How to Configure Super Admin Emails in awesome-gpt-image-2

Set the SUPER_ADMIN_EMAILS environment variable to a comma-separated list of email addresses in your .env file to grant super-admin privileges to specific users.

The awesome-gpt-image-2 repository implements role-based access control through an environment-based whitelist. When a user authenticates, the backend checks their email against this list to determine whether to assign elevated super_admin permissions that protect sensitive administrative endpoints.

Setting the SUPER_ADMIN_EMAILS Environment Variable

The application relies on a single environment variable to define which users receive super-admin rights. In your project root, create or edit the .env file and add the SUPER_ADMIN_EMAILS key.

Variable Format

The value must be a comma-separated string of email addresses. Spaces around commas are automatically trimmed by the parser.


# .env

SUPER_ADMIN_EMAILS=admin@example.com, owner@company.org, root@myapp.io

How Email Validation Works

The core validation logic resides in api/_lib/supabase.js. The exported function isSuperAdminEmail() reads process.env.SUPER_ADMIN_EMAILS, splits the string on commas, normalizes case, and checks for matches.

// api/_lib/supabase.js
export function isSuperAdminEmail(email) {
  const list = process.env.SUPER_ADMIN_EMAILS?.split(',') ?? [];
  return list.map(e => e.trim().toLowerCase()).includes(email.toLowerCase());
}

This utility performs case-insensitive matching and tolerates arbitrary whitespace around email addresses.

Role Assignment and Route Protection

When isSuperAdminEmail() returns true for an authenticated user, the system assigns the super_admin role to their profile (as implemented in api/_lib/supabase.js around line 81). Subsequent API calls verify this flag to restrict access to administrative operations.

Protected endpoints such as api/generate-image.js and api/admin/metrics.js check the isSuperAdmin property or the role field before executing sensitive logic.

// Example route guard pattern from api/generate-image.js
import { getAuth } from './_lib/supabase.js';

export default async function handler(req, res) {
  const { auth } = await getAuth(req);
  
  if (!auth.profile?.isSuperAdmin) {
    return res.status(403).json({ error: 'Super-admin access required' });
  }
  
  // Admin-only logic proceeds here
}

Deploying Configuration Changes

Environment variables are loaded at startup. After modifying .env, you must restart the Node.js process or redeploy your Vercel instance to apply the updated super-admin whitelist.

Summary

  • Set SUPER_ADMIN_EMAILS in your .env file to define the super-admin whitelist
  • Multiple emails are supported as comma-separated values
  • The isSuperAdminEmail() function in api/_lib/supabase.js handles case-insensitive validation
  • Super-admin status grants access to protected routes like api/admin/metrics.js
  • Always restart the server after updating environment variables

Frequently Asked Questions

What is the exact name of the environment variable for super admin emails?

The variable is named SUPER_ADMIN_EMAILS. The application expects this exact key in the environment configuration to populate the admin whitelist used by the isSuperAdminEmail() function.

Can I assign super admin privileges to multiple users?

Yes. Provide multiple email addresses separated by commas. The parser in api/_lib/supabase.js splits the string on commas and trims whitespace, allowing any number of administrators in the list.

Is the email address comparison case-sensitive?

No. The validation logic converts both the environment variable entries and the user's email to lowercase using toLowerCase() before comparison. This ensures that Admin@Example.com matches admin@example.com.

Which API routes require super admin access?

Routes such as api/generate-image.js and api/admin/metrics.js check auth.profile?.isSuperAdmin or auth.profile?.role === 'super_admin' to restrict access. Any endpoint performing administrative functions, accessing system metrics, or managing resources implements this guard clause.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →