# Brainerce Sales Channel — preferred env var name.
NEXT_PUBLIC_BRAINERCE_SALES_CHANNEL_ID=<%= connectionId %>
# Legacy alias kept for backwards compatibility — both are accepted by the SDK.
# @deprecated will be removed when SDK 2.0 ships.
NEXT_PUBLIC_BRAINERCE_CONNECTION_ID=<%= connectionId %>
# Store name and currency. The storefront prefers the LIVE values from the
# Brainerce API wherever it can (server components,
, JSON-LD, the OG
# card); these are the fallback the client bundle carries for the moments
# before that data arrives, and what renders if the API is unreachable.
# Refresh them with `npm run setup` (`npm run connect` runs it for you).
#
# ⛔ NEXT_PUBLIC_* values are inlined at BUILD time. Editing this file changes
# nothing already built: run `npm run build` before deploying, and restart a
# running dev server. Values are quoted the way Next.js's env loader reads
# them; `setup` and `connect` write the same form (see scripts/env-file.mjs).
NEXT_PUBLIC_STORE_NAME=<%- storeNameEnv %>
NEXT_PUBLIC_STORE_CURRENCY=<%- currencyEnv %>
# Backend API URL (server-side only — used by BFF proxy and SSR, never exposed to browser)
#
# ⛔ There is no API key here, and there must never be one. This storefront runs
# entirely on the PUBLIC sales channel credentials above. An admin key
# (brainerce_*) in a browser-reachable app is readable by anyone who opens
# devtools, and it is full write access to the live store. In particular, never
# give this project the `gift_cards:issue` scope: it mints stored value.
# Redeeming a card from the storefront needs no key at all (applyGiftCard /
# removeGiftCard / checkGiftCardBalance); issuing one is a dashboard action, or
# server-side on infrastructure the merchant controls.
BRAINERCE_API_URL=<%- apiBaseUrlEnv %>
# Public API origin for the AI chat widget (public, unauthenticated endpoints only).
# The widget streams chat directly from the browser, so this one IS public.
NEXT_PUBLIC_BRAINERCE_API_URL=<%- apiBaseUrlEnv %>
# Public site URL — canonical tags, sitemap.xml, robots.txt, JSON-LD, and the
# Origin header the Brainerce backend checks against your sales channel's
# configured domain.
#
# Intentionally unset. Nothing at setup time knows where this store will be
# served from, so the storefront resolves its own origin at runtime: hosting
# platform variables first (Vercel / Netlify / Render / Railway / Cloudflare
# Pages), then the incoming request's forwarded host. It is correct in local
# development and on any host, with nothing set here.
#
# ⛔ Do not write a placeholder address into this variable. A wrong absolute
# URL is indistinguishable from a right one to a search crawler, so a guess
# here is worse than leaving it empty. Either set your real domain or nothing.
#
# Once you have that domain, set it — an explicit value is the only source a
# request header cannot forge, and it keeps canonical URLs stable across
# preview deployments:
#
# SITE_URL=https://shop.example.com
#
# Set it in your hosting provider's environment variables, not in this file:
# .env.local is gitignored and never travels with a deploy.
# `NEXT_PUBLIC_SITE_URL` is still read as a backwards-compatible alias.
#
# On some hosts SITE_URL is NOT optional. Platforms whose proxy forwards
# requests to the app as `Host: localhost:` (OpenAI Sites /
# *.chatgpt.site, among others) hide the real hostname from the server, so
# nothing can be resolved from the request. Set SITE_URL there, or server-side
# API calls send `Origin: http://localhost:3000` and a sales channel with a
# configured Domain rejects them with 403.
# Optional: floating WhatsApp contact button. Nothing shipped reads this today,
# including the `atelier` design. It is a naming convention for a button you
# build. Digits only, international format without "+"
# (e.g. 14155550123). Leave unset to hide the button.
# NEXT_PUBLIC_WHATSAPP_PHONE=