> ## Documentation Index
> Fetch the complete documentation index at: https://docs.blnkfinance.com/llms.txt
> Use this file to discover all available pages before exploring further.

# License configuration

> Configure the enterprise launcher, branding, authentication, email, cold storage, monitoring, and Watch for your production license deployment.

export const RelatedTopics = ({title = "Related topics", items = []}) => {
  if (!items.length) {
    return null;
  }
  return <nav className="related-topics not-prose mt-20 mb-10 flex flex-col" aria-label={title}>
      <p className="related-topics-heading m-0 border-b border-zinc-200 pb-3 text-sm font-medium text-zinc-500 dark:border-white/10 dark:text-zinc-400">
        {title}
      </p>
      <ul className="related-topics-list m-0 mt-3 flex list-none flex-col gap-0.5 p-0">
        {items.map(item => {
    const isExternal = typeof item.href === "string" && (/^https?:\/\//i).test(item.href);
    return <li key={item.href} className="m-0 p-0">
              <a href={item.href} target={isExternal ? "_blank" : undefined} rel={isExternal ? "noopener noreferrer" : undefined} className="related-topics-link group inline-flex items-center gap-2 text-sm font-semibold text-zinc-700 no-underline transition-colors dark:text-zinc-300">
                <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="16" height="16" fill="none" stroke="currentColor" strokeWidth="2" strokeLinecap="round" strokeLinejoin="round" className="related-topics-icon shrink-0 text-zinc-400 dark:text-zinc-500" aria-hidden="true">
                  <path d="M15 2H6a2 2 0 0 0-2 2v16a2 2 0 0 0 2 2h12a2 2 0 0 0 2-2V7Z" />
                  <path d="M14 2v4a2 2 0 0 0 2 2h4" />
                  <path d="M10 9H8" />
                  <path d="M16 13H8" />
                  <path d="M16 17H8" />
                </svg>
                <span className="relative top-px transition-colors group-hover:text-[#DD7B1B]">
                  {item.title}
                </span>
              </a>
            </li>;
  })}
      </ul>
    </nav>;
};

