{
  "manifest_version": "1.0.0",
  "template": {
    "id": "b4bcfe4b-842e-4b03-8847-b128dda252f0",
    "slug": "inbox-zero",
    "name": "Inbox Zero | Open-Source AI Email Assistant for Gmail and Outlook",
    "description": "AI email assistant for Gmail and Outlook with your own LLM key and cron",
    "url": "https://railway.com/deploy/inbox-zero",
    "upstream": {
      "repo_url": "https://github.com/nomideusz/inbox-zero-railway"
    }
  },
  "status": "unvalidated",
  "validated_at": null,
  "success_rate_30d": null,
  "services": [
    {
      "name": "Redis",
      "source": {
        "image": "redis:8.10.2-alpine"
      },
      "needs_volume": true,
      "volume_mount_path": "/data",
      "http": false
    },
    {
      "name": "Redis-HTTP",
      "source": {
        "image": "hiett/serverless-redis-http:0.0.10"
      },
      "needs_volume": false,
      "http": false
    },
    {
      "name": "Inbox Zero",
      "source": {
        "repo": "https://github.com/nomideusz/inbox-zero-railway"
      },
      "needs_volume": false,
      "http": true
    },
    {
      "name": "Postgres",
      "source": {
        "image": "ghcr.io/railwayapp-templates/postgres-ssl:17"
      },
      "needs_volume": true,
      "volume_mount_path": "/var/lib/postgresql/data",
      "http": false
    }
  ],
  "required_inputs": [
    {
      "key": "REDIS_PASSWORD",
      "service": "Redis",
      "description": "Auto-generated Redis password",
      "secret": true,
      "strategy": "generate",
      "generate": "strong_password"
    },
    {
      "key": "SRH_IPV6",
      "service": "Redis-HTTP",
      "description": "Listen on IPv6 for Railway's private network - leave as is",
      "secret": false,
      "strategy": "default",
      "default": "true"
    },
    {
      "key": "SRH_MODE",
      "service": "Redis-HTTP",
      "description": "Single Redis connection from the variables below - leave as is",
      "secret": false,
      "strategy": "default",
      "default": "env"
    },
    {
      "key": "SRH_TOKEN",
      "service": "Redis-HTTP",
      "description": "Bearer token Inbox Zero uses for the proxy",
      "secret": true,
      "strategy": "generate",
      "generate": "random_base64_32"
    },
    {
      "key": "SRH_CONNECTION_STRING",
      "service": "Redis-HTTP",
      "description": "Redis on the private network - leave as is",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "PORT",
      "service": "Inbox Zero",
      "description": "Port Inbox Zero listens on - leave as is",
      "secret": false,
      "strategy": "default",
      "default": "3000"
    },
    {
      "key": "HOSTNAME",
      "service": "Inbox Zero",
      "description": "Listen on IPv4 and IPv6 - leave as is",
      "secret": false,
      "strategy": "default",
      "default": "::"
    },
    {
      "key": "REDIS_URL",
      "service": "Inbox Zero",
      "description": "Redis for live inbox updates - private network, leave as is",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "DIRECT_URL",
      "service": "Inbox Zero",
      "description": "Postgres connection for migrations - leave as is",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "AUTH_SECRET",
      "service": "Inbox Zero",
      "description": "Signs login sessions",
      "secret": true,
      "strategy": "generate",
      "generate": "random_base64_32"
    },
    {
      "key": "CRON_SECRET",
      "service": "Inbox Zero",
      "description": "Authenticates the built-in scheduled jobs",
      "secret": true,
      "strategy": "generate",
      "generate": "random_base64_32"
    },
    {
      "key": "LLM_API_KEY",
      "service": "Inbox Zero",
      "description": "API key for the provider in DEFAULT_LLMS (Anthropic, OpenAI, Google, OpenRouter, ...) - needs API billing, not a chat subscription",
      "secret": true,
      "strategy": "generate",
      "generate": "random_base64_32"
    },
    {
      "key": "API_KEY_SALT",
      "service": "Inbox Zero",
      "description": "Salt for hashing user API keys - never change",
      "secret": true,
      "strategy": "generate",
      "generate": "random_base64_32"
    },
    {
      "key": "DATABASE_URL",
      "service": "Inbox Zero",
