[{"data":1,"prerenderedAt":1544},["ShallowReactive",2],{"navigation_docs":3,"-guide-environment-variables":168,"-guide-environment-variables-surround":1540},[4,146],{"title":5,"icon":6,"path":7,"stem":8,"children":9,"page":36},"Guide","i-lucide-book-open","\u002Fguide","1.guide",[10,14,37,55,59,63,67,71,75,79,83,87,109,134,138,142],{"title":11,"path":12,"stem":13},"What is Agent Zero?","\u002Fguide\u002Fintroduction","1.guide\u002F1.introduction",{"title":15,"icon":16,"path":17,"stem":18,"children":19,"page":36},"API","i-lucide-plug","\u002Fguide\u002Fapi","1.guide\u002F10.api",[20,24,28,32],{"title":21,"path":22,"stem":23},"API overview","\u002Fguide\u002Fapi\u002Foverview","1.guide\u002F10.api\u002F1.overview",{"title":25,"path":26,"stem":27},"Define endpoints","\u002Fguide\u002Fapi\u002Fdefine-endpoints","1.guide\u002F10.api\u002F2.define-endpoints",{"title":29,"path":30,"stem":31},"Use the API from a client","\u002Fguide\u002Fapi\u002Fuse-from-client","1.guide\u002F10.api\u002F3.use-from-client",{"title":33,"path":34,"stem":35},"Protect endpoints","\u002Fguide\u002Fapi\u002Fprotect-endpoints","1.guide\u002F10.api\u002F4.protect-endpoints",false,{"title":38,"icon":39,"path":40,"stem":41,"children":42,"page":36},"Authentication","i-lucide-lock","\u002Fguide\u002Fauthentication","1.guide\u002F11.authentication",[43,47,51],{"title":44,"path":45,"stem":46},"Authentication overview","\u002Fguide\u002Fauthentication\u002Foverview","1.guide\u002F11.authentication\u002F1.overview",{"title":48,"path":49,"stem":50},"GitHub OAuth","\u002Fguide\u002Fauthentication\u002Foauth","1.guide\u002F11.authentication\u002F2.oauth",{"title":52,"path":53,"stem":54},"Permissions","\u002Fguide\u002Fauthentication\u002Fpermissions","1.guide\u002F11.authentication\u002F3.permissions",{"title":56,"path":57,"stem":58},"Organizations","\u002Fguide\u002Forganizations","1.guide\u002F12.organizations",{"title":60,"path":61,"stem":62},"Frontend","\u002Fguide\u002Ffrontend","1.guide\u002F13.frontend",{"title":64,"path":65,"stem":66},"Mails","\u002Fguide\u002Fmails","1.guide\u002F14.mails",{"title":68,"path":69,"stem":70},"Internationalization","\u002Fguide\u002Finternationalization","1.guide\u002F15.internationalization",{"title":72,"path":73,"stem":74},"Deployment","\u002Fguide\u002Fdeployment","1.guide\u002F16.deployment",{"title":76,"path":77,"stem":78},"Tech stack","\u002Fguide\u002Ftech-stack","1.guide\u002F2.tech-stack",{"title":80,"path":81,"stem":82},"Installation","\u002Fguide\u002Finstallation","1.guide\u002F3.installation",{"title":84,"path":85,"stem":86},"Environment variables","\u002Fguide\u002Fenvironment-variables","1.guide\u002F4.environment-variables",{"title":88,"icon":89,"path":90,"stem":91,"children":92,"page":36},"Codebase","i-lucide-folder-tree","\u002Fguide\u002Fcodebase","1.guide\u002F5.codebase",[93,97,101,105],{"title":94,"path":95,"stem":96},"Codebase structure","\u002Fguide\u002Fcodebase\u002Fstructure","1.guide\u002F5.codebase\u002F1.structure",{"title":98,"path":99,"stem":100},"Dependencies","\u002Fguide\u002Fcodebase\u002Fdependencies","1.guide\u002F5.codebase\u002F2.dependencies",{"title":102,"path":103,"stem":104},"Formatting and linting","\u002Fguide\u002Fcodebase\u002Fformatting-linting","1.guide\u002F5.codebase\u002F3.formatting-linting",{"title":106,"path":107,"stem":108},"Agent Skills","\u002Fguide\u002Fcodebase\u002Fagent-skills","1.guide\u002F5.codebase\u002F4.agent-skills",{"title":110,"icon":111,"path":112,"stem":113,"children":114,"page":36},"Architecture","i-lucide-layers","\u002Fguide\u002Farchitecture","1.guide\u002F6.architecture",[115,118,122,126,130],{"title":110,"path":116,"stem":117},"\u002Fguide\u002Farchitecture\u002Foverview","1.guide\u002F6.architecture\u002F1.overview",{"title":119,"path":120,"stem":121},"State