Environment variables
Web app
VITE_API_URL— base URL of the MagiCMS API (https://api.app.magicms.cloudin production).VITE_ANALYTICS— (optional) Plausible or custom analytics endpoint.
API
JWT_SECRET— HS256 signing key and encryption root. Rotate carefully.GITHUB_CLIENT_ID,GITHUB_CLIENT_SECRET— OAuth app credentials.GOOGLE_CLIENT_ID,GOOGLE_CLIENT_SECRET— OAuth credentials.WEB_APP_URL— base URL of the web app (forsafeReturnTo).FUNCTION_URL— base URL of the API itself (for OAuth redirects).ALLOWED_ORIGINS— comma-separated browser origins allowed to call the API, for examplehttps://app.magicms.cloud.BUNNY_DB_URL,BUNNY_DB_KEY— libSQL connection.
Secrets are configured per-environment in Bunny Edge Scripting. Refresh sessions use Secure HttpOnly cookies; OAuth callbacks exchange a short-lived one-time code instead of putting tokens in the URL.