ANTHROPIC_API_KEY=your_anthropic_api_key_here DATABASE_URL=sqlite+aiosqlite:///./data/discovery.db HOST_BIND_IP=0.0.0.0 HOST_PORT=8011 # Optional: override the Anthropic model used for extraction ANTHROPIC_MODEL=claude-sonnet-4-6 # Durable CSV copies of discovery questions + answers. The per-conversation # files live in QUESTIONS_DIR; QUESTIONS_MASTER_CSV is an append-only log of # every save/complete event across conversations. Both default under ./data. QUESTIONS_DIR=./data/questions QUESTIONS_MASTER_CSV=./data/questions_master.csv # Google OAuth (web client type). Register the redirect URI below as an # authorized redirect URI in the Google Cloud Console for this client. GOOGLE_CLIENT_ID=xxxx.apps.googleusercontent.com GOOGLE_CLIENT_SECRET=GOCSPX-xxxx OAUTH_REDIRECT_URI=http://localhost:8011/api/auth/callback # Random 64-char URL-safe strings. Generate with: # python -c "import secrets; print(secrets.token_urlsafe(48))" JWT_SECRET=generate-a-random-64-char-string IMPACTFLOW_API_KEY=generate-another-random-64-char-string # JWT lifetimes (minutes / days). JWT_ACCESS_MINUTES=15 JWT_REFRESH_DAYS=7 # Browser session cookies. COOKIE_SECURE must be true in production (HTTPS); # set it false ONLY for local http://localhost dev, where Secure cookies are # never sent. POST_LOGIN_REDIRECT is where the OAuth callback lands the # browser after setting the session cookies. COOKIE_SECURE=false POST_LOGIN_REDIRECT=/static/discovery.html # Comma-separated allow-list of browser origins for CORS. CORS_ALLOWED_ORIGINS=http://localhost:8011,http://100.103.206.4:8011 # Optional comma-separated email-domain allow-list (e.g. "computerim.com"). # Empty means any verified Google email is accepted. ALLOWED_EMAIL_DOMAINS=