export const CtaCallout = props => {
  const {title, buttonLabel, href, trackingEvent, buttonTarget, rel = "noopener noreferrer", children} = props;
  const handleCtaClick = () => {
    if (typeof window === "undefined" || !trackingEvent) {
      return;
    }
    try {
      window.dispatchEvent(new CustomEvent("blnk:docs-cta", {
        detail: {
          name: trackingEvent,
          href
        }
      }));
    } catch {}
    try {
      window.posthog?.capture?.(trackingEvent, {
        href
      });
    } catch {}
    const gaPayload = {
      cta_href: href
    };
    try {
      window.gtag?.("event", trackingEvent, gaPayload);
    } catch {}
    try {
      window.dataLayer = window.dataLayer || [];
      window.dataLayer.push({
        event: trackingEvent,
        ...gaPayload
      });
    } catch {}
  };
  const isExternal = typeof href === "string" && (/^https?:\/\//i).test(href);
  const target = buttonTarget ?? (isExternal ? "_blank" : undefined);
  const linkRel = isExternal ? rel : undefined;
  return <section className="cta-callout not-prose relative my-8 w-full min-w-0 overflow-hidden rounded-xl border border-zinc-200 p-5 dark:border-white/10">
      <div className="cta-callout-noise" aria-hidden="true" />
      <div className="cta-callout-layout">
        {title ? <div className="cta-callout-title-row">
            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 28 28" width="14" height="14" className="cta-callout-icon shrink-0 text-zinc-800 dark:text-zinc-200" aria-hidden="true">
              <g fill="none" fillRule="nonzero">
                <path d="M28 0v28H0V0h28ZM14.691833333333335 27.134333333333334l-0.012833333333333334 0.0023333333333333335 -0.08283333333333333 0.04083333333333334 -0.023333333333333334 0.004666666666666667 -0.016333333333333335 -0.004666666666666667 -0.08283333333333333 -0.04083333333333334c-0.011666666666666667 -0.004666666666666667 -0.022166666666666668 -0.0011666666666666668 -0.028000000000000004 0.005833333333333334l-0.004666666666666667 0.011666666666666667 -0.019833333333333335 0.49933333333333335 0.005833333333333334 0.023333333333333334 0.011666666666666667 0.015166666666666667 0.12133333333333333 0.08633333333333333 0.0175 0.004666666666666667 0.014000000000000002 -0.004666666666666667 0.12133333333333333 -0.08633333333333333 0.014000000000000002 -0.018666666666666668 0.004666666666666667 -0.019833333333333335 -0.019833333333333335 -0.4981666666666667c-0.0023333333333333335 -0.011666666666666667 -0.0105 -0.019833333333333335 -0.019833333333333335 -0.021Zm0.3091666666666667 -0.13183333333333336 -0.015166666666666667 0.0023333333333333335 -0.21583333333333335 0.1085 -0.011666666666666667 0.011666666666666667 -0.0035000000000000005 0.012833333333333334 0.021 0.5016666666666667 0.005833333333333334 0.014000000000000002 0.009333333333333334 0.008166666666666668 0.23450000000000004 0.1085c0.014000000000000002 0.004666666666666667 0.026833333333333334 0 0.03383333333333334 -0.009333333333333334l0.004666666666666667 -0.016333333333333335 -0.03966666666666667 -0.7163333333333334c-0.0035000000000000005 -0.014000000000000002 -0.011666666666666667 -0.023333333333333334 -0.023333333333333334 -0.025666666666666667Zm-0.8341666666666667 0.0023333333333333335a0.026833333333333334 0.026833333333334334 0 0 0 -0.0315 0.007000000000000001l-0.007000000000000001 0.016333333333333335 -0.03966666666666667 0.7163333333333334c0 0.014000000000000002 0.008166666666666668 0.023333333333333334 0.019833333333333335 0.028000000000000004l0.0175 -0.0023333333333333335 0.23450000000000004 -0.1085 0.011666666666666667 -0.009333333333333334 0.004666666666666667 -0.012833333333333334 0.019833333333333335 -0.5016666666666667 -0.0035000000000000005 -0.014000000000000002 -0.011666666666666667 -0.011666666666666667 -0.21466666666666667 -0.10733333333333334Z" strokeWidth="1.1667" />
                <path fill="currentColor" d="M14 2.916666666666667A1.75 1.75 0 0 1 15.750000000000002 4.666666666666667v6.302333333333334L21.207666666666668 7.816666666666667a1.75 1.75 0 0 1 1.75 3.031L17.5 14l5.457666666666667 3.151166666666667a1.75 1.75 0 0 1 -1.75 3.031l-5.457666666666667 -3.1500000000000004V23.333333333333336a1.75 1.75 0 0 1 -3.5 0v-6.302333333333334L6.792333333333334 20.183333333333337a1.75 1.75 0 1 1 -1.75 -3.031L10.5 14 5.042333333333334 10.848833333333333a1.75 1.75 0 0 1 1.75 -3.031l5.457666666666667 3.1500000000000004V4.666666666666667A1.75 1.75 0 0 1 14 2.916666666666667Z" strokeWidth="1.1667" />
              </g>
            </svg>
            <p className="cta-callout-title min-w-0 font-semibold text-zinc-800 dark:text-zinc-200">
              {title}
            </p>
          </div> : null}
        <div className={`cta-callout-body text-sm leading-normal text-zinc-800 dark:text-zinc-200${title ? " cta-callout-body--indented" : ""}`}>
          {children}
        </div>
        <a href={href} target={target} rel={linkRel} onClick={handleCtaClick} data-docs-cta={trackingEvent || undefined} className="cta-callout-button inline-flex items-center justify-center gap-1 rounded-full bg-white px-3 py-1.5 text-sm font-semibold transition hover:bg-zinc-100 focus-visible:outline focus-visible:outline-2 focus-visible:outline-offset-2 focus-visible:outline-white/50 dark:bg-white dark:hover:bg-zinc-200">
          {buttonLabel}
          <span className="cta-callout-button-arrow" aria-hidden="true">
            →
          </span>
        </a>
      </div>
    </section>;
};

This is the full configuration reference for your Production License.

