-
Notifications
You must be signed in to change notification settings - Fork 5
Expand file tree
/
Copy path.env.example
More file actions
186 lines (167 loc) · 9.47 KB
/
Copy path.env.example
File metadata and controls
186 lines (167 loc) · 9.47 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
# Copy to .env and fill in. Used by bot (npm run bot:local) and optionally by Expo.
# Do not commit .env.
# Telegram bot (required for local bot; optional for Expo app)
# Get token from @BotFather on Telegram
BOT_TOKEN=1234567890:ABCdefGHIjklMNOpqrsTUVwxyz-EXAMPLE
# Neon/Postgres connection string (from Neon dashboard)
DATABASE_URL=postgresql://user:password@ep-xxx-xxx.region.aws.neon.tech/neondb?sslmode=require
# OpenAI API key for /api/ai (fallback when Vercel AI Gateway is unset).
# Get from https://platform.openai.com/api-keys
OPENAI=sk-proj-xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
# Preferred (cheapest path): Vercel AI Gateway — tried before direct OpenAI.
# Create a key in Vercel Dashboard → AI Gateway, or rely on VERCEL_OIDC_TOKEN on Vercel.
# AI_GATEWAY_API_KEY=...
# AI_GATEWAY_BASE_URL=https://ai-gateway.vercel.sh/v1
# AI_GATEWAY_MINI_MODEL=openai/gpt-4.1-mini
# AI_GATEWAY_FRONTIER_MODEL=openai/gpt-4.1
# Optional: TinyModel encoder sidecar (classify + RAG over program corpus).
# Run from TinyModel repo: python scripts/phase3_reference_server.py --model HyperlinksSpace/TinyModel1 --port 8765
# TINYMODEL_API_URL=http://127.0.0.1:8765
# TINYMODEL_TIMEOUT_MS=8000
# AI_PROVIDER=hybrid
# Optional: Universal Brain generative chat (used when AI tools → Tiny Model).
# Defaults to the HyperlinksSpace TinyModel1 Space when unset.
# Self-host (recommended for prod): horizon2_server or Gradio artifact from TinyModel.
# UB_CHAT_URL=https://hyperlinksspace-tinymodel1space.hf.space
# UB_CHAT_TIMEOUT_MS=45000
# AI_ALLOW_HF_SPACE=true
# Optional: base URL for calling APIs in dev (used by app and bot).
# Example for local Vercel dev: http://localhost:3000
# EXPO_PUBLIC_API_BASE_URL=http://localhost:3000
# Set automatically on Vercel builds (matches deployment id in the Vercel dashboard URL).
# EXPO_PUBLIC_VERCEL_DEPLOYMENT_ID=7xdsFT59DsLvHWPQ9uaaVBW35mzx
# Monotonic counter incremented in Postgres on each Vercel build (see scripts/stamp-deploy-version.ts).
# EXPO_PUBLIC_DEPLOY_VERSION=42
# Optional: Swap.Coffee API key for TON token info and routing.
# COFFEE=your-swap-coffee-api-key
# COFFEE_BASE_URL=https://api.swap.coffee
# COFFEE_TOKENS_BASE_URL=https://tokens.swap.coffee
# Optional: TonAPI token from https://tonconsole.com/ (server-side wallet balance proxy).
# Set on Vercel as a Secret (not EXPO_PUBLIC_*) — used by /api/ton-account-holdings.
# TONAPI_KEY=AE...
# TON address that receives Pro Access payments and DLLR top-ups (native TON + USDT jetton).
# Same treasury for subscriptions and DLLR purchase. Set on Vercel for production builds.
EXPO_PUBLIC_PRO_PAYMENT_TON_ADDRESS=UQBY1YCIlm0cB00xcyaWV0xd_N-Zcgw_-6gWA3XUUNgM-NF8
