# --------------------------------------------------------------------------- # Template for `.env.local` — your LOCAL overrides. Copy it: # # cp .env.example .env.local # # Do not copy it to `.env`. `.env` is committed and already holds the # production values; `.env.local` is loaded ahead of it and is gitignored. # --------------------------------------------------------------------------- # The one shared Loyaly platform API (Behavision). Server-side only and # deliberately NOT NEXT_PUBLIC: publishing the host would let a browser bypass # the BFF, which is what keeps the access token out of JavaScript. # # local dev http://127.0.0.1:8088 ← what belongs in .env.local # production https://mcp.loyaly.ai ← already set in the committed .env # # NOT platform.loyaly.ai — that host serves THIS console, not the API. Pointing # the variable there makes the BFF call its own origin, which fails in a way # that looks like a broken login form rather than a misconfiguration. # # Production no longer requires this: it accepts exactly one origin, so an unset # value can only have meant that one, and platformApi resolves it. Any OTHER # host set explicitly is still rejected. Locally it is worth setting, because a # dev machine legitimately means a different address. LOYALY_API_BASE=http://127.0.0.1:8088 # Signs the session cookie and encrypts the platform token bundle. # # The ONLY variable production requires, the only real secret, and the only one # taken solely from the environment — it is in no committed file, by design. # Set it as a Dokploy environment variable in the RUNTIME panel (a build # argument is not present at runtime), or mount it and set AUTH_SECRET_FILE to # its path. Locally, any string works; leave it blank and a development key is # used. # # Generate with: openssl rand -hex 32 (hex, not base64 — a trailing '=' can be # mangled by a dashboard env editor that splits on the first '=') AUTH_SECRET= # Browser → this app's own BFF routes. Same origin, so leave it empty. Inlined # at BUILD time (NEXT_PUBLIC), so changing it at runtime does nothing. NEXT_PUBLIC_API_BASE=