Use these environment variables to control launcher behavior, public access, branding, authentication, email delivery, and more.

<Tip>Set these values in your runtime `.env` or `enterprise.env` file before starting the deployment.</Tip>

<CtaCallout title="Need more custom configurations?" href="https://blnkfinance.com/contact/us?utm_source=blnk_docs&utm_medium=documentation&utm_campaign=cloud%2Fstart%2Flicense%2Fconfiguration" buttonLabel="Get Pro Support" trackingEvent="clicked_pro_support">
  Reach out to us to discuss your requirements and customize your setup for you.
</CtaCallout>

***

## Enterprise launcher

The enterprise launcher starts and coordinates the services in your production stack. Use these variables to connect the launcher to shared infrastructure and provide the license used at startup.

```dotenv .env wrap theme={"system"}
ENTERPRISE_POSTGRES_URL=postgres://user:password@host:5432/postgres?sslmode=require
ENTERPRISE_REDIS_URL=redis://host:6379/0
ENTERPRISE_LICENSE_B64=your_base64_license_string
ENTERPRISE_LICENSE_FILE=/run/secrets/blnk-enterprise.lic

# Core and Cloud use separate databases on the Postgres instance above
# Defaults: blnk (Core ledger) and blnk-cloud (Cloud Dashboard)
ENTERPRISE_CORE_DB_NAME=blnk
ENTERPRISE_PLANE_DB_NAME=blnk-cloud
```

| Environment variable       | Default      | Description                                                                                                                                                     |
| :------------------------- | :----------- | :-------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `ENTERPRISE_POSTGRES_URL`  | —            | Postgres connection string used by the launcher to derive the Core and Plane database connections. Point this at the Postgres server that hosts both databases. |
| `ENTERPRISE_REDIS_URL`     | —            | Redis connection string passed to Core for queueing, caching, and other Redis-backed runtime work.                                                              |
| `ENTERPRISE_LICENSE_B64`   | —            | Base64-encoded license string from your onboarding email. Takes precedence over `ENTERPRISE_LICENSE_FILE` when both are set.                                    |
| `ENTERPRISE_LICENSE_FILE`  | —            | Path to your `.lic` license file mounted into the container. Use this instead of `ENTERPRISE_LICENSE_B64` when you mount the license as a file.                 |
| `ENTERPRISE_CORE_DB_NAME`  | `blnk`       | Name of the Postgres database the launcher assigns to Blnk Core ledger data.                                                                                    |
| `ENTERPRISE_PLANE_DB_NAME` | `blnk-cloud` | Name of the Postgres database the launcher assigns to Plane, which powers the Cloud Dashboard.                                                                  |

***

## Bundled services

The production license ships Core, workers, Watch, and query-agent bootstrap in a single enterprise image. Use these variables when you want to run Cloud and Plane only and manage those services separately.

```dotenv .env wrap theme={"system"}
ENTERPRISE_SKIP_CORE=true
ENTERPRISE_SKIP_MIGRATIONS=true
ENTERPRISE_SKIP_WORKERS=true
ENTERPRISE_SKIP_WATCH=true
ENTERPRISE_SKIP_QUERY_AGENT=true
```

| Environment variable          | Default | Description                                                           |
| :---------------------------- | :------ | :-------------------------------------------------------------------- |
| `ENTERPRISE_SKIP_CORE`        | `true`  | Do not start bundled Core in the image.                               |
| `ENTERPRISE_SKIP_MIGRATIONS`  | `true`  | Do not run Core migrations. Implied when `ENTERPRISE_SKIP_CORE=true`. |
| `ENTERPRISE_SKIP_WORKERS`     | `true`  | Do not start Core workers. Implied when `ENTERPRISE_SKIP_CORE=true`.  |
| `ENTERPRISE_SKIP_WATCH`       | `true`  | Do not start bundled Watch.                                           |
| `ENTERPRISE_SKIP_QUERY_AGENT` | `true`  | Do not bootstrap query-agent.                                         |

***

## Public app configuration

These variables control how users reach the deployment and how the launcher connects the internal services.

