Configuring the .env File
The Nextcloud Exchange Connector is entirely configuration-driven. This reference guide explains every parameter available to customize the synchronization behavior, performance limits, and connectivity of your application.
Tip: This configuration guide is extensive. To quickly find a specific parameter from your .env file, use your browser's search function (Ctrl + F or Cmd + F) and enter the variable name.
Warning: Strict File Naming
Your configuration file must be named exactly “.env” (an empty filename with an .env extension). Naming the file settings.env or anything else will cause the application to fail to read the configuration.
Warning: Escaping Special Characters in Docker
When configuring passwords, connection strings, or secrets in your .env file, be aware of Docker's character constraints. Specifically, the dollar sign $) is reserved for variable interpolation. If your actual password contains a literal $, you must escape it by doubling the character (e.g., a password of Pa$word must be written as Pa$$word in the .env file).
Failure to escape this will cause Docker to drop the character, resulting in severe authentication errors.
Configuration Strategy: Minimal vs. Full
To simplify deployments, it is recommended to build your .env file based on your needs:
Configuration Reference
Service Configuration
These settings control the core behavior, identification, and scheduling of the synchronization instances.
Parameter | Meaning & Usage | Example | Applies To |
| Meaning: Dictates if this instance is the primary synchronization coordinator.
|
| Docker, Binary |
| Meaning: Specifies the hosting method.
|
| Docker, Binary |
| Meaning: The internal port and URL for the application. Usage: Must be unique for every instance running on the same host to prevent port collisions. |
| Binary |
| Meaning: The unique identifier for the instance. Usage: Used in logs and database tracking to identify which worker processed a task. |
| Docker, Binary |
| Meaning: Maximum number of elements per EWS request.
|
| Docker, Binary |
| Meaning: The sleep interval between global application runs.
|
| Docker, Binary |
| Meaning: The standard cooldown delay before a specific user is scheduled for their next sync.
|
| Docker, Binary |
| Meaning: The retry delay for users whose synchronization failed.
|
| Docker, Binary |
| Meaning: Database transaction chunk size.
|
| Docker, Binary |
| Meaning: Defines the day that marks the start of the weekend. Usage: Used in calendar logic (1 = Monday, 6 = Saturday, 7 = Sunday). |
| Docker, Binary |
| Meaning: Declares which data entities are synchronized.
|
| Docker, Binary |
| Meaning: Level of detail for synchronization.
|
| Docker, Binary |
What is the difference between Full and Sensitive Sync?
Synchronization modes determine the level of data privacy when transferring between calendars.
Full Synchronization:
Absolutely everything is synced.
NextCloud and Exchange fully map events, creating the missing entities on both servers.
The comparison mechanism uses hash codes and modification dates to make update decisions.
Sensitive Synchronization:
Nextcloud —> Exchange:
All data related to identification is completely "scrubbed".
Only the following data is kept: datetime, timezone, length, and reminder.
Events are displayed in Exchange as empty slots ("dummies") for time booking without revealing details.
Exchange —> Nextcloud:
All event data is synced; however, the recipients list is forced into the appointment body.
Events are marked in red for visual distinction.
In Sensitive Sync mode, attachments are not synced in either direction.
Pro Tip
When using Sensitive Sync, modifying events is only allowed in their "native" calendars. Any attempt to change the description or status of a NextCloud event via Exchange will be rejected, and the application will revert it to its original empty state. Similarly, attempts to modify Exchange events via NextCloud are blocked and reverted.
Database Configuration
These settings connect the application to your storage backend.
Parameter | Meaning & Usage | Example | Applies To |
| Meaning: Selects the database provider.
|
| Docker, Binary |
| Meaning: Secret key for encrypting sensitive data.
|
| Docker, Binary |
| Meaning: The connection string to reach the database.
|
| Docker, Binary |
Nextcloud Configuration
These settings belong on the DAV sync client (Provider=Dav). They must match the Nextcloud URL, service account, and Shared Secret from the Sendent Sync app.
Warning: Shared Secret Mismatch
Your EventSyncClients__1__Settings__SharedSecret value must exactly match the shared secret generated in the Sendent Sync app within your Nextcloud web interface.
