Repository navigation
Expand file tree
/
Copy path.env.example
More file actions
108 lines (96 loc) · 4.68 KB
/
Copy path.env.example
File metadata and controls
108 lines (96 loc) · 4.68 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
# NVIDIA NIM
NIM_API_KEY="YOUR_API_KEY"
# Optional backward-compatible alias:
# NVIDIA_NIM_API_KEY="YOUR_API_KEY"
NVIDIA_NIM_BASE_URL="https://integrate.api.nvidia.com/v1"
NVIDIA_NIM_CHAT_MODEL="moonshotai/kimi-k2-instruct"
NVIDIA_NIM_EMBEDDING_MODEL="nvidia/nv-embedqa-e5-v5"
LANGCHAIN_CALLBACKS_BACKGROUND=false
# Required for using web search tool
# SERPAPI_API_KEY="YOUR_API_KEY"
# Auth0 configuration
APP_BASE_URL="http://localhost:3000"
AUTH0_SECRET="use [openssl rand -hex 32] to generate a 32 bytes value"
AUTH0_DOMAIN="{yourDomain}"
AUTH0_CLIENT_ID="{yourClientId}"
AUTH0_CLIENT_SECRET="{yourClientSecret}"
# Default login scopes for the Auth0 session.
# IMPORTANT: `offline_access` is required if you want Auth0 to issue a refresh token
# (needed to seed `auth0_subject_refresh_tokens` for headless Token Vault token exchange).
AUTH0_SCOPE="openid profile email offline_access"
# Headhunt offer clearance (CIBA)
# Founder user id(s) allowed to approve and release offers
# HEADHUNT_FOUNDER_USER_ID="auth0|founder_user_id"
# HEADHUNT_FOUNDER_USER_IDS="auth0|founder_user_id_1,auth0|founder_user_id_2"
# AUTH0_FOUNDER_USER_ID="auth0|founder_user_id" # alias fallback
# Audience used for CIBA requests
# AUTH0_CIBA_AUDIENCE="https://api.headhunt.local"
# AUTH0_CIBA_SCOPE="openid"
# Optional issuer override for login_hint. Defaults to https://<AUTH0_DOMAIN>/
# AUTH0_CIBA_LOGIN_HINT_ISSUER="https://{yourDomain}/"
# FastMCP server auth/runtime configuration
# Example audience: https://api.headhunt.local
MCP_AUTH_AUDIENCE="https://api.headhunt.local"
# Optional override for issuer if different from AUTH0_DOMAIN
# MCP_AUTH_ISSUER="https://{yourDomain}"
# MCP_TRANSPORT="httpStream"
# MCP_HOST="0.0.0.0"
# MCP_PORT="8080"
# MCP_ENDPOINT="/mcp"
# MCP_STATELESS="false"
# Local stdio dev-only fallback (never enable in production)
# MCP_DEV_USER_ID="auth0|demo-user"
# MCP_DEV_ORG_ID="org_demo_headhunt"
# MCP_DEV_ROLES="founder"
# Optional Auth0 Token Vault connection overrides for Headhunt integrations
# AUTH0_GOOGLE_CONNECTION="google-oauth2"
# AUTH0_SLACK_CONNECTION="sign-in-with-slack"
# Use only scopes recognized by the configured federated connection.
# Add offline_access only if that provider connection explicitly supports it.
# AUTH0_SLACK_SCOPES="channels:read,groups:read"
# Prefer token exchange for Slack to support headless/background automations.
# Values: auto|token_exchange|token_vault
# AUTH0_SLACK_ACCESS_TOKEN_SOURCE="token_exchange"
# AUTH0_SLACK_TOKEN_EXCHANGE_MODE="refresh" # refresh|access (default: refresh)
# AUTH0_SLACK_AUTHORIZATION_PARAMS="prompt=consent"
# AUTH0_CAL_CONNECTION="cal"
# AUTH0_CAL_SCOPES="PROFILE_READ,SCHEDULE_WRITE,SCHEDULE_READ,BOOKING_WRITE,BOOKING_READ,EVENT_TYPE_WRITE,EVENT_TYPE_READ"
# AUTH0_CAL_TOKEN_EXCHANGE_MODE="refresh" # refresh|access (default: refresh)
# AUTH0_CAL_AUTHORIZATION_PARAMS="prompt=consent"
# Optional overrides for access-token subject exchange
# AUTH0_TOKEN_VAULT_SUBJECT_AUDIENCE="https://YOUR_AUTH0_API_AUDIENCE" # must issue JWT access tokens
# AUTH0_TOKEN_VAULT_SUBJECT_SCOPE="openid profile email"
# If AUTH0_TOKEN_VAULT_SUBJECT_AUDIENCE is not set, code falls back to MCP_AUTH_AUDIENCE.
# AUTH0_ENFORCE_GOOGLE_EMAIL_MATCH="true"
# CAL_COM_API_BASE_URL="https://api.cal.com/v2"
# CAL_SLOTS_API_VERSION="2024-09-04"
# CAL_BOOKINGS_API_VERSION="2026-02-25"
# CAL_TEST_EVENT_TYPE_ID="123"
# Database configuration
DATABASE_URL="postgresql://postgres:postgres@localhost:5432/ai_documents_db"
# Supabase automation runtime
# NEXT_PUBLIC_SUPABASE_URL="https://<project-ref>.supabase.co"
# SUPABASE_FUNCTIONS_URL="https://<project-ref>.functions.supabase.co"
# SUPABASE_SERVICE_ROLE_KEY="<supabase-service-role-key>"
# Shared secret for automation edge functions and route proxies
# SUPABASE_AUTOMATION_FUNCTION_SECRET="<long-random-secret>"
# Secret accepted by /api/automation/cron (and used by proxies when set)
# AUTOMATION_CRON_SECRET="<long-random-secret>"
# Supabase worker callback URL back into app for handler execution
# AUTOMATION_EXECUTE_URL="https://<your-app-domain>/api/automation/execute"
# Secret accepted by /api/automation/execute
# AUTOMATION_EXECUTE_SECRET="<same-or-different-long-secret>"
# Vercel cron auth secret for /api/cron/intake-polling (can match AUTOMATION_CRON_SECRET)
# CRON_SECRET="<long-random-secret>"
# AUTOMATION_AUTO_INTAKE_ENABLED="true"
# AUTOMATION_INTAKE_QUERY="in:inbox newer_than:14d -category:promotions -category:social"
# Auth0 FGA
FGA_STORE_ID=<your-fga-store-id>
FGA_CLIENT_ID=<your-fga-store-client-id>
FGA_CLIENT_SECRET=<your-fga-store-client-secret>
FGA_API_URL=https://api.xxx.fga.dev
FGA_API_AUDIENCE=https://api.xxx.fga.dev/
# Optional: Other model keys
# ANTHROPIC_API_KEY="YOUR_API_KEY"
# Turn on demo mode
# NEXT_PUBLIC_DEMO="true"