Use the public values for browser access and the internal port values only when you need to change service bindings.

```dotenv .env wrap theme={"system"}
ENTERPRISE_PUBLIC_PORT=8080
ENTERPRISE_PUBLIC_URL=https://ledger.yourdomain.com
ENTERPRISE_CORE_PORT=5001
ENTERPRISE_WORKERS_PORT=5004
ENTERPRISE_WATCH_PORT=8081
ENTERPRISE_UI_PORT=3001
```

| Environment variable      | Default | Description                                                                                                                      |
| :------------------------ | :------ | :------------------------------------------------------------------------------------------------------------------------------- |
| `ENTERPRISE_PUBLIC_PORT`  | `8080`  | Port the launcher exposes for the public Plane gateway. Map your host or load balancer to this port when running the deployment. |
| `ENTERPRISE_PUBLIC_URL`   | —       | Public URL where users open the Cloud Dashboard, including the scheme such as `https://`. Use the same origin in `CORS_ORIGINS`. |
| `ENTERPRISE_CORE_PORT`    | `5001`  | Internal port used by the Blnk Core API process.                                                                                 |
| `ENTERPRISE_WORKERS_PORT` | `5004`  | Internal port used by the Core workers monitoring endpoint.                                                                      |
| `ENTERPRISE_WATCH_PORT`   | `8081`  | Internal port used by the bundled Watch service.                                                                                 |
| `ENTERPRISE_UI_PORT`      | `3001`  | Internal port used by the Cloud Dashboard UI process.                                                                            |

***

## Custom branding

Customize the Cloud Dashboard theme to match your brand colours. Set your organization name and primary colour so the dashboard feels like your product, not a generic install.

```dotenv .env wrap theme={"system"}
ENTERPRISE_BRAND_NAME=Acme Ledger
ENTERPRISE_BRAND_PRIMARY_COLOR="#A34EF4"
ENTERPRISE_BRAND_LOGO_URL=https://cdn.acme.com/logo.svg
ENTERPRISE_BRAND_FAVICON_URL=https://cdn.acme.com/favicon.ico
ENTERPRISE_BRAND_OG_IMAGE_URL=https://cdn.acme.com/og-image.png
ENTERPRISE_BRAND_HELPER_LINKS_JSON={"ledgers":"https://docs.acme.com/ledgers","balances":"https://docs.acme.com/balances"}
```

| Environment variable                 | Default | Description                                                                                                                                                                            |
| :----------------------------------- | :------ | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `ENTERPRISE_BRAND_NAME`              | —       | Display name used for your deployment in the Cloud Dashboard.                                                                                                                          |
| `ENTERPRISE_BRAND_PRIMARY_COLOR`     | —       | Primary accent color used by the Cloud Dashboard UI. Use a six-digit hex color value, such as `"#A34EF4"`.                                                                             |
| `ENTERPRISE_BRAND_LOGO_URL`          | —       | URL for the logo shown in the Cloud Dashboard.                                                                                                                                         |
| `ENTERPRISE_BRAND_FAVICON_URL`       | —       | URL for the browser favicon.                                                                                                                                                           |
| `ENTERPRISE_BRAND_OG_IMAGE_URL`      | —       | URL for the Open Graph preview image.                                                                                                                                                  |
| `ENTERPRISE_BRAND_HELPER_LINKS_JSON` | —       | JSON object that overrides learn-more banner and CTA links in Cloud. Supported keys: `ledgers`, `ledgerDetails`, `balances`, `transactions`, `identities`, `reconciliation`, `alerts`. |