# Optional: Toncenter JSON-RPC for built-in wallet deploy (/api/wallet-activate).
# Without a key, public toncenter rate limits apply.
# TONCENTER_API_KEY=
# TONCENTER_RPC_URL=https://toncenter.com/api/v2/jsonRPC
# Google OAuth (Sign in with Google on welcome page). Web client from Google Cloud Console.
# GOOGLE_OAUTH_CLIENT_ID=....apps.googleusercontent.com
# GOOGLE_OAUTH_CLIENT_SECRET=...
# Optional override when API origin differs from redirect host:
# GOOGLE_OAUTH_REDIRECT_URI=https://hsbexpo.vercel.app/api/auth/google/callback
# GitHub OAuth (Sign in with GitHub on welcome page).
# Create an OAuth App: https://github.com/settings/developers
# Authorization callback URL must match redirect below (path is fixed in code).
# GITHUB_OAUTH_CLIENT_ID=Ov23li...
# GITHUB_OAUTH_CLIENT_SECRET=...
# Optional: force callback host when API public URL differs from request origin (Vercel/proxy).
# GITHUB_OAUTH_REDIRECT_URI=https://hsbexpo.vercel.app/api/auth/github/callback
#
# Sign in with Apple (Services ID + Sign in with Apple key from Apple Developer).
# APPLE_OAUTH_CLIENT_ID=com.example.app.web
# APPLE_OAUTH_TEAM_ID=ABCDE12345
# APPLE_OAUTH_KEY_ID=ABC123DEFG
# APPLE_OAUTH_PRIVATE_KEY="-----BEGIN PRIVATE KEY-----\n...\n-----END PRIVATE KEY-----"
# Optional:
# APPLE_OAUTH_REDIRECT_URI=https://hsbexpo.vercel.app/api/auth/apple/callback
#
# Also set EXPO_PUBLIC_API_BASE_URL to the same API origin the welcome page calls
# (e.g. https://hsbexpo.vercel.app) so /api/auth/github/start uses the matching redirect.
# Email OTP sign-in (welcome page). Uses Resend for delivery — no Railway server needed.
# Sign up at https://resend.com, verify your sending domain, add DNS records (SPF/DKIM).
# RESEND_API_KEY=re_...
# AUTH_EMAIL_FROM=Hyperlinks Space Program <noreply@yourdomain.com>
# Optional display name in the email subject/body:
# AUTH_EMAIL_FROM=Hyperlinks Space Program <noreply@hyperlinks.space>
# AUTH_EMAIL_APP_NAME=Hyperlinks Space Program
# Without RESEND_API_KEY + AUTH_EMAIL_FROM, local dev logs the OTP code to the API console.
# Telegram browser OIDC (Sign in with Telegram outside Mini App). In @BotFather → your bot → Web Login:
# register site origin AND callback URL exactly (see texts/telegram-login-outside-telegram.md).
# TELEGRAM_CLIENT_ID=1234567890
# TELEGRAM_CLIENT_SECRET=...
# Must match a URL registered in @BotFather Web Login. Unregistered hosts (localhost, hsbexpo,
# other *.vercel.app) make Telegram show the misleading error "redirect_uri required".
# TELEGRAM_OIDC_REDIRECT_URI=https://program.hyperlinks.space/api/auth/telegram/callback
# TELEGRAM_CLIENT_ID must be the numeric bot id (digits only), e.g. 1234567890 from BOT_TOKEN before ":".
# Cloud KMS: full service-account JSON for /api/wallet/register (wraps DEK). See README § GCP_SERVICE_ACCOUNT_JSON.
# GCP_SERVICE_ACCOUNT_JSON={"type":"service_account",...}
# Ops-only: POST /api/wallet/envelope-verify proves Neon+KMS round-trip (never returns mnemonic). Set a long random secret.
