# aa-bridge configuration # Copy to .env and fill in. # Auth0 sub of @jeffrey (the only allowed user) ADMIN_SUB=auth0|63effeeb2a7d55f8098d62f9 # Auth0 tenant AUTH0_DOMAIN=aesthetic.us.auth0.com # Port the bridge listens on (matches macbook side of help tunnel) AA_PORT=3004 # Working directory the spawned `claude` runs in AA_WORK_DIR=/Users/aesthetic/aesthetic-computer # Path to the claude binary CLAUDE_BIN=/Users/aesthetic/.local/bin/claude # Permission mode for the spawned claude # bypassPermissions = autonomous (admin-only setup) # acceptEdits = auto-accept file edits, prompt for bash # default = prompt for everything (will hang the bridge) AA_PERMISSION_MODE=bypassPermissions # Optional model override. Empty = claude default (opus on Max plan). # For cheaper phone use try "sonnet" or "haiku". AA_MODEL=sonnet # Where per-user session ids are persisted AA_SESSION_FILE=/Users/aesthetic/.aa-bridge/sessions.json # Comma-separated CORS allow list AA_ALLOWED_ORIGINS=https://aesthetic.computer,https://hi.aesthetic.computer,http://localhost:8888 # Set AA_DEV=1 to bypass all auth checks for local smoke tests. # AA_DEV=1 # ───────── pp (sub-whitelisted vibe-coding; publishes as the caller) ───────── # Comma-separated Auth0 subs allowed to use /api/pp/chat. NOT handles — subs. # ADMIN_SUB is always allowed implicitly. Empty = pp is closed to everyone. PP_ALLOWED_SUBS= # Model for pp turns (sonnet is a good cost/quality default). PP_MODEL=sonnet # Per-turn wall clock + concurrency + rate limits. PP_TIMEOUT_MS=180000 PP_MAX_CONCURRENCY=2 PP_PER_USER_HOUR=30 PP_PER_USER_DAY=120 PP_GLOBAL_DAY=600 # Built AC publish MCP entry. Default: /mcp-server/dist/index.js # On the box, build it once: (cd mcp-server && npm install && npm run build) # PP_MCP_ENTRY=/opt/help/aesthetic-computer/mcp-server/dist/index.js # Where transient per-turn mcp-configs (carrying the caller's AC_TOKEN) live. # PP_MCP_DIR=/home/help/.pp-bridge