Repository navigation
Expand file tree
/
Copy path.env.local.example
More file actions
100 lines (96 loc) · 5.39 KB
/
Copy path.env.local.example
File metadata and controls
100 lines (96 loc) · 5.39 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
# All values below are runtime configuration. `next build` requires none of
# them: service clients initialize lazily on first use. For local dev,
# Firebase values may be left dummy; real data/uploads need real values.
# Public Firebase web config (not secret — identifies the project only).
NEXT_PUBLIC_FIREBASE_API_KEY=
NEXT_PUBLIC_FIREBASE_AUTH_DOMAIN=
NEXT_PUBLIC_FIREBASE_PROJECT_ID=
NEXT_PUBLIC_FIREBASE_STORAGE_BUCKET=
NEXT_PUBLIC_FIREBASE_MESSAGING_SENDER_ID=
NEXT_PUBLIC_FIREBASE_APP_ID=
NEXT_PUBLIC_FIREBASE_MEASUREMENT_ID=G-XXXXXXXXXX
NEXT_PUBLIC_SITE_URL=https://deepdivebrewing.com
# Google Tag Manager container id (GTM-XXXXXXX). GTM scripts are rendered
# only in Vercel production builds (VERCEL_ENV=production), so a value here
# never affects local dev. The GA4 measurement id (G-5VBQTMP37H) lives in the
# GTM container config, not the app — see docs/operations/analytics.md.
NEXT_PUBLIC_GTM_ID=GTM-XXXXXXX
# In deployed environments this is supplied by the Vercel-managed Resend
# integration (which also injects RESEND_EMAIL_DOMAIN — intentionally unused;
# explicit senders below are clearer). For local dev, create a key in the
# Resend console.
RESEND_API_KEY=re_xxxxxxxxx
TRADE_INQUIRY_TO_EMAIL=your-email@example.com
# Canonical staff notification mailbox for the trade pipeline (new inquiry
# alerts + customer-reply alerts on unassigned leads). Falls back to
# TRADE_INQUIRY_TO_EMAIL when unset — set this and remove the legacy name.
# TRADE_NOTIFICATION_EMAIL=your-email@example.com
# Sender for trade-inquiry emails; also the fallback sender for admin
# invitations. Optional — defaults to noreply@mail.deepdivebrewing.com
# (the verified Resend sending domain).
RESEND_FROM_EMAIL=deepdive@mail.deepdivebrewing.com
# Sender for customer-facing lead email sent from /admin/trade. Optional —
# falls back to RESEND_FROM_EMAIL, then trade@mail.deepdivebrewing.com
# (verified domain).
# TRADE_FROM_EMAIL=trade@mail.deepdivebrewing.com
# Domain for per-lead inbound addresses (<token>@<domain>) used in Reply-To
# and the "attach email to this lead" feature. Requires an inbound-configured
# domain in Resend (MX records) — defaults to reply.deepdivebrewing.com.
# TRADE_REPLY_DOMAIN=reply.deepdivebrewing.com
# Signing secret (whsec_…) for POST /api/webhooks/resend — required for the
# endpoint to accept inbound email and delivery events. Configure the same
# secret on the webhook in the Resend console.
# RESEND_WEBHOOK_SECRET=whsec_xxxxxxxxxxxx
# Optional preferred sender for admin invitation emails.
ADMIN_INVITE_FROM_EMAIL=invitations@mail.deepdivebrewing.com
# Optional cooldown in milliseconds before an invitation email can be resent (default 60,000).
ADMIN_INVITE_RESEND_COOLDOWN_MS=60000
# Error monitoring (Sentry). Optional and production-only — the browser and
# server SDKs are inert without these, and only report when the deployment
# is Vercel Production. The public DSN is inlined into the browser bundle by
# design (it is not a credential — it only lets events reach the project).
# NEXT_PUBLIC_SENTRY_DSN=https://xxxxxxxxxxxxxxxx@o0000000.ingest.us.sentry.io/0000000
# Build-time only (Production scope): source-map upload + release metadata.
# SENTRY_AUTH_TOKEN is a real secret — never commit it or expose it to the
# client. SENTRY_ORG/SENTRY_PROJECT are slugs, not secrets.
# SENTRY_AUTH_TOKEN=
# SENTRY_ORG=
# SENTRY_PROJECT=
VERCEL_DEPLOY_HOOK_URL=https://api.vercel.com/v1/integrations/deploy/xxxxxxxxxxxxxxxx
# Legacy fallback used only when VERCEL_DEPLOY_HOOK_URL is unset.
# VERCEL_REBUILD_DEPLOY_HOOK_URL=
FIREBASE_ADMIN_PROJECT_ID=
FIREBASE_ADMIN_CLIENT_EMAIL=
FIREBASE_ADMIN_PRIVATE_KEY="-----BEGIN PRIVATE KEY-----\n...\n-----END PRIVATE KEY-----\n"
ADMIN_REBUILD_COOLDOWN_MS=600000
# Stripe — admin payments (issue #155). Server-only secrets: never expose
# through NEXT_PUBLIC_*. Use sk_test_* / whsec_* values from the Stripe
# Dashboard's test mode for development and preview; live keys only in
# production. The key prefix decides the mode the admin UI badges.
# STRIPE_SECRET_KEY=sk_test_xxxxxxxxxxxxxxxx
# Signing secret for the Stripe webhook at /api/webhooks/stripe. Create the
# endpoint in the Dashboard (Developers → Webhooks) subscribed to
# checkout.session.* events, or use `stripe listen --forward-to` locally.
# STRIPE_WEBHOOK_SECRET=whsec_xxxxxxxxxxxxxxxx
# Bootstrap superadmin email. Must be a verified Google account.
# This value is server-only; do not expose it to the browser.
SUPER_ADMIN_EMAIL=your-superadmin@example.com
# --- QuickBooks Online integration (server-only — never NEXT_PUBLIC_*) ---
# OAuth + API credentials from the Intuit Developer Portal app. Use the
# app's *Development* keys with QBO_ENVIRONMENT=sandbox (local dev and
# Vercel Preview) and *Production* keys with QBO_ENVIRONMENT=production
# (Vercel Production only). See docs/operations/quickbooks.md.
# QBO_ENVIRONMENT=sandbox
# QBO_CLIENT_ID=
# QBO_CLIENT_SECRET=
# Exact callback URL registered in the Intuit app's redirect-URI list,
# e.g. https://<preview-host>/api/admin/quickbooks/callback (https
# required outside localhost).
# QBO_REDIRECT_URI=
# Verifier token from the Intuit app's webhook configuration — HMAC key
# for POST /api/webhooks/quickbooks.
# QBO_WEBHOOK_VERIFIER_TOKEN=
# AES-256-GCM key for OAuth token material at rest: 64 hex chars or a
# base64-encoded 32-byte value. Generate with:
# node -e "console.log(require('crypto').randomBytes(32).toString('hex'))"
# QBO_TOKEN_ENCRYPTION_KEY=