# WALLET_ENVELOPE_VERIFY_SECRET=your-long-random-string
# Optional: log non-secret envelope persistence diagnostics from wallet-register.
# WALLET_ENVELOPE_DEBUG=1
# TDLib user-session gateway (real Telegram messages connect — QR login).
# Create an app at https://my.telegram.org/apps (api_id + api_hash). Server-only — never EXPO_PUBLIC_*.
# TELEGRAM_API_ID=12345678
# TELEGRAM_API_HASH=0123456789abcdef0123456789abcdef
# Local gateway (npm run tdlib:gateway): listens on 127.0.0.1:8787 by default.
# TDLIB_GATEWAY_PORT=8787
# TDLIB_GATEWAY_SECRET=change-me-long-random
# TDLIB_DB_ROOT=.tdlib-data
# Production: deploy gateway on Fly/Railway/GCP and point Vercel at it:
# TDLIB_GATEWAY_URL=https://your-tdlib-gateway.example.com
# GCP one-command deploy (after billing enabled): npm run gcp:tdlib-gateway
# GCP Console steps: deploy/gcp/CONSOLE.md
# No credit card: run gateway on your PC + tunnel — deploy/no-card/README.md
# Founder dashboard (/founder) — server-only password (min 8 chars). Never EXPO_PUBLIC_*.
# FOUNDER_DASHBOARD_PASSWORD=change-me-long-random
# Optional salt for session cookie:
# FOUNDER_DASHBOARD_SALT=hsp-founder-v1
#
# Pro tariff overrides used by /api/founder (defaults match UI plans):
# PRO_TARIFF_MONTH_USD=20
# PRO_TARIFF_QUARTER_TOTAL_USD=55.5
# PRO_TARIFF_YEAR_TOTAL_USD=204
# FOUNDER_MIX_MONTH=0.55
# FOUNDER_MIX_QUARTER=0.25
# FOUNDER_MIX_YEAR=0.2
#
# Monthly cost inputs (USD) for the financial model:
# FOUNDER_COST_RAILWAY_USD_MONTH=15
# FOUNDER_COST_VERCEL_USD_MONTH=20
# FOUNDER_COST_GCP_USD_MONTH=0
# Amnezia self-hosted VPN VPS on GCP (e2-small + disk + IP list-price default ~$19/mo)
# FOUNDER_COST_AMNEZIA_VPN_USD_MONTH=19.08
# FOUNDER_AMNEZIA_GCP_PROJECT=hyperlinksspacebot
# FOUNDER_AMNEZIA_GCP_ZONE=europe-central2-a
# FOUNDER_AMNEZIA_GCP_INSTANCE=amnezia-vpn
# FOUNDER_COST_NEON_USD_MONTH=0
# FOUNDER_COST_AI_USD_MONTH=20
# FOUNDER_COST_OTHER_INFRA_USD_MONTH=5
# FOUNDER_COST_CURSOR_USD_MONTH=50
# FOUNDER_COST_RENT_USD_MONTH=250
# FOUNDER_COST_FOOD_USD_MONTH=150
# FOUNDER_COST_ELECTRICITY_USD_MONTH=40
# FOUNDER_COST_SIM_USD_MONTH=15
# FOUNDER_COST_ELECTRONICS_USD_MONTH=50
# FOUNDER_COST_OTHER_PERSONAL_USD_MONTH=30
# FOUNDER_VARIABLE_PER_ACTIVE_HOUR_USD=0.08
# FOUNDER_TDLIB_FIXED_UNTIL_USERS=25
# Intensity multiplier applied to 5-min probe $/hour for Telegram-connected usage:
# FOUNDER_CONNECTED_INTENSITY_MULTIPLIER=15
# Optional JSON from scripts/founder-consumption-probe.mjs:
# FOUNDER_CONSUMPTION_PROBE_JSON={"durationMs":300000,...}
# Optional live provider billing for founder daily spend:
# VERCEL_TOKEN= (account token with billing read — team scope may 403 if data-sharing refused)
# VERCEL_TEAM_ID=team_...
# RAILWAY_API_TOKEN= (account/team Bearer token, or project UUID token → Project-Access-Token)
# RAILWAY_PROJECT_ID=
# RAILWAY_WORKSPACE_ID=
# FOUNDER_COST_RAILWAY_PLAN_USD_MONTH=5
# FOUNDER_COST_GCP_USD_MONTH=0
# Optional per-day GCP spend JSON (manual fallback): [{"day":"2026-09-01","usd":0.12}, ...]
# FOUNDER_COST_GCP_DAILY_JSON=
# Live Amnezia VPN VPS (Compute creationTimestamp + Billing export / list-price fill)
# FOUNDER_COST_AMNEZIA_VPN_USD_MONTH=19.08
# FOUNDER_AMNEZIA_GCP_PROJECT=hyperlinksspacebot
# FOUNDER_AMNEZIA_GCP_ZONE=europe-central2-a
# FOUNDER_AMNEZIA_GCP_INSTANCE=amnezia-vpn
# Start date always comes from GCP Compute Engine creationTimestamp (not env).
# Day $ prefers BigQuery resource billing for that instance; list-price fills export lag.
# Live GCP: Cloud Billing export → BigQuery (auto-discovers gcp_billing_export_v1_* tables)
# GCP_SERVICE_ACCOUNT_JSON={"type":"service_account",...} # needs BigQuery Job User + Data Viewer on export dataset
# GCP_BIGQUERY_BILLING_TABLE=project.dataset.gcp_billing_export_v1_XXXX # optional if auto-discover works
# GCP_BIGQUERY_BILLING_DATASET=billing_export # optional: limit discovery to one dataset
# GCP_BILLING_PROJECT_ID=hyperlinksspacebot # optional override of SA project_id
# GCP_BIGQUERY_LOCATION=US # optional query location