Parameter | Meaning & Usage | Example | Applies To |
| Meaning: The Base URL of your Nextcloud instance.
|
| Docker, Binary |
| Meaning: Username of the Nextcloud service account.
|
| Docker, Binary |
| Meaning: Password of the Nextcloud service account.
|
| Docker, Binary |
| Meaning: Cryptographic shared secret.
|
| Docker, Binary |
Exchange Server Configuration
Optional admin-pool settings. The Exchange connection itself is configured on EventSyncClients in the next section.
Parameter | Meaning & Usage | Example | Applies To |
| Meaning: Microsoft tenant ID for the webhook path. Usage: Optional. Calendar sync reads |
| Docker, Binary |
| Meaning: Path to a JSON file of extra Exchange admin accounts. Usage: Optional. Use only for an admin pool. Connection settings stay on |
| Docker, Binary |
Service__ExchangeConfiguration__ExchangeAdminRaw | Meaning: Same admin list as a JSON array in Usage: Optional alternative to |
| Docker, Binary |
Sync Clients
The connector syncs a pair of clients: one Exchange-side (Ews or Graph) and one Nextcloud-side (Dav). Identifier values must match EventSync__Pairs.
Indexes in the examples: __0__ = Exchange (EWS or Graph), __1__ = DAV.
Warning: EventSyncClients__*__Settings__ExchangeOnPremUrl and ExchangeOnPremDomain are invalid. On an on-premise EWS client the keys are OnPremUrl and OnPremDomain.
Parameter | Meaning & Usage | Example | Applies To |
|---|---|---|---|
| Meaning: Name of the Exchange-side client. Usage: Referenced by |
| Docker, Binary |
| Meaning: Exchange-side stack. Usage: |
| Docker, Binary |
| Meaning: Name of the Nextcloud client. Usage: Must match the pair target. |
| Docker, Binary |
| Meaning: Nextcloud stack. Usage: Always |
| Docker, Binary |
| Meaning: The Exchange-side client in the pair. Usage: Must match |
| Docker, Binary |
| Meaning: The Nextcloud-side client in the pair. Usage: Must match |
| Docker, Binary |
| Meaning: Highest-priority calendar source on conflict. Usage: Usually the same Identifier as the Exchange client. |
| Docker, Binary |
| Meaning: Fallback calendar source on conflict. Usage: Usually the DAV Identifier. |
| Docker, Binary |
Concurrency Configuration
These settings control the application's throughput and scaling behavior.
Parameter | Meaning & Usage | Example | Applies To |
| Meaning: Global limit of concurrent users processed per instance.
|
| Docker, Binary |
| Meaning: Maximum users processed concurrently by a single Exchange service account.
|
| Docker, Binary |
| Meaning: The number of secondary containers to deploy automatically.
|
| Docker |
EWS settings (Provider=Ews)
Parameter | Meaning & Usage | Example | Applies To |
|---|---|---|---|
| Meaning: EWS environment. Usage: |
| Docker, Binary |
| Meaning: Microsoft Entra tenant ID. Usage: EWS Cloud ( |
| Docker, Binary |
| Meaning: Entra application (client) ID. Usage: EWS Cloud only. |
| Docker, Binary |
| Meaning: Entra client secret. Usage: EWS Cloud, or ADFS ( |
| Docker, Binary |
| Meaning: EWS endpoint URL. Usage: On-premise EWS only ( |
| Docker, Binary |
| Meaning: Active Directory domain of the service account. Usage: Kerberos and BasicAuth ( |
| Docker, Binary |
| Meaning: On-premise service account. Usage: Kerberos and BasicAuth only. |
| Docker, Binary |
| Meaning: Password for that service account. Usage: Kerberos and BasicAuth only. |
| Docker, Binary |
| Meaning: ADFS authority URL. Usage: ADFS ( |
| Docker, Binary |
| Meaning: ADFS client ID.
Usage: ADFS only. |
| Docker, Binary |
Graph settings (Provider=Graph)
Use these instead of the EWS settings when the Exchange-side client is Graph. Do not set ExchangeType, OnPremUrl, or OnPremDomain.