machine","\u002Fguide\u002Farchitecture\u002Fstate-machine","1.guide\u002F6.architecture\u002F2.state-machine",{"title":123,"path":124,"stem":125},"Execution boundary","\u002Fguide\u002Farchitecture\u002Fexecution-boundary","1.guide\u002F6.architecture\u002F3.execution-boundary",{"title":127,"path":128,"stem":129},"Issue-to-PR workflow","\u002Fguide\u002Farchitecture\u002Fissue-to-pr","1.guide\u002F6.architecture\u002F4.issue-to-pr",{"title":131,"path":132,"stem":133},"Adding a capability","\u002Fguide\u002Farchitecture\u002Fadding-a-capability","1.guide\u002F6.architecture\u002F5.adding-a-capability",{"title":135,"path":136,"stem":137},"Repository policy","\u002Fguide\u002Fconfiguration","1.guide\u002F7.configuration",{"title":139,"path":140,"stem":141},"Safety model","\u002Fguide\u002Fsafety","1.guide\u002F8.safety",{"title":143,"path":144,"stem":145},"Database","\u002Fguide\u002Fdatabase","1.guide\u002F9.database",{"title":147,"icon":148,"path":149,"stem":150,"children":151,"page":36},"Reference","i-lucide-book-marked","\u002Freference","2.reference",[152,156,160,164],{"title":153,"path":154,"stem":155},"CLI","\u002Freference\u002Fcli","2.reference\u002F1.cli",{"title":157,"path":158,"stem":159},"Model providers","\u002Freference\u002Fmodel-providers","2.reference\u002F2.model-providers",{"title":161,"path":162,"stem":163},"Source-control providers","\u002Freference\u002Fsource-control-providers","2.reference\u002F3.source-control-providers",{"title":165,"path":166,"stem":167},"Sandbox providers","\u002Freference\u002Fsandbox-providers","2.reference\u002F4.sandbox-providers",{"id":169,"title":84,"body":170,"description":1533,"extension":1534,"links":1535,"meta":1536,"navigation":1537,"path":85,"seo":1538,"stem":86,"__hash__":1539},"docs\u002F1.guide\u002F4.environment-variables.md",{"type":171,"value":172,"toc":1519},"minimark",[173,182,187,194,319,326,384,390,393,409,422,425,524,531,535,550,622,628,632,638,670,691,694,697,877,882,896,954,1002,1040,1057,1061,1078,1169,1173,1177,1199,1203,1213,1288,1301,1305,1309,1324,1350,1357,1360,1444,1457,1475,1482,1486,1515],[174,175,176,177,181],"p",{},"Agent Zero reads credentials and deployment policy exclusively from the environment. Endpoint URLs and credentials can never be named or embedded in ",[178,179,180],"code",{},".agent-zero.yml",", so untrusted repository policy cannot redirect a secret.",[183,184,186],"h2",{"id":185},"one-env-file-per-process","One env file per process",[174,188,189,190,193],{},"Each process reads exactly one ",[178,191,192],{},".env",", and that file sits next to the process that reads it. Nothing is shared implicitly: a file is loaded only by the process it belongs to, by that process's own tooling.",[195,196,197,216],"table",{},[198,199,200],"thead",{},[201,202,203,207,210,213],"tr",{},[204,205,206],"th",{},"File",[204,208,209],{},"Read by",[204,211,212],{},"Loaded by",[204,214,215],{},"Holds",[217,218,219,250,273,292],"tbody",{},[201,220,221,226,237,244],{},[222,223,224],"td",{},[178,225,192],{},[222,227,228,229,232,233,236],{},"the ",[178,230,231],{},"zero"," CLI (",[178,234,235],{},"aube run zero …",")",[222,238,239,240,243],{},"Node's ",[178,241,242],{},"--env-file-if-exists=.env"," in the root script",[222,245,246,247],{},"Model providers, subscription transports, ",[178,248,249],{},"GITHUB_TOKEN",[201,251,252,257,260,266],{},[222,253,254],{},[178,255,256],{},"apps\u002Fdashboard\u002F.env",[222,258,259],{},"the dashboard: UI, control plane, webhooks, auth, mail",[222,261,262,263],{},"Nuxt, from beside ",[178,264,265],{},"nuxt.config.ts",[222,267,268,269,272],{},"Control plane, webhook ingress, ",[178,270,271],{},"DATABASE_URL",", authentication, mail, site URL",[201,274,275,280,283,287],{},[222,276,277],{},[178,278,279],{},"apps\u002Fdocs\u002F.env",[222,281,282],{},"the documentation