***

## Security & authentication

These variables configure browser access, local authentication, and encryption for Plane.

```dotenv .env wrap theme={"system"}
CORS_ORIGINS=http://localhost:8080,http://localhost:3001
JWT_SECRET=thisisasecret
BLNK_ENCRYPTION_KEY=0123456789abcdef0123456789abcdef
```

| Environment variable  | Default | Description                                                                                                                                                                          |
| :-------------------- | :------ | :----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `CORS_ORIGINS`        | —       | Comma-separated list of browser origins allowed to call the Plane API. Do not include spaces. Include `ENTERPRISE_PUBLIC_URL` so the Cloud Dashboard can reach the API.              |
| `JWT_SECRET`          | —       | Strong random secret used to sign and verify local authentication tokens. Store this as a secret and keep it stable across restarts.                                                 |
| `BLNK_ENCRYPTION_KEY` | —       | Unique 32-character key used to encrypt sensitive data, including instance connection keys. Do not change it after deployment because existing encrypted data may become unreadable. |

***

## Email handling

Configure SMTP so Plane can send login alerts, password resets, and other Cloud notifications from your deployment.

If you do not already have an SMTP provider, services such as [Resend](https://resend.com), [SendGrid](https://sendgrid.com), or [Amazon SES](https://aws.amazon.com/ses/) can be used.

<Note>
  SMTP is optional. You can skip these variables if you do not need email notifications yet.
</Note>

```dotenv .env wrap theme={"system"}
EMAIL_PROVIDER=smtp
SMTP_HOST=
SMTP_PORT=587
SMTP_AUTH_USERNAME=
SMTP_AUTH_PASSWORD=
SMTP_TLS_MODE=auto
SMTP_SKIP_TLS_VERIFY=false
```

| Environment variable   | Default | Description                                                                                                                                |
| :--------------------- | :------ | :----------------------------------------------------------------------------------------------------------------------------------------- |
| `EMAIL_PROVIDER`       | —       | Email transport Plane should use. Set this to `smtp`, or leave it unset so Plane uses SMTP when `SMTP_HOST` is configured.                 |
| `SMTP_HOST`            | —       | Hostname of the SMTP server that sends mail for your deployment.                                                                           |
| `SMTP_PORT`            | `587`   | Port your SMTP server listens on. Use the value required by your provider.                                                                 |
| `SMTP_AUTH_USERNAME`   | —       | Username used for SMTP authentication. Some providers require a fixed username such as `resend`.                                           |
| `SMTP_AUTH_PASSWORD`   | —       | Password or API key used for SMTP authentication. Store this as a secret.                                                                  |
| `SMTP_TLS_MODE`        | `auto`  | TLS mode Plane uses for the SMTP connection. Use `auto` for STARTTLS-capable servers unless your provider requires another supported mode. |
| `SMTP_SKIP_TLS_VERIFY` | `false` | Whether to skip TLS certificate verification. Use `false` in production.                                                                   |

***

## Cold storage

Configure object-storage archiving for your Lake service.

When enabled, Lake copies eligible older transactions, balances, ledgers, and identities into verified Parquet files while hot Postgres stays lean. Lake keeps archive indexes in sync and leaves hot database rows untouched unless purge is explicitly enabled.

```dotenv .env wrap theme={"system"}
LAKE_ENABLED=true
LAKE_ARCHIVER_ENABLED=true
LAKE_S3_BUCKET=your-bucket
LAKE_S3_ENDPOINT=https://your-s3-endpoint
LAKE_S3_ACCESS_KEY_ID=
LAKE_S3_SECRET_ACCESS_KEY=
LAKE_S3_REGION=auto
LAKE_S3_PATH_STYLE=true
```

| Environment variable        | Default | Description                                                                                                                                  |
| :-------------------------- | :------ | :------------------------------------------------------------------------------------------------------------------------------------------- |
| `LAKE_ENABLED`              | `false` | Turns on the lake feature in Plane.                                                                                                          |
| `LAKE_ARCHIVER_ENABLED`     | `false` | Starts the background worker that archives eligible old rows.                                                                                |
| `LAKE_S3_BUCKET`            | —       | Object storage bucket where Parquet archive files and index files are stored.                                                                |
| `LAKE_S3_ENDPOINT`          | —       | S3-compatible endpoint (e.g., DigitalOcean Spaces, R2, MinIO, or AWS S3 endpoint).                                                           |
| `LAKE_S3_ACCESS_KEY_ID`     | —       | Access key used by Plane to write/read archive objects.                                                                                      |
| `LAKE_S3_SECRET_ACCESS_KEY` | —       | Secret key used with the access key. Store this as a secret.                                                                                 |
| `LAKE_S3_REGION`            | `auto`  | Region passed to the S3 client. `auto` is useful for S3-compatible providers.                                                                |
| `LAKE_S3_PATH_STYLE`        | `true`  | When set to `true`, uses path-style object URLs (`endpoint/bucket/object-key`) instead of virtual-host style (`bucket.endpoint/object-key`). |