Parameter | Meaning & Usage | Example | Applies To |
|---|---|---|---|
| Meaning: Microsoft Entra tenant ID. Usage: Required for Graph. |
| Docker, Binary |
| Meaning: Graph application (client) ID. Usage:The Graph app registration, not the old EWS app. |
| Docker, Binary |
| Meaning: Graph client secret. Usage: Required for Graph. |
| Docker, Binary |
| Meaning: Timezone Graph uses for event start/end. Usage: Optional. |
| Docker, Binary |
DAV keys are in the Nextcloud Configuration table above.
Specific Synchronization Configurations
Parameter | Meaning & Usage | Example | Applies To |
| Meaning: Allows or disallows processing of attachments.
|
| Docker, Binary |
| Meaning: Custom title applied to events in Exchange.
|
| Docker, Binary |
| Meaning: Custom category tag applied to events.
|
| Docker, Binary |
Logging & Monitoring Configuration
These settings control how and where the application outputs health and debug data.
Warning: Grafana Security
If you choose to enable Grafana logging (Service__LoggingConfiguration__LogsOutput includes value 8), be aware that the Grafana web interface is designed to run securely within the local host machine only.
It is intentionally not exposed or forwarded to external networks.
Parameter | Meaning & Usage | Example | Applies To |
| Meaning: The global log verbosity level.
The default value is |
| Docker, Binary |
| Meaning: Determines where logs are stored (Bitwise).
|
| Docker, Binary |
| Meaning: Name of the folder where file logs are saved.
|
| Docker, Binary |
| Meaning: Maximum size of a single log file.
|
| Docker, Binary |
| Meaning: Maximum number of log files to retain.
|
| Docker, Binary |
| Meaning: Internal URL used to push logs to Loki.
|
| Docker |
| Meaning: Custom administrator credentials for Grafana.
|
| Docker |
Example Configurations
Minimal Config for Docker deployment (Single Instance)
# Service ConfigurationService__StartWeekend=6Service__SyncMode=1Service__SyncType=0 # Database ConfigurationDatabaseConfiguration__DatabaseType=2DatabaseConfiguration__DatabaseEncryptionKey=YourSuperSecretKey123!DatabaseConfiguration__ConnectionString=YourDatabaseConnectionString # Exchange ConfigurationService__ExchangeConfiguration__ExchangeAdminFile= # Sync Clients — REQUIRED# For Graph, set Identifier/Provider to graph and drop ExchangeType.# For on-premise Kerberos, set ExchangeType=2 and use OnPremUrl / OnPremDomain / UserName / Password (not ExchangeOnPremUrl).EventSyncClients__0__Identifier=ewsEventSyncClients__0__Provider=EwsEventSyncClients__0__Settings__ExchangeType=1EventSyncClients__0__Settings__TenantId=yor-exchange-tenant-idEventSyncClients__0__Settings__AppId=your-app-idEventSyncClients__0__Settings__ClientSecret=your-client-secret EventSyncClients__1__Identifier=davEventSyncClients__1__Provider=DavEventSyncClients__1__Settings__BaseUrl=your-nextcloud-base-urlEventSyncClients__1__Settings__ServiceUsername=your-nextcloud-adminEventSyncClients__1__Settings__ServicePassword=your-nextcloud-passwordEventSyncClients__1__Settings__SharedSecret=your-shared-secret EventSync__Pairs__0__SourceClientId=ewsEventSync__Pairs__0__TargetClientId=davEventSync__CalendarPriorityOrder__0=ewsEventSync__CalendarPriorityOrder__1=dav # Full Synchronization ConfigurationService__FullSyncConfiguration__ProcessAttachments=true # Sensitive Synchronization ConfigurationService__SensitiveSyncConfiguration__SensitiveTitle="Busy"Service__SensitiveSyncConfiguration__SensitiveCategory="Nextcloud Sync" # Logging (Serilog & Loki)Serilog__MinimumLevel__Default=ErrorService__LoggingConfiguration__LogsOutput=3Service__LoggingConfiguration__LogDirectoryPath=Service__LoggingConfiguration__LogFileSizeLimit=50Service__LoggingConfiguration__LogFileAmountLimit=20Service__LoggingConfiguration__LokiInternalUrl=http://loki:3100 # Grafana ConfigurationGRAFANA_USER="YourAdminLogin"GRAFANA_PASSWORD="YourAdminPassword"
Full Config for Docker deployment (Multi-Instance)
