{ "$schema": "node_modules/wrangler/config-schema.json", "name": "tessera", "main": "src/worker/index.ts", "compatibility_date": "2026-03-16", // Better Auth 1.6.23 imports node:crypto at module scope. Keep bindings // and secrets off process.env; tessera passes Env explicitly. "compatibility_flags": [ "nodejs_compat", "nodejs_compat_do_not_populate_process_env" ], "observability": { "enabled": true, }, "assets": { "directory": "dist/client", "binding": "ASSETS", "not_found_handling": "single-page-application", "run_worker_first": [ "/api/*", "/.well-known/*", "/healthz" ], }, "ratelimits": [ // Tight tier. Used for sign-in, invite, OAuth issuance, admin, and // anything under /api/auth/* not in the loose set or exempt list. { "name": "RL_AUTH", "namespace_id": "110001", "simple": { "limit": 10, "period": 60, }, }, // Loose tier. Used for high-volume reads served by the Better Auth // catchall: session reads (/get-session, /update-session, // /list-sessions, /list-accounts) and RP-backend OAuth reads // (/oauth2/userinfo, /oauth2/introspect). { "name": "RL_API", "namespace_id": "110002", "simple": { "limit": 300, "period": 60, }, }, ], "d1_databases": [ { "binding": "DB", "database_name": "tessera-prod", "database_id": "e2f541f9-781a-4d10-811a-82fc7b51df82", "migrations_dir": "drizzle/d1", }, ], "vars": { "LOG_LEVEL": "info", // Production deployment: tessera answers on auth.limic.dev. The OIDC // `iss` claim and Better Auth's cookie/baseURL all key off this. // Override locally via .dev.vars (or leave it empty there to let the // worker derive the base URL from the incoming request). "BETTER_AUTH_URL": "https://auth.limic.dev", "OIDC_ISSUER": "https://auth.limic.dev", // OPERATOR_NAME and OPERATOR_CONTACT_EMAIL drive the operator // identity rendered on /privacy and /terms. They are required at // runtime — /api/config fails closed when either is empty — and are // set per deployment via the Cloudflare dashboard (Workers → // Settings → Variables) or locally via .dev.vars, not committed // here. }, "routes": [ { "pattern": "auth.limic.dev", "custom_domain": true, }, ], }