# The one shared Loyaly platform API (Behavision). Server-side only and # deliberately NOT NEXT_PUBLIC: publishing the host would let a browser bypass # the BFF, which is what keeps the access token out of JavaScript. # # local dev http://127.0.0.1:8088 # production https://mcp.loyaly.ai # # NOT platform.loyaly.ai — that host serves THIS console, not the API. Pointing # the variable there makes the BFF call its own origin, which fails in a way # that looks like a broken login form rather than a misconfiguration. # # There is no fallback: production refuses to start without this set. LOYALY_API_BASE=http://127.0.0.1:8088 # Signs the session cookie and encrypts the platform token bundle. # Required in production — the app refuses to start signing sessions with the # development key. Generate with: openssl rand -base64 48 AUTH_SECRET= # Browser → this app's own BFF routes. Same origin, so normally left empty. NEXT_PUBLIC_API_BASE=