# Service ConfigurationService__IsPrimary=trueService__DeploymentType=0Service__DefaultWorkerName="SendentWorker" # NOTE: these four are real settings, but are NOT in the default docker-compose.yml# environment: allowlist yet — add their names there before they take effect.Service__BatchLimit=50Service__WorkerIntervalSeconds=60Service__BatchSaveSize=100Service__StartWeekend=6 Service__SyncMode=1Service__SyncType=0 # Database ConfigurationDatabaseConfiguration__DatabaseType=2DatabaseConfiguration__DatabaseEncryptionKey=YourSuperSecretKey123!DatabaseConfiguration__ConnectionString=YourDatabaseConnectionString # Exchange ConfigurationService__ExchangeConfiguration__ExchangeAdminFile= # Sync Clients — REQUIRED# For Graph, set Identifier/Provider to graph and drop ExchangeType.# For on-premise Kerberos, set ExchangeType=2 and use OnPremUrl / OnPremDomain / UserName / Password (not ExchangeOnPremUrl).EventSyncClients__0__Identifier=ewsEventSyncClients__0__Provider=EwsEventSyncClients__0__Settings__ExchangeType=1EventSyncClients__0__Settings__TenantId=yor-exchange-tenant-idEventSyncClients__0__Settings__AppId=your-app-idEventSyncClients__0__Settings__ClientSecret=your-client-secret EventSyncClients__1__Identifier=davEventSyncClients__1__Provider=DavEventSyncClients__1__Settings__BaseUrl=your-nextcloud-base-urlEventSyncClients__1__Settings__ServiceUsername=your-nextcloud-adminEventSyncClients__1__Settings__ServicePassword=your-nextcloud-passwordEventSyncClients__1__Settings__SharedSecret=your-shared-secret EventSync__Pairs__0__SourceClientId=ewsEventSync__Pairs__0__TargetClientId=davEventSync__CalendarPriorityOrder__0=ewsEventSync__CalendarPriorityOrder__1=dav # Concurrency ConfigurationService__ConcurrencyConfiguration__MaxParallelProcessingUsers=100Service__ConcurrencyConfiguration__MaxUsersPerAdmin=100Secondary_Replicas_Amount=2 # Full Synchronization ConfigurationService__FullSyncConfiguration__ProcessAttachments=true # Sensitive Synchronization ConfigurationService__SensitiveSyncConfiguration__SensitiveTitle="Busy"Service__SensitiveSyncConfiguration__SensitiveCategory="Nextcloud Sync" # Logging (Serilog & Loki)Serilog__MinimumLevel__Default=ErrorService__LoggingConfiguration__LogsOutput=9Service__LoggingConfiguration__LogDirectoryPath=Service__LoggingConfiguration__LogFileSizeLimit=50Service__LoggingConfiguration__LogFileAmountLimit=20Service__LoggingConfiguration__LokiInternalUrl=http://loki:3100 # Grafana ConfigurationGRAFANA_USER="YourAdminLogin"GRAFANA_PASSWORD="YourAdminPassword"
Minimal Config for Binary deployment (Single Instance)
# Service ConfigurationService__IsPrimary=trueService__DeploymentType=1Service__AspNetCoreUrl="http://localhost:5001"Service__DefaultWorkerName="SendentWorker-1"Service__StartWeekend=6Service__SyncMode=1Service__SyncType=0 # Database ConfigurationDatabaseConfiguration__DatabaseType=2DatabaseConfiguration__DatabaseEncryptionKey=YourSuperSecretKey123!DatabaseConfiguration__ConnectionString=YourDatabaseConnectionString # Exchange ConfigurationService__ExchangeConfiguration__ExchangeAdminFile= # Sync Clients — REQUIRED# For Graph, set Identifier/Provider to graph and drop ExchangeType.