# Generate both with: pnpm env:setup-dev CLIENT_ASSERTION_KEY= COOKIE_SECRET= # Set to your tunnel URL to use a confidential client in dev # OAUTH_PUBLIC_URL=https://your-tunnel.trycloudflare.com # Random string used to AES-GCM encrypt each community's Rookery signing key # in D1. Generate with: openssl rand -base64 32 COMMUNITY_ENCRYPTION_KEY= # Shared secret required by the Rookery PDS when creating new community accounts. ROOKERY_SIGNUP_SECRET= # Optional: if set, /_cron/check-dms requires ?secret=... when called manually. # The scheduled handler bypasses this via an internal header. # CRON_SECRET=