# Handler configuration — copy to .env and fill in. Never commit real secrets. # Database. SQLite fallback (single-node) or Postgres (centralized, default for real deploys). # SQLite: sqlite:////absolute/path/to/handler.db # Postgres: postgresql+psycopg://user:pass@host:5432/handler DATABASE_URL=sqlite:////var/lib/handler/handler.db # Single global bearer token gating every API route. Required for the API to start. AUTH_TOKEN=change-me-to-a-long-random-string # Optional higher-trust token gating PUT /shared/context/:key. # Falls back to AUTH_TOKEN if unset. # SHARED_CONTEXT_WRITE_TOKEN= # Optional generic webhook target for the Notification hook (ntfy, Pushover, Slack, ...). # Fully bring-your-own; the Notification hook is a no-op when unset. # WEBHOOK_URL=https://ntfy.sh/my-topic # Base directory under which per-project roots and agent worktrees live (isolation). PROJECTS_ROOT=/var/lib/handler/projects # Binary overrides (defaults shown). Point at fakes in tests/CI. # CLAUDE_BIN=claude # MISE_BIN=mise # TMUX_BIN=tmux # FORGE_BIN=forge # GIT_BIN=git # Phase 2 (forge integration). Pin the forge version your base image installs; spawn # verifies the injected forge matches and warns on drift. Leave unset to skip the check. # FORGE_VERSION=1.2.3 # Branches a direct `git push` may not reach without a standing approval (comma-separated). # Closes the "merge locally, push to main" path around the forge-merge approval gate. # PROTECTED_BRANCHES=main,master # Per-project credentials are NOT set here — they live on each project's `credential_ref` # as a POINTER (env:VAR / file:/path / cmd:...), resolved and injected only at spawn. # The database never stores the raw token. Example, when registering a project: # credential_ref = "env:LEEWORKS_TOKEN" (then export LEEWORKS_TOKEN where the control # layer runs; it's injected as FORGE_TOKEN + # the host-specific var, e.g. GITHUB_TOKEN)