***

## Monitoring

Configure object-storage persistence for your Monitoring service.

When set, Monitoring stores traces, metrics, and logs captured from connected instances in your configured S3-compatible bucket so they can be retained and retrieved outside the control-plane database.

```dotenv .env wrap theme={"system"}
MONITORING_STORAGE_S3_BUCKET=
MONITORING_STORAGE_S3_ENDPOINT=
MONITORING_STORAGE_S3_ACCESS_KEY_ID=
MONITORING_STORAGE_S3_SECRET_ACCESS_KEY=
MONITORING_STORAGE_S3_REGION=auto
MONITORING_STORAGE_S3_PATH_STYLE=true
```

| Environment variable                      | Default | Description                                                                        |
| :---------------------------------------- | :------ | :--------------------------------------------------------------------------------- |
| `MONITORING_STORAGE_S3_BUCKET`            | —       | Object storage bucket where Monitoring payloads are stored.                        |
| `MONITORING_STORAGE_S3_ENDPOINT`          | —       | S3-compatible endpoint (e.g., DigitalOcean Spaces, R2, MinIO, or AWS S3 endpoint). |
| `MONITORING_STORAGE_S3_ACCESS_KEY_ID`     | —       | Access key used by Monitoring to write/read stored payloads.                       |
| `MONITORING_STORAGE_S3_SECRET_ACCESS_KEY` | —       | Secret key used with the access key. Store this as a secret.                       |
| `MONITORING_STORAGE_S3_REGION`            | `auto`  | Region passed to the S3 client.                                                    |
| `MONITORING_STORAGE_S3_PATH_STYLE`        | `true`  | When set to `true`, uses path-style object URLs instead of virtual-host style.     |

***

## Watch

Configure Git-based rule loading for your Watch service. When `WATCH_SCRIPT_GIT_REPO` is set, Watch clones the repository, loads `.ws` rule files from it, and keeps the local copy in sync.

For additional Watch settings, see [Watch configuration](/watch/configuration).

```dotenv .env wrap theme={"system"}
WATCH_SCRIPT_GIT_REPO=
WATCH_SCRIPT_GIT_BRANCH=main
WATCH_SCRIPT_GIT_USERNAME=x-access-token
WATCH_SCRIPT_GIT_TOKEN=
```

| Environment variable        | Default          | Description                                                                                                                              |
| :-------------------------- | :--------------- | :--------------------------------------------------------------------------------------------------------------------------------------- |
| `WATCH_SCRIPT_GIT_REPO`     | —                | Git repository URL containing Watch rule files. When set, Watch loads rules from this repository instead of relying only on local files. |
| `WATCH_SCRIPT_GIT_BRANCH`   | `main`           | Git branch Watch tracks when `WATCH_SCRIPT_GIT_REPO` is set. Use the branch that contains the rules for this deployment.                 |
| `WATCH_SCRIPT_GIT_USERNAME` | `x-access-token` | Username used to authenticate when cloning a private rules repository over HTTPS.                                                        |
| `WATCH_SCRIPT_GIT_TOKEN`    | —                | Personal access token or password used with `WATCH_SCRIPT_GIT_USERNAME` for private repository access. Store this as a secret.           |

<RelatedTopics
  items={[
{ title: "Installation", href: "/cloud/start/license/start" },
{ title: "Watch quick start", href: "/watch/quick-start" },
{ title: "Getting started", href: "/cloud/start/guide" },
]}
/>
