# Public URL the worker serves on. Production: https://auth.limic.dev. # Local dev: leave empty to let the worker derive the base URL from the # request origin (so OIDC discovery, iss, cookie domain, and JWKS all match # whichever port Vite picks). Set explicitly only if you need a fixed value. BETTER_AUTH_URL= # OIDC issuer claim. Defaults to BETTER_AUTH_URL if empty. OIDC_ISSUER= # Local development emits debug logs; production wrangler config defaults to info+. LOG_LEVEL=debug # Operator identity rendered in /privacy and /terms. /api/config returns 503 # if either is empty, so the legal pages and any other config consumer fail # closed on misconfiguration. Set per deployment via the Cloudflare dashboard # (Workers → Settings → Variables) or locally here. OPERATOR_NAME= OPERATOR_CONTACT_EMAIL= # Better Auth secret. Used for: HMAC on sessions, symmetric encryption of # JWKS private bytes (`jwt` plugin) and OAuth provider access/refresh/id # tokens (`account.encryptOAuthTokens`). Rotate by replacing this value and # re-linking social providers; existing JWKS rows that can't decrypt under # the new secret will be regenerated on the next sign / rotation. # Generate: openssl rand -hex 32 BETTER_AUTH_SECRET=replace-me-with-64-hex-chars # GitHub OAuth app (Settings → Developer settings → OAuth Apps). # Callback URL: https://auth.limic.dev/api/auth/callback/github GITHUB_OAUTH_CLIENT_ID= GITHUB_OAUTH_CLIENT_SECRET= # Google OAuth client (console.cloud.google.com → Credentials). # Callback URL: https://auth.limic.dev/api/auth/callback/google GOOGLE_OAUTH_CLIENT_ID= GOOGLE_OAUTH_CLIENT_SECRET= # Cloudflare Turnstile. The worker always calls siteverify (no host-based # short-circuit). The always-pass test keys below work for local dev # because tessera recognizes Cloudflare's test-mode siteverify response # shape (action="test" / metadata.result_with_testing_key) and skips the # action/hostname comparisons that would otherwise fail. Register a real # Turnstile site for production. TURNSTILE_SITE_KEY=1x00000000000000000000AA TURNSTILE_SECRET_KEY=1x0000000000000000000000000000000AA # Bootstrap path: signup with this email auto-promotes to admin role. # Remove the variable once the operator account is created. BOOTSTRAP_ADMIN_EMAIL=