Configuration
Every REZEPTE_* environment variable and command-line flag
Rezepte takes its entire configuration from environment variables — there is no config file.
Prop
Type
REZEPTE_LOCALE is only a starting point: every member picks their own language in Settings, and the "Add account" dialog in the app starts on the language of the admin filling it in rather than on this value.
The account created on the first start owns the instance. It cannot be deleted, it cannot lose its admin rights, nobody else can reset its password, and it is the only account that can make someone else an admin — see First login. Changing REZEPTE_ADMIN_USER later changes nothing — it is read only while the instance has no accounts at all. REZEPTE_ADMIN_PASSWORD is read on that first start too, and after that by --reset-superadmin-password below and by nothing else, so setting it on a running instance changes no password on its own.
REZEPTE_OIDC_ISSUER, REZEPTE_OIDC_CLIENT_ID and REZEPTE_PUBLIC_URL go together: set one of the first two without the others and Rezepte refuses to start, naming all three. Rezepte asks the provider for its settings only when someone first presses the button, so a provider that is down never keeps Rezepte from starting, and password sign-in keeps working without it. Single sign-on walks through setting it up with Google and Authelia.
Rezepte can mail setup links to the people you invite, links for a new password (or a sign-in hint for someone who signs in with an identity provider) and links that confirm an email address. Forgot password and address confirmation need mail; without it the login page shows no Forgot password? link. Set REZEPTE_SMTP_HOST and REZEPTE_SMTP_FROM (and the username and password your mail provider gave you) and mail is on; Rezepte refuses to start when REZEPTE_SMTP_HOST is set without REZEPTE_SMTP_FROM or REZEPTE_PUBLIC_URL, or with a security other than starttls, tls or none. With starttls Rezepte never falls back to an unencrypted connection: a server that does not offer it is an error.
While REZEPTE_SMTP_HOST is set, the Email card in Settings shows these values and cannot change them; change the variables and restart instead. Leave it unset and the owner sets mail up in the app instead, as Mail describes. For mail to reach inboxes rather than spam folders, publish the SPF and DKIM records your provider documents for the domain of the sender address.
Command-line flags
--demo
rezepte --demoFills an empty data directory with twelve sample recipes and photos for most of them. The English and German recipes come with AI-generated photos; for a language without sample recipes of its own, --demo uses the English ones, photos included. Only a sample set that has no photos at all gets simple placeholder images instead. If REZEPTE_ADMIN_PASSWORD is unset, it also creates the demo account demo / demo1234 instead of requiring a password, and three more members: mila / mila1234 and jonas / jonas1234, who wrote a few of the sample recipes (Mila locked one of hers) and have marked a few others tasty, and noah, left with an open setup link and no password instead, the way you would leave an account for somebody who has not signed in yet. All four go by made-up names from the pantry in the demo's language — in English Damson Dill, Mila Marjoram, Jonas Cinnamon and Noah Nutmeg — so you can tell a display name from a login name at a glance. The demo account and the two signed-in members also hold a few public links, which stay paused until you switch public sharing on under Settings → People (see Public links). With your own REZEPTE_ADMIN_PASSWORD set, none of those extra accounts is created. On an instance that already has recipes, --demo does nothing and starts normally.
--reset-superadmin-password
REZEPTE_ADMIN_PASSWORD='the new password' rezepte --reset-superadmin-passwordThe way back in when the owner's password is lost. Nobody inside the app can reset that account, so this runs on the server instead: it sets the owner's password to REZEPTE_ADMIN_PASSWORD (an empty value is an error), signs that account out on every device, and exits without starting the server. Start Rezepte normally afterwards and log in with the new password.
Everyone else's password is reset from "Settings" → "People" — see People.
--version
rezepte --versionPrints the version this binary was built from and exits. The same value comes back from /healthz on a running instance — see Updates.
--healthcheck
rezepte --healthcheckAsks the instance on this machine's REZEPTE_ADDR whether it is serving, then exits: 0 if it answered, non-zero with a reason if it did not. It starts nothing and touches neither the database nor the data directory, so it is safe to run beside a live instance.
The container image uses it for its own HEALTHCHECK, which is why it exists — the image has no shell and no curl for one to call. With the binary it works the same way, so a systemd watchdog or a monitoring check can use it too.
Logging
REZEPTE_LOG_FORMAT=text (the default):
time=2026-09-18T10:00:00.000+02:00 level=INFO msg=listening addr=:8060REZEPTE_LOG_FORMAT=json:
{"time":"2026-09-18T10:00:00.000+02:00","level":"INFO","msg":"listening","addr":":8060"}