# Google OAuth Web client (gmail.readonly) GOOGLE_CLIENT_ID= GOOGLE_CLIENT_SECRET= # Must match an Authorized redirect URI in Google Cloud Console. # Local (Vite proxies /callback to Fastify): GOOGLE_REDIRECT_URI=http://localhost:5173/callback # Production: # GOOGLE_REDIRECT_URI=https://oauth.0dev.web.id/callback # 32+ random characters. Used to derive the session cookie key. SESSION_SECRET=change-me-to-a-long-random-string PORT=3000 NODE_ENV=development # Watcher (apps/watcher) — Gmail Pub/Sub push WATCHER_PORT=3001 # Full topic name, e.g. projects/my-gcp-project/topics/gmail-push # A short name like gmail-push is expanded if GOOGLE_CLOUD_PROJECT is set. GOOGLE_PUBSUB_TOPIC= # GOOGLE_CLOUD_PROJECT= # Shared secret. Push URL: https://host/pubsub/gmail?token=... PUBSUB_VERIFICATION_TOKEN= # Defaults to apps/api/data/app.db (same OAuth tokens as the web app) # SQLITE_PATH= # PocketBase (watcher writes parsed receipts to collection `spendings`) # Use a _superusers account (admin), not a users-collection login. POCKETBASE_URL= POCKETBASE_USER= POCKETBASE_PASSWORD= # ntfy alerts for parse failures / non-duplicate skips (default: system topic) # NTFY_URL=https://n.0dev.web.id/system