# Brainerce Sales Channel — preferred env var name. NEXT_PUBLIC_BRAINERCE_SALES_CHANNEL_ID=<%= connectionId %> # Legacy alias kept for backwards compatibility — both are accepted by the SDK. # @deprecated will be removed when SDK 2.0 ships. NEXT_PUBLIC_BRAINERCE_CONNECTION_ID=<%= connectionId %> # Store name and currency. The storefront prefers the LIVE values from the # Brainerce API wherever it can (server components, , JSON-LD, the OG # card); these are the fallback the client bundle carries for the moments # before that data arrives, and what renders if the API is unreachable. # Refresh them with `npm run setup` (`npm run connect` runs it for you). # # ⛔ NEXT_PUBLIC_* values are inlined at BUILD time. Editing this file changes # nothing already built: run `npm run build` before deploying, and restart a # running dev server. Values are quoted the way Next.js's env loader reads # them; `setup` and `connect` write the same form (see scripts/env-file.mjs). NEXT_PUBLIC_STORE_NAME=<%- storeNameEnv %> NEXT_PUBLIC_STORE_CURRENCY=<%- currencyEnv %> # Backend API URL (server-side only — used by BFF proxy and SSR, never exposed to browser) # # ⛔ There is no API key here, and there must never be one. This storefront runs # entirely on the PUBLIC sales channel credentials above. An admin key # (brainerce_*) in a browser-reachable app is readable by anyone who opens # devtools, and it is full write access to the live store. In particular, never # give this project the `gift_cards:issue` scope: it mints stored value. # Redeeming a card from the storefront needs no key at all (applyGiftCard / # removeGiftCard / checkGiftCardBalance); issuing one is a dashboard action, or # server-side on infrastructure the merchant controls. BRAINERCE_API_URL=<%- apiBaseUrlEnv %> # Public API origin for the AI chat widget (public, unauthenticated endpoints only). # The widget streams chat directly from the browser, so this one IS public. NEXT_PUBLIC_BRAINERCE_API_URL=<%- apiBaseUrlEnv %> # Public site URL — canonical tags, sitemap.xml, robots.txt, JSON-LD, and the # Origin header the Brainerce backend checks against your sales channel's # configured domain. # # Intentionally unset. Nothing at setup time knows where this store will be # served from, so the storefront resolves its own origin at runtime: hosting # platform variables first (Vercel / Netlify / Render / Railway / Cloudflare # Pages), then the incoming request's forwarded host. It is correct in local # development and on any host, with nothing set here. # # ⛔ Do not write a placeholder address into this variable. A wrong absolute # URL is indistinguishable from a right one to a search crawler, so a guess # here is worse than leaving it empty. Either set your real domain or nothing. # # Once you have that domain, set it — an explicit value is the only source a # request header cannot forge, and it keeps canonical URLs stable across # preview deployments: # # SITE_URL=https://shop.example.com # # Set it in your hosting provider's environment variables, not in this file: # .env.local is gitignored and never travels with a deploy. # `NEXT_PUBLIC_SITE_URL` is still read as a backwards-compatible alias. # # On some hosts SITE_URL is NOT optional. Platforms whose proxy forwards # requests to the app as `Host: localhost:<port>` (OpenAI Sites / # *.chatgpt.site, among others) hide the real hostname from the server, so # nothing can be resolved from the request. Set SITE_URL there, or server-side # API calls send `Origin: http://localhost:3000` and a sales channel with a # configured Domain rejects them with 403. # Optional: floating WhatsApp contact button. Nothing shipped reads this today, # including the `atelier` design. It is a naming convention for a button you # build. Digits only, international format without "+" # (e.g. 14155550123). Leave unset to hide the button. # NEXT_PUBLIC_WHATSAPP_PHONE=