# ============================================ # LOGIN FLOW v2 MULTI-USER QUICK START (Recommended) # ============================================ # Multi-user deployment with OAuth/OIDC authentication (ADR-022). # Use for: Multi-user production deployments, enhanced security. # The MCP server authenticates clients via OIDC and holds per-user # Nextcloud app passwords (encrypted) obtained via Login Flow v2. # # See docs/login-flow-v2.md for the full guide. # Copy this file to .env and configure # ===== REQUIRED SETTINGS ===== # Your Nextcloud instance URL (without trailing slash) NEXTCLOUD_HOST=https://nextcloud.example.com # ===== REQUIRED: LEAVE USERNAME/PASSWORD EMPTY ===== # OAuth mode activates when these are NOT set NEXTCLOUD_USERNAME= NEXTCLOUD_PASSWORD= # ===== REQUIRED: DEPLOYMENT MODE ===== MCP_DEPLOYMENT_MODE=login_flow # ===== STRONGLY RECOMMENDED: STATIC OIDC CLIENT ===== # Register a static client for the MCP server in your IdP and set these. # With Nextcloud's built-in `oidc` app you MUST do this: the DCR fallback # registers an ephemeral client that the app deletes after ~1h, which breaks # auth permanently ("Access forbidden" on reconnect — see issue #907). # Create one under Administration settings -> OpenID Connect provider. NEXTCLOUD_OIDC_CLIENT_ID= NEXTCLOUD_OIDC_CLIENT_SECRET= # MCP Server URL (for OAuth redirects) NEXTCLOUD_MCP_SERVER_URL=http://localhost:8000 # ===== OPTIONAL: SEMANTIC SEARCH (Recommended) ===== # AI-powered semantic search with automatic background operation setup # # When you enable semantic search in multi-user mode: # 1. ENABLE_SEMANTIC_SEARCH automatically enables background operations # 2. Server requests refresh tokens for offline indexing # 3. Tokens are stored encrypted in TOKEN_STORAGE_DB # 4. No need to set ENABLE_BACKGROUND_OPERATIONS separately! # ENABLE_SEMANTIC_SEARCH=true # Vector Database (required for semantic search) QDRANT_URL=http://qdrant:6333 # OR for in-memory mode: #QDRANT_LOCATION=:memory: # Embedding Provider (required for semantic search) # Option 1: Ollama (recommended for local deployment) OLLAMA_BASE_URL=http://ollama:11434 OLLAMA_EMBEDDING_MODEL=nomic-embed-text # Option 2: Amazon Bedrock (for AWS deployments) #AWS_REGION=us-east-1 #BEDROCK_EMBEDDING_MODEL=amazon.titan-embed-text-v2:0 # Token Storage (required for background operations - auto-enabled by semantic search) # Generate encryption key: python -c "from cryptography.fernet import Fernet; print(Fernet.generate_key().decode())" TOKEN_ENCRYPTION_KEY=your-encryption-key-here TOKEN_STORAGE_DB=/app/data/tokens.db # ===== OPTIONAL: DOCUMENT PROCESSING ===== # Extract text from PDFs, images, DOCX for semantic search #ENABLE_DOCUMENT_PROCESSING=true #ENABLE_UNSTRUCTURED=true #UNSTRUCTURED_API_URL=http://unstructured:8000 # ===== SUMMARY OF AUTO-ENABLEMENT ===== # With ENABLE_SEMANTIC_SEARCH=true in OAuth mode: # ✅ Background operations enabled automatically # ✅ Refresh token storage enabled automatically # ✅ Static OIDC client credentials required (see above) # ✅ Encryption key required for token storage # # You only need to set ENABLE_SEMANTIC_SEARCH and provide the required # infrastructure (static OIDC client, Qdrant, Ollama, encryption key). # The rest is automatic! # For more advanced configuration, see env.sample