# ============================================================================ # Hermy HQ — environment template # ---------------------------------------------------------------------------- # Copy this file to `.env` and fill in your own values: # cp .env.example .env # # NEVER commit your real .env. The values below are FAKE placeholders — replace # every one of them. When you deploy, set the same vars in your host (Vercel → # Project → Settings → Environment Variables). # ============================================================================ # ─── REQUIRED · Core ───────────────────────────────────────────── # The dashboard will not run without these. # Postgres connection string. This same database is the message bus shared # with your Hermes bridge. Get one from Neon, Prisma Postgres, Supabase, or # Vercel Postgres. Keep sslmode=require for hosted databases. DATABASE_URL="postgresql://user:pass@host:5432/db?sslmode=require" # Same Postgres URL again (some tooling reads POSTGRES_URL). Usually identical # to DATABASE_URL. POSTGRES_URL="postgresql://user:pass@host:5432/db?sslmode=require" # Public URL of the site. Use http://localhost:3000 locally, and your real # domain in production (e.g. https://your-app.vercel.app). NEXTAUTH_URL="http://localhost:3000" # Secret used to sign NextAuth sessions. Generate one with: # openssl rand -base64 32 NEXTAUTH_SECRET="your-generated-secret" # Google OAuth credentials for login. Create an OAuth 2.0 Client (type: Web) # at https://console.cloud.google.com/apis/credentials and add the redirect # URI: /api/auth/callback/google GOOGLE_CLIENT_ID="xxxxxxxxxxxx.apps.googleusercontent.com" GOOGLE_CLIENT_SECRET="your-google-client-secret" # Comma-separated allowlist of emails permitted to sign in. Anyone else is # rejected even with a valid Google account. ALLOWED_EMAILS="you@example.com,teammate@example.com" # Your display name, shown in the dashboard UI. Public (NEXT_PUBLIC_). NEXT_PUBLIC_OWNER_NAME="Owner" # Public base URL of the site. Usually the same as NEXTAUTH_URL. Public. NEXT_PUBLIC_BASE_URL="http://localhost:3000" # ─── Hermes / bridge ───────────────────────────────────────────── # How the website coordinates with your local Hermes agent via the bridge. # The bridge (hermes-bridge/) reads HERMES_* and DATABASE_URL on your machine; # the website reads the shared ones below for scheduling and internal calls. # Kanban board slug the bridge mirrors into HermesTask. HERMES_BOARD="default" # Path to the `hermes` CLI on the bridge machine, if it is not already on PATH. HERMES_BIN="hermes" # Path to your Hermes memory-wiki root (git-tracked markdown) that the bridge # mirrors into HermesMemory. Set on the bridge machine. HERMES_WIKI="/path/to/hermes/wiki" # Hour of day (0-23, local time) to generate the Chief-of-Staff daily brief. BRIEF_HOUR="7" # Shared secret required by internal API routes (agent bus, bridge callbacks). # Generate with: openssl rand -hex 32 INTERNAL_API_SECRET="your-internal-api-secret" # Shared secret required by scheduled/cron endpoints so only your scheduler can # trigger them. Generate with: openssl rand -hex 32 CRON_SECRET="your-cron-secret" # ─── OPTIONAL · AI providers ───────────────────────────────────── # Only needed for features that call an LLM (briefs, scoring, content). Leave # blank to disable those features. # OpenAI API key — https://platform.openai.com/api-keys OPENAI_API_KEY="sk-xxxxx" # OpenRouter API key (multi-model gateway) — https://openrouter.ai/keys OPENROUTER_API_KEY="sk-or-xxxxx" # xAI (Grok) API key — https://console.x.ai XAI_API_KEY="xai-xxxxx" # Brave Search API key, used for web lookups — https://brave.com/search/api BRAVE_API_KEY="your-brave-api-key" # ─── OPTIONAL · YouTube ────────────────────────────────────────── # Only needed for the YouTube idea/script features. Get a key from the Google # Cloud console (enable "YouTube Data API v3"). YOUTUBE_API_KEY="your-youtube-api-key" # The channel ID you want to pull stats/videos for (starts with UC...). YOUTUBE_CHANNEL_ID="UCxxxxxxxxxxxxxxxxxxxxxx" # ─── OPTIONAL · X / Twitter ────────────────────────────────────── # Only needed for Content OS metrics. Create an app at # https://developer.twitter.com and copy the Bearer token. TWITTER_BEARER_TOKEN="your-twitter-bearer-token" # ─── OPTIONAL · Notion ─────────────────────────────────────────── # Only needed if you sync clients/data from Notion. Create an integration at # https://www.notion.so/my-integrations and share the relevant pages with it. NOTION_API_KEY="secret_xxxxx" # ─── OPTIONAL · Client Pulse ───────────────────────────────────── # The Client Pulse board reads client-health data from your Postgres. This # template ships the dashboard + API only — wire up your own ingestion (a cron, # a bot, a webhook) to populate it. Skip this block if you don't use the board. # Admin secret for the Client Pulse admin/map-chat routes (falls back to CRON_SECRET). CLIENT_PULSE_ADMIN_SECRET="your-client-pulse-admin-secret" # ─── OPTIONAL · Trading / Watchlist Radar ──────────────────────── # Only needed if you use the trading-related widgets. Leave blank otherwise. # A public wallet address to display balances/positions for (read-only). HL_WALLET="0xyour-wallet-address"