site",[222,284,262,285],{},[178,286,265],{},[222,288,289],{},[178,290,291],{},"NUXT_APP_BASE_URL",[201,293,294,299,312,315],{},[222,295,296],{},[178,297,298],{},"packages\u002Fdatabase\u002F.env",[222,300,301,304,305,308,309,236],{},[178,302,303],{},"drizzle-kit"," (",[178,306,307],{},"db:generate",", ",[178,310,311],{},"db:migrate",[222,313,314],{},"drizzle-kit, from its own working directory",[222,316,317],{},[178,318,271],{},[174,320,321,322,325],{},"Each has a checked-in ",[178,323,324],{},".env.example"," next to it; copy the ones you need:",[327,328,333],"pre",{"className":329,"code":330,"language":331,"meta":332,"style":332},"language-bash shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","cp .env.example .env\ncp apps\u002Fdashboard\u002F.env.example apps\u002Fdashboard\u002F.env\ncp apps\u002Fdocs\u002F.env.example apps\u002Fdocs\u002F.env\ncp packages\u002Fdatabase\u002F.env.example packages\u002Fdatabase\u002F.env\n","bash","",[178,334,335,351,362,373],{"__ignoreMap":332},[336,337,340,344,348],"span",{"class":338,"line":339},"line",1,[336,341,343],{"class":342},"sBMFI","cp",[336,345,347],{"class":346},"sfazB"," .env.example",[336,349,350],{"class":346}," .env\n",[336,352,354,356,359],{"class":338,"line":353},2,[336,355,343],{"class":342},[336,357,358],{"class":346}," apps\u002Fdashboard\u002F.env.example",[336,360,361],{"class":346}," apps\u002Fdashboard\u002F.env\n",[336,363,365,367,370],{"class":338,"line":364},3,[336,366,343],{"class":342},[336,368,369],{"class":346}," apps\u002Fdocs\u002F.env.example",[336,371,372],{"class":346}," apps\u002Fdocs\u002F.env\n",[336,374,376,378,381],{"class":338,"line":375},4,[336,377,343],{"class":342},[336,379,380],{"class":346}," packages\u002Fdatabase\u002F.env.example",[336,382,383],{"class":346}," packages\u002Fdatabase\u002F.env\n",[174,385,386,387,389],{},"Every file is optional. A deployment that sets real environment variables ships no ",[178,388,192],{}," at all, and real variables always win over the file.",[174,391,392],{},"A variable two processes both read is written in both files on purpose, rather than one process inheriting the other's configuration:",[394,395,396,406],"ul",{},[397,398,399,401,402,405],"li",{},[178,400,271],{}," is read by the dashboard (the only process that opens the database) and by drizzle-kit when migrating. Point both at the same database — ",[178,403,404],{},"drizzle.config.ts"," and the server resolve it through the same function precisely so migrations cannot target one store while the dashboard opens another.",[397,407,408],{},"The model-provider keys are read by the CLI and, when the hosted control plane executes runs, by the dashboard.",[174,410,411,414,415,417,418,421],{},[178,412,413],{},"server\u002Fauth.config.ts"," resolves ",[178,416,271],{}," at module load, so a dashboard started without it fails on the first request (",[178,419,420],{},"missing required environment variable: DATABASE_URL",") rather than degrading quietly.",[183,423,157],{"id":424},"model-providers",[195,426,427,437],{},[198,428,429],{},[201,430,431,434],{},[204,432,433],{},"Variable",[204,435,436],{},"Purpose",[217,438,439,456,468,480,493,504,514],{},[201,440,441,446],{},[222,442,443],{},[178,444,445],{},"OPENAI_API_KEY",[222,447,448,449,452,453,236],{},"Credential for ",[178,450,451],{},"openai"," (and legacy fallback for ",[178,454,455],{},"openai-compatible",[201,457,458,463],{},[222,459,460],{},[178,461,462],{},"ANTHROPIC_API_KEY",[222,464,448,465],{},[178,466,467],{},"anthropic",[201,469,470,475],{},[222,471,472],{},[178,473,474],{},"GOOGLE_GENERATIVE_AI_API_KEY",[222,476,448,477],{},[178,478,479],{},"google",[201,481,482,487],{},[222,483,484],{},[178,485,486],{},"AI_GATEWAY_API_KEY",[222,488,448,489,492],{},[178,490,491],{},"ai-gateway"," (or Vercel