File
Blob: .dev.vars.example
| 1 | # Public URL the worker serves on. Production: https://auth.limic.dev. |
| 2 | # Local dev: leave empty to let the worker derive the base URL from the |
| 3 | # request origin (so OIDC discovery, iss, cookie domain, and JWKS all match |
| 4 | # whichever port Vite picks). Set explicitly only if you need a fixed value. |
| 5 | BETTER_AUTH_URL= |
| 6 | # OIDC issuer claim. Defaults to BETTER_AUTH_URL if empty. |
| 7 | OIDC_ISSUER= |
| 8 | |
| 9 | # Local development emits debug logs; production wrangler config defaults to info+. |
| 10 | LOG_LEVEL=debug |
| 11 | |
| 12 | # Operator identity rendered in /privacy and /terms. /api/config returns 503 |
| 13 | # if either is empty, so the legal pages and any other config consumer fail |
| 14 | # closed on misconfiguration. Set per deployment via the Cloudflare dashboard |
| 15 | # (Workers → Settings → Variables) or locally here. |
| 16 | OPERATOR_NAME= |
| 17 | OPERATOR_CONTACT_EMAIL= |
| 18 | |
| 19 | # Better Auth secret. Used for: HMAC on sessions, symmetric encryption of |
| 20 | # JWKS private bytes (`jwt` plugin) and OAuth provider access/refresh/id |
| 21 | # tokens (`account.encryptOAuthTokens`). Rotate by replacing this value and |
| 22 | # re-linking social providers; existing JWKS rows that can't decrypt under |
| 23 | # the new secret will be regenerated on the next sign / rotation. |
| 24 | # Generate: openssl rand -hex 32 |
| 25 | BETTER_AUTH_SECRET=replace-me-with-64-hex-chars |
| 26 | |
| 27 | # GitHub OAuth app (Settings → Developer settings → OAuth Apps). |
| 28 | # Callback URL: https://auth.limic.dev/api/auth/callback/github |
| 29 | GITHUB_OAUTH_CLIENT_ID= |
| 30 | GITHUB_OAUTH_CLIENT_SECRET= |
| 31 | |
| 32 | # Google OAuth client (console.cloud.google.com → Credentials). |
| 33 | # Callback URL: https://auth.limic.dev/api/auth/callback/google |
| 34 | GOOGLE_OAUTH_CLIENT_ID= |
| 35 | GOOGLE_OAUTH_CLIENT_SECRET= |
| 36 | |
| 37 | # Cloudflare Turnstile. The worker always calls siteverify (no host-based |
| 38 | # short-circuit). The always-pass test keys below work for local dev |
| 39 | # because tessera recognizes Cloudflare's test-mode siteverify response |
| 40 | # shape (action="test" / metadata.result_with_testing_key) and skips the |
| 41 | # action/hostname comparisons that would otherwise fail. Register a real |
| 42 | # Turnstile site for production. |
| 43 | TURNSTILE_SITE_KEY=1x00000000000000000000AA |
| 44 | TURNSTILE_SECRET_KEY=1x0000000000000000000000000000000AA |
| 45 | |
| 46 | # Bootstrap path: signup with this email auto-promotes to admin role. |
| 47 | # Remove the variable once the operator account is created. |
| 48 | BOOTSTRAP_ADMIN_EMAIL= |