      "description": "Postgres connection - private network, leave as is",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "DEFAULT_LLMS",
      "service": "Inbox Zero",
      "description": "Main model as provider:model, e.g. openai:gpt-6-luna or google:gemini-3.8-flash",
      "secret": false,
      "strategy": "default",
      "default": "anthropic:claude-sonnet-5-5"
    },
    {
      "key": "ECONOMY_LLMS",
      "service": "Inbox Zero",
      "description": "Cheaper model for high-volume tasks, same provider:model format - optional, falls back to DEFAULT_LLMS",
      "secret": false,
      "strategy": "default",
      "default": "anthropic:claude-haiku-4-5"
    },
    {
      "key": "REDIS_HTTP_URL",
      "service": "Inbox Zero",
      "description": "Upstash-compatible Redis REST proxy - private network, leave as is",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "GOOGLE_CLIENT_ID",
      "service": "Inbox Zero",
      "description": "Google OAuth client ID (see the template README for the redirect URIs) - set to skipped if you only use Outlook",
      "secret": false,
      "strategy": "ask_user"
    },
    {
      "key": "INTERNAL_API_KEY",
      "service": "Inbox Zero",
      "description": "Authenticates internal job calls",
      "secret": true,
      "strategy": "generate",
      "generate": "random_base64_32"
    },
    {
      "key": "INTERNAL_API_URL",
      "service": "Inbox Zero",
      "description": "Background jobs call the app inside its own container - leave as is",
      "secret": false,
      "strategy": "default",
      "default": "http://localhost:3000"
    },
    {
      "key": "REDIS_HTTP_TOKEN",
      "service": "Inbox Zero",
      "description": "Token for the Redis REST proxy - leave as is",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "EMAIL_ENCRYPT_SALT",
      "service": "Inbox Zero",
      "description": "Salt for token encryption - never change after the first sign-in",
      "secret": false,
      "strategy": "generate",
      "generate": "random_base64_32"
    },
    {
      "key": "AUTH_ALLOWED_EMAILS",
      "service": "Inbox Zero",
      "description": "Comma-separated email addresses allowed to sign up - everyone else is refused, so nobody else can use your AI key",
      "secret": false,
      "strategy": "ask_user"
    },
    {
      "key": "EMAIL_ENCRYPT_SECRET",
      "service": "Inbox Zero",
      "description": "Encrypts stored OAuth tokens - never change after the first sign-in",
      "secret": true,
      "strategy": "generate",
      "generate": "random_base64_32"
    },
    {
      "key": "GOOGLE_CLIENT_SECRET",
      "service": "Inbox Zero",
      "description": "Google OAuth client secret - set to skipped if you only use Outlook",
      "secret": true,
      "strategy": "generate",
      "generate": "random_base64_32"
    },
    {
      "key": "NEXT_PUBLIC_BASE_URL",
      "service": "Inbox Zero",
      "description": "Public URL - set it to your custom domain after adding one, and update the OAuth redirect URIs to match",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_domain"
    },
    {
      "key": "GOOGLE_PUBSUB_TOPIC_NAME",
      "service": "Inbox Zero",
      "description": "Pub/Sub topic for Gmail push notifications: projects/<project-id>/topics/<topic> - set to skipped if you only use Outlook",
      "secret": false,
      "strategy": "ask_user"
    },
    {
      "key": "MICROSOFT_WEBHOOK_CLIENT_STATE",
      "service": "Inbox Zero",
      "description": "Verifies Outlook webhook notifications - leave as is",
      "secret": false,
      "strategy": "generate",
      "generate": "random_base64_32"
    },
    {
      "key": "NEXT_PUBLIC_EMAIL_SEND_ENABLED",
      "service": "Inbox Zero",
      "description": "Allows sending and replying from Inbox Zero",
      "secret": false,
      "strategy": "default",
      "default": "true"
    },
    {
      "key": "RAILWAY_HEALTHCHECK_TIMEOUT_SEC",
      "service": "Inbox Zero",
      "description": "First boot waits for Postgres and runs the database migrations",
      "secret": false,
      "strategy": "default",
      "default": "600"
    },
    {
      "key": "GOOGLE_PUBSUB_VERIFICATION_TOKEN",
      "service": "Inbox Zero",