OIDC)",[201,494,495,500],{},[222,496,497],{},[178,498,499],{},"OPENAI_COMPATIBLE_API_KEY",[222,501,448,502],{},[178,503,455],{},[201,505,506,511],{},[222,507,508],{},[178,509,510],{},"AGENT_ZERO_MODEL",[222,512,513],{},"Default model name",[201,515,516,521],{},[222,517,518],{},[178,519,520],{},"AGENT_ZERO_MODEL_BASE_URL",[222,522,523],{},"Operator-owned base URL for custom gateways and self-hosted endpoints",[174,525,526,527,530],{},"Each provider reads only its documented variable. See ",[528,529,157],"a",{"href":158}," for the full matrix.",[183,532,534],{"id":533},"control-plane","Control plane",[174,536,537,538,541,542,545,546,549],{},"The control-plane API (",[178,539,540],{},"\u002Frpc\u002F**"," and ",[178,543,544],{},"\u002Fapi\u002Fv1\u002F**",") fails closed: without ",[178,547,548],{},"AGENT_ZERO_CONTROL_PLANE_TOKENS"," every mutation is rejected while reads stay open.",[195,551,552,560],{},[198,553,554],{},[201,555,556,558],{},[204,557,433],{},[204,559,436],{},[217,561,562,575,589,609],{},[201,563,564,568],{},[222,565,566],{},[178,567,548],{},[222,569,570,571,574],{},"Comma-separated ",[178,572,573],{},"name:token"," bearer credentials",[201,576,577,582],{},[222,578,579],{},[178,580,581],{},"AGENT_ZERO_CONTROL_PLANE_REPOSITORIES",[222,583,584,585,588],{},"Comma-separated repository paths ",[178,586,587],{},"tasks.create"," may target",[201,590,591,596],{},[222,592,593],{},[178,594,595],{},"AGENT_ZERO_CONTROL_PLANE_MODES",[222,597,570,598,601,602,541,605,608],{},[178,599,600],{},"name:mode|mode"," execution-mode grants; without one a principal may only request the non-writable ",[178,603,604],{},"observe",[178,606,607],{},"suggest"," modes",[201,610,611,616],{},[222,612,613],{},[178,614,615],{},"AGENT_ZERO_CONTROL_PLANE_ORIGINS",[222,617,618,619,621],{},"Comma-separated origins allowed to read ",[178,620,544],{}," cross-origin via CORS; empty by default",[174,623,624,625,627],{},"See ",[528,626,33],{"href":34}," for how these are enforced.",[183,629,631],{"id":630},"webhooks","Webhooks",[174,633,634,637],{},[178,635,636],{},"POST \u002Fwebhooks\u002Fgithub"," fails closed (503, nothing ingested) until both variables are set.",[195,639,640,648],{},[198,641,642],{},[201,643,644,646],{},[204,645,433],{},[204,647,436],{},[217,649,650,660],{},[201,651,652,657],{},[222,653,654],{},[178,655,656],{},"GITHUB_WEBHOOK_SECRET",[222,658,659],{},"HMAC secret for GitHub webhook authentication",[201,661,662,667],{},[222,663,664],{},[178,665,666],{},"AGENT_ZERO_CHECKOUT_PATH",[222,668,669],{},"Checkout the webhook route binds incoming events to",[174,671,672,673,308,675,308,678,308,681,308,684,687,688,690],{},"Status publishing reads one fixed variable per provider (",[178,674,249],{},[178,676,677],{},"GITLAB_TOKEN",[178,679,680],{},"BITBUCKET_CLOUD_TOKEN",[178,682,683],{},"BITBUCKET_DATA_CENTER_TOKEN",[178,685,686],{},"GITEA_TOKEN",") — see ",[528,689,161],{"href":162},".",[183,692,38],{"id":693},"authentication",[174,695,696],{},"Registration and GitHub OAuth are off until you turn them on, so a fresh deployment cannot be signed up for by a stranger.",[195,698,699,713],{},[198,700,701],{},[201,702,703,705,708,711],{},[204,704,433],{},[204,706,707],{},"Required",[204,709,710],{},"Default",[204,712,436],{},[217,714,715,735,752,774,792,808,824,846,863],{},[201,716,717,722,725,728],{},[222,718,719],{},[178,720,721],{},"NUXT_BETTER_AUTH_SECRET",[222,723,724],{},"yes",[222,726,727],{},"–",[222,729,730,731,734],{},"Session signing secret. Required under this name in production; ",[178,732,733],{},"BETTER_AUTH_SECRET"," is a development-only fallback",[201,736,737,741,743,745],{},[222,738,739],{},[178,740,271],{},[222,742,724],{},[222,744,727],{},[222,746,747,748,751],{},"Postgres connection string; the pre-split ",[178,749,750],{},"AUTH_DATABASE_URL"," is still read when this is