# Runtime configuration. Committed on purpose - it carries no secret. # Precedence: process.env > .env.production.local > .env.local > .env.production > .env # # The platform API. https://mcp.loyaly.ai is the default in every environment # and the only value production accepts; it is written here so `docker run` # is self-describing. NOT platform.loyaly.ai - that host serves this console. LOYALY_API_BASE=https://mcp.loyaly.ai # Browser -> this app's own routes, same origin. Empty is correct. NEXT_PUBLIC_API_BASE= # AUTH_SECRET is deliberately NOT here: it signs sessions, so a committed value # is a session-forging key in git. Set it in the runtime environment (or point # AUTH_SECRET_FILE at a mounted secret). Generate with: openssl rand -hex 32