      "description": "Token for the Pub/Sub push endpoint: https://<domain>/api/google/webhook?token=<this value>",
      "secret": true,
      "strategy": "generate",
      "generate": "random_base64_32"
    },
    {
      "key": "NEXT_PUBLIC_BYPASS_PREMIUM_CHECKS",
      "service": "Inbox Zero",
      "description": "Unlocks all features on a self-hosted instance - leave as is",
      "secret": false,
      "strategy": "default",
      "default": "true"
    },
    {
      "key": "PGDATA",
      "service": "Postgres",
      "description": "Data subdirectory - keeps Postgres happy on Railway volumes",
      "secret": false,
      "strategy": "default",
      "default": "/var/lib/postgresql/data/pgdata"
    },
    {
      "key": "POSTGRES_DB",
      "service": "Postgres",
      "description": "Database name",
      "secret": false,
      "strategy": "default",
      "default": "inboxzero"
    },
    {
      "key": "POSTGRES_USER",
      "service": "Postgres",
      "description": "Database user",
      "secret": false,
      "strategy": "default",
      "default": "inboxzero"
    },
    {
      "key": "POSTGRES_PASSWORD",
      "service": "Postgres",
      "description": "Auto-generated database password",
      "secret": true,
      "strategy": "generate",
      "generate": "strong_password"
    },
    {
      "key": "RAILWAY_DEPLOYMENT_DRAINING_SECONDS",
      "service": "Postgres",
      "description": "Time for Postgres to shut down cleanly on redeploy",
      "secret": false,
      "strategy": "default",
      "default": "60"
    }
  ],
  "deploy": {
    "mcp": {
      "server": "railway",
      "tool": "deploy_template",
      "args": {
        "template_code": "inbox-zero"
      }
    },
    "cli": "railway deploy --template inbox-zero",
    "api": {
      "method": "POST",
      "path": "/graphql/v2",
      "body": {
        "query": "mutation templateDeploy($input: TemplateDeployV2Input!) { templateDeployV2(input: $input) { projectId workflowId } }",
        "variables": {
          "input": {
            "templateId": "b4bcfe4b-842e-4b03-8847-b128dda252f0",
            "serializedConfig": {
              "services": {
                "20d5490c-7652-4f9d-b23c-223d1a0c26d0": {
                  "icon": "https://devicons.railway.app/i/redis.svg",
                  "name": "Redis",
                  "build": {},
                  "deploy": {
                    "startCommand": "/bin/sh -c \"rm -rf /data/lost+found && exec docker-entrypoint.sh redis-server --requirepass $REDIS_PASSWORD --appendonly yes --dir /data\"",
                    "healthcheckPath": null,
                    "restartPolicyType": "ON_FAILURE",
                    "restartPolicyMaxRetries": 10
                  },
                  "source": {
                    "image": "redis:8.10.2-alpine"
                  },
                  "variables": {
                    "REDIS_PASSWORD": {
                      "isOptional": false,
                      "description": "Auto-generated Redis password",
                      "defaultValue": "{{REDIS_PASSWORD}}"
                    }
                  },
                  "networking": {
                    "serviceDomains": {}
                  },
                  "volumeMounts": {
                    "20d5490c-7652-4f9d-b23c-223d1a0c26d0": {
                      "mountPath": "/data"
                    }
                  }
                },
                "5795ddee-4c98-4b74-81d2-ef8c21aed880": {
                  "icon": "https://devicons.railway.app/i/redis.svg",
                  "name": "Redis-HTTP",
                  "build": {},
                  "deploy": {
                    "startCommand": null,
                    "healthcheckPath": null,
                    "restartPolicyType": "ON_FAILURE",
                    "restartPolicyMaxRetries": 10
                  },
                  "source": {
                    "image": "hiett/serverless-redis-http:0.0.10"
                  },
                  "variables": {
                    "SRH_IPV6": {
                      "isOptional": false,
                      "description": "Listen on IPv6 for Railway's private network - leave as is",
                      "defaultValue": "true"
                    },
