Deploy NextChat

NextChat with strict access-code protection and a required server-side provider key.

Deploy NextChat

Deploy and Host NextChat on Railway

A thin security wrapper around official NextChat v2.16.1, pinned to sha256:eaaa469ddeeb5fa58fb35f8767e9e096a2f1c8468c54b6703323624bf3071c5a. No full application rebuild is needed.

Deploy

  1. Supply OPENAI_API_KEY: a nonempty server-side OpenAI or OpenAI-compatible provider credential is required, with no default.
  2. Railway generates required CODE. Copy it privately from service variables and enter it in NextChat's Access Code field.
  3. Optionally set BASE_URL to a trusted compatible provider origin/prefix, without trailing /v1. Empty uses https://api.openai.com.
  4. Open the Railway HTTPS domain. Healthcheck is GET /, port 3000, timeout 120 seconds.
VariableRequiredDefaultPurpose
CODEYes${{secret()}}Shared access password; startup fails closed if empty.
OPENAI_API_KEYYesNoneServer provider credential; startup fails closed if empty or equal to CODE.
BASE_URLNoOpenAI originTrusted OpenAI-compatible backend; requests carry the server key.
HIDE_USER_API_KEYForced1Strict CODE authentication; browser BYOK bypass is disabled.
HOSTNAMEYes0.0.0.0Container bind address.
PORTYes3000Public domain target port.

The wrapper validates configuration before loading the application and drops entire known [Auth] and [Server Config] console calls before formatting arguments, including newline-containing secrets. A fetch guard rejects outgoing NextChat access-code bearer headers. It does not rewrite minified JavaScript. Strict CODE mode cannot be disabled through HIDE_USER_API_KEY. The wrapper directly launches Node; the upstream optional PROXY_URL/proxychains launcher is not supported.

This template supports the server-key OpenAI-compatible path. Other vendor-specific integrations are not validated. Do not use CODE as a provider key, and do not configure untrusted BASE_URL endpoints. The shared code is not individual user accounts or rate limiting. Keep provider quotas and Railway log access restricted.

Storage and use cases

Use as a personal or shared chat UI backed by your provider. No database or volume is required: history and settings live in the browser, not in a server backup. Export important conversations. Cross-device sync and real-provider inference are not implied by mock testing.

Source and verification

Source: https://github.com/leoisadev1/railway-template-nextchat. The Dockerfile extends the digest-pinned official upstream image and runs node --test tests/security.test.cjs during its thin build. Local tests can be run with the same command.

The unwrapped upstream image logs access codes and server-key diagnostics and can forward CODE without a server key. This wrapper suppresses those diagnostic calls and requires a distinct server-side provider credential before startup. Previously exposed credentials should be rotated; installing the wrapper does not erase old logs.

Real Railway/browser verification at commit a894c5b007f833ac6b46240f7e6cffab5f08395b covered missing/wrong-code denial, correct-code streaming against a controlled mock, history reload, and simulated provider failure. The mock received the server credential, not CODE, and a private runtime-log scan found no generated CODE. No real model keys or inference were used, and these tests do not validate your provider account, billing, or model access.

Commit bc5b2e389ba39d4b4b53f79a58787704503f8f48 adds only whole-call [Server Config] suppression and its regression case. All ten tests and replay of the actual upstream diagnostic statements pass locally. That final log-suppression delta was locally tested but not redeployed. Subsequent README-only changes do not alter runtime behavior. The earlier real-browser workflows remain relevant to the unchanged UI/network behavior; this is not a blanket production-security certification.


Template Content

More templates in this category

View Template
Chat Chat
Chat Chat, your own unified chat and search to AI platform.

okisdev
116
View Template
stella
Self-host stella with web, API, Postgres, Redis, and object storage.

Jan Kubica
7
View Template
Hermes Agent | OpenClaw Alternative with Dashboard
Self-Hosted Hermes AI Agent for Telegram, Discord & Slack

codestorm
82