# --------------------------------------------------------------------------- # Template for `.env.local` — your LOCAL overrides. Copy it: # # cp .env.example .env.local # # Do not copy it to `.env`. `.env` is committed and already holds the # production values; `.env.local` is loaded ahead of it and is gitignored. # --------------------------------------------------------------------------- # The one shared Loyaly platform API (Behavision). Server-side only and # deliberately NOT NEXT_PUBLIC: publishing the host would let a browser bypass # the BFF, which is what keeps the access token out of JavaScript. # # local dev http://127.0.0.1:8088 ← what belongs in .env.local # production https://mcp.loyaly.ai ← already set in the committed .env # # NOT platform.loyaly.ai — that host serves THIS console, not the API. Pointing # the variable there makes the BFF call its own origin, which fails in a way # that looks like a broken login form rather than a misconfiguration. # # There is no remote fallback: production refuses to serve without this set. # That is why it is committed in `.env` rather than left to a dashboard. LOYALY_API_BASE=http://127.0.0.1:8088 # Signs the session cookie and encrypts the platform token bundle. # # The ONLY variable that is a real secret, and the only one production takes # solely from the environment — it is in no committed file, by design. Set it # as a Dokploy environment variable / secret. Locally, any string works; leave # it blank and a development key is used. # # Generate with: openssl rand -base64 48 AUTH_SECRET= # Browser → this app's own BFF routes. Same origin, so leave it empty. Inlined # at BUILD time (NEXT_PUBLIC), so changing it at runtime does nothing. NEXT_PUBLIC_API_BASE=