unset",[201,753,754,759,762,767],{},[222,755,756],{},[178,757,758],{},"AUTH_ENABLE_SIGNUP",[222,760,761],{},"no",[222,763,764],{},[178,765,766],{},"false",[222,768,769,770,773],{},"Set to ",[178,771,772],{},"true"," to allow self-registration",[201,775,776,785,787,789],{},[222,777,778,781,782],{},[178,779,780],{},"GITHUB_CLIENT_ID"," \u002F ",[178,783,784],{},"GITHUB_CLIENT_SECRET",[222,786,761],{},[222,788,727],{},[222,790,791],{},"Enables the GitHub button when both are set",[201,793,794,799,801,805],{},[222,795,796],{},[178,797,798],{},"AUTH_ENABLE_ORGANIZATIONS",[222,800,761],{},[222,802,803],{},[178,804,766],{},[222,806,807],{},"Enables organizations; requires a working mail transport",[201,809,810,815,817,821],{},[222,811,812],{},[178,813,814],{},"AUTH_ALLOW_ORGANIZATION_CREATION",[222,816,761],{},[222,818,819],{},[178,820,766],{},[222,822,823],{},"Whether any signed-in user may create an organization",[201,825,826,831,833,837],{},[222,827,828],{},[178,829,830],{},"AUTH_ENABLE_DEVICE_AUTHORIZATION",[222,832,761],{},[222,834,835],{},[178,836,766],{},[222,838,769,839,841,842,845],{},[178,840,772],{}," to let ",[178,843,844],{},"zero login"," obtain a session through the RFC 8628 device flow",[201,847,848,856,858,860],{},[222,849,850,781,853],{},[178,851,852],{},"OAUTH_PROXY_PRODUCTION_URL",[178,854,855],{},"OAUTH_PROXY_SECRET",[222,857,761],{},[222,859,727],{},[222,861,862],{},"Routes a preview or local origin's OAuth round trip through production; both required, and the secret must match across environments",[201,864,865,870,872,874],{},[222,866,867],{},[178,868,869],{},"NUXT_PUBLIC_SITE_URL",[222,871,761],{},[222,873,727],{},[222,875,876],{},"Base URL override for a custom domain or deterministic OAuth callbacks; auto-detected from the request otherwise",[878,879,881],"h3",{"id":880},"hosted-infrastructure","Hosted infrastructure",[174,883,884,885,888,889,541,892,895],{},"Cloud-managed deployments only. ",[178,886,887],{},"@better-auth\u002Finfra","'s ",[178,890,891],{},"sentinel()",[178,893,894],{},"dash()"," plugins are registered only when all three are set; a self-hosted install leaves them empty and gets neither.",[195,897,898,910],{},[198,899,900],{},[201,901,902,904,906,908],{},[204,903,433],{},[204,905,707],{},[204,907,710],{},[204,909,436],{},[217,911,912,926,940],{},[201,913,914,919,921,923],{},[222,915,916],{},[178,917,918],{},"BETTER_AUTH_API_URL",[222,920,761],{},[222,922,727],{},[222,924,925],{},"Dash API origin",[201,927,928,933,935,937],{},[222,929,930],{},[178,931,932],{},"BETTER_AUTH_KV_URL",[222,934,761],{},[222,936,727],{},[222,938,939],{},"KV service origin; also what the browser-side sentinel client identifies visitors against",[201,941,942,947,949,951],{},[222,943,944],{},[178,945,946],{},"BETTER_AUTH_API_KEY",[222,948,761],{},[222,950,727],{},[222,952,953],{},"Project API key",[955,956,957,963,972],"warning",{},[174,958,959],{},[960,961,962],"strong",{},"Third-party data flow",[174,964,965,966,968,969,971],{},"Setting these opts the deployment into a service outside it. ",[178,967,891],{}," reports sign-in and sign-up attempts for scoring, and the browser-side sentinel client fingerprints every visitor and identifies them against ",[178,970,932],{}," — which is why that client plugin is loaded only when these variables are configured.",[174,973,974,976,977,980,981,308,984,308,987,990,991,994,995,998,999,1001],{},[178,975,894],{}," mounts roughly 79 endpoints under ",[178,978,979],{},"\u002Fapi\u002Fauth\u002Fdash\u002F**",", including ",[178,982,983],{},"execute-adapter",[178,985,986],{},"impersonate-user",[178,988,989],{},"delete-many-users",", and ",[178,992,993],{},"export-users",". All but two require a JWT signed by the hosted service, verified against its JWKS with a five-minute maximum age, whose ",[178,996,997],{},"apiKeyHash"," claim must also match a hash of ",[178,1000,946],{}," — so controlling the API origin alone does