# For on-premise Kerberos, set ExchangeType=2 and use OnPremUrl / OnPremDomain / UserName / Password (not ExchangeOnPremUrl).EventSyncClients__0__Identifier=ewsEventSyncClients__0__Provider=EwsEventSyncClients__0__Settings__ExchangeType=1EventSyncClients__0__Settings__TenantId=yor-exchange-tenant-idEventSyncClients__0__Settings__AppId=your-app-idEventSyncClients__0__Settings__ClientSecret=your-client-secret EventSyncClients__1__Identifier=davEventSyncClients__1__Provider=DavEventSyncClients__1__Settings__BaseUrl=your-nextcloud-base-urlEventSyncClients__1__Settings__ServiceUsername=your-nextcloud-adminEventSyncClients__1__Settings__ServicePassword=your-nextcloud-passwordEventSyncClients__1__Settings__SharedSecret=your-shared-secret EventSync__Pairs__0__SourceClientId=ewsEventSync__Pairs__0__TargetClientId=davEventSync__CalendarPriorityOrder__0=ewsEventSync__CalendarPriorityOrder__1=dav # Full Synchronization ConfigurationService__FullSyncConfiguration__ProcessAttachments=true # Sensitive Synchronization ConfigurationService__SensitiveSyncConfiguration__SensitiveTitle="Busy"Service__SensitiveSyncConfiguration__SensitiveCategory="Nextcloud Sync" # Logging (Serilog)Serilog__MinimumLevel__Default=ErrorService__LoggingConfiguration__LogsOutput=3Service__LoggingConfiguration__LogDirectoryPath=Service__LoggingConfiguration__LogFileSizeLimit=50Service__LoggingConfiguration__LogFileAmountLimit=20
Full Config for Binary deployment (Multi-Instance)
# Service Configuration — edit these three per-instanceService__IsPrimary=trueService__DeploymentType=1Service__AspNetCoreUrl="http://localhost:5001"Service__DefaultWorkerName="SendentWorker-1" Service__BatchLimit=50Service__WorkerIntervalSeconds=60Service__BatchSaveSize=100Service__StartWeekend=6 Service__SyncMode=1Service__SyncType=0 # Database ConfigurationDatabaseConfiguration__DatabaseType=2DatabaseConfiguration__DatabaseEncryptionKey=YourSuperSecretKey123!DatabaseConfiguration__ConnectionString=YourDatabaseConnectionString # Exchange ConfigurationService__ExchangeConfiguration__ExchangeAdminFile= # Sync Clients — REQUIRED# For Graph, set Identifier/Provider to graph and drop ExchangeType.# For on-premise Kerberos, set ExchangeType=2 and use OnPremUrl / OnPremDomain / UserName / Password (not ExchangeOnPremUrl).EventSyncClients__0__Identifier=ewsEventSyncClients__0__Provider=EwsEventSyncClients__0__Settings__ExchangeType=1EventSyncClients__0__Settings__TenantId=yor-exchange-tenant-idEventSyncClients__0__Settings__AppId=your-app-idEventSyncClients__0__Settings__ClientSecret=your-client-secret EventSyncClients__1__Identifier=davEventSyncClients__1__Provider=DavEventSyncClients__1__Settings__BaseUrl=your-nextcloud-base-urlEventSyncClients__1__Settings__ServiceUsername=your-nextcloud-adminEventSyncClients__1__Settings__ServicePassword=your-nextcloud-passwordEventSyncClients__1__Settings__SharedSecret=your-shared-secret EventSync__Pairs__0__SourceClientId=ewsEventSync__Pairs__0__TargetClientId=davEventSync__CalendarPriorityOrder__0=ewsEventSync__CalendarPriorityOrder__1=dav # Concurrency ConfigurationService__ConcurrencyConfiguration__MaxParallelProcessingUsers=1000Service__ConcurrencyConfiguration__MaxUsersPerAdmin=100 # Full Synchronization ConfigurationService__FullSyncConfiguration__ProcessAttachments=true # Sensitive Synchronization ConfigurationService__SensitiveSyncConfiguration__SensitiveTitle="Busy"Service__SensitiveSyncConfiguration__SensitiveCategory="Nextcloud Sync" # Logging (Serilog)Serilog__MinimumLevel__Default=ErrorService__LoggingConfiguration__LogsOutput=5Service__LoggingConfiguration__LogDirectoryPath=Service__LoggingConfiguration__LogFileSizeLimit=50Service__LoggingConfiguration__LogFileAmountLimit=20