                    "SRH_MODE": {
                      "isOptional": false,
                      "description": "Single Redis connection from the variables below - leave as is",
                      "defaultValue": "env"
                    },
                    "SRH_TOKEN": {
                      "isOptional": false,
                      "description": "Bearer token Inbox Zero uses for the proxy",
                      "defaultValue": "{{SRH_TOKEN}}"
                    },
                    "SRH_CONNECTION_STRING": {
                      "isOptional": false,
                      "description": "Redis on the private network - leave as is",
                      "defaultValue": "redis://:${{Redis.REDIS_PASSWORD}}@${{Redis.RAILWAY_PRIVATE_DOMAIN}}:6379"
                    }
                  },
                  "networking": {
                    "serviceDomains": {}
                  }
                },
                "84bf10c6-4f76-459a-a0dc-b97f5c021204": {
                  "icon": "https://cdn.jsdelivr.net/gh/elie222/inbox-zero@main/apps/web/public/icons/icon-192x192.png",
                  "name": "Inbox Zero",
                  "build": {},
                  "deploy": {
                    "startCommand": null,
                    "healthcheckPath": "/api/health",
                    "restartPolicyType": "ON_FAILURE",
                    "restartPolicyMaxRetries": 10
                  },
                  "source": {
                    "repo": "https://github.com/nomideusz/inbox-zero-railway",
                    "rootDirectory": "/"
                  },
                  "variables": {
                    "PORT": {
                      "isOptional": false,
                      "description": "Port Inbox Zero listens on - leave as is",
                      "defaultValue": "3000"
                    },
                    "HOSTNAME": {
                      "isOptional": false,
                      "description": "Listen on IPv4 and IPv6 - leave as is",
                      "defaultValue": "::"
                    },
                    "REDIS_URL": {
                      "isOptional": false,
                      "description": "Redis for live inbox updates - private network, leave as is",
                      "defaultValue": "redis://default:${{Redis.REDIS_PASSWORD}}@${{Redis.RAILWAY_PRIVATE_DOMAIN}}:6379?family=0"
                    },
                    "DIRECT_URL": {
                      "isOptional": false,
                      "description": "Postgres connection for migrations - leave as is",
                      "defaultValue": "postgresql://${{Postgres.POSTGRES_USER}}:${{Postgres.POSTGRES_PASSWORD}}@${{Postgres.RAILWAY_PRIVATE_DOMAIN}}:5432/${{Postgres.POSTGRES_DB}}?schema=public"
                    },
                    "AUTH_SECRET": {
                      "isOptional": false,
                      "description": "Signs login sessions",
                      "defaultValue": "{{AUTH_SECRET}}"
                    },
                    "CRON_SECRET": {
                      "isOptional": false,
                      "description": "Authenticates the built-in scheduled jobs",
                      "defaultValue": "{{CRON_SECRET}}"
                    },
                    "LLM_API_KEY": {
                      "isOptional": false,
                      "description": "API key for the provider in DEFAULT_LLMS (Anthropic, OpenAI, Google, OpenRouter, ...) - needs API billing, not a chat subscription",
                      "defaultValue": "{{LLM_API_KEY}}"
                    },
                    "API_KEY_SALT": {
                      "isOptional": false,
                      "description": "Salt for hashing user API keys - never change",
                      "defaultValue": "{{API_KEY_SALT}}"
                    },
                    "DATABASE_URL": {
                      "isOptional": false,
                      "description": "Postgres connection - private network, leave as is",
                      "defaultValue": "postgresql://${{Postgres.POSTGRES_USER}}:${{Postgres.POSTGRES_PASSWORD}}@${{Postgres.RAILWAY_PRIVATE_DOMAIN}}:5432/${{Postgres.POSTGRES_DB}}?schema=public"
                    },
                    "DEFAULT_LLMS": {
                      "isOptional": false,
                      "description": "Main model as provider:model, e.g. openai:gpt-6-luna or google:gemini-3.8-flash",
                      "defaultValue": "anthropic:claude-sonnet-5-5"
                    },
                    "ECONOMY_LLMS": {
                      "isOptional": true,
                      "description": "Cheaper model for high-volume tasks, same provider:model format - optional, falls back to DEFAULT_LLMS",
                      "defaultValue": "anthropic:claude-haiku-4-5"
                    },
                    "REDIS_HTTP_URL": {
                      "isOptional": false,
                      "description": "Upstash-compatible Redis REST proxy - private network, leave as is",
                      "defaultValue": "http://${{Redis-HTTP.RAILWAY_PRIVATE_DOMAIN}}:80"
                    },
                    "GOOGLE_CLIENT_ID": {
                      "isOptional": false,
                      "description": "Google OAuth client ID (see the template README for the redirect URIs) - set to skipped if you only use Outlook",
                      "defaultValue": "{{GOOGLE_CLIENT_ID}}"
                    },
                    "INTERNAL_API_KEY": {
                      "isOptional": false,
                      "description": "Authenticates internal job calls",
                      "defaultValue": "{{INTERNAL_API_KEY}}"
                    },
                    "INTERNAL_API_URL": {
                      "isOptional": false,
                      "description": "Background jobs call the app inside its own container - leave as is",
                      "defaultValue": "http://localhost:3000"
                    },
                    "REDIS_HTTP_TOKEN": {
                      "isOptional": false,
                      "description": "Token for the Redis REST proxy - leave as is",
                      "defaultValue": "${{Redis-HTTP.SRH_TOKEN}}"
                    },
                    "EMAIL_ENCRYPT_SALT": {
                      "isOptional": false,
                      "description": "Salt for token encryption - never change after the first sign-in",
                      "defaultValue": "{{EMAIL_ENCRYPT_SALT}}"
                    },
                    "AUTH_ALLOWED_EMAILS": {
                      "isOptional": false,
                      "description": "Comma-separated email addresses allowed to sign up - everyone else is refused, so nobody else can use your AI key",
                      "defaultValue": "{{AUTH_ALLOWED_EMAILS}}"
                    },
                    "MICROSOFT_CLIENT_ID": {
                      "isOptional": true,
                      "description": "Microsoft Entra application (client) ID - optional, for Outlook accounts",
                      "defaultValue": ""
                    },
                    "EMAIL_ENCRYPT_SECRET": {
                      "isOptional": false,
                      "description": "Encrypts stored OAuth tokens - never change after the first sign-in",
                      "defaultValue": "{{EMAIL_ENCRYPT_SECRET}}"
                    },
                    "GOOGLE_CLIENT_SECRET": {
                      "isOptional": false,
                      "description": "Google OAuth client secret - set to skipped if you only use Outlook",
                      "defaultValue": "{{GOOGLE_CLIENT_SECRET}}"
                    },
                    "NEXT_PUBLIC_BASE_URL": {
                      "isOptional": false,
                      "description": "Public URL - set it to your custom domain after adding one, and update the OAuth redirect URIs to match",
                      "defaultValue": "https://${{RAILWAY_PUBLIC_DOMAIN}}"
                    },
                    "MICROSOFT_CLIENT_SECRET": {
                      "isOptional": true,
                      "description": "Microsoft Entra client secret value - optional, for Outlook accounts",
                      "defaultValue": ""
                    },
                    "GOOGLE_PUBSUB_TOPIC_NAME": {
                      "isOptional": false,
                      "description": "Pub/Sub topic for Gmail push notifications: projects/<project-id>/topics/<topic> - set to skipped if you only use Outlook",