not admit a caller.",[1003,1004,1005,1010,1031],"caution",{},[174,1006,1007],{},[960,1008,1009],{},"Account creation bypasses your sign-up policy",[174,1011,1012,888,1014,541,1017,1020,1021,1024,1025,1027,1028,690],{},[178,1013,894],{},[178,1015,1016],{},"accept-invitation",[178,1018,1019],{},"complete-invitation"," endpoints cannot carry that JWT guard, because the invitee holds no API key. They are authorized by an invitation token validated against the hosted API, and they create a user with ",[178,1022,1023],{},"emailVerified: true",", optionally a password account, and a session — through the internal adapter, so they bypass both ",[178,1026,758],{}," and the invitation flow gated by ",[178,1029,1030],{},"AUTH_ENABLE_INVITATIONS",[174,1032,1033,1034,1036,1037,690],{},"In other words: enabling ",[178,1035,894],{}," delegates account creation in your database to whoever can mint an invitation in the hosted console. Treat access to that console as equivalent to ",[178,1038,1039],{},"AUTH_ENABLE_SIGNUP=true",[955,1041,1042,1047],{},[174,1043,1044],{},[960,1045,1046],{},"Build-time capture",[174,1048,1049,1050,1052,1053,1056],{},"The sign-in methods the login page offers are derived at build time from the same policy variables the server reads at runtime. Whenever you change ",[178,1051,758],{},", the GitHub OAuth credentials, or the ",[178,1054,1055],{},"BETTER_AUTH_*"," hosted-infrastructure variables, rebuild the app, or the login page will keep advertising the old capabilities (the server still enforces its own policy either way).",[183,1058,1060],{"id":1059},"mail","Mail",[174,1062,1063,1066,1067,1070,1071,1074,1075,1077],{},[178,1064,1065],{},"console"," logs instead of delivering and is the default when neither ",[178,1068,1069],{},"MAIL_PROVIDER"," nor ",[178,1072,1073],{},"RESEND_API_KEY"," is configured, so an unconfigured deployment cannot silently attempt real delivery. If ",[178,1076,1069],{}," is absent, a Resend credential selects Resend automatically; an explicit provider always wins.",[195,1079,1080,1088],{},[198,1081,1082],{},[201,1083,1084,1086],{},[204,1085,433],{},[204,1087,436],{},[217,1089,1090,1109,1119,1131,1153],{},[201,1091,1092,1096],{},[222,1093,1094],{},[178,1095,1069],{},[222,1097,1098,1099,308,1101,1104,1105,1108],{},"Optional explicit ",[178,1100,1065],{},[178,1102,1103],{},"resend",", or ",[178,1106,1107],{},"smtp"," selector",[201,1110,1111,1116],{},[222,1112,1113],{},[178,1114,1115],{},"MAIL_FROM",[222,1117,1118],{},"Sender address",[201,1120,1121,1125],{},[222,1122,1123],{},[178,1124,1073],{},[222,1126,1127,1128,1130],{},"Required for Resend; also selects it when ",[178,1129,1069],{}," is absent",[201,1132,1133,1147],{},[222,1134,1135,781,1138,781,1141,781,1144],{},[178,1136,1137],{},"SMTP_HOST",[178,1139,1140],{},"SMTP_PORT",[178,1142,1143],{},"SMTP_USER",[178,1145,1146],{},"SMTP_PASSWORD",[222,1148,1149,1150],{},"Required when ",[178,1151,1152],{},"MAIL_PROVIDER=smtp",[201,1154,1155,1160],{},[222,1156,1157],{},[178,1158,1159],{},"SMTP_SECURE",[222,1161,1162,1163,1165,1166,1168],{},"Implicit TLS: ",[178,1164,772],{}," on 465, ",[178,1167,766],{}," on 587",[174,1170,624,1171,690],{},[528,1172,64],{"href":65},[183,1174,1176],{"id":1175},"dashboard","Dashboard",[195,1178,1179,1187],{},[198,1180,1181],{},[201,1182,1183,1185],{},[204,1184,433],{},[204,1186,436],{},[217,1188,1189],{},[201,1190,1191,1196],{},[222,1192,1193],{},[178,1194,1195],{},"PORT",[222,1197,1198],{},"Dashboard port (default 3000)",[183,1200,1202],{"id":1201},"deployment-target","Deployment target",[174,1204,1205,1206,1209,1210,690],{},"Build-time only: these pick the deployment preset the dashboard build emits, and with it the KV\ndriver its task history resolves. Unset means the self-hosted ",[178,1207,1208],{},"node-server"," bundle in ",[178,1211,1212],{},".output\u002F",[195,1214,1215,1223],{},[198,1216,1217],{},[201,1218,1219,1221],{},[204,1220,433],{},[204,1222,436],{},[217,1224,1225,1249,1275],{},[201,1226,1227,1232],{},[222,1228,1229],{},[178,1230,1231],{},"NITRO_PRESET",[222,1233,1234,1235,308,1238,308,1240,308,1243,308,1246],{},"Deployment target as the Nitro preset each plan pins: ",[178,1236,1237],{},"vercel",[178,1239,1208],{},[178,1241,1242],{},"cloudflare-module",[178,1244,1245],{},"deno-deploy",[178,1247,1248],{},"netlify",[201,1250,1251,1256],{},[222,1252,1253],{},[178,1254,1255],{},"VITEHUB_HOSTING",[222,1257,1258,1259,308,1261,308,1264,308,1267,308,1270,1272,1273],{},"The same target as a ViteHub plan name: ",[178,1260,1237],{},[178,1262,1263],{},"node",[178,1265,1266],{},"cloudflare",[178,1268,1269],{},"deno",[178,1271,1248],{},"; takes precedence over ",[178,1274,1231],{},[201,1276,1277,1285],{},[222,1278,1279,781,1282],{},[178,1280,1281],{},"KV_REST_API_URL",[178,1283,1284],{},"KV_REST_API_TOKEN",[222,1286,1287],{},"Upstash credentials the KV store reads at runtime on a host without a writable filesystem",[174,1289,1290,1291,1294,1295,1297,1298,1300],{},"Each variable is matched against its own vocabulary and nothing else: a value ViteHub would refuse\nto build under — ",[178,1292,1293],{},"vercel-edge"," or a bare ",[178,1296,1263],{}," in ",[178,1299,1231],{},", say — is rejected up front\nrather than resolved to the neighbouring target.",[174,1302,624,1303,690],{},[528,1304,72],{"href":73},[183,1306,1308],{"id":1307},"build-metadata","Build metadata",[174,1310,1311,1312,1315,1316,1319,1320,1323],{},"Every Nuxt app resolves what build it is — version, commit, branch, deploy channel, deploy URL —\nand publishes it under ",[178,1313,1314],{},"runtimeConfig.public.buildInfo",", read with ",[178,1317,1318],{},"useBuildInfo()",". The resolution\nlives in ",[178,1321,1322],{},"packages\u002Fbuild-env"," and runs in two passes.",[174,1325,1326,1327,1330,1331,541,1334,1337,1338,1341,1342,1345,1346,1349],{},"The first pass runs during the build. It asks the hosting provider first and the checkout second:\na provider knows the branch a detached CI checkout cannot name, and knows whether the deploy is\nproduction. ",[178,1328,1329],{},"VERCEL_GIT_COMMIT_SHA"," and friends on Vercel, ",[178,1332,1333],{},"COMMIT_REF",[178,1335,1336],{},"CONTEXT"," on Netlify,\n",[178,1339,1340],{},"CF_PAGES_COMMIT_SHA"," on Cloudflare Pages, ",[178,1343,1344],{},"GITHUB_SHA"," on a GitHub Actions runner. None of these\nare set by you; they are set by the platform, and are listed in ",[178,1347,1348],{},"turbo.jsonc"," so a build never\nrestores a cached bundle that reports a different commit.",[174,1351,1352,1353,1356],{},"The second pass runs in the deployed server, and is what every target that is not Vercel needs. A\ncontainer image built in CI has none of the platform variables in scope while it is being built, so\nits first pass resolves what git can tell it and leaves the rest as ",[178,1354,1355],{},"unknown",". Those fields — and\nonly those — are completed when the server starts, from the environment the host actually runs it\nin. A field the build resolved is never overwritten: the commit a bundle was compiled from is a\nproperty of the bundle, not of the machine serving the request.",[174,1358,1359],{},"For a deployment on no recognised platform, or one that wants to state outright what it is:",[195,1361,1362,1370],{},[198,1363,1364],{},[201,1365,1366,1368],{},[204,1367,433],{},[204,1369,436],{},[217,1371,1372,1382,1392,1402,1412,1422],{},[201,1373,1374,1379],{},[222,1375,1376],{},[178,1377,1378],{},"AGENT_ZERO_BUILD_COMMIT",[222,1380,1381],{},"Full commit SHA the bundle was built from",[201,1383,1384,1389],{},[222,1385,1386],{},[178,1387,1388],{},"AGENT_ZERO_BUILD_BRANCH",[222,1390,1391],{},"Git