
Deploy NextChat
NextChat with strict access-code protection and a required server-side provider key.
Just deployed
Deploy and Host NextChat on Railway
A thin security wrapper around official NextChat v2.16.1, pinned to sha256:eaaa469ddeeb5fa58fb35f8767e9e096a2f1c8468c54b6703323624bf3071c5a. No full application rebuild is needed.
Deploy
- Supply OPENAI_API_KEY: a nonempty server-side OpenAI or OpenAI-compatible provider credential is required, with no default.
- Railway generates required CODE. Copy it privately from service variables and enter it in NextChat's Access Code field.
- Optionally set BASE_URL to a trusted compatible provider origin/prefix, without trailing
/v1. Empty useshttps://api.openai.com. - Open the Railway HTTPS domain. Healthcheck is
GET /, port3000, timeout 120 seconds.
| Variable | Required | Default | Purpose |
|---|---|---|---|
| CODE | Yes | ${{secret()}} | Shared access password; startup fails closed if empty. |
| OPENAI_API_KEY | Yes | None | Server provider credential; startup fails closed if empty or equal to CODE. |
| BASE_URL | No | OpenAI origin | Trusted OpenAI-compatible backend; requests carry the server key. |
| HIDE_USER_API_KEY | Forced | 1 | Strict CODE authentication; browser BYOK bypass is disabled. |
| HOSTNAME | Yes | 0.0.0.0 | Container bind address. |
| PORT | Yes | 3000 | Public domain target port. |
The wrapper validates configuration before loading the application and drops entire known [Auth] and [Server Config] console calls before formatting arguments, including newline-containing secrets. A fetch guard rejects outgoing NextChat access-code bearer headers. It does not rewrite minified JavaScript. Strict CODE mode cannot be disabled through HIDE_USER_API_KEY. The wrapper directly launches Node; the upstream optional PROXY_URL/proxychains launcher is not supported.
This template supports the server-key OpenAI-compatible path. Other vendor-specific integrations are not validated. Do not use CODE as a provider key, and do not configure untrusted BASE_URL endpoints. The shared code is not individual user accounts or rate limiting. Keep provider quotas and Railway log access restricted.
Storage and use cases
Use as a personal or shared chat UI backed by your provider. No database or volume is required: history and settings live in the browser, not in a server backup. Export important conversations. Cross-device sync and real-provider inference are not implied by mock testing.
Source and verification
Source: https://github.com/leoisadev1/railway-template-nextchat. The Dockerfile extends the digest-pinned official upstream image and runs node --test tests/security.test.cjs during its thin build. Local tests can be run with the same command.
The unwrapped upstream image logs access codes and server-key diagnostics and can forward CODE without a server key. This wrapper suppresses those diagnostic calls and requires a distinct server-side provider credential before startup. Previously exposed credentials should be rotated; installing the wrapper does not erase old logs.
Real Railway/browser verification at commit a894c5b007f833ac6b46240f7e6cffab5f08395b covered missing/wrong-code denial, correct-code streaming against a controlled mock, history reload, and simulated provider failure. The mock received the server credential, not CODE, and a private runtime-log scan found no generated CODE. No real model keys or inference were used, and these tests do not validate your provider account, billing, or model access.
Commit bc5b2e389ba39d4b4b53f79a58787704503f8f48 adds only whole-call [Server Config] suppression and its regression case. All ten tests and replay of the actual upstream diagnostic statements pass locally. That final log-suppression delta was locally tested but not redeployed. Subsequent README-only changes do not alter runtime behavior. The earlier real-browser workflows remain relevant to the unchanged UI/network behavior; this is not a blanket production-security certification.
Template Content
OPENAI_API_KEY
Required server-side OpenAI or OpenAI-compatible provider key. No default; startup refuses to run without it. Browser BYOK is disabled.
