Skip to content
File

Blob: .dev.vars.example

2.2 KB
1# Public URL the worker serves on. Production: https://auth.limic.dev.
2# Local dev: leave empty to let the worker derive the base URL from the
3# request origin (so OIDC discovery, iss, cookie domain, and JWKS all match
4# whichever port Vite picks). Set explicitly only if you need a fixed value.
5BETTER_AUTH_URL=
6# OIDC issuer claim. Defaults to BETTER_AUTH_URL if empty.
7OIDC_ISSUER=
8 
9# Local development emits debug logs; production wrangler config defaults to info+.
10LOG_LEVEL=debug
11 
12# Operator identity rendered in /privacy and /terms. /api/config returns 503
13# if either is empty, so the legal pages and any other config consumer fail
14# closed on misconfiguration. Set per deployment via the Cloudflare dashboard
15# (Workers → Settings → Variables) or locally here.
16OPERATOR_NAME=
17OPERATOR_CONTACT_EMAIL=
18 
19# Better Auth secret. Used for: HMAC on sessions, symmetric encryption of
20# JWKS private bytes (`jwt` plugin) and OAuth provider access/refresh/id
21# tokens (`account.encryptOAuthTokens`). Rotate by replacing this value and
22# re-linking social providers; existing JWKS rows that can't decrypt under
23# the new secret will be regenerated on the next sign / rotation.
24# Generate: openssl rand -hex 32
25BETTER_AUTH_SECRET=replace-me-with-64-hex-chars
26 
27# GitHub OAuth app (Settings → Developer settings → OAuth Apps).
28# Callback URL: https://auth.limic.dev/api/auth/callback/github
29GITHUB_OAUTH_CLIENT_ID=
30GITHUB_OAUTH_CLIENT_SECRET=
31 
32# Google OAuth client (console.cloud.google.com → Credentials).
33# Callback URL: https://auth.limic.dev/api/auth/callback/google
34GOOGLE_OAUTH_CLIENT_ID=
35GOOGLE_OAUTH_CLIENT_SECRET=
36 
37# Cloudflare Turnstile. The worker always calls siteverify (no host-based
38# short-circuit). The always-pass test keys below work for local dev
39# because tessera recognizes Cloudflare's test-mode siteverify response
40# shape (action="test" / metadata.result_with_testing_key) and skips the
41# action/hostname comparisons that would otherwise fail. Register a real
42# Turnstile site for production.
43TURNSTILE_SITE_KEY=1x00000000000000000000AA
44TURNSTILE_SECRET_KEY=1x0000000000000000000000000000000AA
45 
46# Bootstrap path: signup with this email auto-promotes to admin role.
47# Remove the variable once the operator account is created.
48BOOTSTRAP_ADMIN_EMAIL=