branch",[201,1393,1394,1399],{},[222,1395,1396],{},[178,1397,1398],{},"AGENT_ZERO_BUILD_PR_NUMBER",[222,1400,1401],{},"Pull request number, for a pull-request deploy",[201,1403,1404,1409],{},[222,1405,1406],{},[178,1407,1408],{},"AGENT_ZERO_BUILD_URL",[222,1410,1411],{},"URL of this deploy",[201,1413,1414,1419],{},[222,1415,1416],{},[178,1417,1418],{},"AGENT_ZERO_BUILD_PRODUCTION_URL",[222,1420,1421],{},"URL of the production domain",[201,1423,1424,1429],{},[222,1425,1426],{},[178,1427,1428],{},"AGENT_ZERO_BUILD_ENV",[222,1430,1431,1432,308,1435,308,1438,1104,1441],{},"Deploy channel: ",[178,1433,1434],{},"dev",[178,1436,1437],{},"preview",[178,1439,1440],{},"canary",[178,1442,1443],{},"release",[174,1445,1446,1447,1449,1450,1452,1453,1456],{},"Setting any of them takes precedence over every auto-detected platform, so an operator's answer\nalways wins over an inferred one. ",[178,1448,1428],{}," is the field detection can never work out\non its own: a self-hosted staging deployment is a ",[178,1451,1437],{}," in every way that matters to the people\nlooking at it, and nothing about a plain ",[178,1454,1455],{},"node .output\u002Fserver\u002Findex.mjs"," says so.",[174,1458,1459,1460,308,1463,1466,1467,1470,1471,1474],{},"Individual fields can also be overridden through Nuxt's own public runtime config channel —\n",[178,1461,1462],{},"NUXT_PUBLIC_BUILD_INFO_COMMIT",[178,1464,1465],{},"NUXT_PUBLIC_BUILD_INFO_BRANCH",", and so on — which applies before\nthe server's own pass and needs no rebuild. There is no ",[178,1468,1469],{},"_SHORT_COMMIT"," variant: the dashboard\nderives the abbreviated form from ",[178,1472,1473],{},"commit"," wherever it is displayed, rather than declaring it as\nits own field that could drift from the commit it abbreviates.",[174,1476,1477,1478,1481],{},"A prerendered route has no server left to ask, so on ",[178,1479,1480],{},"apps\u002Fmarketing"," the second pass runs while\nthe page is prerendered rather than while it is served. On Vercel that changes nothing: the build\nalready resolved every field.",[183,1483,1485],{"id":1484},"documentation","Documentation",[195,1487,1488,1496],{},[198,1489,1490],{},[201,1491,1492,1494],{},[204,1493,433],{},[204,1495,436],{},[217,1497,1498],{},[201,1499,1500,1504],{},[222,1501,1502],{},[178,1503,291],{},[222,1505,1506,1507,1510,1511,1514],{},"Base path (default ",[178,1508,1509],{},"\u002F","; use ",[178,1512,1513],{},"\u002F\u003Crepository>\u002F"," on Pages)",[1516,1517,1518],"style",{},"html pre.shiki code .sBMFI, html code.shiki .sBMFI{--shiki-light:#E2931D;--shiki-default:#FFCB6B;--shiki-dark:#FFCB6B}html pre.shiki code .sfazB, html code.shiki .sfazB{--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":332,"searchDepth":353,"depth":353,"links":1520},[1521,1522,1523,1524,1525,1528,1529,1530,1531,1532],{"id":185,"depth":353,"text":186},{"id":424,"depth":353,"text":157},{"id":533,"depth":353,"text":534},{"id":630,"depth":353,"text":631},{"id":693,"depth":353,"text":38,"children":1526},[1527],{"id":880,"depth":364,"text":881},{"id":1059,"depth":353,"text":1060},{"id":1175,"depth":353,"text":1176},{"id":1201,"depth":353,"text":1202},{"id":1307,"depth":353,"text":1308},{"id":1484,"depth":353,"text":1485},"Agent Zero reads credentials and deployment policy exclusively from the environment. Endpoint URLs and credentials can never be named or embedded in .agent-zero.yml, so untrusted repository policy cannot redirect a secret.","md",null,{},true,{"title":84,"description":1533},"RGXopcOw1YME3tMjxw2-Tv_E8SveK5s7fsqQPSzWvuo",[1541,1542],{"title":80,"path":81,"stem":82,"description":332,"children":-1},{"title":94,"path":95,"stem":96,"description":1543,"children":-1},"Agent Zero is a dependency-directed monorepo managed with Turborepo and aube. Workspaces live under apps\u002F* and packages\u002F* (declared in pnpm-workspace.yaml).",1787482151330]