. Crypto exchange API keys are unaffected.
ALLOW_LOCAL_DESKTOP_BROKERS=true
# IBKR: clientId for live orders (strategy worker). Must differ from POST /api/ibkr/connect
# default (1) or TWS will disconnect one of the sessions within seconds.
#IBKR_ORDER_CLIENT_ID=7
# =========================
# Captcha / OAuth (optional)
# =========================
TURNSTILE_SITE_KEY=
TURNSTILE_SECRET_KEY=
GOOGLE_CLIENT_ID=
GOOGLE_CLIENT_SECRET=
GOOGLE_REDIRECT_URI=http://localhost:5000/api/auth/oauth/google/callback
GITHUB_CLIENT_ID=
GITHUB_CLIENT_SECRET=
GITHUB_REDIRECT_URI=http://localhost:5000/api/auth/oauth/github/callback
# =========================
# Billing / payments
# =========================
BILLING_ENABLED=false
# 积分单价
BILLING_COST_AI_ANALYSIS=10
BILLING_COST_AI_CODE_GEN=30
CREDITS_REGISTER_BONUS=100
CREDITS_REFERRAL_BONUS=50
# Membership plans
MEMBERSHIP_MONTHLY_PRICE_USD=19.9
MEMBERSHIP_YEARLY_PRICE_USD=199
MEMBERSHIP_LIFETIME_PRICE_USD=499
MEMBERSHIP_MONTHLY_CREDITS=500
MEMBERSHIP_YEARLY_CREDITS=8000
MEMBERSHIP_LIFETIME_MONTHLY_CREDITS=800
# USDT payment
USDT_PAY_ENABLED=false
USDT_PAY_CHAIN=TRC20
USDT_TRC20_XPUB=
USDT_TRC20_CONTRACT=TXLAQ63Xg1NAzckPwKHvzw7CSEmLMEqcdj
TRONGRID_BASE_URL=https://api.trongrid.io
TRONGRID_API_KEY=
USDT_PAY_CONFIRM_SECONDS=30
USDT_PAY_EXPIRE_MINUTES=30
USDT_WORKER_POLL_INTERVAL=30
# =========================
# Advanced / rarely changed
# =========================
# Network / App tuning
PYTHON_API_HOST=0.0.0.0
PYTHON_API_PORT=5000
PYTHON_API_DEBUG=false
RATE_LIMIT=100
ENABLE_CACHE=false
ENABLE_REQUEST_LOG=true
# Strategy / execution tuning
PENDING_ORDER_STALE_SEC=90
ORDER_MODE=market
MAKER_WAIT_SEC=10
MAKER_OFFSET_BPS=2
STRATEGY_TICK_INTERVAL_SEC=10
# 单进程内「实盘/信号策略」并发线程上限(每个运行中策略约占用 1 条线程)。默认 64;调高需评估内存与系统线程上限,改后重启 API。
STRATEGY_MAX_THREADS=64
PRICE_CACHE_TTL_SEC=10
K_LINE_HISTORY_GET_NUMBER=500
SIGNAL_NOTIFY_TIMEOUT_SEC=6
# LLM advanced tuning
OPENROUTER_API_URL=https://openrouter.ai/api/v1/chat/completions
OPENROUTER_TEMPERATURE=0.7
OPENROUTER_MAX_TOKENS=4000
OPENROUTER_TIMEOUT=300
OPENROUTER_CONNECT_TIMEOUT=30
OPENAI_BASE_URL=https://api.openai.com/v1
DEEPSEEK_BASE_URL=https://api.deepseek.com/v1
GROK_BASE_URL=https://api.x.ai/v1
MINIMAX_BASE_URL=https://api.minimax.io/v1
# Data sources
DATA_SOURCE_TIMEOUT=30
DATA_SOURCE_RETRY=3
DATA_SOURCE_RETRY_BACKOFF=0.5
FINNHUB_API_KEY=
FINNHUB_TIMEOUT=10
FINNHUB_RATE_LIMIT=60
CCXT_DEFAULT_EXCHANGE=coinbase
CCXT_TIMEOUT=10000
AKSHARE_TIMEOUT=30
YFINANCE_TIMEOUT=30
TIINGO_API_KEY=
TIINGO_TIMEOUT=10
# Crypto derivatives / on-chain data (optional, used by some AI prompts)
COINGLASS_API_KEY=
CRYPTOQUANT_API_KEY=
# Twelve Data (CN/HK stock K-lines — recommended for overseas servers)
# Free tier: 800 API credits/day, 8 requests/minute. https://twelvedata.com
TWELVE_DATA_API_KEY=
# Adanos Market Sentiment (optional US stock sentiment enrichment)
# If ADANOS_API_KEY is empty, /api/global-market/adanos-sentiment returns enabled=false.
ADANOS_API_KEY=
ADANOS_SENTIMENT_SOURCE=reddit
ADANOS_API_BASE_URL=https://api.adanos.org
ADANOS_API_TIMEOUT=10
# AI search / news
SEARCH_PROVIDER=google
SEARCH_MAX_RESULTS=10
SEARCH_GOOGLE_API_KEY=
SEARCH_GOOGLE_CX=
SEARCH_BING_API_KEY=
TAVILY_API_KEYS=
SERPAPI_KEYS=
# SMS / phone (optional)
TWILIO_ACCOUNT_SID=
TWILIO_AUTH_TOKEN=
TWILIO_FROM_NUMBER=
# Security / verification tuning
SECURITY_IP_MAX_ATTEMPTS=10
SECURITY_IP_WINDOW_MINUTES=5
SECURITY_IP_BLOCK_MINUTES=15
SECURITY_ACCOUNT_MAX_ATTEMPTS=5
SECURITY_ACCOUNT_WINDOW_MINUTES=60
SECURITY_ACCOUNT_BLOCK_MINUTES=30
VERIFICATION_CODE_EXPIRE_MINUTES=10
VERIFICATION_CODE_RATE_LIMIT=60
VERIFICATION_CODE_IP_HOURLY_LIMIT=10
VERIFICATION_CODE_MAX_ATTEMPTS=5
VERIFICATION_CODE_LOCK_MINUTES=30
# AI analysis tuning
ENABLE_CONFIDENCE_CALIBRATION=false
ENABLE_AI_ENSEMBLE=false
AI_ENSEMBLE_MODELS=openai/gpt-4o,openai/gpt-4o-mini
ENABLE_REFLECTION_WORKER=false
REFLECTION_WORKER_INTERVAL_SEC=86400
REFLECTION_MIN_AGE_DAYS=7
REFLECTION_VALIDATE_LIMIT=200
AI_CALIBRATION_MARKETS=Crypto
AI_CALIBRATION_LOOKBACK_DAYS=30
AI_CALIBRATION_MIN_SAMPLES=80
AI_ANALYSIS_CONSENSUS_TIMEFRAMES=1D,4H
# Redis cache (auto-configured by docker-compose; set CACHE_ENABLED=true to use)
REDIS_HOST=redis
REDIS_PORT=6379
CACHE_ENABLED=true
# Internal
INTERNAL_API_KEY=
SHOW_CN_STOCK=false
# ============================================================
# ALPACA MARKETS (US stocks, ETFs, crypto)
# ============================================================
# Paper: keys start with "PK..." (paper-api.alpaca.markets)
# Live: keys start with "AK..." (api.alpaca.markets)
# Get keys: https://app.alpaca.markets
ALPACA_API_KEY=
ALPACA_SECRET_KEY=
ALPACA_PAPER=true