                      "defaultValue": "{{GOOGLE_PUBSUB_TOPIC_NAME}}"
                    },
                    "MICROSOFT_WEBHOOK_CLIENT_STATE": {
                      "isOptional": false,
                      "description": "Verifies Outlook webhook notifications - leave as is",
                      "defaultValue": "{{MICROSOFT_WEBHOOK_CLIENT_STATE}}"
                    },
                    "NEXT_PUBLIC_EMAIL_SEND_ENABLED": {
                      "isOptional": false,
                      "description": "Allows sending and replying from Inbox Zero",
                      "defaultValue": "true"
                    },
                    "RAILWAY_HEALTHCHECK_TIMEOUT_SEC": {
                      "isOptional": false,
                      "description": "First boot waits for Postgres and runs the database migrations",
                      "defaultValue": "600"
                    },
                    "GOOGLE_PUBSUB_VERIFICATION_TOKEN": {
                      "isOptional": false,
                      "description": "Token for the Pub/Sub push endpoint: https://<domain>/api/google/webhook?token=<this value>",
                      "defaultValue": "{{GOOGLE_PUBSUB_VERIFICATION_TOKEN}}"
                    },
                    "NEXT_PUBLIC_BYPASS_PREMIUM_CHECKS": {
                      "isOptional": false,
                      "description": "Unlocks all features on a self-hosted instance - leave as is",
                      "defaultValue": "true"
                    }
                  },
                  "networking": {
                    "serviceDomains": {
                      "<hasDomain>": {}
                    }
                  }
                },
                "b1dab965-c446-483a-a8cd-ce71a87e3144": {
                  "icon": "https://devicons.railway.app/i/postgresql.svg",
                  "name": "Postgres",
                  "build": {},
                  "deploy": {
                    "startCommand": null,
                    "healthcheckPath": null,
                    "restartPolicyType": "ON_FAILURE",
                    "restartPolicyMaxRetries": 10
                  },
                  "source": {
                    "image": "ghcr.io/railwayapp-templates/postgres-ssl:17"
                  },
                  "variables": {
                    "PGDATA": {
                      "isOptional": false,
                      "description": "Data subdirectory - keeps Postgres happy on Railway volumes",
                      "defaultValue": "/var/lib/postgresql/data/pgdata"
                    },
                    "POSTGRES_DB": {
                      "isOptional": false,
                      "description": "Database name",
                      "defaultValue": "inboxzero"
                    },
                    "POSTGRES_USER": {
                      "isOptional": false,
                      "description": "Database user",
                      "defaultValue": "inboxzero"
                    },
                    "POSTGRES_PASSWORD": {
                      "isOptional": false,
                      "description": "Auto-generated database password",
                      "defaultValue": "{{POSTGRES_PASSWORD}}"
                    },
                    "RAILWAY_DEPLOYMENT_DRAINING_SECONDS": {
                      "isOptional": false,
                      "description": "Time for Postgres to shut down cleanly on redeploy",
                      "defaultValue": "60"
                    }
                  },
                  "networking": {
                    "serviceDomains": {}
                  },
                  "volumeMounts": {
                    "b1dab965-c446-483a-a8cd-ce71a87e3144": {
                      "mountPath": "/var/lib/postgresql/data"
                    }
                  }
                }
              }
            }
          }
        }
      }
    }
  },
  "post_deploy": {
    "healthcheck": {
      "service": "Inbox Zero",
      "method": "GET",
      "path": "/api/health",
      "expect_status": 200
    }
  },
  "resources": {
    "expected_services": 4,
    "needs_volume": true
  },
  "generated_at": "2026-10-06T16:14:38.430Z",
  "generator_version": "0.1.0"
}
