Skip to content
Niftyhelp 2026.10.1-beta.1 Support

Beta This is the help for Nifty 2026.10.1-beta.1, which isn't released yet. Help for the current release

Configuration

Every setting nifty run takes, as a flag or an environment variable.

On this page

Server

FlagEnvironmentDefaultWhat it does
--dataNIFTY_DATAData directory, default the OS's per-user data directory.
--listenNIFTY_LISTEN127.0.0.1:4000Address to listen on.
--originNIFTY_ORIGINPublic origin (scheme://host[:port]) clients use; default http://<listen>, required off loopback.
--trusted-proxiesNIFTY_TRUSTED_PROXIESProxies whose X-Forwarded-For is believed: CIDRs or addresses, comma separated.

HTTPS

FlagEnvironmentDefaultWhat it does
--acmeNIFTY_ACMEoffServe https with a Let's Encrypt certificate for the origin's host: off, tls (the internet reaches ports 443 or 80) or cloudflare (DNS, with NIFTY_CLOUDFLARE_API_TOKEN).
--acme-directoryNIFTY_ACME_DIRECTORYhttps://acme-v02.api.letsencrypt.org/directoryACME directory URL, e.g. Let's Encrypt staging for trials: https://acme-staging-v02.api.letsencrypt.org/directory.
--acme-emailNIFTY_ACME_EMAILContact address for the ACME account, optional.
--redirect-httpNIFTY_REDIRECT_HTTPAddress that redirects http to https (and answers HTTP-01); default port 80 on --listen's host when serving https on port 443, off turns it off.
--tailscale-portNIFTY_TAILSCALE_PORT443The tailnet https port for --tailscale-serve.
--tailscale-serveNIFTY_TAILSCALE_SERVEoffOn or off: on puts the loopback --listen on the tailnet with tailscale serve, and works out the origin.
--tls-certNIFTY_TLS_CERTServe https with this PEM certificate chain, re-read when it changes.
--tls-keyNIFTY_TLS_KEYThe --tls-cert certificate's PEM private key.

Updates

FlagEnvironmentDefaultWhat it does
--update-checksNIFTY_UPDATE_CHECKSonOn, or off when updates come from elsewhere (the desktop app, a package manager).
--update-urlNIFTY_UPDATE_URLWhere releases are published: https, or http on loopback; default https://releases.niftyware.io (a dry-run build's own local server).

Secrets (environment only)

FlagEnvironmentDefaultWhat it does
NIFTY_SECRET_KEYSeals stored secrets such as AI providers' API keys; default <data>/secret.key, made on first run.
NIFTY_CLOUDFLARE_API_TOKENA Cloudflare API token with Zone → DNS → Edit, for --acme cloudflare.

Menu

2026.10.1-beta.1Contact support