# Generate both with: pnpm env:setup-dev CLIENT_ASSERTION_KEY= COOKIE_SECRET= # Set to your tunnel URL to use a confidential client in dev # OAUTH_PUBLIC_URL=https://your-tunnel.trycloudflare.com # 32-byte base64 secret used to envelope-encrypt community signing keys. # Generate with: openssl rand -base64 32 COMMUNITY_MASTER_KEY= # 32-byte base64 secret used to HMAC-sign realtime subscription tickets. # Generate with: openssl rand -base64 32 REALTIME_TICKET_SECRET= # Service DID for JWT verification (aud claim). did:web: for prod. SERVICE_DID=did:web:localhost # Dev-only: trust the HMAC-signed session cookie instead of atproto service-auth # JWTs, so the loopback OAuth client can reach contrail without a tunnel. NEVER # set this in production — it turns the cookie into the only auth signal. DEV_AUTH=1